Daniel Cuthbert

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

2025-04-09

By far the best episode of “between two nerds”: podcasts.apple.com/gb/podcast/

I couldn’t agree with both of them anymore. The forced scarcity of bugs and misconception that so many in this industry have about the use of ohdayz is baffling. Both Tom and The Gruqg really do spell it out

2025-04-09

@wirepair thanks. Lesson learned. These things go missing too easily if you don’t tie them to a block of wood like a petrol station toilet key

2025-04-08

Aaaand found that missing yubikey so I could finally auth to this.

2024-11-08

@kurtseifried I do agree and seeing the impact ECH has on those trying to subvert and control, it makes me wonder why more don't enable it.

I'm now making it my mission to get it into the ASVS so we can push this more, that's for sure

Daniel Cuthbert boosted:
2024-11-08

You can bypass path-based WAF restrictions by appending raw/unencoded non-printable and extended-ASCII characters like \x09 (Spring), \xA0 (Express), and \x1C-1F (Flask):

2024-11-08

I guess we now know that Encrypted Client Hello (ECH) technology works, especially when it pisses off the FSB and other Russians who like controlling the narrative

Roskomnadzor it took the decision after Cloudflare enabled ECH by default for customer accounts in October.

The agency said ECH was being used by Russian citizens to bypass its censorship measures and access restricted resources.

So if it's annoying the russkis that much, I know it's good and as such now have added it as a PR for 5.0

github.com/OWASP/ASVS/pull/235

If it annoys them, I like it and think this is mosdef an addition we need to enable all to help push privacy.

2024-11-07

PR merged after 72 hours of mega work, if anyone fancies seeing/commenting, i'd love the insights

github.com/OWASP/ASVS/blob/mas

2024-11-05

For those who have bandwidth, there are a load of issues already present on this new branch, namely:

github.com/OWASP/ASVS/issues

2024-11-05

Soooooo, our PR was merged into 5.0 and there's still a lot of work needed here, but more importantly, there's comments from the community that would help us too.

github.com/OWASP/ASVS/blob/mas

If you see an issue, raise an issue and help us make this usable for all.

Thank you

2024-11-04

@SiteRelEnby the struggle real. Today is crunch day

2024-11-03

That yearly decision process where I debate profusely if I renew the .io domain I’ve yet to use but costs 50 a year….

2024-11-02

Very interesting issue with Okta here, especially with the use of bcrypt

trust.okta.com/security-adviso

As Yan (@bcrypt) said

“reminder that the bcrypt hash function ignores input above a certain length! so if you do bcrypt(username || password) for some reason, a sufficiently long username will make it accept any password. to fix this you can sha256 the input first”

2024-11-01

It has taken a while but Mark Carney and I have just done a pull request to the OWASP ASVS 5.0 branch introducing major changes to V6 Cryptography

github.com/OWASP/ASVS/pull/221

It builds upon the work we’ve done to hopefully make apps more secure from a cryptographic perspective & we are sure will see a lot of good discourse from all involved

We’d love to hear your thoughts and comments, as it’s a community-driven standard and always has been

github.com/OWASP/ASVS/pull/221

2024-10-23

@cynicalsecurity @marasawr please anonymise and share

2024-10-22

Err, hmmm, I, just….

“It works by taking static screenshots that are constantly sent back to the API in real-time”

Said most malware writers who use multi-stage payloads to exfiltrate data out or an AI giant announcing their new feature

It’s hard to tell these days

2024-10-18

If you are going to own a high-profile target, maybe OPSEC should be a level above "skid"

#justsayin

2024-10-10

@Viss hell yes!!!! Not far but I’ll make the trip

2024-10-10

Benefits of country living is amazing red aurora in the skies with hardly any light pollution

2024-09-30

@vfxsup I’ve tried to stay away from drones for this exact reason

2024-09-30

Africa, as a continent has truly epic talent, it’s just you rarely hear about it.

Peter is a Kenyan hacker of note. Adding a custom ECU, he designed, to classic cars and a bloody good job at the same time. All designed around the @arduino with custom maps too. Make no mistake, what he’s done is off the scale, that’s coming from someone with classic Mercedes-Benz’s and who likes to tinker

youtu.be/TMDtOC3X2o4?si=-cLsoo

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst