Hon1nbo

Paid to take selfies in other people's vaults. I don't know if it's real. views my own. typos I know
profile art: twitter\@3rdPerson_IZ & twitter\@marpaparp

Am I crazy? Did something change recently and it's become socially acceptable for corporate sales to call an IC's personal phones?

I've had multiple companies do this over the past few months.

It's an exceptionally bad look for you to use an IC's personal number. Save personal numbers for people who golf with you for sales pitches.

Been a while since I went making memes, even longer since they involved Thomas the Tank Engine

Meme of USA Vice President JD Vance as Henry the Engine from Thomas the Tank Engine. Vance is being bricked up behind a wall because he is afraid of Elon the Mayor, who is facing him on a ladder flanked by two lackeys.
Text reads: "Once, an engine attached to a Trump was afraid of Elon the mayor.. It went into a tunnel and squeaked through its funnel and wouldn't come out again" - Narrator
Hon1nbo boosted:
Andy Thompson (rainmaker)Andy_Thompson@infosec.exchange
2025-02-19

If anyone is interested, later this morning I'll be giving a presentation on social engineering and psychological manipulation. It's a collection of stories from my friends at the Dallas Hackers Association.

linkedin.com/events/socialengi

Hon1nbo boosted:
2025-01-22

I don't expect a lot of victories at the federal level fighting government surveillance in the coming years, so I am going to enjoy the hell out of every one we get.

eff.org/deeplinks/2025/01/vict

Fresh Electroharmonic 12ax7 tubes? Check
Newly arrived album for glass animals? Check
Headphones? Check
New SSD? Check

Time to reinstall my desktop.

It's good to practice disaster recovery on a known cadence... This time it wasn't practice!

Interior room. Focus is on a Turntable and tube preamplified to its left. Tube amplifier has 3 small tubes protruding out the top. Turntable has a pink and white LP album spinning and the strobe light on.

@phreakmonkey @foone that was a great talk, and one of the first bits of conference published research I ever saw when I was getting started.

@kkarhan @foone what makes it a non-starter?

No one said this would be trivial. No one said you had to shoehorn it into the existing HID protocol

HVTs often remove legacy or basic protocols from systems when they don't need them, or implement detections for their activated presence.

@kkarhan @foone certificate based authentication of hardware is not "security by obscurity"

And the attacks I described to call it security by obscurity would require any attempt to prevent them or hide them in the first place.

But key authentication of a keyboard would actually be useful if implemented meaningfully (key revoked/zero upon device tampering, hmac on keystrokes to mitigate mitm after initial key authentication, actually disabling legacy HID and USB support, etc)

@foone hmmm so more a manufacturer choice for keyboard makers geared towards enthusiasts I guess. Lots of boutique and midsized keyboard makers these days.
I haven't poke current trends for keyboard hardware in some time since I don't have that as part of my job anymore.

But authenticatable keyboards would be killer.

@foone what would make mechanical keyboards more "trivial?"
the typical size having more hardware space? the propensity for mechanical keyboard users to bring their own?

when we tampered with keyboards we typically hit your standard "came with the workstation" dell keyboards etc.

@SwiftOnSecurity you need these for your Lockheed Martin Pride Socks

Screenshot of an Instagram post showing off the Transparent Ugh boots. The boots are facing to the left, with bare feet clearly visible. The person wearing them has black leggings.
The text on the Instagram post reads "Give me one good reason not to purchase these Ugh boots. That's all I need. They're on clearance."
It is posted by Instagram user laura_matthews02

@turao oh, these electricians have worked with me for years I'm not worried.

Engineer on the other hand I have no idea what's up and we're still sorting it out.

Fun times installing solar.
Electricians forgot to wire the disconnect, so I spent 1.5 days debugging my Tigo RSDs+Optimizers
And the engineer screwed up and didn't have the CAD for the carport correct, so we have to move the whole array over because it's too close to the edge of the carport.

FML.... Or not, I got the system working at least...

View of electrical box mounted to the side of a purple-painted carport. The box is open, and tools are spread around the carport roof. The wiring inside the box is red, black, and green. The red and black wires are all unterminated and hanging free rather than wired to the switch block in the middle.Several solar panels are mounted to the white sheet metal roof of a carport, adjacent to a house's traditional shingle roof. The solar panels are mounted towards the edge of the carport on one side.

Beautiful day for snowboarding

Photograph taken on the snow of a mountain with trees and multiple ski routes. Mountains in distance are not full of snow, indicating it may be the off season.

This brightened my dreary time boarding a flight after a long day

What were the odds I'd see this card again?

@corbden defcon.social/@corbden/1135965

@corbden aha! Found it.

@corbden NGL, I never thought I'd see one of these again that wasn't my own.

Gotta see if I can find a photo of the card or any of us now; we were pretty hammered a chunk of the time due to the tamper evident competition since it was actually competitive that year and people wouldn't stop dropping us beer

@corbden the number just went to a cash prepaid phone, and at 11pm local time the voicemail was set to the primary fake party address but sometimes it was actually answered for funzies.

There were a *lot* of voicemails looking for the party, followed by voicemails seeking revenge and/or to buy us a beer for the prank.

@corbden I was with the person handing these out! I still have mine somewhere. They had asked if they could use our table in the competition area to help hand them out.

Some people were sent to circus, others elsewhere.

Firsy DefCon, but second prank to be involved in (even if only tangentially).

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst