Royce Williams

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = probably stole you from follows of someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers with the heat of 400B suns

❤️:⚛👨‍👩‍👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!

Royce Williams boosted:
2025-05-31

A different take on the CISO / Cybersecurity Leader Job Description.

philvenables.com/post/ciso---c

Royce Williams boosted:
2025-05-31

I've heard of Pink Tax, but Linux Tax?
The free OS is $169 more than the "Pro" Proprietary OS.
#Linux #Dell

Operating System A
Which operating system is right for you?
Dell Technologies recommends Windows 11 Pro for business
Warranty support options vary by operating system: Dell offers support plans for businesses with Windows Pro and support plans for
personal use with Windows Home.
Windows 11 Home, Copilot+ PC @® -$229.00
Windows 11 Pro, Copilot+ PC @® -$169.00
Ubuntu® Linux® 24.04 LTS Selected
Royce Williams boosted:
Patrick C Miller :donor:patrickcmiller@infosec.exchange
2025-05-31
2025-05-31

"In writing, your audience is one single reader. I have found that sometimes it helps to pick out one person—a real person you know, or an imagined person and write to that one."

-- John Steinbeck
(via @adamshand)

2025-05-31

TIL that Pure Storage issues YubiKeys branded with their logo!

(eBay, not my listing:)

ebay.com/itm/135898756327

Interesting: Just over the side of the logo, the phrase "NO NFC" is seen (not sure if an add-on label, or part of the logo). NFC-enabled keys ship with NFC disabled by default until first power-up (and can be re-disabled in ykman -R / --restrict option):

yubico.com/getting-started/

... so I'm not sure if this means NFC is permanently disabled, but it seems likely. Will update when I get one.

#YubiKey

Closeup of YubiKey in a transparent antistatic bag. Key is oriented "portrait", angled away. Through the bag, the QR-like code, the serial, the "FIPS" label, and the PureStorage logo can be seen.The Pure Storage logo - an orange hexagon as if drawn with a very thick line, with soft corners, and with a break in the lower-right, as if that side had been shortened but leaving the bottom each horizontal. The effect is like a very fat P.
2025-05-31

@simon

Hey, I know that you recently introduced a "pay a little to get less" subscription model. I have a value-add suggestion (if it doesn't already exist?)

As I explore the LLM space, I often find myself asking "what would Simon use?" So if I had my druthers, your subscription would include a living, opinionated "best model / approach for X" table -- with diffs published as an RSS feed or a simple, dedicated repo -- that matches your current opinion as it evolves over time.

Ideally, this would be published live as it happens, rather than waiting until the end of the month.

And I understand that the table would need a few fields to capture the nuance, such as size of model, affordability, local vs remote, etc.

But boy howdy would I mash the subscribe button for that (if I wasn't already - I just fixed that gap -- and, dear other readers, if you want to efficiently grow your understanding of LLMs ... so should you!)

Royce Williams boosted:
2025-05-31

Projects left undone

What's the attainable, practical and generous thing you haven't done yet? What will it take for it to become a priority?

seths.blog/2025/05/projects-le

Royce Williams boosted:

For my Security Fest talk next week I'll be releasing a new tool to help automate non-distributed hashcat workflows, allowing people to chain multiple attacks with no downtime.

Keep your eyes peeled!

Royce Williams boosted:
Jason Lefkowitzjalefkowit@vmst.io
2025-05-30

“Stop trying to fix the user. It’s not the user’s fault if they click on a link and it infects their system. It’s not their fault if they plug in a strange USB drive or ignore a warning message that they can’t understand. It’s not even their fault if they get fooled by a look-alike bank website and lose their money. The problem is that we’ve designed these systems to be so insecure that regular, nontechnical people can’t use them with confidence. We’re using security awareness campaigns to cover up bad system design.”

schneier.com/blog/archives/202

2025-05-30

@Alice I feel like you are addressing the sharks, like some kind of aquatic Pied Piper. Maybe that's how Sharknado started?

Royce Williams boosted:
2025-05-30

The more mental energy you expend parsing a programming language's syntax, the less you have available for parsing a program's logic—or creating it yourself. This is why core fluency is so important; it frees up your own compute cycles for more important work.

It's also another reason why "vibe coding" is so toxic. It robs you of the opportunity to gain that fluency.

Royce Williams boosted:
2025-05-30

CMIYC (contest.korelogic.com/) will not make it to DEF CON this year. passwordvillage.org/ will be there! We intend to do a contest later this year.

2025-05-29

@evedazzle Oh no!

Anyone know why Fakespot is shutting down? No mention on the main Mozilla blog.

fakespot.com/

Edit: I was wrong -- they just titled the post super vaguely.

blog.mozilla.org/en/mozilla/bu

We acquired Fakespot in 2023 to help people navigate unreliable product reviews using AI and privacy-first tech. While the idea resonated, it didn’t fit a model we could sustain.

Fakespot

Important Update: Fakespot will shut down on July 1, 2025.

On July 1, you will no longer be able to use Fakespot. Thanks for supporting our
journey.

Learn how to uninstall: (link to Chrome Web Store KB article)
Button: Close this message
Royce Williams boosted:
2025-05-29

@RuthMalan reminds me of this Jens Rasmussen dynamic safety model diagram I’m always on about

2025-05-29

@drahardja It's all about making leverage possible close to the receptacle!

2025-05-29

@drahardja

This made me so mad that I came up with a way to unplug from inaccessible receptacles (but you have to have enough headroom/space for the unplugging to actually happen):

diy.stackexchange.com/question

Took some heat for it from the DIYers ("just disassembled the bookshelf noob") ... but it has saved my bacon a few times.

Royce Williams boosted:
2025-05-29

Massive lit review found these four affordances that help teams create long term achievement. This is developer thriving!
- learning culture
- sense of belonging
- self-efficacy and motivation
- sense of agency @grimalkina

2025-05-29

@mhoye Single pass:

awk '{c[$0]++} END {for (line in c) print c[line], line}'

(well, at least one fewer pass)

2025-05-29

@vees Miniflux featureset lists "Provides a regex filter to include or exclude articles based on specific patterns". In the Mastodon filter featureset, there are "filter action" options ""hide with a warning" or "hide completely". I assume that Miniflux implements regex as "hide completely"; does it support "hide with a warning" ?

2025-05-29

@vees Intriguing. Does it support a "show why it was filtered, and optionally view it anyway" model, similar to Mastodon clients? Or is the filtering silent?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst