WTF is happening on tcp:0? 2020 edition
tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk…
A few good cybersecurity companies
I spend a lot of time looking at cybersecurity solutions and companies, partly on request, and partly because it always fascinates me to see people are attempting to solve big problems.
On not being not-racist
An active problem needs an active opposing response, a passive response will always allow the aggressor to succeed in the end.
First principles
Simple is strong.
Respect is key.
Build it like you own it.
Don’t be valuable, create value.
Think like a hacker.
360-degree accountability.
Priority One: Insights into Submission and Payment Trends
2020: Chaos is a Ladder
As 2020 comes to a close, I’ve started to see summaries of the year
To err is human - Kerckhoffs' Principle in Software Transparency
Shannon and Kerckhoff were pioneers of disclosure thinking — They understood the concept of “build it like it’s broken”. This was especially true in WWII cryptography, but it’s becoming increasingly clear in its relevance to the 'peacetime' software that we use today.
Hacking styles
Broadly, there are two things that come into play when it comes to the style a person applies to hacking: The level of experience, and the overall wiring of the hacker.
A message to folks providing "free testing" at the moment
TLDR: If you’re performing any active, unsanctioned testing on healthcare systems: Please stop it. Don’t make their job any harder than it is right now.
COVID-19/Coronavirus - What are the bad guys up to?
As expected, the covid19 pandemic has out brought some of the Internet’s worst. I’ve been working with several groups to information share and fight back on this stuff, including the COVID-19 CTI Group.
Changes
You know that awkward thing at the moment when you see someone and go to shake their hand or hug