<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-03-25T09:19:48Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Lee Holmes :donor:</title>
  <author>
    <name>Lee Holmes :donor:</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub10nrg25d2v23mxukzvqtptr25cp6dlsxzwunm7jnsd5cavkmsmc8svyvymp.rss" />
  <link href="https://yabu.me/npub10nrg25d2v23mxukzvqtptr25cp6dlsxzwunm7jnsd5cavkmsmc8svyvymp" />
  <id>https://yabu.me/npub10nrg25d2v23mxukzvqtptr25cp6dlsxzwunm7jnsd5cavkmsmc8svyvymp</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/310/112/408/973/051/original/f64b53d4de8b6e4d.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/310/112/408/973/051/original/f64b53d4de8b6e4d.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqs22u0c4qsnf3zfyt8qe54rvuulsm0fvza7ldaf76ve676x3mm55rqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7glnan5</id>
    
      <title type="html">THE BLOOMSCROLLING WILL CONTINUE UNTIL MORALE IMPROVES ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs22u0c4qsnf3zfyt8qe54rvuulsm0fvza7ldaf76ve676x3mm55rqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7glnan5" />
    <content type="html">
      THE BLOOMSCROLLING WILL CONTINUE UNTIL MORALE IMPROVES&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/297/204/852/167/147/original/383af77551222f5b.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-26T19:49:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs85zuwsjtcag7jscwjt4pp6r352h5sjjr2ndkuqd642ln0ynm5a2czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7t5uxcg</id>
    
      <title type="html">This seems more likely to be an acquihire. I doubt they care ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs85zuwsjtcag7jscwjt4pp6r352h5sjjr2ndkuqd642ln0ynm5a2czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7t5uxcg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszd29nt3qa4crs8sajh0uzfy50raevp4utkyv0yf52h3enwqvzdrg2zurda&#39;&gt;nevent1q…urda&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This seems more likely to be an acquihire. I doubt they care about a social network for bots. But somebody that can make a viral AI one is definitely a better hire than a rando that stuffed their resume with the right keywords :)
    </content>
    <updated>2026-03-11T00:41:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs26ae6mpr7ur84n3mg4vkkl270a6tpl8uha0yeylqz3mzw5nc70fczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7yejknl</id>
    
      <title type="html">Whoa, this post is doing some numbers on social media! ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs26ae6mpr7ur84n3mg4vkkl270a6tpl8uha0yeylqz3mzw5nc70fczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7yejknl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst9rqjwg4djjv496kaerylhuwz5qljnuqy26qm3gt8acxvkj23m7qp7exg2&#39;&gt;nevent1q…exg2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Whoa, this post is doing some numbers on social media! &lt;a href=&#34;https://www.leeholmes.com/projects/mastodon-engagement-viewer/?url=https%3A%2F%2Finfosec.exchange%2Fdeck%2F%40jerry%2F116121792535418308&#34;&gt;https://www.leeholmes.com/projects/mastodon-engagement-viewer/?url=https%3A%2F%2Finfosec.exchange%2Fdeck%2F%40jerry%2F116121792535418308&lt;/a&gt;
    </content>
    <updated>2026-02-23T23:04:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxe9rs99ssgj7clle7m9v0lfk0qxx3v438ej53hs6nh5qd9ejt8kszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q75yhz8l</id>
    
      <title type="html">Good update to the MSRC leaderboards now that everything is in ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxe9rs99ssgj7clle7m9v0lfk0qxx3v438ej53hs6nh5qd9ejt8kszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q75yhz8l" />
    <content type="html">
      Good update to the MSRC leaderboards now that everything is in scope by default: &lt;a href=&#34;https://www.microsoft.com/en-us/msrc/blog/2026/02/points-to-payouts-evolution-of-microsoft-security-researcher-leaderboard&#34;&gt;https://www.microsoft.com/en-us/msrc/blog/2026/02/points-to-payouts-evolution-of-microsoft-security-researcher-leaderboard&lt;/a&gt;
    </content>
    <updated>2026-02-06T19:14:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrjgaaqn8ndew8e2xsulcyqm0ccrtf5anapcqdqnn6lshz4mjnakqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7khse94</id>
    
      <title type="html">Congrats, Brian. You deserve it.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrjgaaqn8ndew8e2xsulcyqm0ccrtf5anapcqdqnn6lshz4mjnakqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7khse94" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy4sqc0rhhrkqzgwe5gnanp224am39jxxh68rne8xyngmz8nytmhccdj69s&#39;&gt;nevent1q…j69s&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Congrats, Brian. You deserve it.
    </content>
    <updated>2026-02-06T17:06:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsq7uur7egdc34eapfs95hl8c7acsn7d3sqznvytd07nk87v9ggwdszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7ft6643</id>
    
      <title type="html">Updated pyco to work even better on mobile (with a virtual ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq7uur7egdc34eapfs95hl8c7acsn7d3sqznvytd07nk87v9ggwdszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7ft6643" />
    <content type="html">
      Updated pyco to work even better on mobile (with a virtual keyboard and function browser)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.leeholmes.com/projects/pyco/&#34;&gt;https://www.leeholmes.com/projects/pyco/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;If you have any reason to use any other calculator, let me know :)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/008/560/577/789/096/original/444f7d18cc0d0389.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-02-03T20:23:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9d570mglt4mxqjvt2je5g83ysdmsl852lyayzxjqje5euvk554gczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7dksgd8</id>
    
      <title type="html">This is a super thought-provoking read: &amp;#34;your password ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9d570mglt4mxqjvt2je5g83ysdmsl852lyayzxjqje5euvk554gczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7dksgd8" />
    <content type="html">
      This is a super thought-provoking read: &amp;#34;your password doesn&amp;#39;t matter&amp;#34;: &lt;a href=&#34;https://techcommunity.microsoft.com/blog/microsoft-entra-blog/your-paword-doesnt-matter/731984&#34;&gt;https://techcommunity.microsoft.com/blog/microsoft-entra-blog/your-paword-doesnt-matter/731984&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;It looks at all of the major failure cases of passwords, pointing out that only one password complexity choice (avoiding a password in the top 10) really influences those failure modes.&lt;br/&gt;&lt;br/&gt;The rest can only be addressed with MFA.
    </content>
    <updated>2026-01-12T17:24:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdy0av34xa5az09zljmm03gl3deup8z7lq79v40d24uunnvjjfmrgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q790d02y</id>
    
      <title type="html">I had a lot of fun writing a PowerShell module to expose the cdb ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdy0av34xa5az09zljmm03gl3deup8z7lq79v40d24uunnvjjfmrgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q790d02y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfgtxtdpuv820p2ywwmps4retwz0gr8kjwqx2u28wpmwl7cmk2rassm03x2&#39;&gt;nevent1q…03x2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I had a lot of fun writing a PowerShell module to expose the cdb engine into PowerShell itself so you could use the full features of the shell rather than be stuck in cdb&amp;#39;s implementation of one: &lt;a href=&#34;https://www.leeholmes.com/extracting-forensic-script-content-from-powershell-process-dumps/&#34;&gt;https://www.leeholmes.com/extracting-forensic-script-content-from-powershell-process-dumps/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Also, this other project hasn&amp;#39;t seen a lot of love recently, but I love the idea: a shell that exposes cdb information as structured data, letting you CD into stack traces, etc.: &lt;a href=&#34;https://github.com/microsoft/DbgShell&#34;&gt;https://github.com/microsoft/DbgShell&lt;/a&gt;
    </content>
    <updated>2025-11-28T18:10:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst7pm76r7yrnepnn9ngh6wd2ultr3ujh0fj5jgw7a3x02uu38w3mszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7xkwqm6</id>
    
      <title type="html">For a long time, Microsoft had a &amp;#34;frontline&amp;#34; program ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst7pm76r7yrnepnn9ngh6wd2ultr3ujh0fj5jgw7a3x02uu38w3mszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7xkwqm6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx9hffmfml83skyfejthsp89tmxuuq9r3v77l3c5yfykps8jtkjdc9ze42u&#39;&gt;nevent1q…e42u&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;For a long time, Microsoft had a &amp;#34;frontline&amp;#34; program where everybody promoted to a certain level spent a week on customer support. It for sure gives you empathy of what real people are dealing which, and it&amp;#39;s rarely what you think.
    </content>
    <updated>2025-11-24T23:37:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxy084nfzj0lxrcnmhz9zjnmy4zv0emprnrfv3f9njzvlt7je2kcszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7kw2agm</id>
    
      <title type="html">This is where evaluation frameworks that focus only on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxy084nfzj0lxrcnmhz9zjnmy4zv0emprnrfv3f9njzvlt7je2kcszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7kw2agm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2tw7wz6puuy48xvd44ch54vj3d9jvap2z3w8evc88vku4kthvl6sc88vxa&#39;&gt;nevent1q…8vxa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This is where evaluation frameworks that focus only on &amp;#34;likelihood&amp;#34; and &amp;#34;impact&amp;#34; struggle so much. Super high likelihood but low impact events (&amp;#34;A user gets their password phished therefore their insta gets hacked&amp;#34;) will always fall behind the low likelihood but super high impact scenarios (&amp;#34;Nation state inverts spacetime and takes over our company and all of our customers.&amp;#34;) Grounding these things in what you&amp;#39;ve observed can go a long way.
    </content>
    <updated>2025-10-07T23:51:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswh77jgap3sme9h84zx9ccppylc7pun88mnrv6eggstp277xfjfrqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q726sa47</id>
    
      <title type="html">This is my primary name confusion: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswh77jgap3sme9h84zx9ccppylc7pun88mnrv6eggstp277xfjfrqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q726sa47" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy5z8a59n9x2zc2vkyx76eqq5jyv8gagafd9qlvxwwycqyp3te9xq80xgcs&#39;&gt;nevent1q…xgcs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This is my primary name confusion: &lt;a href=&#34;https://www.amazon.com/Heal-Your-Gut-Supercharged-Food/dp/1743365616&#34;&gt;https://www.amazon.com/Heal-Your-Gut-Supercharged-Food/dp/1743365616&lt;/a&gt;
    </content>
    <updated>2025-09-24T20:12:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9phvg5klsvmaguv5sreetn3w2kmfglqvdlh37csgdmrla4ffx2zszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7t3k9nh</id>
    
      <title type="html">I haven&amp;#39;t used APK lab - was it giving reports, or were you ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9phvg5klsvmaguv5sreetn3w2kmfglqvdlh37csgdmrla4ffx2zszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7t3k9nh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvpv6dlf7scak0deluevwswf0tweztcl3l6ry5avxddrfllxuv9nssyupu6&#39;&gt;nevent1q…upu6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I haven&amp;#39;t used APK lab - was it giving reports, or were you using it to get the source and then later looking through the source and resources?
    </content>
    <updated>2025-09-04T22:45:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8pqsfcv57uhygwngf7gm5vgmafn4jrjvvekkucfqh79fvskyms9czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7duzh8l</id>
    
      <title type="html">OK, Mesh hackers @npub1dqd…8xy4 . Don&amp;#39;t disappoint. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8pqsfcv57uhygwngf7gm5vgmafn4jrjvvekkucfqh79fvskyms9czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7duzh8l" />
    <content type="html">
      OK, Mesh hackers &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dqdh3ta2uxg4wz5qf7h6j0qywrxryzcyjw4vhq0n0alu83d6mgnsxm8xy4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;DEF CON&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dqd…8xy4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; . Don&amp;#39;t disappoint.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/989/678/138/109/825/original/c4ae77eb47047083.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-07T21:48:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0vxe2n995pljylefqv4e40sd29v6f3fkzvc2k2cr2g0axfk5c0yszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7654ph7</id>
    
      <title type="html">Sometimes, both the machine and the human are doing mechanical ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0vxe2n995pljylefqv4e40sd29v6f3fkzvc2k2cr2g0axfk5c0yszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7654ph7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgccdx9drvdhq54nzu3tn3x0cehuw92gc6jh5zdmg3wwx97fn5nvqeavk66&#39;&gt;nevent1q…vk66&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Sometimes, both the machine and the human are doing mechanical work and it&amp;#39;s wonderful. I&amp;#39;ve had the pleasure of using several Curtas and even the simplest of calculations brings joy.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://youtu.be/P0cGjC62XRQ?t=265&#34;&gt;https://youtu.be/P0cGjC62XRQ?t=265&lt;/a&gt;
    </content>
    <updated>2025-07-11T20:01:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8vvqhcnaqctuj9yl6hqm7k2gep8dnmdchcmy3g60y7kc9kv4cegqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7v6cvpq</id>
    
      <title type="html">The security industry is made up of people from the security ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8vvqhcnaqctuj9yl6hqm7k2gep8dnmdchcmy3g60y7kc9kv4cegqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7v6cvpq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyrmxy04x96hst7e83mq0cfcpqd5nmkwac54dgmtqqvyfeyxz76eg9cecch&#39;&gt;nevent1q…ecch&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The security industry is made up of people from the security community, so it&amp;#39;s a weird distinction to make.
    </content>
    <updated>2025-07-03T19:04:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswzk4vtw8q4esurrn0ul895gxtptmd88v4nclaay84fqes94vlacczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7aqvgqj</id>
    
      <title type="html">Could be BS or could be video amplification! Here&amp;#39;s a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswzk4vtw8q4esurrn0ul895gxtptmd88v4nclaay84fqes94vlacczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7aqvgqj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs94qcd6swmcn8j33w2w82f0j7h5da4zmtppecf5k4juwv5mssv9mctujqy5&#39;&gt;nevent1q…jqy5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Could be BS or could be video amplification! Here&amp;#39;s a fantastic video from Steve Mould showing detecting pulse two ways (motion of the vein as well as color change in the face) that actually works.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://youtu.be/rEoc0YoALt0?t=504&#34;&gt;https://youtu.be/rEoc0YoALt0?t=504&lt;/a&gt;
    </content>
    <updated>2025-06-18T00:05:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswctpf729vx8xep4wyxm0zq6aw7stff7jfnp424dfh0ev0w6n0wwszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7exgz0m</id>
    
      <title type="html">I&amp;#39;m sure there&amp;#39;s something here, but I don&amp;#39;t have the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswctpf729vx8xep4wyxm0zq6aw7stff7jfnp424dfh0ev0w6n0wwszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7exgz0m" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfe59zs0wwle37w332wc06634es3mrkua3ndyx9lf9ea4wn3e6rmqxeyqfv&#39;&gt;nevent1q…yqfv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;m sure there&amp;#39;s something here, but I don&amp;#39;t have the patience to find it :)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/473/501/074/152/027/original/68ca177c0aeea792.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-08T17:57:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfe59zs0wwle37w332wc06634es3mrkua3ndyx9lf9ea4wn3e6rmqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7lqsewa</id>
    
      <title type="html">It makes me super uncomfortable that globbing in Bash can turn ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfe59zs0wwle37w332wc06634es3mrkua3ndyx9lf9ea4wn3e6rmqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7lqsewa" />
    <content type="html">
      It makes me super uncomfortable that globbing in Bash can turn into code execution. The fact that the name of a file can change the behavior of ls is scary. This also works for other commands that you tend to glob with, such as rm.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/473/365/560/779/121/original/e99ebbf9bf333d0f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-08T17:45:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrflm2dv3ehgf0y6uyjktleunnqzsl4cwhqpk9tauvehuc3crvclqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7zn70e2</id>
    
      <title type="html">I love finding &amp;#34;always done this way&amp;#34; things at work that ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrflm2dv3ehgf0y6uyjktleunnqzsl4cwhqpk9tauvehuc3crvclqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7zn70e2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx79v7phr5kgafaglfy0uu5g6z8mtljxapwp3x0qhs7zwxe4n2z8g5kd97j&#39;&gt;nevent1q…d97j&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I love finding &amp;#34;always done this way&amp;#34; things at work that are wasting time and then killing them :)
    </content>
    <updated>2025-04-23T22:34:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv0sgeudk0gs9h295hmzpucv87yar4x4nwkcvfghx37ejgwtdknkczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q79fa8a3</id>
    
      <title type="html">Accidentally unzipped an archive via Gnome into a directory ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv0sgeudk0gs9h295hmzpucv87yar4x4nwkcvfghx37ejgwtdknkczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q79fa8a3" />
    <content type="html">
      Accidentally unzipped an archive via Gnome into a directory called &amp;#34;~&amp;#34; in my home directory. I did not trust myself to delete it without renaming it first 😂
    </content>
    <updated>2025-04-21T01:42:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgqr7dujms208vgxw2p9wjxhhuuqv4ya8czlgd7qprd3puel747tczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7q6x5uc</id>
    
      <title type="html">I wonder how FEDRAMP&amp;#39;s vulnerability scanning and reporting ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgqr7dujms208vgxw2p9wjxhhuuqv4ya8czlgd7qprd3puel747tczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7q6x5uc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfn5z6dk06tnekdnyrkqk8vlckht8gls9f8nkhw48j73nqdyayxaq40x6kt&#39;&gt;nevent1q…x6kt&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I wonder how FEDRAMP&amp;#39;s vulnerability scanning and reporting requirement feels about this. &lt;a href=&#34;https://www.fedramp.gov/assets/resources/documents/CSP_Vulnerability_Scanning_Requirements.pdf&#34;&gt;https://www.fedramp.gov/assets/resources/documents/CSP_Vulnerability_Scanning_Requirements.pdf&lt;/a&gt;
    </content>
    <updated>2025-04-15T20:26:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdwsu4v4sh7zrt9kr0l84en9tv0ukm4nvqad3amvvfqkqz0mz5g4qzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7cw5f47</id>
    
      <title type="html">We need to stop being so binary about VPN shaming in the same way ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdwsu4v4sh7zrt9kr0l84en9tv0ukm4nvqad3amvvfqkqz0mz5g4qzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7cw5f47" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswd8yxaq9smqqchjwzl6ezdcw9ef7vkmc7fa3wkag7l5ur9vaa3hcqumwrx&#39;&gt;nevent1q…mwrx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;We need to stop being so binary about VPN shaming in the same way that we realized we needed to be less binary about SMS-based 2FA shaming.&lt;br/&gt;&lt;br/&gt;The Wall of Sheep at DEF CON still claims victims.
    </content>
    <updated>2025-03-18T00:45:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx2vre43lmdrp2lmxn6ffgwm3ac968p9uq9pps3l7kfuueyrzn75gzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7stzp9w</id>
    
      <title type="html">The last music player generation to have a gyroscopic effect when ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx2vre43lmdrp2lmxn6ffgwm3ac968p9uq9pps3l7kfuueyrzn75gzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7stzp9w" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0gajvgfsdf6u8uapjav5p5z0k29l2sxtzy86rn4n4p6ejx2p562clhdaq8&#39;&gt;nevent1q…daq8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The last music player generation to have a gyroscopic effect when you moved it.
    </content>
    <updated>2025-03-06T08:07:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9ueq4tqh4hv9ygrfek9gpkxh8t753w8205yh6tud355h0c2qd9xgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q737wrnr</id>
    
      <title type="html">The whole caliber of VPN discourse is so stupid. Dozens of times ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9ueq4tqh4hv9ygrfek9gpkxh8t753w8205yh6tud355h0c2qd9xgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q737wrnr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs90su3mml46qkmlw9w5kxlvsfdfw4fdndtguwlkwja7rxk9kcn2hced8828&#39;&gt;nevent1q…8828&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The whole caliber of VPN discourse is so stupid. Dozens of times a year - our industry takes something the public generally considers safe, finds a huge flaw in it, gives it a name, and then shames users for not doing more to protect themselves. Or worse, takes something that is not a real problem (*cough juice jacking*) and shames them yet again.&lt;br/&gt;&lt;br/&gt;But somehow VPNs are the thing we&amp;#39;re going to start being grown-ups about, throw around words like &amp;#34;depending on your threat model&amp;#34;, and then shame users for falling for security theater?&lt;br/&gt;&lt;br/&gt;And then we wonder why nobody listens to us.
    </content>
    <updated>2025-02-12T18:47:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfzvwcvyzuu8qdwqd83vx7fsucxas7wmlxddreqzmzx4rcuzt9ajczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7jd7r56</id>
    
      <title type="html">Pebble Watches are coming back! ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfzvwcvyzuu8qdwqd83vx7fsucxas7wmlxddreqzmzx4rcuzt9ajczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7jd7r56" />
    <content type="html">
      Pebble Watches are coming back! &lt;a href=&#34;https://ericmigi.com/blog/why-were-bringing-pebble-back&#34;&gt;https://ericmigi.com/blog/why-were-bringing-pebble-back&lt;/a&gt;
    </content>
    <updated>2025-01-28T01:29:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgwv6lzrulf906gxvlqga4kxnr563f2s02typtpt5nvqv3z6kfkjgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7ae2ask</id>
    
      <title>Nostr event nevent1qqsgwv6lzrulf906gxvlqga4kxnr563f2s02typtpt5nvqv3z6kfkjgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7ae2ask</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgwv6lzrulf906gxvlqga4kxnr563f2s02typtpt5nvqv3z6kfkjgzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7ae2ask" />
    <content type="html">
       &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/556/997/442/879/267/original/c40f1b388b4ce825.gif&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-11-27T21:19:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstrg25mln8h5k6a5stjv7hl2ftl7j5dhdqjsm7xuj7yu02qd7ahjczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7jfdkfd</id>
    
      <title type="html">Nice try, robot. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstrg25mln8h5k6a5stjv7hl2ftl7j5dhdqjsm7xuj7yu02qd7ahjczyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7jfdkfd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs03dxd6dxcscwvy6m07epqgxjrq5ktw3l3kvmmfg0m4s3wqxqpdsgh732mx&#39;&gt;nevent1q…32mx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Nice try, robot.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/556/331/489/407/594/original/ecfa395e8f2345fc.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-11-27T18:28:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswe3lcxatwkx90evgquyf4ya4n9kd8p5nvh2vxapr66dhqlvm0v9czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7lvvxj5</id>
    
      <title type="html">Also interesting at scale is that when patch availability is made ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswe3lcxatwkx90evgquyf4ya4n9kd8p5nvh2vxapr66dhqlvm0v9czyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7lvvxj5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz7t0wr73t0fy9y6xm7z0lprgfytxr8x4ugeqg306f3qchdkqj7rc8lwzld&#39;&gt;nevent1q…wzld&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also interesting at scale is that when patch availability is made more predictable (rather than releasing randomly throughout the month), companies are better able to deploy them quickly. Hence Patch Tuesday: &lt;a href=&#34;https://msrc.microsoft.com/blog/2023/11/reflecting-on-20-years-of-patch-tuesday/&#34;&gt;https://msrc.microsoft.com/blog/2023/11/reflecting-on-20-years-of-patch-tuesday/&lt;/a&gt;
    </content>
    <updated>2024-11-20T17:04:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9nnj03jk2c5lh0y20qem98e0t2f5jzk2kjz8w5and53j7l0uru2gzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7y4p7em</id>
    
      <title type="html">This is very interesting. What do you think is causing the jumps ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9nnj03jk2c5lh0y20qem98e0t2f5jzk2kjz8w5and53j7l0uru2gzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7y4p7em" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2yk5h9swmty6scrudazzuexf640cly4nzzr36xnr0qzv5vku90qqnysa07&#39;&gt;nevent1q…sa07&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This is very interesting. What do you think is causing the jumps with Apache, Apple, and F5?&lt;br/&gt;&lt;br/&gt;Also, the shape of the blue graph is primarily driven by a the defender company&amp;#39;s operational practices right? Once a patch is available, a company could technically enforce immediate patching of all systems if they were interested and capable.
    </content>
    <updated>2024-11-20T16:23:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfrq8upwkd5u82w2akmkpn02z73w736du78fz832ylyva3ng4k5fqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7rawgq5</id>
    
      <title type="html">Whoa, that&amp;#39;s easy! -----BEGIN MASTODON E2EE MESSAGE----- ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfrq8upwkd5u82w2akmkpn02z73w736du78fz832ylyva3ng4k5fqzyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7rawgq5" />
    <content type="html">
      Whoa, that&amp;#39;s easy!&lt;br/&gt;&lt;br/&gt;-----BEGIN MASTODON E2EE MESSAGE-----&lt;br/&gt;Version: GnuPG v1.0.6 (MingW32) - WinPT 0.5.13&lt;br/&gt;&lt;br/&gt;qANQR1DBwU4DCvEOP3P2HscQCAC1WEffP8p9FbVT02q/pixpOWMe7nyiMcJSqx9q&lt;br/&gt;&#43;DpiM84MTDActM9dBXJgwwnGRMYs0SYky2ZZKjoWbIh43rTVx2qIA50Bg0zNZVZ8&lt;br/&gt;ZnL1ZY2guMWENw5fIIls8sLYEk&#43;MErdCvkAgDIAXKzRE7Dk7lMa1ncbgkiZgURHO&lt;br/&gt;S3Zy81LRc/1J&#43;vDatddDT0J9AofZw0Cd1cxcqOZBNrk1Ia7cYBiyEMtFij9ovZXu&lt;br/&gt;wx8AgM25l28gz5v1NrG7wXpXmZE5duUPYKV3IvmMAJsa5nhlD9cj72/UwFpjv7Xs&lt;br/&gt;KHN7FYZ3yRcS7Mk5n8lZJCeKD&#43;bgEsED1dwam8SNDg==&lt;br/&gt;=h1A1&lt;br/&gt;-----END MASTODON E2EE MESSAGE-----
    </content>
    <updated>2024-10-24T18:14:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrpvfnmyhh4ym4s7em36cuqdkj0hh6mkm8tvxvj8lkdh8l6dzh87szyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7a68c5p</id>
    
      <title type="html">I.e., don&amp;#39;t focus on making the attacker&amp;#39;s life harder by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrpvfnmyhh4ym4s7em36cuqdkj0hh6mkm8tvxvj8lkdh8l6dzh87szyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7a68c5p" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszuxpz4kkqep63wclxwlvl7vkejum9rnjemmyyk4rx3xwef2d7p9sh42tws&#39;&gt;nevent1q…2tws&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I.e., don&amp;#39;t focus on making the attacker&amp;#39;s life harder by constraining yourself to their playing field, but rather focus on making the defender&amp;#39;s life easier by focusing on the things that we control&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Great point, and our industry misses opportunities for this all the time. When we were looking to make PowerShell less attractive to attackers, attempting only to remove its power would have been a fool&amp;#39;s errand.&lt;br/&gt;&lt;br/&gt;By focusing on making it the noisiest possible tool to use, we made far more progress: &lt;a href=&#34;https://devblogs.microsoft.com/powershell/powershell-the-blue-team/&#34;&gt;https://devblogs.microsoft.com/powershell/powershell-the-blue-team/&lt;/a&gt;
    </content>
    <updated>2024-10-17T16:41:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswa3j6m4v9y2kv4d6sekgcc8vcs86rdlr0h7usrcv02rzyr7xl4kszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7yt0duj</id>
    
      <title type="html">Those watches 🤩</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswa3j6m4v9y2kv4d6sekgcc8vcs86rdlr0h7usrcv02rzyr7xl4kszyp7vdp234f328vmjcfspv9vd2nq8fh7qcfmj0062wpknr4jmwr0q7yt0duj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0rcfdn6p9guyarjsq7zxtjvq5vjpdlzhg4chhkxz9my7muv7zs0ct0psfv&#39;&gt;nevent1q…psfv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Those watches 🤩
    </content>
    <updated>2024-09-20T17:51:31Z</updated>
  </entry>

</feed>