Advertisement · 728 × 90

Posts by starkzarn

Post image

Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀

1 month ago 9 5 0 0
Preview
How to Run Custom Linux Images on Oracle Free Tier Bypass the Oracle free-tier limitation of running only Linux distributions provided by Oracle by sideloading a QCOW2 image to a boot volume and attaching it to a new instance.

roguesecurity.dev/blog/custom-...

A quick writeup on a hacky but effective method of bypassing Oracle's restrictions on #Linux distro use in their free tier. I don't trust them, but I'll happily burn some of their compute.

#selfhosting #cloud #OpenSuse

4 months ago 1 0 0 0

I have not, but maybe I don't follow. I have only seen QR used for onboarding passkeys, never authenticating with them. Untrusted devices and BLE connections seems equally strange as far as threat modeling goes, to me. Have not found it in the Bitwarden docs either. Enlighten me?

5 months ago 0 0 1 0

Love @bitwarden.bsky.social
I'm already a user and a fan! I use it for the few things that have passkeys in my life currently, but I still don't agree with the overarching implementation of passkeys.

5 months ago 0 0 0 0

I'm a user and general fan of Bitwarden -- self-hosted. It works great for me, but it still means that to use it on a "guest" device, I need to access my password manager *on that device*. The alternative being accessing my password manager on my trusted device (my phone), and transposing the data.

5 months ago 0 0 1 0

Passkeys are all well and good until you need to access a service on another device.

When did we sign up to be chained to a phone or endpoint with access to a service that manages passkeys?

I get the benefit, but it feels like entrapment was engineered into the workflow.

5 months ago 0 0 1 0
The fourth monkey has emerged. He sees no one, hears no one and speaks to no one.

The fourth monkey has emerged. He sees no one, hears no one and speaks to no one.

5 months ago 139 32 4 1
Preview
End-to-End Encrypted Chat that YOU Control: Hosting XMPP (Jabber) with Prosody Start-to-finish guide for setting up a modern XMPP (Jabber) Server to facilitate E2EE chat on your own infrastructure, podman style

After a bit of a break, I've got a new homelab post in the books on #XMPP

Take control of your chat experience with #E2ee and own your data. Maybe relevant for those potentially affected by a future #chatcontrol ruling.

Check it out, let me know what you think!

roguesecurity.dev/blog/xmpp

5 months ago 1 0 0 0

It's like planting a tree. The best time to do it was yesterday.

5 months ago 1 0 0 0
Advertisement

I know it’s been said again and again, but what does it say about ChatControl that its backers keep explicitly *exempting* law enforcement and national security accounts from content scanning?

6 months ago 93 41 3 8

So by proxy, RC4 with Kerberos is bad.

6 months ago 2 1 0 0

RC4 used with Kerberos isn't the fundemental flaw we think. Yes, RC4 is deprecated, but the real issue is the key generation for AES v RC4 for cracking (Kerberoasting). With RC4 the key = password hash. With AES it is 4096 rounds of hashing of hash+username+domain. The 4096 rounds matters, a lot!

6 months ago 7 2 1 0
Preview
Zero Day Initiative — The September 2025 Security Update Review There’s a crispness in the air – at least here in North America – and with it comes the latest security patches from Adobe and Microsoft. Take a break from your scheduled activities and join us as we ...

It's a moderate release from both #Adobe and #Microsoft, but there's still lots to cover. Join @dustinchilds.bsky.social as he breaks down the September Patch Tuesday and highlights some fixes that require some extra attention. www.zerodayinitiative.com/blog/2025/9/...

6 months ago 2 2 0 0
Preview
Meet Rayhunter: A New Open Source Tool from EFF to Detect Cellular Rayhunter is a new open source tool we’ve created that runs off an affordable mobile hotspot that we hope empowers everyone, regardless of technical skill, to help search out cell-site simulators

We know very little about how cell-site simulators (CSS), devices that masquerade as legitimate cell-phone towers, are being deployed in the US or globally, but with Rayhunter, we hope to change that. www.eff.org/deeplinks/2...

7 months ago 227 87 4 3
Preview
Cyd 1.1.21 released | Cyd Docs We're pleased to announce Cyd 1.1.21 is released. Here's what's new:

Cyd 1.1.21 is out. This is a bug fix release resolving issues importing from X export files and in migrating media to Bluesky:
docs.cyd.social/blog/cyd-1.1...

Thank you to the bug reporters!

7 months ago 13 2 2 1

Ah yes, the life of a cybersecurity pro. Here to be hated...

7 months ago 0 0 0 0
Preview
SystemD Service Hardening Discover additional security options for systemd units, to include quadlets. These options are everything from system permissions, time manage, BPF, syscall & seccomp filters, etc., all to make your s...

Another #selfhosting blog down, this time some casual notes on #systemd #security. Love it or hate it, systemd is a big player in the bulk of Linux systems out there, and these are a few notes on how to lock down some of the defaults.

roguesecurity.dev/blog/systemd...

7 months ago 2 0 0 0
Preview
GitHub is no longer independent at Microsoft after CEO resignation GitHub will be part of Microsoft’s AI engineering team

This is big. GitHub is no longer independent at Microsoft after CEO resignation: GitHub CEO Thomas Dohmke has resigned, and now GitHub will be part of Microsoft’s core AI engineering team. Github is no longer independent company.

www.theverge.com/news/757461/...

7 months ago 120 79 10 20
Advertisement
Page logo: SONICWALL

Title: Recommended Mitigation Steps.

Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions:

**1. Disable SSLVPN Services Where Practical**

Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.

Page logo: SONICWALL Title: Recommended Mitigation Steps. Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions: **1. Disable SSLVPN Services Where Practical** Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.

So the official SonicWall mitigation leads with "turn it off" ? ooooof.

8 months ago 3 5 2 0

Don't give your government issued Id to YouTube.

8 months ago 87 24 2 1
Preview
"Meshtrics:" A Nosy Neighbor's Guide to Meshtastic Airtime Metrics in Grafana Start using Prometheus metrics from a PC-connected Meshtastic node to keep tabs on the local mesh in your area. Discover which nodes are misconfigured, hogging airtime, and see patterns in high-use ti...

roguesecurity.dev/blog/meshtas...

Check out my take on grokking metrics for @meshtastic.org using @grafana.bsky.social dashboards with @prometheus.io. Figure out who your top mesh offenders by keeping tabs on nearby nodes, all with pretty dashboards.

8 months ago 0 0 0 0

It's easy to bash vulnerabilities with logos but... I couldn't resist, say hello to http1mustdie.com :)

8 months ago 13 3 2 0
OPNsense 25.7 released OPNsense 25.7 released

#OPNsense 25.7 "Visionary Viper" is now available.

8 months ago 22 5 3 0
Post image Post image

EFF's @tsnvaa.bsky.social will be sharing the history of Flock in the U.S. and the growing risks and concerns with the technology at this teach-in for the Denver community on 7/15 from 6-8pm MT. You can join online at bit.ly/FLOCKteachin.

8 months ago 127 64 3 3

@garmin.com what's your take on this? how are you going to guarantee you're keeping customer data safe?

8 months ago 0 0 0 0
Monarch Lisa looking a bit disheveled

Monarch Lisa looking a bit disheveled

Good morning! ☕️☕️☕️☕️☕️

9 months ago 1235 152 24 11
Advertisement
Preview
Kennedy guts CDC's vaccine panel of independent experts The Advisory Committee for Immunization Practices helps the agency make recommendations on who should get certain vaccines.

An outspoken vaccine conspiracy theorist just fired every last member of CDC's vaccine advisory committee.

RFK Jr. is paving the way to reshape vaccine policy based not on decades of science, but on his own unhinged fanaticism.

This is unprecedented, and unthinkably dangerous.

9 months ago 1990 741 141 64
Preview
Monitor your AREDN Node with Prometheus and Grafana Utilize the newly added prometheus metrics exporter in the AREDN firmware to add analytics and performance metrics to Grafana. Read about the metrics endpoint and a basic dashboard to monitor performa...

This week I'm combining data enthusiast homelab metrics with @grafana.bsky.social and #arednmesh #hamradio goodness, by setting up @prometheus.io collection of performance metrics of your AREDN node and displaying them in Grafana! Homelabbers and hams unite!

roguesecurity.dev/blog/aredn-m...

9 months ago 0 0 0 0

Last night I went to see Mission Impossible: Final Reckoning, where a rogue AI takes over the entire US nuclear arsenal, and all I could think was: this shit wouldn’t have happened if they’d published ISO 19790:2025 for free.

10 months ago 62 12 1 0