FishermansEnemy

Musings of an infosec nerd


Articles in category “InfoSec”

Why I'm Leaving Facebook

TLDR;

Social data is being weaponised, and I'll have no more to do with it

What has happened?

Last night Channel 4 aired a documentary showing the inner workings of the social media influence platform Cambridge Analytica. If you have 20 minuets to spare I suggest you go and give …

Continue reading…

Watch out for wireless technologies

This is a cross post of a blog article I wrote at xiphosresearch.com

Common risk assessment blind spots

Wireless technologies have become commonplace in the last few decades, everything with a battery seems to have an IP stack and an antenna. Ubiquitous connectivity allows us access to  the whole …

Continue reading…

The Method of Loci

buckinghamIn my earlier post I mentioned that I was studying for my PA-DSS exam and that I was using a memory palace technique to commit the standard to memory prior to the exam. I'll find out in a couple of weeks whether it actually helped as the exam didn't actually …

Continue reading…

My experience of San Francisco and the BSides SF conference

[caption id="attachment_345" align="alignleft" width="300"]San Francisco City Street San Francisco City Street[/caption]

I'm currently sat waiting to finish the PA-QSA course and take my exam. I should probably be studying a little more, but I've memorised the standard with a memory palace technique that I used for PCI-DSS so I …

Continue reading…

Breakerfaire 21st August slides

Here are the slides that I used at the my Breakerfaire talk last night.

Breakerfaire Liverpool August 21st

Thanks to Mat for asking me to come and speak, and the great attendees that really made me feel welcome. Hopefully I'll be back again soon.

Continue reading…

Bad password policies

Ever since I got my Yubikey I've been a big fan of making sure my many web application accounts are as secure as possible. Thanks to services like LastPass you can now keep up unique complex passwords on every account you own with very little extra effort.

So, in this …

Continue reading…

Using DVWA as a learning tool - OWASP Birmingham March 2012

Decoding the SANS Bsides london 2012 t shirt

Now that I've had a little while to recover from my tip to Atlantis ... sorry, London last week I thought I'd turn my hand to something that's been bothering me ever since I saw it.

Let me introduce the SANS variant of the offical bsides London t shirt.

[caption id …

Continue reading…

Why the London 2012 WiFi network will be a boon for information theives

  •   Wed 11 January 2012
  •   InfoSec

image0I was reading twitter the other day and came across a report on London getting blanketed by free WiFi coverage courtesy of O2 and this got me thinking. If I were a bad guy this would present me with such a very tasty target. Lots of tourists coming into the …

Continue reading…

OWASP Birmingham registration is now open!

  •   Thu 01 December 2011
  •   InfoSec
About
The personal blog of a UK based penetration tester