shellsharks

@shellsharks@infosec.exchange

Infosec researcher | Find me @ https://shellsharks.com

#fedi22 #infosec #cybersecurity #tech #indieweb #apple searchable

Profile picture: A red shark holding a terminal window shaped like a surfboard. The terminal reads โ€œ> whoami shellsharksโ€

https://keyoxide.org/FA7AC5E3626AEF016A5AD0BB172E73E0A585273E

This profile is from a federated server and may be incomplete. Browse more on the original instance.

imajeanpeace, to random

Employers: We want to diversify our cyber workforce

Also them: Must hold certifications such as CISSP, CISA, CISM or equivalent.

Bitch, I can't afford those shits.

shellsharks,

@imajeanpeace ๐Ÿคฃ

Hidde, to random

Haven't been on Masto a lot lately.

Life just got... too busy.
Between work, pup, and a rapidly ramping up training schedule, I find I'm avoiding socials on my down time and hiding in familiar games.

I'll be back, not to worry.

shellsharks,

@Hidde We'll be here, tootin' away ๐Ÿ˜.

1s6bp, to random

Giving another chance to infosec exchange. lets see how it goes

shellsharks,

@1s6bp Welcome back. Follow people, turn your timeline into an awesome infosec feed! https://shellsharks.com/notes/2023/10/20/infosec-mastodon-starter-pack#for-infosec-folks

Lee_Holmes, to random

If you are at all engaged at work in protecting your company or organization, you need to really look at this Postman issue: https://infosec.exchange/deck/

Your company likely has policies around where it is safe to store secrets and credentials (i.e.: with companies that care and account for that in their threat model), and I'm sure that Postman isn't one of them.

We've done some analysis in our organization while eliminating Postman and you'll be surprised what's there.

shellsharks,

@raptor @Lee_Holmes @buherator I saved this thread to follow up on this exact question - https://infosec.exchange/@neilmadden/111776304723415347

shellsharks, to random

I've been following @404mediaco since they went live last year and this most recent post from @jasonkoebler (https://mastodon.social/@jasonkoebler/111823811997186188) and the team there really got me thinking. (That toot links to https://www.404media.co/why-404-media-needs-your-email-address/).

They've had some incredible stories and scoops over the last couple months. I see all the headlines come through Mastodon or RSS and I say "wow that's crazyโ€, or โ€œdang, I never knew thatโ€, but that doesn't always translate into me fully reading the post. Maybe I don't have time to read it, maybe I mean to but then forget, in other cases I think the story is interesting but doesn't necessarily impact me specifically. But these stories are meant to be read, they need to be read, maybe not by me all the time, but by someoneโ€ฆ in reality, A LOT of someones if you ask me. Everything they call out in terms of rampaging AI theft, social network decay, traditional journalism in freefall, etc... is no joke. I'm seeing it happen each day and it is in fact quite troubling.

I'll admit, I've always relied on the free-ness of stuff on the web and as a result have been somewhat reluctant to choose creators/publications to support. But given the state of the web, HELL, the state of the world, I really can't justify that any more. I want to see more of what 404 produces, and to help ensure that, I plan to support that end. I've also been working on a list of other causes, publications, etc... to support as this I feel is an ever precarious point in time. (If you have any suggestions I would be interested in hearing what you believe could use the support - comment or DM me).

So what's my point? I suppose it's support what you like, what's impactful, what's important to not just you but to everyone, otherwise it may vanish. The world has changed and I need to as well.

shellsharks, to infosec

once again. Here are some awesome / accounts I've discovered in the past week. As usual, the Local feed at infosec.exchange pops off!

Bonus:

clueax, to mastodon

Anybody know of a non-tech, non-news company active on #mastodon? Aside from repost bots like bird.makeup, I'm not seeing any.

What are your feelings about if/when companies start to join us: would they be greeted with open arms for abandoning corporate-controlled platforms, or would they be shunned for bringing commercialism into our little non-profit eutopia?

Little of column A, little of column B?

I'd been thinking about the Mandiant account takeover recently & realized I was less disappointed in the account being compromised than I was in them still having a presence on that platform.

shellsharks,

@clueax None are coming to mind. I think if they were to come by way of the "traditional" Fediverse, there would be the usual loud subset of folks here who would attempt to shout them away. I believe the majority of people would either want them here or be indifferent. After all, since our feeds aren't ruled by algos, it's easy enough to keep them corpo-free if we want.

This said, with the coming of Threads, the Fediverse (at least the parts of it that won't wall up) will have plenty of brands soon enough.

barunick, to random

Good morning friends! Itโ€™s we made it.

What are you doing this weekend?

shellsharks,

@barunick chillin'

riamaria, to random

I wish I could personally afford SANS courses :\

shellsharks,

@riamaria Have you tried applying for work study? https://www.sans.org/work-study-program/. Makes the price a bit more palatable. I've done it a few times and it was a good experience.

Oh and NO one can personally afford full-price SANS courses. If you could, you're making enough you obviously don't need the sans course. ๐Ÿ˜…

feedle, to blogging
@feedle@mastodon.social avatar

What is your favorite blog? Post a link in the replies.


shellsharks,

@feedle Ill shoutout my own haha ๐Ÿ˜†. I love tinkering with the site and over time I've made it uniquely me. Other sites I follow likely have better content, cleaner, better-functioning code - but mine feels like home. I just enjoy clicking around ๐Ÿ˜„.

https://shellsharks.com/

shellsharks, to random

At least Microsoft and HP are getting hacked by a cool-sounding threat actor like "Midnight Blizzard" and not something lame like "Cinnamon Sleet", which sounds more like a seasonal Starbucks beverage.

shellsharks,

@mttaggart You've got a point ๐Ÿ˜†

goldbe, to random

I would like these AIs to stop trying to write my emails for me. It's distracting and I do not need help writing an email! How do you turn these things off? I don't even know where they are coming from...

shellsharks,

@goldbe Time to move off of anything Google or Microsoft. Well past time ๐Ÿ˜„

thatprivacyguy, to privacy
@thatprivacyguy@eupolicy.social avatar
shellsharks,
hannukle, to random

Hello Mastodon and infosec.exchange!

I'm a technical generalist with history in software development. Mostly I'm writing code, but I tend to hold many hats from C-suite to fiddling with technical bits and pieces on software or cloud environments. I come equipped with keen interest in securing things and following up on latest happenings in infosec space.

Here I'll be most likely posting or commenting about:

  • Information security news and tidbits focusing on things that potentially affect small businesses (daytime me with collared shirt on)
  • Stuff related to AWS or software development - some things you usually either love or hate. (daytime me on a t-shirt coding on Friday afternoon)
  • Cyber security nerdism (night-time me losing my mind on first steps of an online CTF)
  • Highlights and/or frustrations about technology (who doesn't?)
  • Probably some GDPR/regulatory highlights (occasional CISO in me)

And this is the last bullet point list from me here. If you catch me using one again, I'll buy you a lunch.

shellsharks,

@hannukle Welcome! ๐Ÿ‘‹

ittavern, to random

Is it possible to add a live feed of another instance somewhere? - Works great for the home instance, but it seems like a pain to surf or keep up with other instances.

That said, I might just miss something.

shellsharks,

@ittavern A lot of clients support this. etcโ€ฆ

SecurityByAndrew, to random

Do we have an opinion on GoDaddy out there?

shellsharks,

@SecurityByAndrew It works. I use it. Havenโ€™t had any problems with them. If there was a compelling reason to switch, whether for features or on moral grounds Iโ€™d consider it. Otherwise, itโ€™s fine.

matthiasott, to random
@matthiasott@mastodon.social avatar

Inhabitants of the open web!

Do you have a on your site? Or did you come across a fantastic example on someone elseโ€™s website?

Let me know the URL below! ๐Ÿ™Œ

(Once more, Iโ€™m also asking for my newsletter subscribers ๐Ÿ˜‰)

shellsharks,
garrett, to random

Any Ghost users on here? Got a couple quick questions:

Any painless ways to integrate additional social media links to Ghost (particularly Mastodon's verification)? Best I've seen is modifying the theme files but I haven't really dove under the hood.

Also, anyone gotten Ghost to integrate with the Fediverse? Tryna spin up a site for tackling some projects and would like it integrated and accessible.

shellsharks,

@garrett @jerry Not sure about Fediverse but there is some IndieWeb / webmention functionality imminent https://hachyderm.io/@molly0xfff/111789178142781544

mttaggart, to random

So in case you needed more reasons to ditch Chrome, generative models are coming in Chrome 121, with a theme generator, tab grouper, and...writing assistant?!

blog.google/products/chrome/google-chrome-generative-ai-features-january-2024/

Chrome AI Text generation tool, showing a "Help Me Write" popover.

shellsharks,

@mttaggart ๐Ÿคข

john_fisherman, to random
@john_fisherman@mastodon.social avatar

โ€œCurators and aggregators are integral to the ecosystem. If we all create, steal, and regurgitate the same content then we only reinforce our own echo chamber. Aggregators bridge subcultures in a world of content bubbles and subreddits. [โ€ฆ] They find beauty in the mundane and surface wisdom from obscure writings. That is valuable, worth more than gold.โ€

https://daverupert.com/2024/01/where-have-all-the-websites-gone/

shellsharks,

@john_fisherman Hey! I read your post here and wanted to let you know about my own experience as a random writer on the web (understanding that everyone's experience differs). I started my blog in 2019 and expected to never really get any interest from people in terms of reading, using or getting feedback on what I had written. After nearly 5 years I've been blown away with the reception and level of feedback I have gotten! So what do I think has helped me in terms of people discovering my site, enjoying it and giving me feedback?โ€ฆ

  • Find a niche, write for that niche. I write about everything but a good bit of what I choose to write about is infosec. Now there is no dearth of infosec content out there but it is slightly more specialized than "techโ€ for example.

  • Network it around! Or an IndieWeb speak, POSSE. You mention this in your piece but getting it out into specific Reddit channels, LinkedIn, Mastodon, etc.. has been great for getting feedback and spreading the world.

  • Keep pieces updated. A lot of my posts are not just point-in-time writings, but rather resources I keep up to date. This has helped what I write maintain relevance and serve as a resource for myself and others.

  • Make it unique. My site is not perfect, but its visual style is certainly unique. People have commented that they like me design, my site, my artwork, etc... In a world filled with cookie cutter Medium sites and other boring facades, this can definitely help. If your site is interesting, than you are by default a bit more interesting haha.

  • Though you should find a niche, also consider just writing about whatever you want and having that hosted on your site too. Some of my most popular (by SEO) posts are not infosec-related but rather things like a chair review or some of my work I did for my Masters.

Cheers!

zak, to linux

I made a #Linux tier list. I'm sure there will be some hot takes in here. In doing this, I realized how many distros I know nothing about at all.

shellsharks,

@zak @jonah Bookmarking in the event of flame war ๐Ÿ˜†

onelin, to random

Nice try. First time I've seen a website try this trick:

shellsharks,

@onelin Eww ๐Ÿคข

shellsharks, to CSS

I canโ€™t overstate how much I hate #CSS. Extremely humbling trying to do anything resembling good, โ€œmodernโ€, responsive #webdesign. Been working on some heavier under-the-hood changes to my #githubpages-based #jekyll #staticwebsite and wow my eyes and soul hurt.

A related question, anyone ever implement full-body text search on a static site / Jekyll site before? Iโ€™ve been looking into maybe lunr.jsโ€ฆ

#fedihelp #webdev

shellsharks,

@kev I tried tinkering with this last night and was not able to get it working ๐Ÿ˜•. I kept getting an error saying it โ€œcould not findโ€ my search.json despite me having it in the root dir of the site as you had instructed on the site ๐Ÿคทโ€โ™‚๏ธ. I probably need to fiddle with it more at a reasonable hour. Did you run into any issues getting it up and running?

starshaped, (edited ) to random
@starshaped@labyrinth.social avatar

Those of you who use a static site generator for your blog (, , etc), what's your workflow for writing posts? Do you write them in a markdown editor and then copy it to your IDE when you're ready to publish (which is what I do), or do you do something else?

I am looking to switch up my workflow and I'm curious about what others do. Let me know!

shellsharks,

@starshaped I've written up something which goes over my publishing/syndication workflow/strategy here if you're interested. https://shellsharks.com/syndication-strategy

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • megavids
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • everett
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • GTA5RPClips
  • ngwrru68w68
  • cisconetworking
  • JUstTest
  • InstantRegret
  • cubers
  • khanakhh
  • ethstaker
  • tacticalgear
  • Durango
  • normalnudes
  • tester
  • modclub
  • provamag3
  • Leos
  • anitta
  • lostlight
  • All magazines