@shellsharks@shellsharks.social avatar

shellsharks

@shellsharks@shellsharks.social

Infosec researcher | Indieweb enthusiast | Find me @ https://shellsharks.com

#fedi22 #infosec #cybersecurity #tech #indieweb #apple searchable

Profile picture: A red shark holding a terminal window shaped like a surfboard. The terminal reads “> whoami shellsharks”

https://keyoxide.org/FA7AC5E3626AEF016A5AD0BB172E73E0A585273E

This profile is from a federated server and may be incomplete. Browse more on the original instance.

robb, to random
@robb@social.lol avatar

Interests: A New Sitelet https://rknight.me/blog/interests-a-new-sitelet/

@chrisburnell came up with the idea for a /interests page so of course I did one as soon as I could (https://rknight.me/interests/). He also made a directory: https://chrisburnell.github.io/interests-directory/

shellsharks,
@shellsharks@shellsharks.social avatar

@robb @chrisburnell I've just been calling them "/pages" (said "slash pages") 🤷‍♂️. I have TONS of them now 😆

kev, to random
@kev@fosstodon.org avatar

Whenever I, or someone else, posts a link to this blog on Mastodon, it DDoS's me and brings the site down for a couple minutes.

https://kevquirk.com/mastodon-is-ddosing-me

shellsharks,
@shellsharks@shellsharks.social avatar

@kev One day I hope my site is popular enough that it gets Fedi-blasted off the Internet 😅

Though maybe GH Pages can handle the load? 🤷‍♂️

shellsharks, to fediverse
@shellsharks@shellsharks.social avatar

I'm pumped that #blogroll's are back but in the spirit of sharing follow recommendations for folks on the #fediverse, not just the #indieweb, I wanted to introduce the idea of a #fediroll. This is simply your shortlist of accounts you love and would recommend others follow! Here's my starting 10 below (there's many more I'd like to add in the future)

campuscodi, to random
@campuscodi@mastodon.social avatar

deleted_by_author

  • Loading...
  • shellsharks,
    @shellsharks@shellsharks.social avatar

    @campuscodi FYI on this particular individual (haven't verified any claims myself)

    https://mastodon.social/

    shellsharks, to devlog
    @shellsharks@shellsharks.social avatar

    Alright, me creating the "Activity" feed on my site really kicked off a bunch of other things I've wanted to do…

    shellsharks, to random
    @shellsharks@shellsharks.social avatar

    I've just published another #indieweb-inspired post that I've been meaning to get out. It describes the various types of post content that I have on the site, e.g. notes, posts, logs, etc…

    https://shellsharks.com/multiplicity-of-writing

    I encourage everyone to

    A. have a website, then…
    B. publish writing on said website, &
    C. have a "mixed content" strategy where you feel free to write in different forms for different reasons and different audiences.

    I explain why in the shared post above. Happy bloggin’!

    janettespeyer, to fediverse
    @janettespeyer@flipboard.social avatar

    Question for fedi experts. What are the benefits of hosting your own instance?

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @janettespeyer I talk a little bit about why I started my own instance here https://shellsharks.com/own-my-social.

    To list some benefits though...

    • De-platforming / censorship resistance
    • "Owning" your data
    • You get a vanity Fediverse handle
    • Customization
    • Control (over moderation, settings, everything)
    • Fediverse instances have died in random ways in the past (domain seizure, server backup fault, etc…). You mitigate this by running your own.

    #ownyoursocial

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @janettespeyer 👍 I also went ahead and added these points here for (easier) future reference https://shellsharks.com/own-my-social#benefits-of-a-personal-fediverse-instance

    atomicpoet, to random
    @atomicpoet@atomicpoet.org avatar

    Have we all stopped saying “pwned” now?

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @atomicpoet I for one haven't. Between all the Halo I played growing up and my infosec career choice, "pwn" is life.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @redfox I've used Tenable for a LONG time. Pretty much their entire suite of products. Cost in the enterprise is going to vary on how many endpoints you have and what solutions you need.

    As for effectiveness. I think it it has been and continues to be VM/scanning best of breed. Security Center specifically is highly extensible. It should be easy enough to get started with though may take some time to build out more advanced things.

    Alts include Qualys and Rapid7.

    Paging @tecnobabble

    atomicpoet, (edited ) to threads
    @atomicpoet@atomicpoet.org avatar

    De-federating does NOT prevent from accessing your public feed.

    This is demonstrably false. Almost all servers that de-federate Threads still broadcast the RSS feed of your posts. This is available to everyone, even servers that are de-federated from yours.

    If you don’t believe me, test this out for yourself. Append “.rss” to the end of your profile URL (exampleserver.com/@username.rss), and see what happens.

    Hell, if I wanted to build a search engine for the Fediverse and not use ActivityPub, I could use RSS instead and I could index most of the Fediverse – whether you opt into it or not.

    Let’s stop spreading the myth that de-federation by itself prevents Threads from accessing your public feed.

    @fediversenews

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @argv_minus_one @atomicpoet Thanks to our feeds here being follower-defined and not "algorithmic”, I don't see how Threads posts (and thus Threads itself) could drown out my feed or anyone else's feed unless they consciously decide to overwhelmingly follow Threads accounts. Plus, since we have access to Threads posts (for now) and not the other way around, this in some ways gives us MORE capability than those natively on Threads.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @argv_minus_one @atomicpoet I think Threads can play in the Fediverse sandbox without the intention of destroying traditional Fedi. I’m not saying they don't have the same surveillance capitalist goals for first-party users of their own platform but I think there are good reasons for them to enable AP support beyond trying to crush us or harvest our data.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @argv_minus_one @atomicpoet Yeah I should have qualified that toot-spree with saying that I am cursed with naive optimism 😅.

    I think what I mean to say is that the people who are here are here because of what Threads isn’t, and what they can't be. Everyone else is already on Threads or X-Twitter. Threads goal is to suck out what remains of Twitters user-base, enable AP-based Federation to block out Bluesky (and perhaps achieve some regulatory req) and then play ball with other LG AP players.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @ferricoxide @argv_minus_one @atomicpoet Ya know what? I honestly hadn't considered concerns around flooding the “Federated" timeline because in my mind this is already entirely unusable. I suppose if you rely on, or regularly use that feature and are concerned about what the Threads deluge would do to it (whether it be homogenizing or potentially harmful) then I can understand why the sheer volume of what Threads brings to the traditional Fediverse is a concern.

    chiefgyk3d, to random
    @chiefgyk3d@social.chiefgyk3d.com avatar

    My toxic trait is going on to Threads to talk about how amazing the fediverse is and how much better it is on Mastodon.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @chiefgyk3d Lol that's me too https://shellsharks.com/notes/2024/01/02/evangelizing-mastodon 🤣

    I sound a little less crazy now that they've enabled the Fediverse beta and other people are talking about it too though.

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @mwguy A little link roundup related to the compromise for anyone trying to find resources - https://shellsharks.com/xz-compromise-link-roundup

    shellsharks, to random
    @shellsharks@shellsharks.social avatar

    I'm not a big April Fools person but in the spirit of silliness, here is a thought experiment / game to play…

    My wife was listening to a podcast which asked, “If you could (magically) make each finger on one hand produce a liquid, what 5 liquids would you choose”. My current list (and briefly why I chose it) in-thread…

    Note: (not sure what the podcast was)

    shellsharks, to infosec
    @shellsharks@shellsharks.social avatar

    There's A LOT going on (analysis, discussion, vendor notices, etc...) related to the ongoing xz/liblzma compromise so I created a "link roundup" which centralizes and buckets a lot of the awesome links and threads I've seen flying around.

    https://shellsharks.com/xz-compromise-link-roundup

    I will try to keep this up-to-date (ish) for a few days while things are hot but I make no promises beyond that.

    #cve20243094 #xz #xzbackdoor #xzorcist #supplychainattack #xz4shell #infosec #cybersecurity

    schizanon, to web
    @schizanon@mastodon.social avatar

    I like the concept of #aboutideasnow. It feels like #microformats, but for URLs. It's kinda weird how few conventions the #web has for urls. Aside from index.html, robots.txt, and favicon.ico there are very few standard URLs that many sites support.

    #smallweb #indieweb #webDev

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @schizanon Yeah I’ve been trying to catalog some URLs that sites may/should have. Some are more common than others…

    My “Website Component Checklist”: https://shellsharks.com/notes/2023/08/15/website-component-checklist

    #indieweb #smallweb

    shellsharks, to mastodon
    @shellsharks@shellsharks.social avatar

    One thing I find ever-delightful about using #Mastodon (as part of the wider #Fediverse) is the experience of encountering folks from unique or whimsically-named instances. A lot of who I follow on this particular account is in infosec and most of those folks (smartly) live on infosec.exchange. But I'll come across someone who's from (as an example) something like (at)superwombat.ninja and be instantly tickled. Friending/following them is like making friends with someone in another country 😄.

    shellsharks, to infosec
    @shellsharks@shellsharks.social avatar

    Another installment of / ! Some awesome accounts below👇

    If you're interested in following along in what is happening in the /c/cybersecurity community on infosec.pub () than you can follow @cybersecurity!

    bentsai, to random
    @bentsai@social.lol avatar

    Can you recommend a podcast about the small/indie web and personal blogging?

    (Please boost for reach)

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @bentsai Not exactly about / personal blogging but I think the @wedistribute podcast (from @deadsuperhero ) touches on a lot of common IndieWeb principles, i.e. empowering people, decorporatization, owning their own web, , etc… 6 episodes in and I've enjoyed each one!

    shellsharks, to mastodon
    @shellsharks@shellsharks.social avatar

    I've recently migrated to this personal / single-user instance and finally got around to writing about that "journey”, explaining how and why I did it.

    https://shellsharks.com/own-my-social

    It is but one more way in which I am pushing further into adoption of ideas.

    Honestly, the hardest part about the move was emotionally leaving infosec.exchange, I explain why in the post (https://shellsharks.com/own-my-social#thanks-to-infosecexchange). Thanks for everything @jerry 🧡!

    jack_daniel, to random
    @jack_daniel@mastodon.social avatar

    Mornin' (or whatever it is where you are) frens.
    What iOS crapplication do y'all loathe the least for Mastodon?

    shellsharks,
    @shellsharks@shellsharks.social avatar

    @neurovagrant Hmm i'm not really sure. I never go a day without checking Mastodon (addicted much?) In my experience the app is pretty spot-on and snappy when it comes to sync-ing my position in the timeline, mentions, etc... If it's a reproducible issue you could msg the devs as they are pretty responsive to bug reports.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • thenastyranch
  • magazineikmin
  • khanakhh
  • InstantRegret
  • everett
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • rosin
  • PowerRangers
  • kavyap
  • DreamBathrooms
  • Leos
  • tester
  • hgfsjryuu7
  • GTA5RPClips
  • tacticalgear
  • mdbf
  • vwfavf
  • ngwrru68w68
  • ethstaker
  • normalnudes
  • modclub
  • cisconetworking
  • cubers
  • provamag3
  • All magazines