I’m Writing a Book with Rob Conery, and It’s Gonna Be Awesome

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

I’ve been chatting about this in some of my recent weekly videos and I thought it was finally time to sit down and write the blog post. So, this is a blog post about a book about blog posts. Gotcha, makes sense.

It all began when Rob Conery reached out

Continue reading I’m Writing a Book with Rob Conery, and It’s Gonna Be Awesome

The Facebook Phone Numbers Are Now Searchable in Have I Been Pwned

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

The headline is pretty self-explanatory so in the interest of time, let me just jump directly into the details of how this all works. There’s been huge interest in this incident, and I’ve seen near-unprecedented traffic to Have I Been Pwned (HIBP) over the last couple of days, let me

Continue reading The Facebook Phone Numbers Are Now Searchable in Have I Been Pwned

Weekly Update 237

Presently sponsored by: @Hack – from the masterminds behind Black Hat. Taking place in Saudi Arabia, 2021. Watch this space.

As soon as I started watching this video back, I remembered why I don’t do daylight mode in these any more. It’s just so… boring. That said, I’ve got a bunch of stuff in the pipeline to enhance the room design and lighting as I think there’s still plenty of

Continue reading Weekly Update 237

I Now Own the Coinhive Domain. Here’s How I’m Fighting Cryptojacking and Doing Good Things with Content Security Policies.

Presently sponsored by: @Hack – from the masterminds behind Black Hat. Taking place in Saudi Arabia, 2021. Watch this space.

If you’ve landed on this page because you saw a strange message on a completely different website then followed a link to here, drop a note to the site owner and let them know what happened. If, on the other hand, you’re on this page because you’re interested in reading

Continue reading I Now Own the Coinhive Domain. Here’s How I’m Fighting Cryptojacking and Doing Good Things with Content Security Policies.

Weekly Update 236

Presently sponsored by: SecurityFWD. A brand new YouTube show from Varonis. Watch Episode 1: How Far can Wi-Fi Travel?

This 🤬🤬🤬 DAC! I mean it’s a lovely device, but it’s just impossible to use it as an audio source in the browser without it killing the camera. I’m very close to being out of ideas right now, only remaining thing I can think of is to set everything up on

Continue reading Weekly Update 236

Weekly Update 235

Presently sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online

A slow start this week as the camera refused to be recognised by any browser. The problem, of course, was that I’d plugged in a new DAC for the replacement speakers 🤷‍♂️ Despite the slow start, there’s a heap in this week’s update on all sorts of different things as I

Continue reading Weekly Update 235

Home Assistant, Pwned Passwords and Security Misconceptions

Presently sponsored by: Get a FREE password audit on your Active Directory users with pwncheck from safepass.me

Two of my favourite things these days are Have I Been Pwned and Home Assistant. The former is an obvious choice, the latter I’ve come to love as I’ve embarked on my home automation journey. So, it was with great pleasure that I saw the two integrated recently:

Continue reading Home Assistant, Pwned Passwords and Security Misconceptions

Weekly Update 233

Presently sponsored by: MEGA – The world’s largest provider of zero-knowledge E2EE cloud storage plus chat. Join 200m others who enjoy privacy – try MEGA for free.

Data breaches all over the place this week! Not just data breaches, but noteworthy data breaches; the VPN ones for being pretty shady, Oxfam because it included my data which was posted to a hacking forum, Ticketcounter because of the interactions I had with them during the disclosure process and

Continue reading Weekly Update 233

Gab Has Been Breached

Presently sponsored by: MEGA – The world’s largest provider of zero-knowledge E2EE cloud storage plus chat. Join 200m others who enjoy privacy – try MEGA for free.

I’ve investigated hundreds of data breaches over the years (there are 514 of them in Have I Been Pwned as I write this), and for the most part, the situation with Gab is just another day on the internet. But Gab is also different, having grown dramatically in recent months

Continue reading Gab Has Been Breached