
Saul Johnson
@lambdacasserole
Followers
123
Following
549
Media
10
Statuses
264
He/him. Opinions my own. 🇬🇧🇮🇪
United Kingdom
Joined October 2012
RT @WeldPond: "Password expiration requirements do more harm than good, because these requirements make users select predictable passwords"….
learn.microsoft.com
Make your organization more secure against password attacks, and ban common passwords and enable risk-based multifactor authentication.
0
431
0
While this might have nothing to do with the latest "sophisticated cyberattack" that you came under @easyJet, I sent you an e-mail and several DMs about this and absolutely nothing was done. I can't help but wonder, were there similar warnings this time?.
0
0
1
Sign in link up top there too, for anyone to fiddle with that happens to be sitting between the user and your server. Honestly really frustrating. @troyhunt wrote on this all the way back in 2017.
troyhunt.com
Occasionally, I feel like I'm just handing an organisation more shovels - "here, keep digging, I'm sure this'll work out just fine..." The latest such event was with NatWest [http://personal.natwes...
1
0
1
RT @alexbloor: WHAT THE SHIT. Seriously, I didn't realise the utter amazingness of this on the day when Marek sent it. If you use their….
0
26
0
If you follow me and don't yet follow @cybergibbons you should definitely do so. Consistently awesome stuff.
1
0
1
RT @bcrypt: hate to post about personal stuff but tl;dr i had to kick a friend out of my life tonite bc they were not respecting boundaries….
0
24
0
Me, a password security researcher, hiding under the bed:. Armed robber: . Me: . Armed robber: . Me: . Armed robber: Enforce password length over password complexity. Me: ACTUALLY THERE IS NO IDEAL PASSWORD POLICY IN ALL ENVIRONMENTS, THREAT MODELLING IS ESSENTIA- oops. .
Me, a web developer, hiding under the bed:. Armed robber: . Me: . Armed robber: . Me: . Armed robber: why call it serverless when there are obviously still servers. Me: YOU THINK YOU’RE SO CLEVER. DON’T DISCOUNT A VERY REAL PARADIGM SHIFT BEC oh shit.
0
1
3
I don't blog much, but in light of the recent @virginmedia tweet about *printing out passwords and popping them in the post* (still can't believe I'm typing that) I thought I'd post this here:
0
0
4
Absolutely wild that you store passwords unhashed, then *print them on a piece of paper* and put them in the mail. This can't be real.
@_Freakyclown_ Posting it to you is secure, as it's illegal to open someone else's mail. ^JGS.
0
0
1
RT @SarahJamieLewis: Can't wait for a cryptocurrency with the ethics of Uber, the censorship resistance of Paypal, and the centralization o….
0
5K
0
Really enjoyed delivering my talk at @OfficialTDFCon on malicious JavaScript encoded as zero-width whitespace characters! The blog post is up now:
0
1
0