shellsharks
shellsharks.com
shellsharks
@shellsharks.com
Infosec researcher | more about me @ https://shellsharks.com

@shellsharks@shellsharks.social on Mastodon
Pinned
Serious question - How will the Bsky team defend against or respond to a Trump/Musk offensive against bsky itself? Bsky is turning into a top competitor of both of their platforms and is certain to harbor posts both of them would not like. Where are the servers/infra hosted? The team members?
Reposted by shellsharks
I put together a little post about my writing mannerisms.

I'd once again like to blame @shellsharks.com for his provocation. He can't keep getting away with this! I should block his domain...

vale.rocks/posts/writin...

#Writing #WritingCommunity #WriterSky
My Writing Style and Mannerisms
Stay tuned for my writing manorialism.
vale.rocks
May 1, 2025 at 11:02 AM
Reposted by shellsharks
Roses are Red
Apples are fruit
I should have sanitised this inputAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
└─# id
uid=0(root) gid=0(root) groups=0(root)
Now I am root!
February 14, 2025 at 9:39 AM
Reposted by shellsharks
Just redesigned my website's landing page as it was starting to feel a tad stale. I blame @shellsharks.com for prompting this with their recent redesign.

vale.rocks
Vale.Rocks
The hippest site this side of MySpace.
vale.rocks
February 14, 2025 at 12:24 PM
#Tapestry is the best Bluesky client just because it keeps track of where I last read in the timeline. Makes this platform kinda usable for me now at least to keep up with some of y'all

usetapestry.com
Tapestry
Weaving your favorite blogs, social media, and more into a unified and chronological timeline.
usetapestry.com
February 9, 2025 at 2:05 PM
Reposted by shellsharks
"It wouldn’t be hard for a billionaire or a hostile government to take down one, two, three or maybe even 10 Bluesky relays. But it seems wholly impractical for a billionaire, or a team of billionaires to snuff out thousands of Fediverse instances."

shellsharks.com/notes/2025/0...

#FreeOurFeeds
Bluesky won't free your feed
Cybersecurity Research and More
shellsharks.com
January 15, 2025 at 9:09 PM
Reposted by shellsharks
It's been a while since I've published something I consider a "blog post" on my site. But thanks to @ApisNecros tossing over the "Blog Questions Challenge", this now exists --> https://shellsharks.com/get-to-know-my-blog

Turns out, I've answer much of these questions in various places across […]
Original post on malici.ous.computer
malici.ous.computer
January 15, 2025 at 9:47 PM
Reposted by shellsharks
Okay, so Cory Doctorow published his take on the #freeourfeeds thingy, all about "billionaire-proofing" the Internet (or more accurately, billionaire-proofing social media), and I have some thoughts...

https://pluralistic.net/2025/01/14/contesting-popularity/#everybody-samba

His main argument […]
Original post on malici.ous.computer
malici.ous.computer
January 15, 2025 at 2:19 PM
Reposted by shellsharks
something i hope more people do on bsky is follow @ap.brid.gy . especially large/notable accounts . it bridges your account to Mastodon meaning people using Mastodon instances can see your posts and interact with you
December 22, 2024 at 12:53 AM
Reposted by shellsharks
Positive Technologies has developed a new attack that exploits the SD Express standard to gain access to a device's memory through its SD card reader

The DaMAgeCard attack exploits the fact that the new SD Express standard can operate in both SDIO and NVMe

swarm.ptsecurity.com/new-dog-old-...
December 8, 2024 at 11:11 AM
This article has been shared by a lot of folks here, but to not a lot of response/discussion.

techcrunch.com/2024/12/05/b...

Is this a collective stick-fingers-in-ears-and-go-la-la-la moment for the bsky populace?

*Stream of consciousness incoming*...
Bluesky CEO Jay Graber isn't ruling out advertising | TechCrunch
Bluesky has blown up this year thanks to a vibrant community of posters, user customization choices, and a decentralized protocol that doesn't lock users
techcrunch.com
December 6, 2024 at 2:36 PM
What's best? Bsky, Mastodon (Fediverse) or Threads?

Trick question! Just having a personal blog/website is best. 😄
December 5, 2024 at 5:10 PM
and like that, the #Fediverse has Starter Packs. Competition is good! The bsky team has some good ideas and with any luck, the popularity of good features here will continue to propel other complimentary networks forward.

fedidevs.com/starter-packs/

My #IndieSec starter pack: fedidevs.com/s/MjQ/
Mastodon Starter Pack Directory | Fedidevs
Discover amazing developers from across the fediverse.
fedidevs.com
December 4, 2024 at 4:17 PM
Reposted by shellsharks
Nice -- someone put together a Threat Modeling Field Guide. Great high-level overview for any org that's at this step in their maturity.

https://shellsharks.com/threat-modeling
The Enchiridion of Impetus Exemplar
A vade mecum for all things Threat Modeling.
shellsharks.com
November 28, 2024 at 1:46 PM
Man, Bluesky would actually be kinda usable for me if it would just remember my timeline position and let me scroll through everything I've missed.

Letting me post more than 300 chars would also be nice but at least it has the ability to create an entire thread of posts and publish simultaneously
November 27, 2024 at 1:06 PM
How does Bluesky's (domain-based) "verification" help the countless high-profile (and low-profile tbh) people who don't have domains/ well-known sites? How can Brad Pitt verify himself here?

shellsharks.social/@shellsharks...
shellsharks (@shellsharks@shellsharks.social)
This *is* an elegant way to "verify" someone, but only if they *have* a website and really only if that website is kinda *known* as being officially associated with that individual. How would this for...
shellsharks.social
November 22, 2024 at 1:24 PM
Reposted by shellsharks
We need a feed for Threat Intel on Bluesky for us #Cybersecurity and #Infosec people.
Something to share CVE's, attacks, and such rather than just the typical cybersecurity news.
November 21, 2024 at 2:22 PM
Introduce yourself with four video games.

- Jill of the Jungle
- Super Mario World
- Ultima Online
- Halo
Bonus: Diablo 3
November 21, 2024 at 6:08 PM
Hey, if you write about #infosec / #cybersecurity let me know what your website/blog is so I can add it here shellsharks.com/infosec-blogs and also sub in my RSS reader!
Infosec Blogs: Our Cup Runneth Over
A list of boutique and commercial information security blogs.
shellsharks.com
November 21, 2024 at 1:06 PM
Reposted by shellsharks
Dragon Yawns the Universe

Acrylic and marker on yupo paper

ugh what year was this... it was a good art year.

2012
November 18, 2024 at 8:29 PM
Reposted by shellsharks
I have complex feelings about Bluesky, but I do feel like it's got the attention of the public in a way that mastodon didn't and is where many of my twitter friends will migrate to.

Thankfully @shellsharks.com wrote a fantastic article about this: shellsharks.com/notes/2024/1...

#socialmedia #bsky
Cloudy with a chance of not enshittifying
Cybersecurity Research and More
shellsharks.com
November 18, 2024 at 12:08 AM
I know it's not *cool* to talk about Mastodon here, and I'm not even here to tell you it's "better". What's better for anyone is completely subjective. I just wanted to say that it's pretty cool that I run my own, completely isolated, yet federated and connected instance for less than $20/mo.
November 17, 2024 at 3:11 PM
Bluesky's got that Threads in 2023 energy. Now, less than 2 years later, you see how it's goin over there... still chuggin' but honeymoon period def over. Enjoy while it lasts!
November 17, 2024 at 4:00 AM
It's a work in progress, but here's the "FediSec" starter pack featuring infosec/cyber folks from the Fediverse who are bridged here via Bridgy Fed.

Note: Included in the pack is @ap.brid.gy which when followed will bridge your Bluesky account back to the Fediverse. Woo!

go.bsky.app/EaxWS7g
November 16, 2024 at 7:00 PM
Reposted by shellsharks
Hey everyone, here's again my #introduction, for #bsky users via https://fed.brid.gy/ (hopefully that works).

I'm a seasoned offensive #security researcher with 25+ years of experience.

As a professional #hacker and polyglot programmer of weird machines, I study how things can go wrong.

Some […]
Original post on infosec.exchange
infosec.exchange
November 16, 2024 at 6:36 PM