Per Thorsheim
banner
thorsheim.bsky.social
Per Thorsheim
@thorsheim.bsky.social
Founder of #PasswordsCon. Above average interested in passwords & digital authentication. Online since 2400baud. I do security & privacy. Want me to speak at your conference / org? Reach out!
You're not really digital before you patch your loudspeakers, lightbulbs, tvs and more on a regular basis. 😞

Nicely coupled with targeted ads for upgrades and content subscriptions...
November 9, 2025 at 2:07 PM
Broadcast tv? Live tv? Does anyone still watch that, given all the ad breaks? 😱🤡🤮
November 9, 2025 at 1:46 PM
2) Works on all your units. Mainkeys (...) will automatically be available across all your synchronized devices.
3) Keep your account safer. Mainkeys (...) offers "state of the art" phishing protection.

Cc @fidoalliance.bsky.social @timcappalli.me
November 2, 2025 at 6:00 PM
Ubiquiti at home, first step would be vpn from her phone and Mac to home when streaming.

Setting up a vpn from her moms home to me though... Could be questionable. 😎
October 17, 2025 at 8:51 PM
Wonderful donation to give! 🤣
October 12, 2025 at 5:38 PM
80% is good enough.
October 12, 2025 at 12:13 PM
🫗
October 12, 2025 at 12:11 PM
...sorry for "reporter-splaining", target of my post is other followers I guess.

And I can't wait to see the *real* truth about ownership and intended/use of these boxes.
September 25, 2025 at 2:16 PM
Origin: Secret Service. They are, by definition from @erratarob.bsky.social, "People that matter"

Hype: It is a massive find, given (afaik) nothing at this scale has been found previously.

Time-to-market news: You report it and others quote you, or the other way around. Winner gets the clicks.
September 25, 2025 at 2:13 PM
September 24, 2025 at 12:20 PM
Tech & methodology is "well known" across the world. Lots of police cases documented, search "sms blasters" at commsrisk.com for stories from around the world.

Young man was convicted here in Norway in spring 2024 for this kind of activity; 2G IMSI catching for sending phishing texts.
Commsrisk | The information exchange for communication risk
commsrisk.com
September 24, 2025 at 12:20 PM
The first type can be detected as a massive flood, can be rate-limited and filtered & then some.

The second type has nothing to do with telcos at all. The only rate-limiting / content filters etc will be whatever you have locally on your phone, and obviously very hard to trace the origin of msgs.
September 24, 2025 at 12:20 PM
These boxes work as massive stacks of phones with preferably anonymous SIMs, sending tons of text messages.

The other option would be boxes that does 2G IMSI catching, sending texts for free directly to your phone, as long as you are within range & you haven't disabled 2G.
September 24, 2025 at 12:20 PM
I'm just one of many messengers on this, @jimfenton.bsky.social is among those who actually write the exact words. 😍

Oh, and Jim will talk about what's new in the latest version at #PasswordsCon in Prague, December 1-3. Sponsored/hosted by @nic.cz!

csrc.nist.gov/pubs/sp/800/...
NIST Special Publication (SP) 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management
This guideline focuses on the authentication of subjects who interact with government information systems over networks to establish that a given claimant is a subscriber who has been previously authe...
csrc.nist.gov
September 22, 2025 at 1:35 PM
✅ Use simple memorable passphrases
✅ write down your passwords
✅ Use a password manager

❤️👍🏼 @brianhonan.bsky.social
September 22, 2025 at 9:39 AM