-
Latest news on Spotlight Knowledge Events
Random Stuff | Apr 18, 2025 - 700 Words |
A couple months ago, I identified a (likely) bug in Intel versions of macOS Sequoia. How's that been going? Though it's faked me out a couple times...the bug is still here, and still just as bad.
-
Word Salad - Slicing and Dicing with awk and sort
Random Stuff | Apr 11, 2025 - 4600 Words |
You've got a big logfile, and something weird is happening, but you don't know what. There's lots of data there, and you're sure there are patterns. How can you make sense of the chaos, quickly, when you really don't even know where to begin? Sometimes, you just need The Old Tools.
-
Managing Sequoia Disk Space
Random Stuff | Mar 11, 2025 - 3000 Words |
After a lot of exploration and experimentation, I'm finally closing in on a strategy that, if it won't SOLVE the problems Ive been having, should at least mitigate them.
-
Update on Spotlight and Disk Space Woes
Random Stuff | Feb 27, 2025 - 2800 Words |
My Mac's disk has been filling up. I think I figured out where the problem was, but spent a week collecting data to be sure. Now I'm more confident, but also more confused.
-
macOS Sequoia Disk Space...Vanishing!
Random Stuff | Feb 19, 2025 - 3500 Words |
My Mac Mini's disk kept filling up. A lot. Even after I got rid of crap, it filled up again. Multiple gigs in just a day. What the hell is going on?
-
Replacing my Synology DS1515+
Random Stuff | Jan 28, 2025 - 2200 Words |
My decade-old NAS finally conked out. Just how easy is it, really, to move the drives to a newer unit? Let's find out.
-
Update on August Ping Storms
Information Security | Oct 1, 2024 - 3900 Words |
Still poking around the Noise Storm rabbit hole. I think I've figured out the four main packet types in this storm.
-
Ping Storms at GreyNoise
Information Security | Sep 27, 2024 - 2600 Words |
GreyNoise has been seeing crazy noise storms full of pings for years. I may have figured out what some of them are.
-
Funemployment, and Next Steps
Finding a new job | Jul 9, 2024 - 2100 Words |
A year ago, I got laid off. It's been a weird ride since then...
-
Using an Adafruit NeoTrellis Keypad with MQTT
Building and Programming | Apr 26, 2021 - 2200 Words |
Writing the firmware for a NeoTrellis keypad to allow it to send and receive MQTT controls, and dealing with keypad library read/write conflicts.
-
Building a remote-control home automation keypad
Building and Programming | Apr 25, 2021 - 1100 Words |
Introduction to a series about a 16-key remote-control MQTT keypad
-
Codenames Board Generator
Puzzles, Fun, Games | Mar 11, 2021 - 1500 Words |
Building a board generator for Codenames as a fun diversion
-
1Password - Full Trip from Unlock to Encryption
Information Security | Nov 12, 2018 - 1900 Words |
Pulling the whole series together to demonstrate the 1Password vault system from unlock to item decryption
-
1Password - Wrapping up with a few quick topics
Information Security | Nov 9, 2018 - 1400 Words |
Finishing the Inside 1Password series with some miscellaneous topics
-
1Password - Local Vaults
Information Security | Nov 9, 2018 - 2400 Words |
Looking at how Local Vaults are encrypted, and how that affects unlocking 1Password clients
-
1Password - Into the Vaults!
Information Security | Nov 9, 2018 - 1500 Words |
How 1Password's shared vaults work
-
1Password - Unlocking Windows Clients
Information Security | Nov 9, 2018 - 2100 Words |
How the Encrypted Master Key works to unlock the Windows 1Password client
-
1Password - MUKing about on the Mac
Information Security | Nov 9, 2018 - 2000 Words |
The Master Unlock Key and unlocking 1Pass on macOS
-
How 1Password Works - Getting under the hood
Information Security | Nov 9, 2018 - 800 Words |
Beginning of a deep dive into how 1password works
-
Encrypting for Apple's Secure Enclave
Information Security | May 31, 2018 - 2200 Words |
How to properly encrypt EICES-format messages to be decrypted by the iOS and macOS Secure Enclave system
-
Infosec Conference Badge Display
Building and Programming | Oct 17, 2017 - 600 Words |
I had way too many conference badges hanging from a stuffed moose head. So I built a nice display for my office.
-
Technology Sucks
Random Stuff | Sep 12, 2017 - 1500 Words |
My 3D Blu-Ray stopped working. It took an hour to figure out the stupid simple cause.
-
Eclipse.
Random Stuff | Aug 24, 2017 - 3900 Words |
I've been waiting for this eclipse for nearly 40 years. Here's how I got to see it firsthand.
-
iPhone Secure Enclave Firmware Key Found
Information Security | Aug 17, 2017 - 1700 Words |
The key to decrypt the firmware for the Secure Enclave Processor (SEP) on the iPhone 5S has been disclosed. It's actually potentially a good thing.
-
New Website Engine
Building and Programming | Aug 7, 2017 - 800 Words |
I decided the site needed a visual overhaul, and didn't want to keep hacking the old engine, so found a new one.
-
New Standing Desk
Building and Programming | Aug 3, 2017 - 1100 Words |
Adding a Fully Jarvis J3 standing desk frame to my IKEA desk
-
ShmooCon 2017 Badge (and more) Contest - Solutions
Puzzles, Fun, Games | Jan 20, 2017 - 8500 Words |
ShmooCon 13 Badge contest, scoring, solutions to the puzzles.
-
Poem Codes - WWII Crypto Techniques
Puzzles, Fun, Games | Mar 27, 2016 - 2700 Words |
A rough introduction to how poem codes work and how they may have been used in practice by SOE agents in WWII.
-
Put away the tin-foil: The Apple unlock case is complicated enough
Information Security | Feb 19, 2016 - 2100 Words |
A high-level summary of what we know, what we think we know, and what we know we don't know, as well as some words of caution.
-
Mobile App Authentication using TouchID and Tidas
Information Security | Feb 10, 2016 - 1000 Words |
A first, rough look at a new mobile app authentication service from Trail of Bits
-
Blizzard of 2016 Time-lapse
Building and Programming | Jan 22, 2016 - 1200 Words |
A quick, simple rig to film a time-lapse video of snow piling up on my desk in a blizzard.
-
DLP Considered Harmful - A Rant about Reliable Certificate Pinning
Information Security | Nov 24, 2015 - 1600 Words |
Yet another uninformed, unrealistically idealistic rant about how things *ought* to be. Most readers will probably strongly disagree.
-
Thoughts on CyberUL and Infosec Research
Information Security | Jul 29, 2015 - 1900 Words |
A discussion of ideas I've been kicking around about security research in general, and how current CyberUL speculation fits in.
-
Salt as a Service: Interesting approach to hashing passwords
Information Security | Apr 21, 2015 - 1100 Words |
A new service called Blind Hashing, that incorporates salts taken from petabyte-sized cloud databases, hopes to make password cracking obsolete.
-
Lenovo, CA Certs, and Trust
Information Security | Feb 20, 2015 - 1000 Words |
The Lenovo-installed SuperFish man-in-the-middle malware has me thinking again about how the CA system is still broken.
-
Bypassing the lockout delay on iOS devices
Information Security | Nov 18, 2014 - 700 Words |
A bug in iOS (fixed in 8.1.1) allows a well-timed reboot to bypass the forced lockout timeout, allowing for multiple PIN attempts.
-
Why I hate voting.
Random Stuff | Nov 4, 2014 - 800 Words |
The parties have made voting even more of a hassle, and more infuriating, than the months of attack ads we endure.
-
What's the deal with keyless entry car thefts?
Information Security | Oct 28, 2014 - 1100 Words |
Videos of people breaking into cars, and reports of hijacked dealer equipment. Real-world example of why backdoors are bad?
-
iPhone SMS forwarding -- cool, but may be risky
Information Security | Oct 24, 2014 - 700 Words |
If you've enabled SMS forwarding on your iPhone, you might want to ensure that messages don't get displayed on your Mac when it's locked.
-
Rebutting FUD and privacy issues surrounding Yosemite Spotlight
Information Security | Oct 21, 2014 - 300 Words |
A response from Apple downplays security concerns raised over how Spotlight search works on Yosemite.
-
Even more posts about iOS encryption
Information Security | Oct 8, 2014 - 700 Words |
The "Apple can't decrypt devices for law enforcement" conversation continues to spawn excellent posts and explanations.
-
A (not so) quick primer on iOS encryption
Information Security | Oct 6, 2014 - 3900 Words |
Making sense of how iOS encryption works, especially what's changed in iOS 8 and how Apple made it harder for law enforcement, can be difficult. I'll try to help.
-
Internet of SCADA, or, why does my HVAC blow?
Building and Programming | Sep 5, 2014 - 1900 Words |
My HVAC system is constantly failing. I'm building a system to closely monitor temps so I can catch failures earlier. After only a couple days with rough prototypes I'm already learning something useful.
-
BSidesLV 2014 Badge Contest
Puzzles, Fun, Games | Aug 10, 2014 - 4500 Words |
A badge puzzle / mini CTF at BSidesLV 2014. Created by Zack Fasel, sponsered by Urbane Security, won (somewhat soundly) by Darth Null.
-
BSLV 2014 - Breaking PRNGs
Information Security | Aug 6, 2014 - 400 Words |
Quick review of BSidesLV Talk, in which they describe problems with the Mersenne Twister and other similer pseudo-random number generators.
-
More Mobile Malware Melodrama
Information Security | Jun 17, 2014 - 500 Words |
Lots of press recently about a potentially serious malware called Svpeng. A nice case study in the use of FUD in mainstream tech press.
-
Memory Pressure, Capacity Limits, and Ubiquitous Computing
Random Stuff | Jun 2, 2014 - 900 Words |
Last year, Apple introduced advanced power saving techniques. Can they do the same for memory? There’s never enough to smoothly switch between apps. If they can fix that, a world of opportunities opens.
-
Making Tunnelblick + Google Authenticator Easier to Use
Building and Programming | May 30, 2014 - 1100 Words |
VPNs which require 2-Factor Google Authenticator codes are a pain to start up in Tunnelblick on OS X. Here's a script to make it easier.
-
Inadvertent OS X Mail Loading of Images in SPAM
Information Security | May 8, 2014 - 300 Words |
Mail.app's protection against loading images on suspected SPAM messages is broken when forwarding the email to a spam-reporting service.
-
Apple ID Madness
Random Stuff | May 4, 2014 - 1100 Words |
How we set up multiple personal iCloud accounts for the family, and a couple of shared accounts for parents and kids.
-
It's time to (re)start.
Random Stuff | May 2, 2014 - 300 Words |
-
Apple, Forensics, Law Enforcement, and FUD
Information Security | May 13, 2013 - 1400 Words |
-
DBIR Cover Challenge 2013
Puzzles, Fun, Games | Apr 29, 2013 - 2400 Words |
-
Fidelis Security Systems' Decode This 2012
Puzzles, Fun, Games | Aug 17, 2012 - 1200 Words |
-
2012 Verizon DBIR Cover Challenge
Puzzles, Fun, Games | Mar 28, 2012 - 3700 Words |
-
Verifying a Detached S/MIME Signature in Python
Information Security | Feb 21, 2012 - 600 Words |
-
BSides Phoenix 2012 Badge Puzzle
Puzzles, Fun, Games | Feb 19, 2012 - 1500 Words |
-
ShmooCon 2008 Badge Puzzle
Puzzles, Fun, Games | Feb 4, 2012 - 1900 Words |
-
ShmooCon 2012 Badge Puzzle
Puzzles, Fun, Games | Feb 3, 2012 - 1800 Words |
-
How to Lose $1000 in Vegas Without Even Gambling
Puzzles, Fun, Games | Aug 30, 2011 - 1900 Words |
-
First Anniversary
Random Stuff | Aug 23, 2011 - 600 Words |
-
Great Googly Moogly! I'm speaking at Black Hat!
Information Security | Jul 28, 2011 - 800 Words |
-
DEF CON 16 Punch Card Puzzle
Puzzles, Fun, Games | Jul 27, 2011 - 1400 Words |
-
CarolinaCon Flag Puzzle
Puzzles, Fun, Games | May 8, 2011 - 1800 Words |
-
Analysis of iOS Location Data from Multiple Devices
Information Security | Apr 25, 2011 - 2100 Words |
-
The 2009 Verizon Data Breach Investigation Report
Puzzles, Fun, Games | Apr 12, 2011 - 1500 Words |
-
Crazy idea for multi-user iPads
Random Stuff | Feb 25, 2011 - 700 Words |
-
Simple Bypass of Safari Restrictions on iOS
Information Security | Feb 15, 2011 - 600 Words |
-
ShmooCon 2011 Badge Contest
Puzzles, Fun, Games | Feb 9, 2011 - 4400 Words |
-
Breaking a 147-Year-Old Message
Puzzles, Fun, Games | Dec 30, 2010 - 4000 Words |
-
Nails in the Crypt
Information Security | Dec 22, 2010 - 800 Words |
-
ToorCon 12 Badge Puzzle
Puzzles, Fun, Games | Dec 6, 2010 - 4500 Words |
-
THOTCON Pre-Sale Code Puzzle
Puzzles, Fun, Games | Nov 22, 2010 - 2700 Words |
-
DEF CON 18 Crypto Challenge
Puzzles, Fun, Games | Sep 2, 2010 - 3700 Words |
-
ShmooCon 2010 Badge Contest
Puzzles, Fun, Games | Aug 29, 2010 - 2500 Words |
-
QuahogCon Flag Puzzle
Puzzles, Fun, Games | May 20, 2010 - 1900 Words |
-
THOTCON 0x1 Puzzle
Puzzles, Fun, Games | May 11, 2010 - 2900 Words |
-
ShmooCon 2009 Badge Contest
Puzzles, Fun, Games | Apr 27, 2010 - 2000 Words |
-
Crazy Security Con Weekend!
Information Security | Apr 23, 2010 - 500 Words |
-
Blind Belief vs Excessive Skepticism
Random Stuff | Apr 20, 2010 - 1300 Words |
-
Half-Baked Idea: Isolate Browser Security Contexts to Limit XSS Attacks
Information Security | Apr 14, 2010 - 1300 Words |
-
It's Time To Start
Random Stuff | Apr 14, 2010 - 200 Words |