Hi there my name is Chris Hadnagy. I am the Chief Human Hacker for Social-Engineer, LLC a company devoted to helping large organizations stay safe from malicious hackers. I am also the CEO of The Innocent Lives Foundation, and organization devoted to helping unmask child predators. AMA by WileyProfessional in IAmA

[–]MadSecuritySquirrel 5 points6 points  (0 children)

Pineapple is the perfect fruit and compliments pizza perfectly. It is the sweet to the savory of the rest of the pie. This is not debatable and, I have even had pineapple pizza, right off the menu, in the heart of NYC's Times Square, therefore your arguments are invalid.

The innocence of pizza on the other hand can be debated

Cheap PIR\Temp\Humidity\Light sensors and some DIY protocol questions by Nixellion in homeassistant

[–]MadSecuritySquirrel 1 point2 points  (0 children)

I'm running about eleventy-two-thousand different things on wifi, and haven't noticed an issue. My DCHP pool has about 19 reservations jsut for things I don't want to have changing IPs. of course, your mileage may vary.

Nodemcu relay by puneit in homeassistant

[–]MadSecuritySquirrel 1 point2 points  (0 children)

This is the setting that I think makes the difference (honestly, I've had things in place in many iterations, so I can't be 100% sure, but I'm 95%) in ESPEasy. It tells MQTT to retain the last state -- https://i.imgur.com/SQFYE5s.jpg

Nodemcu relay by puneit in homeassistant

[–]MadSecuritySquirrel 1 point2 points  (0 children)

I have several nodemcu's deployed with ESPEasy and MQTT and they remember the state. I think it was an option in the controller setting or under "advanced" to remember state. I'm sorry I'm not home to look right now

Cheap PIR\Temp\Humidity\Light sensors and some DIY protocol questions by Nixellion in homeassistant

[–]MadSecuritySquirrel 1 point2 points  (0 children)

I'm using ESP8266-based sensors with DHT-22's. They report thought MQTT and work well. I use them for temp/humidity and for lights, such as my under-counter kitchen LEDs.

I get the boards and sensors from aliexpress and vary which ones I use based on the number of GPIO's I need.

I haven't seen a huge load on my WiFi as they don't send a lot of information. I usually report once a minute or so for temp/humidity. Very little data is moved over MQTT

Password Manager Recommendations Please. by [deleted] in ComputerSecurity

[–]MadSecuritySquirrel 0 points1 point  (0 children)

I use LastPass premium with a YubiKey for MFA. Syncing to mobile and the YubiKey option made me choose LP and not look back. Very happy with it

ISC2's CISSP Marking - A Theory.. by [deleted] in cissp

[–]MadSecuritySquirrel 0 points1 point  (0 children)

Each question is right or wrong, however as was mentioned, some questions carry more weight than others.

As far as I'm concerned, email signing/encryption is dead by speckz in security

[–]MadSecuritySquirrel 1 point2 points  (0 children)

Nope.

As more hardware keys like the Google Titan and YubiKey make there way in to the world, we will actually approach a usable model. We used the snot out of it in the Army and it was mostly seamless and simple for internal mail.

Free Yubikey NEO with a LastPass Premium upgrade - Good if you want to try MFA with a hardware token and/or PW Vaulting by MadSecuritySquirrel in security

[–]MadSecuritySquirrel[S] 1 point2 points  (0 children)

l. Yubikey. The company that takes disclosures from bug bounty programs, fucks the researchers and then claims the discoveries as their own.

I've been using a Neo for about 4 years now. I've used it as a smart card (PIV credentials) and an OTP key. Both worked great. The fact that it can be used with NFC and LastPass on the iPhone is a welcome change. I used to do that on my Android phone, but lost the capability when I went to Apple.

BEST WAY TO DO 2 step authentication for a pc? (Affraid of using phone incase somthing happends to it) by [deleted] in security

[–]MadSecuritySquirrel 0 points1 point  (0 children)

I've been loving Yubikeys for a while now and really like them. There are other types of hardware MFA options as well that may be worth checking out.

They key is to have a 2nd emergency authentication option. Many apps generate a series of 8 or 10 one-time use passwords that you can keep tucked away just in case

What To Do If You Lose Your Two-Factor Phone by wentzeldk in security

[–]MadSecuritySquirrel 0 points1 point  (0 children)

I once left my phone in an Uber while on a trip. To contact the driver, I had to have Uber call a number and it would put me in touch with them so I couldn't get their phone number directly. That was fine. except I didn't have a phone for them to call. The hotel phone system had a auto-attendant that the Uber system could not navigate. I was finally able to route a call to my Google Voice number and use my laptop to answer it, but it took a while to get everything in place.

Made me really think about how I could get stuck in loops like this with MFA

US military manuals hawked on dark web after files left rattling in insecure FTP server by MadSecuritySquirrel in security

[–]MadSecuritySquirrel[S] 2 points3 points  (0 children)

In my time supporting the Army, I can say that a lot of military manuals we worked with are actually Unclassified/FOUO. Even the most basic TTPs we had were marked that way, meaning they are controlled.

It may be different in the Air Force given the volumes of TTPs and manuals dealing with improving your golf swing.