Ryan Basden's Avatar

Ryan Basden

@ryanbasden.com

Independent contractor at @ empiricsecurity.com #1 photography account about hacking. Previously: @bishopfox.bsky.social Red Team @risk3sixty Pentesting Practice Lead

82
Followers
107
Following
82
Posts
09.08.2023
Joined
Posts Following

Latest posts by Ryan Basden @ryanbasden.com

Preview
Ocean's Eleven Heists In a Louvre Four World Are physical security assessments a fun novelty? Or are fewer businesses taking them as seriously as they should?

I really love breaking into buildings, but when clients have asked me about the specific threat model, I haven't had a great answer. Here's my attempt at figuring it out.

empiricsecurity.substack.com/p/oceans-ele...

02.03.2026 16:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Oh, this? Yeah, I only use AI on the command line. I’m a bit of a power user. ChatGPT? I’ve heard of it, but Claude just sort of gets me, you know? Plus it understands my Vim commands, so the mental load is almost nonexistent. Vim? Yeah, hard to explain, you might be better off with the web UI.

01.03.2026 14:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

- Key Steps to Ensuring Your Purple Team Fails Miserably
- Guerrilla Metric Reporting Warfare for Technical Teams
- The Only Difference Between Felons and Professionals is Getting Caught
- There's Always a Bigger Phish: Internal Messaging as Forbidden Fruit

21.02.2026 16:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Spicy blog drafts I've had in the hopper for a long time:

- How to Fool Your PCI Auditor and Get That Bag
- Continuous Pentesting or Just Continuous Vulnerability Management?
- Your Executives Make Phishing Easier For Me and My Friends
- A Song of Supply Chains and Drive-By 0-days

21.02.2026 16:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

If @bsky.app could add TOTP as an MFA option instead of emailing me a code that is not only case sensitive but doesn't use a font that clearly differentiates between uppercase O and the number 0, that would be fantastic.

14.02.2026 18:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

stop being so conscientious and considerate, this is infosec

13.02.2026 16:29 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
How Shadow Incentives Harm Real Security Despite the millions upon millions of dollars thrown at penetration testing ever year, big data breaches are still as common as ever.

We’ve all seen it: the "compliance-first" mindset that checks every box while leaving the front door wide open, but out of scope.

If you’re tired of the theatre and actually want to move the needle, give this a read.

empiricsecurity.substack.com/p/how-shadow...

12.02.2026 23:58 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

One more stressful event away from making disappearing into the woods part of my personality

14.01.2026 15:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Have you guys checked out your Kroger 2025 Wrapped yet

09.01.2026 21:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

beep beep boop

20.12.2025 21:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Some of the best hackers I know still manage to overestimate their expertise in completely unrelated fields, medical science being a big one. I can go from soaking in some arcane tech wisdom to fielding batshit takes about vaccines in the span of a few seconds with some of you guys. Why?

20.12.2025 19:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Every time I go on a podcast as a guest, I spend the next 24 hours trying to remember if I said anything painfully stupid that will tank my career.

03.12.2025 16:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Does Bluesky really still not support TOTP? Can I stop having to copy a code from my email and remove the backticks that it includes?

01.11.2025 19:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

STOP CALLING IT VISHING AND SMISHING

YOU SOUND LIKE A FUCKING TODDLER BABBLING NONSENSE

ITS PHISHING OR SOCIAL ENGINEERING

REEEEEEEEE

03.09.2025 16:16 πŸ‘ 37 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1

Watch out for people who take your personal growth personally.

19.08.2025 16:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Working on a conference talk

13.08.2025 21:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

"nano is for babies" - crontab

07.08.2025 17:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Smartsheet Forms

app.smartsheet.com/b/form/05da2...

23.07.2025 18:43 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

ISACA Atlanta is hosting 404con, a technical security conference, on October 14th and 15th, and they're looking for talk submissions for the hacking track. If you live in the area and would like to speak, check out the link below!

23.07.2025 18:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It's a personal conviction of mine that, for how much of the tech industry operates out of Atlanta, there is a serious lack of quality security conferences and communities. But I know some people trying to change that.

23.07.2025 18:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Solving Dumb Hacker Problems With Nix | Ryan Basden
Solving Dumb Hacker Problems With Nix | Ryan Basden YouTube video by Wild West Hackin' Fest

Most fun I've ever had speaking at a conference, hands down. If you were there at @wildwesthackinfest.bsky.social , you were the best audience a guy could hope for.

www.youtube.com/watch?v=Vrtp...

23.07.2025 14:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I would simply write memory-safe code

03.07.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Saait: a boring HTML page generator - Codemadness Saait: a boring HTML page generator

codemadness.org/saait.html

16.06.2025 19:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Laptop numpads are psychotic, why do I have to overextend my right shoulder just to type

16.06.2025 14:31 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Finally getting around to watching Chernobyl and all I see is a bunch of MBAs making fun of technical experts and high-fiving

11.06.2025 15:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If there's anything I can count on BlueSky for, it's showing me all of the stuff I've painstakingly worked to not have to look at on Twitter.

06.06.2025 13:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Dystopian Dream Team

"In addition, ChatGPT doesn’t just itself fail to recognize the difference between fact and fiction, it presents these answers to people who are themselves unable to discern the difference."

lmnt.me/blog/the-dys...

29.05.2025 16:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

A little tired of getting random junk in conference "swag bags", can I opt out? I don't need fifty branded drawstring bags that I'm just going to donate and might eventually end up in a landfill.

20.05.2025 16:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

iPad babies can be any age.

19.05.2025 19:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Hey Gemini, which spreadsheet does this company store passwords in

21.04.2025 16:35 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0