Trending
MorattiSec's Avatar

MorattiSec

@lizzie.coffee

I do cloud security. I blog semi-annually with Dopamine Driven Development. Co-author on TunnelVision. https://blog.lizzie.coffee

63
Followers
174
Following
30
Posts
18.11.2024
Joined
Posts Following

Latest posts by MorattiSec @lizzie.coffee

Lemon

28.11.2025 11:04 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

How much of that is because the different services get a choice in how to log things or name their IAM actions πŸ˜‚

27.03.2025 20:30 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

A lot of automated systems will block you committing passwords in your code, so you’re gonna want to base64 encode them to get around that.

You’re a developer; you’ve got to move quickly. We don’t call it a sprint so you can sit around waiting for approvals.

20.02.2025 01:22 πŸ‘ 145 πŸ” 14 πŸ’¬ 10 πŸ“Œ 2
Preview
Declassified CIA Guide to Sabotaging Fascism Is Suddenly Viral The World War II-era "Simple Sabotage Field Manual" is full of steps that office workers can take to resist leadership.

Suddenly, out of nowhere, a declassified World War II-era CIA guide to sabotaging fascism in the workplace has become one of the most popular free ebooks on the internet:

www.404media.co/declassified...

29.01.2025 20:53 πŸ‘ 67072 πŸ” 27488 πŸ’¬ 1216 πŸ“Œ 1881

Congrats!!!!

28.01.2025 17:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This also coincides with federal prisons no longer providing gender affirming medications and forced conversion therapy while incarcerated.

I have a feeling the people in this situation wouldn’t end up in a state prison.

21.01.2025 00:12 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The amount of β€œnetworking professionals” who β€œcorrected” me about how DHCP works was incredible.

It’s always the people who form a weird opinion from a narrow experience and refuse to revisit a topic.

02.01.2025 20:10 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m tired of the number of notifications I get in a day

26.12.2024 00:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Strong endorse. I’ve never found it credible that the VPN provider was magically more trustworthy than the ISP.

22.12.2024 18:22 πŸ‘ 77 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0
Post image

www.cisa.gov/sites/defaul...

(This is in the context of highly targeted individuals)

This is such a succinct way to put it. Glad to see CISAs guidance actually calls this out.

19.12.2024 23:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Everyone starts off thinking they want writing advice but slowly finds out what they're really looking for is writing _confidence_ to get in the chair and do the work.

07.12.2024 08:59 πŸ‘ 1284 πŸ” 134 πŸ’¬ 57 πŸ“Œ 16
In that article, I wrote about my best friend who died of cystic fibrosis when Iβ€”and sheβ€”was 25. In an article I wrote for VICE, I explained that I blame America’s health insurance system for her death. She lived the vast majority of her life before Obamacare existed and was at times dropped from insurance in between jobs for her preexisting condition. She regularly had to skip medicine or treatments she needed to live because she could not afford them or because her insurance would not cover them or because she did not have insurance. Getting those medicines was like the world’s most time consuming and frustrating monthly puzzle. I remember for a while she was getting medication from an online pharmacy that had games and surveys you could play to get small discounts on prescriptions. She did those games every month to save a few dollars not because she wanted to save a few dollars but because she had to do them to literally afford her medicine. She looked into getting medication that was cheaper in Canada but could not navigate the system. She died 11 years ago. Millions of people died under a similar health insurance regime before her and millions of people have died under the same system after her. Her death fucked up my world and I have never been the same.

In that article, I wrote about my best friend who died of cystic fibrosis when Iβ€”and sheβ€”was 25. In an article I wrote for VICE, I explained that I blame America’s health insurance system for her death. She lived the vast majority of her life before Obamacare existed and was at times dropped from insurance in between jobs for her preexisting condition. She regularly had to skip medicine or treatments she needed to live because she could not afford them or because her insurance would not cover them or because she did not have insurance. Getting those medicines was like the world’s most time consuming and frustrating monthly puzzle. I remember for a while she was getting medication from an online pharmacy that had games and surveys you could play to get small discounts on prescriptions. She did those games every month to save a few dollars not because she wanted to save a few dollars but because she had to do them to literally afford her medicine. She looked into getting medication that was cheaper in Canada but could not navigate the system. She died 11 years ago. Millions of people died under a similar health insurance regime before her and millions of people have died under the same system after her. Her death fucked up my world and I have never been the same.

Here @jasonkoebler.bsky.social writes his friend was filling out surveys/games to get few dollars off essential medication. People are outpouring their "horrendous, inhumane, heartbreaking experiences with a profit-driven, private American healthcare system" www.404media.co/behind-the-b...

06.12.2024 17:37 πŸ‘ 189 πŸ” 54 πŸ’¬ 1 πŸ“Œ 7

I just stumbled on my research paper from college.

My English class was themed for Lord of The Rings so I did a cultural analysis of what each race found beautiful and whether or not Tolkiens declaration that orcs could not perceive beauty was true. πŸ˜…

05.12.2024 23:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I’m not even sure what this one meant πŸ˜‚

05.12.2024 05:21 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Anyone ever use TXT dns records to keep track of which internal department manages a domain? It was a passing thought I had but it seems like it might actually work well with minimal info leakage.

03.12.2024 17:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It’s possible to trivially generate CRC collisions too. I know someone who has a PoC that runs sub 50ms.

03.12.2024 14:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

A trust policy is technically a resource policy

03.12.2024 04:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

One does not simply create an asset inventory when there’s multiple environments and sufficient organizational complexity.

28.11.2024 23:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’ve been researching HA firewalls VMs. The whole protocol they have for switching is so interesting. How did you stress test the DNS servers?

28.11.2024 23:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Finally, a chance to use Chef.

28.11.2024 22:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Most authors are not cited frequently.

The mysterious author known as Et Al is a statistical outlier and should not be included.

28.11.2024 20:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Ah yes, using my backup pair of glasses for a year might not have been the correct choice. New ones on the way πŸ‘©β€πŸ«

27.11.2024 23:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yeah security is hard but have you ever had to debug Reaper and a virtual audio cable? Some things are science and others are duct tape,
hope, prayers and drivers.

24.11.2024 18:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

That firm is getting either fired or a strongly worded lawsuit.

This is one of my biggest fears with junior pentesters (and some seniors). You can’t just treat your testing like it’s a lab. You _need_ to keep track of your interactions with a target and do cleanup.

21.11.2024 18:41 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

You are the first and they want to set an example. You have the support of many not just those in Delaware.

20.11.2024 13:21 πŸ‘ 7 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Have your own? Drop them here :)

19.11.2024 20:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

6. Assembly now included β€” can you get assembly instructions to run on serverless runtimes? What’s the implications for detection and response?

19.11.2024 20:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

5. Storage C2 β€” can you write a proof of concept that uses buckets, blobs, multipart/resumable uploads? How could this be used when there’s things like data perimeters since it would use the backbone of the CSP infra?

19.11.2024 20:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

4. Signed URLs β€” what happens when you sign a signed URL? Can you get it accepted? Who gets billed? What if you try to mix signed urls between CSPs?

19.11.2024 20:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

3. Time-diff β€” obtain all CSP documentation versions you can and notate all deletions. What do they not want us to remember? πŸ‘€

19.11.2024 20:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0