shellsharks
@shellsharks.com
π€ 2835
π₯ 278
π 206
Infosec researcher | more about me @
https://shellsharks.com
@
[email protected]
on Mastodon
pinned post!
Serious question - How will the Bsky team defend against or respond to a Trump/Musk offensive against bsky itself? Bsky is turning into a top competitor of both of their platforms and is certain to harbor posts both of them would not like. Where are the servers/infra hosted? The team members?
over 1 year ago
6
19
5
reposted by
shellsharks
Catalin Cimpanu
15 days ago
Security researcher Shellsharks has created Vulnerability.Garden, a catalog of named vulnerabilities. So far, we're 25 vulnerabilities away from 1K branded security bugs. Don't worry,
@shellsharks.com
... we'll get you there!
vulnerability.garden
2
9
4
reposted by
shellsharks
Vale
about 1 year ago
I put together a little post about my writing mannerisms. I'd once again like to blame
@shellsharks.com
for his provocation. He can't keep getting away with this! I should block his domain...
vale.rocks/posts/writin...
#Writing
#WritingCommunity
#WriterSky
loading . . .
My Writing Style and Mannerisms
Stay tuned for my writing manorialism.
https://vale.rocks/posts/writing-style-and-mannerisms
0
6
2
reposted by
shellsharks
B:\a.zza
over 1 year ago
Roses are Red Apples are fruit I should have sanitised this inputAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA ββ# id uid=0(root) gid=0(root) groups=0(root) Now I am root!
2
77
24
reposted by
shellsharks
Vale
over 1 year ago
Just redesigned my website's landing page as it was starting to feel a tad stale. I blame
@shellsharks.com
for prompting this with their recent redesign.
vale.rocks
loading . . .
Vale.Rocks
The hippest site this side of MySpace.
https://vale.rocks
0
4
2
#Tapestry
is the best Bluesky client just because it keeps track of where I last read in the timeline. Makes this platform kinda usable for me now at least to keep up with some of y'all
usetapestry.com
loading . . .
Tapestry
Weaving your favorite blogs, social media, and more into a unified and chronological timeline.
https://usetapestry.com/
over 1 year ago
0
3
0
reposted by
shellsharks
Reilly Spitzfaden (they/them)
over 1 year ago
"It wouldnβt be hard for a billionaire or a hostile government to take down one, two, three or maybe even 10 Bluesky relays. But it seems wholly impractical for a billionaire, or a team of billionaires to snuff out thousands of Fediverse instances."
shellsharks.com/notes/2025/0...
#FreeOurFeeds
loading . . .
Bluesky won't free your feed
Cybersecurity Research and More
https://shellsharks.com/notes/2025/01/15/bluesky-wont-free-your-feed
1
4
1
reposted by
shellsharks
shellsharks
over 1 year ago
It's been a while since I've published something I consider a "blog post" on my site. But thanks to @ApisNecros tossing over the "Blog Questions Challenge", this now exists -->
https://shellsharks.com/get-to-know-my-blog
Turns out, I've answer much of these questions in various places across [β¦]
loading . . .
Original post on malici.ous.computer
https://malici.ous.computer/@shellsharks/statuses/01JHNWWGC4TD5PAE7BSW6PNV3R
0
0
2
reposted by
shellsharks
shellsharks
over 1 year ago
Okay, so Cory Doctorow published his take on the
#freeourfeeds
thingy, all about "billionaire-proofing" the Internet (or more accurately, billionaire-proofing social media), and I have some thoughts...
https://pluralistic.net/2025/01/14/contesting-popularity/#everybody-samba
His main argument [β¦]
loading . . .
Original post on malici.ous.computer
https://malici.ous.computer/@shellsharks/statuses/01JHN5A9844W3SMPE2A39K0V4J
1
3
27
reposted by
shellsharks
Emma (IPG)
over 1 year ago
something i hope more people do on bsky is follow
@ap.brid.gy
. especially large/notable accounts . it bridges your account to Mastodon meaning people using Mastodon instances can see your posts and interact with you
9
75
39
reposted by
shellsharks
Catalin Cimpanu
over 1 year ago
Positive Technologies has developed a new attack that exploits the SD Express standard to gain access to a device's memory through its SD card reader The DaMAgeCard attack exploits the fact that the new SD Express standard can operate in both SDIO and NVMe
swarm.ptsecurity.com/new-dog-old-...
4
59
28
This article has been shared by a lot of folks here, but to not a lot of response/discussion.
techcrunch.com/2024/12/05/b...
Is this a collective stick-fingers-in-ears-and-go-la-la-la moment for the bsky populace? *Stream of consciousness incoming*...
loading . . .
Bluesky CEO Jay Graber isn't ruling out advertising | TechCrunch
Bluesky has blown up this year thanks to a vibrant community of posters, user customization choices, and a decentralized protocol that doesn't lock users
https://techcrunch.com/2024/12/05/bluesky-ceo-jay-graber-is-reshaping-social-media-but-advertising-isnt-off-the-table/?guccounter=1
over 1 year ago
2
1
0
What's best? Bsky, Mastodon (Fediverse) or Threads? Trick question! Just having a personal blog/website is best. π
over 1 year ago
1
4
0
and like that, the
#Fediverse
has Starter Packs. Competition is good! The bsky team has some good ideas and with any luck, the popularity of good features here will continue to propel other complimentary networks forward.
fedidevs.com/starter-packs/
My
#IndieSec
starter pack:
fedidevs.com/s/MjQ/
loading . . .
Mastodon Starter Pack Directory | Fedidevs
Discover amazing developers from across the fediverse.
https://fedidevs.com/starter-packs/
over 1 year ago
0
1
0
reposted by
shellsharks
Eric Capuano
almost 4 years ago
Nice -- someone put together a Threat Modeling Field Guide. Great high-level overview for any org that's at this step in their maturity.
https://shellsharks.com/threat-modeling
loading . . .
The Enchiridion of Impetus Exemplar
A vade mecum for all things Threat Modeling.
https://shellsharks.com/threat-modeling
1
5
1
Man, Bluesky would actually be kinda usable for me if it would just remember my timeline position and let me scroll through everything I've missed. Letting me post more than 300 chars would also be nice but at least it has the ability to create an entire thread of posts and publish simultaneously
over 1 year ago
2
9
1
How does Bluesky's (domain-based) "verification" help the countless high-profile (and low-profile tbh) people who don't have domains/ well-known sites? How can Brad Pitt verify himself here?
shellsharks.social/@shellsharks...
loading . . .
shellsharks (@
[email protected]
)
This *is* an elegant way to "verify" someone, but only if they *have* a website and really only if that website is kinda *known* as being officially associated with that individual. How would this for...
https://shellsharks.social/@shellsharks/113526792835797334
over 1 year ago
2
0
0
reposted by
shellsharks
ChiefGyk3D
over 1 year ago
We need a feed for Threat Intel on Bluesky for us
#Cybersecurity
and
#Infosec
people. Something to share CVE's, attacks, and such rather than just the typical cybersecurity news.
9
101
12
Introduce yourself with four video games. - Jill of the Jungle - Super Mario World - Ultima Online - Halo Bonus: Diablo 3
add a skeleton here at some point
over 1 year ago
1
3
1
Hey, if you write about
#infosec
/
#cybersecurity
let me know what your website/blog is so I can add it here
shellsharks.com/infosec-blogs
and also sub in my RSS reader!
loading . . .
Infosec Blogs: Our Cup Runneth Over
A list of boutique and commercial information security blogs.
https://shellsharks.com/infosec-blogs
over 1 year ago
0
2
0
reposted by
shellsharks
Laura Siadak
over 1 year ago
Dragon Yawns the Universe Acrylic and marker on yupo paper ugh what year was this... it was a good art year. 2012
3
158
50
reposted by
shellsharks
TribesmanJohn
over 1 year ago
I have complex feelings about Bluesky, but I do feel like it's got the attention of the public in a way that mastodon didn't and is where many of my twitter friends will migrate to. Thankfully
@shellsharks.com
wrote a fantastic article about this:
shellsharks.com/notes/2024/1...
#socialmedia
#bsky
loading . . .
Cloudy with a chance of not enshittifying
Cybersecurity Research and More
https://shellsharks.com/notes/2024/11/15/cloudy-with-a-chance-of-not-enshittifying#title
0
2
1
I know it's not *cool* to talk about Mastodon here, and I'm not even here to tell you it's "better". What's better for anyone is completely subjective. I just wanted to say that it's pretty cool that I run my own, completely isolated, yet federated and connected instance for less than $20/mo.
over 1 year ago
1
2
0
Bluesky's got that Threads in 2023 energy. Now, less than 2 years later, you see how it's goin over there... still chuggin' but honeymoon period def over. Enjoy while it lasts!
over 1 year ago
1
2
0
It's a work in progress, but here's the "FediSec" starter pack featuring infosec/cyber folks from the Fediverse who are bridged here via Bridgy Fed. Note: Included in the pack is
@ap.brid.gy
which when followed will bridge your Bluesky account back to the Fediverse. Woo!
go.bsky.app/EaxWS7g
add a skeleton here at some point
over 1 year ago
1
0
0
reposted by
shellsharks
raptor
over 1 year ago
Hey everyone, here's again my
#introduction
, for
#bsky
users via https://fed.brid.gy/ (hopefully that works). I'm a seasoned offensive
#security
researcher with 25+ years of experience. As a professional
#hacker
and polyglot programmer of weird machines, I study how things can go wrong. Some [β¦]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@raptor/113494070046381330
0
4
2
reposted by
shellsharks
Damon ο£Ώ
over 1 year ago
Please educate newcomers on using bridgy fed to bridge their accounts to the
#Fediverse
this is an excellent tool for not needing an account on bsky and Mastodon while strengthening the open social web.
fed.brid.gy
#introduction
#welcometobsky
loading . . .
Bridgy Fed
https://fed.brid.gy/
5
65
40
Is there a Bluesky client that would allow me to write more than 300 characters? I'm pretty sure 300 chars isn't a limitation of the protocol so it must be possible. I feel like for posts, but especially for replies, you often need more room to say something actually thoughtful. Can't just be me!
over 1 year ago
3
3
0
reposted by
shellsharks
shellsharks
over 1 year ago
Report - Trump nominates Jia Tan as director of CISA
1
6
1
I promise this isn't a hit piece about Bluesky. But for everyone who has recently left place A to come to place B(luesky), wherever place A may have been for you - I think you might have something to takeaway by reading. Let me know what you think, good or bad. It's how I learn π
add a skeleton here at some point
over 1 year ago
2
6
2
Bluesky.com
website doesn't even have a Bluesky social link. Ouch
over 1 year ago
0
0
0
reposted by
shellsharks
Fran Donoso
over 1 year ago
Hey new folks, welcome to BlueSky! My name is Fran and I run the following
#cybersecurity
feed:
bsky.app/profile/did:...
I'll be working keep it spam free & good. If you're curious here are the keywords I'm looking for:
gist.github.com/francisck/d8...
Please provide feedback if you have any.
add a skeleton here at some point
13
81
20
Serious question - How will the Bsky team defend against or respond to a Trump/Musk offensive against bsky itself? Bsky is turning into a top competitor of both of their platforms and is certain to harbor posts both of them would not like. Where are the servers/infra hosted? The team members?
over 1 year ago
6
19
5
You made it to Bluesky! Things are growing and active here which is great! But did you know you can connect with even MORE people through the "Bridgy Fed" bsky βοΈ Fediverse bridge? (
fed.brid.gy
) For example you can follow my Mastodon account from Bsky!
@shellsharks.shellsharks.social.ap.brid.gy
loading . . .
Bridgy Fed
https://fed.brid.gy/
over 1 year ago
1
3
1
Funny how no one ever cares about being in the top apps of the Google Play store π Also...
add a skeleton here at some point
over 1 year ago
0
1
0
Mastodon: "democracy dies in darkness" Bsky: "democracy dies in darkness" Threads: "lol, here's some Lord of the rings memes" X: (wouldn't know, don't wanna know)
over 1 year ago
0
1
0
All you *.bsky.social people... buy a domain!!! It's like... $6?
over 1 year ago
2
2
1
I'm
#OpenToWok
- could really go for Hibachi like any time.
over 1 year ago
1
1
0
They 100% need a monetization model. Don't think these *specific* features are going to get enough overall buy-in, but it's a start! The community-funded model (think Mastodon instances) has shown it can work. Premium features over selling user data / ads is a must must must!
add a skeleton here at some point
over 1 year ago
1
2
0
Is there a best/definitive guide to hosting/standing up a
#ATproto
#PDS
someone can recommend me?
over 1 year ago
2
2
0
@howelloneill.bsky.social
hey! Wouldn't mind being added to the cyber starter pack! Appreciate it!
over 1 year ago
0
1
0
I can't have bluesky becoming good or relevant for me. I spend too much time on social media (Mastodon/Threads) as it is π€¦ββοΈ
over 1 year ago
2
2
0
reposted by
shellsharks
ChiefGyk3D
over 1 year ago
Tried my hand at making my first starter pack as I couldnβt find some for
#IT
,
#Infosec
, and/or
#cybersecurity
and I saw
@shellsharks.com
asking for one too. Feel free to give feedback
go.bsky.app/QYMa3yN
add a skeleton here at some point
8
42
16
Now is there an
#infosec
/
#cybersecurity
starter pack?
over 1 year ago
1
3
1
reposted by
shellsharks
shellsharks
almost 2 years ago
Almost two years ago, I published this relatively exhaustive "threat modeling field guideβ which seeks to describe and illuminate the multitude of threat modeling methodologies/frameworks that exist (e.g. PASTA, OCTAVE, Trike, LINDDUN, VAST, TARA, IDDIL/ATC, hTMM, QTMM, Microsoft TM, NIS SP [β¦]
loading . . .
Original post on shellsharks.social
https://shellsharks.social/@shellsharks/112830853523851037
0
1
2
Mastodon has been bridged to bsky, follow me on bsky here!
@shellsharks.shellsharks.social.ap.brid.gy
πππ¦
about 2 years ago
0
0
0
reposted by
shellsharks
Matt Pogue
about 2 years ago
1/For my fellow tech nerds, you need to check
shellsharks.com
! Aside from being awesome enough to include a link to my blog, it's got TONS of great content. Honestly, it's inspirational, in that it's what I'd like my blog to become. In addition,
@shellsharks.com
is fully on board with the Fediverse.
add a skeleton here at some point
1
1
1
Link roundup related to xz/liblzma compromise (CVE-2024-3094)
shellsharks.com/xz-compromis...
loading . . .
xz/liblzma Compromise Link Roundup
Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094)
https://shellsharks.com/xz-compromise-link-roundup
about 2 years ago
1
2
1
Is there a way to make Bsky timeline not snap to latest post in the home timeline? I'd like to be able to read through all "unread". Maybe a third-party client has this or it's a setting in the native client I've missed??
about 2 years ago
0
0
0
Load more
feeds!
log in