What happened to the site
Everything from 2014 through 2019 is restored, images and all… the Alienware and Buffalo Wild Wings disclosures, the MongoDB ransom research, the Arris and NetGear write-ups, the password manager rant, and the political pieces I told myself I would stop writing. The old links still work. If you find something broken, tell me.
I also went back and read all of it. Some of it aged well. Some of it did not. I am leaving it up either way. A researcher who deletes the posts they got wrong is not a researcher… they are a marketer.
About that “no politics” promise
Back in 2017 I wrote that I was done posting political opinions here and would stick to research. I meant it. I also failed at it within a year, because it turns out you cannot write honestly about information security without writing about who controls information. Net neutrality was a security story. The government “shutdown” theater was a security story. Every leak, every “whistleblower,” every election cycle… security story.
Simply put, the two subjects stopped being separable, if they ever were. So I am dropping the pretense. This blog is about how information is protected, stolen, controlled, and weaponized. Sometimes that means a database left open on the internet. Sometimes that means a government or a company deciding what you are allowed to know. I will call both what they are.
What has not changed: I deal in things I can verify. If I do not have data or first-hand knowledge, I will say so or I will keep my mouth shut. The internet has enough people who are experts on everything.
What is coming
- Exposed data, again. In 2017 I found almost fifteen thousand open MongoDB servers in the United States and watched nearly all of them get ransomed inside ten days. The technology has changed. The mistake has not. I have been looking at what is sitting open on the internet right now and [a sentence about what you have been finding].
- Research and disclosures. I still find holes. I still report them. I will still write about the ones I am allowed to write about, and I will still name the companies that ignore the report and then get breached. Legal is not my enemy, but it is not my editor either.
- Information control. Who gets to see what, who decides, and what it costs when they get it wrong. Leaks, censorship, surveillance, “awareness” campaigns that exist to raise money, and the propaganda that buries the real victims.
- Tools. I have newer things to release once they are cleaned up enough that I am not embarrassed by them. One of which is… something special. It is called project SUNDERKEY.
- The basics, because nobody does them. Password managers, source control hygiene, not exposing database servers to the planet. Boring. Still the cause of most breaches.
Ground rules
Same as they have always been. Have written consent before you test anything. Know what is in scope. Know the law, because the company that invited you in is not the one who will prosecute you. Don’t be stupid.
And for readers: research something. Anything. Then share what you actually found, not what you were told to be angry about.
I can’t promise a schedule. I never could. But the popcorn is back out, and there is plenty to watch.
Remember… computers have no agenda. People do.