#general
1 messages Β· Page 1459 of 1
I'm confused about Passkeys
If you use passkeys and a theif takes your devices and guesses your pin, then they can login to all the sites you used passkeys on.
Sure it's more secure from a remote standpoint since there is public and private key, but if you use a password manager which forces a login, then they would have to know that too, not just your windows pin
Yet, they say Oh, it's more secure!
Hi
Hello Honeycomb, how are you?
Its going okay
Are you learning a lot?
Yes
HI Chrollo
everyone is confused about passkeys, including the fido alliance apparently
it's.... problematic to say the least
Well that's good to hear. I don't like where all this is headed lol.
the original pitch for passkeys was effectively "hardware attestation" or "hardware backed keys"
with the obvious downsides to that still being "if you lose the hardware, you're locked out"
as it has always been
well, turns out user friction is too big of a problem and that wasn't going to fly for adoption
so modern passkeys have turned into "hardware backed except not really, they can be transferred between devices because they are effectively just stored in your password manager anyways"
and a lot of the "promise" of their security and utility doesn't really go so well with that just from a conceptual level
so now it's just a really annoying psuedo-password that doesnt achieve the things they seem to claim it will, at least not all of them
If the hardware keys are stored on the computer, they can be recovered and used on another machine unless it needs to use the onboard TPM in which case as you mentioned, lose the hardware, lsoe the key
right
that's the deal
they were ORIGINALLY billed as being effectively TPM/HSM locked keys
but they are implemented completely different to that
and treated like "fancy" passwords
it's a huge mess imo
I say the use of different passwords on every site is crucial and password manager with a tough password + authenticator is still the way to go
imo, yeah
a lot of the problems passkeys were touted to solve are already solveable, we just don't do it
and passkeys don't actually fix that in a lot of cases
I get an email from last pass after putting in my correct password + authenticator if it doesn't like my location
so 3 factor lol
lol
authentication and authorization are something that consistently have solutions proposed to problems that are deeply baked into how these systems are built
and whenever these solutions are eventually implemented, they have all the same problems again
lastpass? after their breaches?
Isn't passkeys just another password/passphrase option? It's just saying: hey here's another indicator that I'm this person please authenticate the request π©Ά
for as much as I don't like lastpass because of that, a "breach" of your password manager should be a complete non-issue
Everyone has breaches, as long as you have a long password, your secured info is probably safer as others will be easier targets
as implemented, yes
sorta not, but mostly yes
what i didnt like was all of the notes on your accout werent encrypted in any way, they were just plaintext
i lost trust in them because of that whole fiasco
not this weird field level stuff they were doing
Why didn't they do total encryption?
Β―_(γ)_/Β―
beat me to it lol
What do you prefer now?
1password
That's an even better question
tho Keypass is nice ive heard
I use a notepad I keep in a safe
I hate keypass
Hello
I use notepad paper and shove it under my laptop case
That's supposedly "bullet proof"
I also use 1Password, though they also should be a bit faster at accepting reports from some of us π
I know it's fire resistant
When will the participation certificate for industrial intrusion be given? It's almost a month already?
the trade offs for using a "online" backed service are certainly present
Cause I threw it in our fire pit and it was fine
but the convenience doesn't break the security model if you "use it right"
so i don't have a problem with it
Hi hello hi
I sadly don't have a gun I can shoot it with to validate the bullet proof claims
Like AWS? I don't know the context
i meant online backed password managers
Ohh password managers!
1Password, online bitwarden, lastpass, etc.
I dislike cloud PMs
I don't use them. I just write all my passwords in a notebook
Not like anyone can understand my handwriting
My passwords should only be accessible to me and me only
cloud PMs can't access your passwords
I put my most secure passwords in Microsoft Works
hence the "doing it right" caveat
All fun and games until someone steals that notepad
That's she you put it behind the case
It's a physical book. Very small and hidden in my backpack
to be fair, physical theft of the notebook is far beyond most people's typical threat model
Thanks for confirming that
if they steal that, they can steal your laptop while your managers unlocked or etc.
Gave +1 Rep to @flint vault (current: #3055 - 1)
Nice thanks for letting us know π
Gave +1 Rep to @flint vault (current: #2008 - 2)
Unless you're a popular songwriter or smth idk why anyone would steal a notebook
Unless you forget it somewhere
I wrote the passwords without mentioning which password it's for. I randomly try them all till if I forgot
Also same π
Exactly!
And i remember most of my passwords
The book is just in case. If i forgot
i dont know ANY of mine π
You use a password manager ?
But you can't guarantee malicious actors in the company decrypting the DB or a specific user
yes
I just use a system to remember them ... here are some of my passwords:
gmail: N0tMyGmAilPasSworD
reddit: N0tMyReDdItPasSwoRd
bank: N0tMyBankPasSwoRd
thats the nice part
Like I understand the case is extremely rare
yes you can
Loll
But I don't want to take that risk
I have a feeling my password manager will get hacked and then Iβll have no passwords π©
My passwords are always ******** for some reason
That happened last time
Without working in the company I can't validate that
Well that didn't work as expected
you can, that's how encryption works
that's the point of encrypting the vault in the first place, so no one else can decrypt it
π
and why they are only decrypted locally on your endpoints
They need to have a key somewhere so you can access the passwords
How am I going to validate that a rogue employee won't attempt something to access that?
no?
Nah you have the key not them
they don't have a key somewhere
Again, this would be extremely rare circumstances
The key is your master password
they can't access that data, no matter what
to unlock a 1Password vault, you need a local device key AND the master password
neither of which they have
and either of which is not enough on it's own
The key is a physical harry Potter looking key that you have to open a door in order to find a scroll with the password
I'm still not taking "there's not someone who won't find a way"
It's an edge case I know is possible
I saw the snake door at the Harry Potter studio
i mean, if someone finds a way there, they can find a way into your accounts regardless of having your passwords
they are protected by the same math
If there's even a risk of 1% that could compromise my accounts by hosting it remotely I'm not trusting it
like, to be clear, if someone manages to break AES for your password manager, they don't need to
if someone found a way, say into 1P, I highly doubt they are going to focus on you anyway
well, that too
but again, if they manage to crack the encryption on the vaults, they can just listen to your traffic and everyone elses lol
There's a 1mil reward for getting through the security so I doubt they'd bother with ppl and just claim the reward
same encryption
Wouldn't be the first time I've been targeted
So yeah, I'm pedantic when it comes to cloud hosting things like that
lmao i love the new name
not to make an appeal to authority here, but breaking into these things is exactly what i do as a specialty
boops you
Even my personal devices are paranoid setups basically
it's.... not really feasible to assume the encryption will fall before everything else in context
Yes but it's still a chance I'm not willing to take
you're far more likely to simply have a local device infected than to lose anything to a cloud manager like 1Password
I'm not doubting what you're saying in full
this is very much wearing a helmet to scoot your office chair across the room, sure it covers the 1% chance but like... why
But my threat matrix is vastly different
and to be clear, i'm not arguing that you should use one, you can definitely do it offline if you want
or have that physical notebook stolen
it's just that it's not actually as unsafe as you might think
you guys arguing about password managers or using cloud vs local?
I keep my passwords in a box on the top of Mt. Everest, because not many people go there and when they do, they don't have time to look for passwords.
More so discussing risk
just cloud v local, and not really arguing just trying to convey the security in place
Not really arguing
yeah that
Just a discussion for learning and growing.
sure makes sense
Basically
just want to make sure i can follow without rereading
Like for 99% of cases, I'm gonna agree with chicken here
But cause I'm paranoid due to past work, I have that 1% exception where I can't and won't trust cloud PMs
Even my MFAs are strictly local only
to be fair, you may be taking more risk by doing so unfortunately
as that means safe handling of your vault is entirely on you
so many things going wrong for graphene os in the last few months
Do you consider the risk of someone taking your backpack lower than somebody breaking aes encryption?
id trust myself more than the companies ngl
and boy have i seen a LOT of problems with self custody of pw manager vaults
i honestly wouldn't
I don't carry around stuff like that for this exact reason
what risks exactly in detail
you would be surprised just how easy it is to drop a vault onto the internet and not realize it
come with local
Passwords i need to use consistently I remember in my head
i see 10s/100s a month come across my feeds
how does that happen?
Anything else I'd have to go unlock my safe
the Entire vault?
shadow considers the following:
getting robbed/mugged at knife or gunpoint
having their home burn down
having their home raided by law enforecement or criminals
it can happen in a TON of ways, and even after looking into it for a long time i've not figured out how it happens in many cases
If it's stored locally and you accidentally push it to git that's a fun one
it seems like a lot of people end up submitting exports and full vaults on accident to a ton of systems
run a virus scan? whole vault ends up in virustotal
and you may not even know the tool you used did that
Do people not blacklist folders?
shouldnt it be encrypted anyways though
Jesus Christ 
like thats standard practice
oh we talking about storing malware now???
How about the programs that tell you to disable your anti-virus or it wont install
Never installing those
just make an exception
if its legitimate
shadow needs their sudo password to install most things
I've flagged 19 plaintext vaults in the past 5 days from my various feeds
none of those were from cloud providers

all of them appear to be local exports from cloud managers or from local managers
I guess I'm just overly paranoid lmfao
It's okay, I was at one point too
All this stuff is something I'm way too paranoid to even do
bitwarden and others have their own numbers but i'm not going to count them all lol
I generally have to because of the places I work π
self custody is apparently hard
most of these relies on having backups of data and also insurance when it comes to fires or criminals
You spend all the time trying to keep your info private only to realize it's already out there
^
one little slip and that stuffs out there forever
and you might not even know
or worse, you may not have the ability to check
shadow sadly knows and have been working on minimising the footprint a lot
Buy a house? On a list
Rent an apartment? On a list
Have a cell? Guess what, you are on a list
that is what extreme privacy 5th edition is teaching you to avoid :D
everything wants your id uploaded to their woefully insecure platform to do anything
renting apartment hotels etc
the PII leaks are going to get worse
this is the bad scenario we are in unfort
Not me I live in a box
especially with the way govt are pushing ID laws right now
The worst part is that most gen-Z will freely hand it out without thinking, millenials too, lower portion of Gen-X will
is the box under your pet rock???
and boomers don't know how
you dont even have a choice Lol\
How did you know ?!
man you should see how many passport/ID photos float around
it's actually insane
sometimes it feels like it's every other open directory i scan through lol
it's really really bad
because shadow likes that model a lot
man you should see how many stores shadow never gets benefits from because they don't have membership accounts
I donβt think itβs just IDs I think our gov will be making everything digital

Best to get out of the uk if you can with everything going digital here
Happened to me too though lol
I even read something about a Brit card
I'll be buying it pretty soon I believe lol
do i have to get premium to get the least knowlg or just watch it in yt ?
well the EU is implementing some form of AGE VERIFICATION using an open source tool inside the next year at latest
both are good options but go with what you can afford
i can afford premium but i am just trying the website still you know
Yeah watch it on YT or if you have some other resources try them out and just skip it. And do the free ones. That's the easy way around tbh
I donβt like the changes being made. I was looking at boats the other day π
id say get it
It's cheaper and will help you out if you buy it but for starters since we aren't getting that much tactical or smth you can work your way around it and learn from other resources
that'd be great tbh
The price is worth it. The trainings are very well done
ngl i already studied that with ccna so i am not that worried about it
i am just intersted to see the content
I think you can preview the paths
I have 25 yrs in IT and I learned things from pre-security
I see.
books everyone should read: https://inteltechniques.com/book7.html
you can defenitely preview some rooms
There are a some free rooms so you can see
u paying for nitro surely u can pay for premium
lmao
otherwise your priorities money wise are kinda odd
its free nitro lol but yeah ill do it
Great π Welcome
i ditched them for 1Password for that reason.
1p ftw
I should have taken better notes. I've learned an enormous amount of IT stuff, perl, python, php, windows server, firewalls, voip, wireless, never been a note taker
keepassxc with multiple location backups goes BRRRTT
But THIS stuff.. you MUST take notes
or you just keep looking for the same stuff over and over
Same before but got into it 3 years ago
Been taking notes daily
haha
that or you gotta go teach it to peers or pet rocks or rubber ducks
Very few password security mechanisms stand up to rubber hose cryptanalysis.
i mean, i don't know any of my passwords π
deniable encryption
It's a pain but when you do a challenge and are like "oh i know this" ... looks for notes "wtf i have nothing on it?" .. where did i find it.. 30 mintues later you forget what you are looking for
lol
Anyone else done that?
yeah done that before
yeah this only works up to a point but also is a thing
generally just resort back to known good sources of info
Got notes so I can just search for it easily in my ob vault
i used to have an encrypted drive work gave me that if you were at risk of being compromised, you put in a different code, and it wiped itself.
and with smartsearch I can even smart search for stuff related to it
this can be legally problematic
yeah it is no silver bullet but it is a potential solution for some cases
deniable encryption is better than "self wiping" for most cases
If you enter an iphone code wrong enough times it will lock you out for a very long time
By the time you're being coerced for your password, legally problematic is the least of your worries.
you'd be surprised lol
really wouldn't.
also when you know you're compromised is usually too late anyways..
lots of countries have started to get weird about that at border crossings
yeah, that's when you wipe it.
Key disclosure laws, also known as mandatory key disclosure, is legislation that requires individuals to surrender cryptographic keys to law enforcement. The purpose is to allow access to material for confiscation or digital forensics purposes and use it either as evidence in a court of law or to enforce national security interests. Similarly, m...
if you want spooky laws
and that's when it's legally problematic unfortunately
cross the border with a blank device.
dude imagine you accidentally put in the other password π
In the US, even citizens MUST provide their passcode to Customs
if you're being investigated for a crime and similar, wiping it can be considered obstruction or destruction of evidence
And if Customs find a pic they don't like they can send you back
If you aren't a citizen
I've always wondered. Who pays for the return trip?
lmao do you remember when the gov made someone hand over a RSA key and they gave it fully printed out
deniable encryption solves the problem of having to provide a password or key
Good question, I imagine the government has to
because you can
that'd be the logical answer
funny fact there's an obsidian plugin called cryptsidian and it allows you to lock vaults or files behind encryption, but the massive flaw is that if you make one typo to the decryption password it fucks it up lol
nope don't recall this
the real question is
if you have an encrypted device that you don't have the encryption key to
does it really have any data on it?
also this discussions reminds shadow of the usa stance of encryption being weapons/arms meanining they were illegal to sell to a lot of countries or even share freely with a lot of countries
actually, not the govt
the airline or whoever transported you is the one on the hook
this is still true
You wouldn't know. You can make bitlocker drives to use on your computer. When you create it, it creates a static size.
really?
So there could be nothing in it, but it's 50GB
yeah, and they can come after you for the cost too
that's crazy
good luck with that.
it's happened apparently
once you're back in your native country, declare bankrupcy. Can't go after you if there's no money to go after.
also, don't go to the usa.
π
lol high stakes
i just subscribed to premium
oh are they hoping someone can crack the encryption???
Woo hoo, now you can start with the precyber and go through the whole thing
no, read through it
thats from 2016
I knew a lot of it but did it anyway
no need, those are the keys
Court ordered lavabit to hand over the keys
That's how I can tell you that they are well done
yp
they dont care about snowden anymore lol (i think)
at 01:35 in the night?? you think shadow can have coherent thoughts at this moment in time???
lol tldr they made lavabit hand over the keys, so lavabit did, but all printed out in teentiny font
Why did Edward Snowden miss the last flight out of Russia?
Because he was snowed in.
runs
paying your bill in pennies
lol
lavabit did something few companies would do in their situation
actually state no F that and dismantling the entire business and getting rid of all customers
doubt thats the full story
instead of fighting while keeping to be a business
reading a bit more on lavabit rn though
realistically they probably gave all the requested keys for whoever else it was requested for
easy innit.
it's not like end to end encryption is some brand new trick
it was in 2016
it definitely wasn't lol
I still don't understand why services like that compromise in the name of usability so often
i mean, i get it, adoption is important to any business model, but that wasn't exactly the business to be compromising around
someday shadow gotta figure out how to get friends and family to switch to end to end encrypted communication
Because those decisions are made by the C level executives who make the decisions based on profit
yeah or someone didn't know better
while also making sure sweden does not pass the law that would make end to end encryption illegal
just throw them all into signal or such and call it good enough imo
because it's easy.
I have this long running tirade with the modern internet, that half the reason it's the mess it is now is because someone wanted to make life easy for the customers.
if you stop sacrificing security for ease of use, you'll have less customers, but the world will be a better, more secure place.
If Company X has a vulerability and they find out about it, but it will cost them $50 milion to fix... and they also find out that if they are breached that they will face a $10 million fine ....
What do you think they will do?
it works, and they don't like that lol
oh i've seen it first hand, i know how that goes, i just think a lot of these systems could have been fixed during the initial design phase
yeah that would work if shadows family had any data plans on their phone plans
it didn't need to be bad in the first place
not to mention to get them to use signal over sms
it's bad because some tit wanted to make life easy for users.
yeah that's been a huge pain point, i really really disagree with the way OWS has treated signal since moxie left
it should be difficult to use computers.
I agree chick, but the devs as you probably are aware are pushed to a deadline and the functionality is more important in many cases than the proper implementation
yeah, this is pretty painful
and signal has plans to walk out of the swedish market if said laws mentioned above gets into legislation
VPNs for all
@sand trench just remember not to press the "invite random journalist" button π
signal has plans to walk out of every market if they keep treating it like facebook messenger and don't care about security a bit more
you say that as if family is willing to switch to signal/session and not see me as a paranoid nut
true but would not admit to planning to break laws in here for lots of reasons
can't we all just go back to IRC and gopher?
god gopher is fun
signals a good place to get US intel
it didn't used to be a hard choice, OWS has made it a hard choice
and I strongly disgree with them for all of that
okay so shadow should press the invite random plumber button instead????
slaps devopstom around a bit with a large trout
Invite All.
That takes me back, thank you.
Gave +1 Rep to @dark wolf (current: #332 - 22)
No problem, mIRC haha
OWS???
MS Comic Chat was my first IRC client.
shadow is bad at abriviations
Haha, yeah
I never heard of that one, I used mIRC and BitchX
Open Whisper Systems (abbreviated OWS) was a software development group that was founded by Moxie Marlinspike in 2013. The group picked up the open source development of TextSecure and RedPhone, and was later responsible for starting the development of the Signal Protocol and the Signal messaging app. In 2018, Signal Messenger was incorporated a...
I loved BitchX ... so customizeable and so many scripts
MS Comic Chat was .... Interesting.
https://en.wikipedia.org/wiki/Microsoft_Comic_Chat
Microsoft Comic Chat (later Microsoft Chat) is a graphical IRC client created by Microsoft, first released with Internet Explorer 3.0 in 1996. Comic Chat was developed by Microsoft Researcher David Kurlander, with Microsoft Research's Virtual Worlds Group and later a group he managed in Microsoft's Internet Division.
guess it's the "Signal Foundation" now lool
Β―_(γ)_/Β―
Oh my
they've been making bad choices for a while now, i'm not a fan of what they've done to Signal but it's still the best option most of the time :/
Best.. no. Good no.. usable maybe..
I mean, there's not a better client using the axolotl ratchet that i'm aware of
Whatsapp doesn't really count
I didn't know about that one either
slightly related, an old member here had windows AV delete their obsidian notes a few hours before they took OSCP because it got flagged π π
yes
Lmfaoo
but was with cherry tree
It was hard finding out what cool programs and stuff there was back then
They coukd have restored those btw
it acually happened multiple times until i set an exception
It onl goes in quarantine
i had a long fight with Windows AV yesterday over PT1 resources. >.>
No google, no real serachable internet
shadows best friend has hit shadow with the nothing to hide statement so many many many many times
oof
Directories.
and it has annoyed shadow so very very very very very much
Those were so cringe lol
I miss webrings and directories actually.
oh yeah, it was years ago
it's all still there
web archive!
just under layers and layers of modern web
SimpleX exists tho
the nearest thing to directories is like, those github repos of "all the tools for X "
different protocol?
hi
Same here lmfao
Mfs think it's a good idea to give all your privacy away
the first website i ever put on the internet is still there, hidden under layers of modern web shite.
it has an under construction gif, and a page hit counter.
shadows youngest sibling is worse though
Ye
as he thinks everything is just fine and dandy as long as he is not losing possesions of things or real life money
LOL... i had one too, every site had a page counter
shadow is sad the internets first webcam has shut down
Any other information that may compromise privacy or forward secrecy of communication between clients using simplex messaging servers (the servers cannot compromise forward secrecy of any application layer protocol, such as double ratchet).
Looks like SimpleX relies on the underlying application layer to actually implement good forward secrecy
loved that coffee pot stream
why is shadow speakin in 3rd person

SLUUUUUUURP
Vigorizante doesn't know
Ibqa doesnt know either
Karma wants coffee
Can someone help me with something
wait that is where you place the breakpoint in your username???
Yeah it does ur right about that
But it's good if the app implements it for it
Signal's protocol has perfect forward secrecy baked in
the protocol is really good afaik
Welcome Lilly, if it is legal, we may be able to help
it's the app that they keep ruining for some reason
Can I dm you
sorta the opposite problem
No, please talk in here
old habit that never died that started so long ago shadow has trouble remembering why
Well most people call me Karma irl so yeah
Karmanya is my real name
So thereβs this guy blackmail me is there any you guys can help me
What a beautiful name
thought it was meant to be split like
kar
man
ya
Contact cyber crime units or police for that
No, we suggest you go to the police
Police

Thank you guys itβs just Iβm scared but thanks for the help
we cant discuss legally dubious stuff in this server
I don't understand ppl who get blackmailed and go like "OHH YEAH THAT ONE PLATFORM THAT TEACHES CYBERSEC, I'M GOING TO GO THERE AND ASK FOR HELP!!!"
Anyone in that position is scared, its best to let the police handle it
yo qurti
Wsp

lol why u screaming
Ohh i was just curious, it does sound unique to you
Quotes
Thank you again.
alrighty
you are welcome, good luck
for swedish people yes it is kinda unique
for all countries??? nope
barabum
I can understand it because maybe they can get advice from people who are experienced in the field or maybe theyβve tried the police and had no luck
Illeism (; from Latin ille: "he; that man") is the act of referring to oneself in the third person instead of first person. It is sometimes used in literature as a stylistic device. In real-life usage, illeism can reflect a number of different stylistic intentions or involuntary circumstances.
good article on the topic
why not π
Ig it's fair then, maybe I'm being ignorant since I'm used to fair treatment here
Yeah, but then again, this is TryHackMe, not TryBlackmailMe, perhaps they clicked on the wrong server
japanese children like to refer to themselves in third person and some stick to it into near adult age
lol
Hello Shadow! 
I was also one of those people that came into the cyber community after being harassed and attacked by hackers. I also did not get the help in the way I wanted which is why I studied it for the last three years π
hi dark π
ello darkfly
The hacking communities are very very different people than most
Not sure how itβs black mail
Ye, understandable in that case
also
meep moops
to the
beep boops
for the
sleep sloops
while
night knight
knightly nights
the night
Goodnight Shadow!
I was saying she came here for help with soemone who is blackmailing her instead of tryblackmailme
Gn shadow
Night night shadow-sama 
Night Shadow, sweet dreams
For me it's wakey wakey time ...office 
hi π
Most criminals are after something I suppose
Austrialia?
Actually I think all of them are π
Clearnet has more toxic ppl lmfao
Plus, what people don't seem to realize here from my experience is that someone could come in here with a made up story and be trying to con people in here.

I'm always very skeptical in a channel of this sort
9AM here
Eh, I'm usually here after studying for so long that brain hurts
So skeptical prob no
Where are you Donut?
Just laughing and observing
Singapore?
South Korea
senator...
lol
Awesome dude
yeah, currently at a cyber event
Iβm conning people because everyone knows the Brits arenβt even real
It's true.
AIs
And I'm from fish world
π
Do you like that Netflix series Squid Games?
A made up country by the Japanese to have a place to fish at
I've only seen the first 2 seasons
ur always leaving then joining
Good morning my friends
Seriously took me so long to get people to trust me when I joined. π
Finally woke up early
anyway welcome back
Good morning, about to go sleep
uhhh Iβm probs underage
"They're always going and coming and coming and going"
Gotta love time zones
Well I leave when I feel like Iβm putting too much energy into discord. If I need to put energy into something else I leave.
lol
Good night, have a good sleep
Gn
What's the time for you?
fair
It's 5:36 AM for me
OSINT it!!
Idk your timezone
i just found like, the biggest scam phishing site π its really weird, anyone wants to disect it?
Yeah, it is for adults, but I'm not familiar with the culture there, whether they are strict with that
Yea....
Nah I'm finding your house and coming for you
2 AM
Close
too much death lol
3?
A couple people die
Anyway, cya guys in a few
uhh a lot of people die
Yup
Yeah or if I need to have some time to think about stuff. Sometimes I just leave peoples life and never return. I do whatever I feel is best at the time.
cya
lol
Fish world
the ocean I guess
This is the day you will always remember as the day you almost caught Captain Jack Sparrow
Good try, but that's not the film i was referencing.
I didnβt know what you were referencing at all tbh
I was just staying in the theme
ahh
π
it's 1am, i'm super eepy. Night!
Night
night

yo denial π
Found you
lol
Hey Donut, what's up
good, at that cyber camp/event
Oh, cool. Have fun π

hi daniel
thanks π
Gave +1 Rep to @mortal ether (current: #306 - 26)
Daniel lol
I donβt get how people notice when I leave and join again.
π€·
Do they have a notification system for stealth lmao
hi π
You usually announce when you're gonna leave, join date changes, mentions fail, you're account is unverified
Good morning !
π
please not this
Egypt/South Africa/some eastern EU country
Booper

Yes?
Good morning
Morning
Its freeeeeezing
Morning
mornin π
Tell me about it π€£
mornin π
Nice change to the heat tbh
Morning love
π’ π§π»βπΌ
lol
sooo cool AC
Do you have the eletric blanket?
The opposite, its the weather AC
The best type
Where u live
Aus
probs Australia
Aus

I see a pen, so i'm just going to assume that's Pentesting camp.
We made the same typo π€£
@blissful current come soon here
Basically the only thing i can understand in that picture is the pen
Fr
I cant be bothered, i want to get out of bed but i dont want to, you feel me?
Yeah I'm not lecturing today
I got no energy π€£
Nailed it.
Hear me out
web app and prompt injection stuff
I have work until midnight, then no transport to get home, and then i have a class at 8 am
with free lunch
Oof

Aus
lol
It really is like that guys
uhuh

π€£
Its sunnyβ¦.boom heavy rainβ¦.then boom cold afβ¦.then boom a little hot
then boom snowing
crazyyy
Then boom windy af
Same shit in my city
then, meteorite strikes
Yes but in sub continent, its usually hot throughout the year
And random weather af ...it will be sunny , next minute it will rain , then again sunny then cloudy ...n shit keeps on going
HAHAHAHAHAHHAHA
Are you in metropolitan?
wya?
London uk
anyway gtg
london is beautiful
cya guys π
cya !!!
It's a metropolitan city I think ..yeah
I hate London but the snow would make it better
Too many brown people there
F them browns
(Im brown)
β¦ okay

Why tf skin colour would affect in that
I donβt know why he went there anyways
London is known to be very diverse, mostly brown people
Yeah...anyways
Made the convo really awkward lmao
And they are involved in a lot of crimes
Indeed he did
Letβs just not talk about race
4chan humor
...Yeah
Letβs talk about cupcakes or something I dunno
Exactly
Hallo salts
4chan humor was more like habbo hotel afros

I mean I didnβt go on that filthy website. πlol
Abdullah you arab?
ngl i thought you were an entirely different person with the pfp change
Nope
I have a real face sometimes
Itβs weird lmao
Minsty hallo
sleepy sleepy
@tight trout Do you like my eyebrows
whats even weirder is that i've seen it lmao
Wait before tonight ?!
thats a really good picture of you! π
π
yah you streamed it in general remember?
And salts also sent a picture some time ago
Do you live near the beach?
Beach days here arent until December @rapid merlin
the entire year is cold here but during Christmas we get summers
You don't like the beach?
Yo
Wahhht
Are active directories really worth studying?
I mean the British beach is pretty grim tbh. Itβs like the water is kinda gross and the beach is just rocks π
Thats why me and Ashlynn are freezing out here 24/7
Tho the beaches here are pretty af
its not that coldddd
Come here
I found a guy with a shovel digging a deep massive hole. He said he was digging for worms for fishing. They were huge
π₯²
whats the temp?
Not much better than mine
Gtg back then
i feel like everything worth studying .. but not everything worth repeating tbh
Look at these worms he dug up
It's only 42c here today!!
Not too shabby
STUDY NOW
Single digit + wind gusts 32km/h @tight trout
Bruh active directories making me feel like Im high for a whole ass hour
He said they were for fishing
Not even the attack box working and shi
THICK worms
Rizz, it's not that we don't like talking to you, we really do... but you really realy do need to study man.
What's the humidity?
Wet or dry?
Hehe thats cuz ur not cool
bro its not the worse thing that you gonna learn
Oh fuck..
There are worse?
They thicc
54%
That's not too bad
ofc
But its morning time atm
98% humidity for me
So night time will be different
FUCK
So it's dry af
Love how our winters reverses how humidity works
The higher the humidity in winter the dryer it is
Look, i like winters, but im not a fan of βunexpectedβ weather
I was also looking at all the boats
Boat!
I like to wait for the water to go out so I can walk in to find treasures
4% Humidty 41.7C
Is that you? @rapid merlin
Boats are cool
Nah thatβs my nan
Lived on one for three months 
Right there
Sadly it was for work tho
Cruise?
Nop
Yeah
I know
Lmao
I almost got scammed when I was younger trying to get a job on a boat π₯²
your single digit or my single digit?
Did you enjoy those times
Oh
I wouldnt know that
Ashlynn can tell prolly
C not F
I did
oh
I still dont know where you are mints
Mints is US
UK?
Yea
Also nice pfp change mints
@merry canyon pleaseeeee tell
i didn't almost say the wrong name
Bro hell nah I feel shit with active directory basics.. and its 4am
Why?
Oh shit I didnt even notice mint with that pfp
Its fun tbh
Wsg mint?
rip lmao
Would've been bad lmao
tell me!!
not the end of the world but yeah
Breakup worthy π
Bro imagine being all day with 1 coffee, 1 monster white, and sitting at 4:46am studying theory about active directories...
I'll explain now wait lemme verify
yeah, we'd have to split π
It would be very sad times
Hello everyone, i'am new at cybersecurity
its normal doing this boring about windows? I just started the path Windows Fundamentals 2.
I don't want to fell that i'm wasting my time or soemthing like that
from what i can tell most of the people here hate those rooms specifically lOl
Oh shit man that's exactly what I was talking about lmao
Windows is a critical OS in most modern infrastructures
Yee it's useful that's what people hack afterall
Bro are active directories really worth it tho...-
pwease? *hides knife behind back*
I feel like my spine is gonna break
yes or else you are not a pentester
LOL
I'm a pen tester and don't touch AD
I know it
i mean MOST likely not a pentester
But I don't touch it
there is IOT pentesting and webapp
I did the windows path I think
Bro I thought cybersecurity is fun
Im suffering π₯²π
Not Iβm verified I can post gifs again
Fuck
Lmfao
How can I study cybersecurity and have fun at the same time?
I was looking at GIFS !!!
Or these two dont match?
pwetty please i'd wuv to knyow whewe you t-t-thought i wived...... >w< pweaseeeeeeeee
π
leveling up on tryhackme for me ig
-# holy water cant wipe that off my hands
Immaculate timing ngl
FOR YOU?
yeah
yep do it
what do you consider fun
Only hard work
nyoooo :3 nyot the boops your nose eviw eviw holy watew. it buwnsss its BUWNSSSS
I find cyber fun
Oh
I enjoy breaking shit and building unholy systems that are insanely complex but secure
teach me your ways pls
Because I dont
I want this blessing
Sounds like a you issue
Bro maybe it's because Im not in practical yet..
-Teach me your ways
-Your issue

you can go try the forensics rooms you wanted
I have been trying to root
autopsy is software used in dfir
....?


