Jesper Stein Sandal (@jespersandal) 's Twitter Profile
Jesper Stein Sandal

@jespersandal

Geek first, then tech journalist, infosec-knowitall, dungeon master, metal fan, TV addict, and zombie apocalypse survivor.

ID: 28152545

calendar_today01-04-2009 17:44:16

4,4K Tweet

566 Followers

385 Following

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

Some days you can identify with a tropical storm. (And some days, you are rooting for them to pull through, when the advisory says "Tropical Storm Betty has been downgraded to a tropical depression")

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

What is everybody's feelings about changing TLP:RED to TLP:HOTPINK? I'm trying to fulfill the accessibility AAA requirement for web contrast, and regular reds just can't get to 7.1:1 😆 #infosecurity #trafficlightprotocol

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

Rimelig sløjt af TV 2 NYHEDERNE at bruge en politisk direktør fra Dansk Industri som primær kilde i en artikel om sygefravær. nyheder.tv2.dk/samfund/2023-1… #dkmedier

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

I persuaded ChatGPT to give me a clever name for the software vulnerability that will ruin Christmas, and I got to say that "JingleShell" is pretty good.

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

Det er vist på tide at være mere kritiske over for fx EDC og Easypark som de seneste eksempler, når de siger "ingen skade sket, bare adresser, tlf. nr. og e-mail". Bare fordi det ikke takseres til en GDPR-bøde, gør det ikke harmløst.

Troy Hunt (@troyhunt) 's Twitter Profile Photo

Alright folks, this is starting to smell like bullshit. Not the alleged breach (which smells bad for reasons I'll explain in a moment), but the "AI" line from both Europcar and the PR agency that just emailed me pitching someone's hot take on it. Here's why:

Ashley - Serious Security Scientist (@infosec_taylor) 's Twitter Profile Photo

STOP. DOING. THIS. Use simulations to train how to report emails. Literally send them saying "let's practice how to report this example phish." All simulations like this do is prove people click links. NO FREAKING KIDDING! There is no avoiding clicking links!

SwiftOnSecurity (@swiftonsecurity) 's Twitter Profile Photo

Getting into Security because you think it grants you authority is a solution for idiots. It doesn’t. You only have authority a human mind isn’t incentivized to subvert. If you want to make change you have to compel a better solution. There’s no debating. There’s just results.

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

It's quite ballsy to make such drastic changes overnight to the UI of perhaps the most successful app in Denmark, #MobilePay. Simple start screen is now cluttered and the workflow is flipped around. Luckily, there's no competition.

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

An overlooked, but fun password advise is that you can totally make up your own words. So you could create a phrase like: "argle godyf riippsj ninu pfff" (I know, password manager, but sometimes that is not an option)

mRr3b00t (@uk_daniel_card) 's Twitter Profile Photo

If you are giving consumers advice about defending against an evil twin captive portal attacks... let me explain what probably doesn't help protect them: 1) a VPN 2) telling people to only use wifi they trust 3) telling them to forget the wifi network after they have used 4)

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

Nej, JFM – det er ikke sådan, awareness fungerer. Medarbejderne er sidste bolværk, efter dit spamfilter og fancy "next gen" isenkram alligevel har ladet mailen slippe igennem til medarbejderens indbakke. Dit forsvar havde allerede fejlet. journalisten.dk/stort-mediehus…

BlackRoomSec (@blackroomsec) 's Twitter Profile Photo

I want to add one other thing to this and that is that in your training especially when you're walking less technical users through multi-factor, it is vital that you explain to the user that they aren't going to break anything if they type the wrong code and that if the account

Andy Greenberg (@agreenberg at the other places) (@a_greenberg) 's Twitter Profile Photo

Intelligence agencies and FBI/DOJ have revealed that unit 29155 of Russia’s GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. wired.com/story/russia-g…

Jesper Stein Sandal (@jespersandal) 's Twitter Profile Photo

Er det kun mig, der bliver gnaven, når man bruger en kortprojektion af Grønland og Arktis, som er virkelig skæv? Hvis man arbejder med infografik burde det være basal viden ikke at bruge Mercator, når vi nærmer os polarcirklen.

Er det kun mig, der bliver gnaven, når man bruger en kortprojektion af Grønland og Arktis, som er virkelig skæv? Hvis man arbejder med infografik burde det være basal viden ikke at bruge Mercator, når vi nærmer os polarcirklen.