Skip to content

Dan Q

    • Articles
    • Everything
    • Notes
    • Reposts (shares)
    • Checkins (geo*)
    • Videos
    • Reviews
    • Comics
    • Tags
    • Stats
    • Subscribe
    • Blogroll
  • About
    • Semi-standard "slash pages" you might like to explore:
    • /about
    • /blank
    • /blogroll
    • /colophon
    • /contact
    • /cv
    • /events
    • /license
    • /pfp
    • /postcards
    • /privacy
    • /salary
    • /shh
    • /slashes
    • /stats
    • /subscribe
    • /where
    • Hide posts of type:
    • Choose how Dan's dressed:
    • Hair
    • T-Shirt
  • Contact
  • Podcast

Tag: security

  • Annotated letter from Halifax addressed to people that are not-me, but showing details of my credit card.

    Halifax Leaked My Financial Information... (Again)

    For the second time in two years, Halifax wrote to me about my credit card... but sent the letter to entirely the wrong person, leaking my personal financial information.

    Read more (293 words)

    • Article
    • posted 9 October, 2026
  • That time I got locked-in at the V&A

    I just realised that I never shared this anecdote online before -

    One time, I got locked-in at the V&A Museum after closing-time. I'd been there for a museums & cultural institutions event and I'd probably had a few too many glasses of champagne before I excused myself to return to my hotel. Unfortunately in my โ€ฆ

    Read more (124 words)

    • Note
    • 1 comment
    • posted 7 October, 2026
  • Composite image showing links to two websites, output from fail2ban showing a banned IP, and the words 'banned! because he visited a different site!)

    Exploiting Fail2ban "portscan" permablocks over HTTP for denial-of-service

    On a forum they and I share, Loebas suggested that I should be careful doing portscans in case I hit e.g. fail2ban rules. I counter that such rulesets would be a terrible idea (and are therefore uncommon), and provide a specific demonstration of how an attacker can turn them against the site's legitimate users!

    Read more - about 5 minutes (1093 words)

    • Article
    • posted 5 October, 2026
  • Delete site data and permissions for www.google.com and its installed app?

    Chrome again exempts Google from user site data settings

    Jeff Johnson observes that Google Chrome has AGAIN started ignoring user privacy settings specifically for .google.com domains. This leads me to ask, not for the first time, why are there still so many people using Chrome as their daily driver, when there are so many perfectly-good alternatives that don't feed the beast in the same way?

    Read more (241 words)

    • Repost
    • of this original
    • posted 6 September, 2026
  • Composite screenshot showing the HTTP Toolkit app running on an emulated Android device, on top of the desktop application which is capturing packet data from the emulated device.

    Your 'App' Could Have Been a Webpage (so I fixed it for you...)

    I was asked to install a mobile app to get access to the itinerary of a trip to Disneyland I'm taking with the kids. Fuck that noise: couldn't it have just been a Web page? An hour of reverse-engineering later, it is, and it's superior in virtually every way to the "app" that it replaces.

    Read more - about 5 minutes (1171 words)

    • Article
    • 156 comments
    • posted 9 July, 2026
  • An interaction with Claude in which I've asked it to summarise and explain this article and am told "This model's safeguards flagged this message."

    Exploiting Thoughtcrime in LLMs

    New malware variants seem to include source code comments about how to build WMDs, presumably in an effort to hamper analysis by AI-based tools. I find myself wondering if the same technique can be used by authors to "protect" their work, too...

    Read more - about 4 minutes (837 words)

    • Article
    • posted 6 July, 2026
  • Image representing post: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

    Meta decided to replace a lot of their tech support with a chatbot. Which meant giving that chatbot the power to manipulate data. Which meant, to the surprise of nobody whatsoever, that hackers tricked the chatbot into giving them access to other people's accounts.

    Read more (176 words)

    • Repost
    • of this original
    • posted 2 June, 2026
  • Image representing post: NHS England rushes to hide software over AI hacking fears

    NHS England rushes to hide software over AI hacking fears

    New Scientist reports that the NHS are closed-sourcing a lot of their code, out of fear that AIs like Mythos will facilitate easier exploitation of their systems if they don't. Which is pretty-much... completely backwards thinking.

    Read more (395 words)

    • Repost
    • of this original
    • posted 1 May, 2026
  • Screenshot of the chat room of a forum, but the new shoutbox message contains an 88ร—31 animated GIF that says 'Dan Q', where the 'Q' spins on its axis.

    Why Security Engineering needs a Hacker Mentality

    Security engineering is about a lot of things, but the best security engineers show the 'hacker mindset' characteristics of curiosity and imagination. Here's an example of how I found an XSS vulnerability in a forum, mostly by accident, and how curiosity was the key.

    Read more - about 4 minutes (718 words)

    • Article
    • 1 comment
    • posted 13 March, 2026
  • Screenshot of Linode's Web interface showing a running VM, overlaid with a terminal using SCP to download wireguard.conf from it.

    Run your own WireGuard VPN

    I stopped paying for VPN services a decade ago and I haven't looked back. When I 'need' a VPN service, I just spin one up on cheap VM services, and then I throw it away when I'm done. It's cheaper and more-customisable... and if the UK goes ahead with an idea to age-gate VPN services, it might soon become more-convenient too.

    Read more - about 5 minutes (972 words)

    • Article
    • 1 comment
    • posted 18 February, 2026
  • 16-bit Windows screenshot with a background image from WarGames. A dialog box asks 'Are you sure you want to quit? If you quit, you will lose the ability to: (a) use network chat tools, (b) play videogames awhen you should be doing coursework, (c) impress your friends and raise your otherwise-pathetic social status'; the cursor hovers over a 'Yes, I'm out' button.

    How an RM Nimbus Taught Me a Hacker Mentality

    Thirty to thirty-five years ago, as a young and curious hacker, I broke out of the restrictions on my secondary school's computer lab and briefly achieved rockstar popularity amongst peers who, through my tools, could now play videogames instead of doing their coursework. But their interest in the results of my exploits were incompatible with my interest in the sheet joy of discovery... and, inevitably, this meant trouble.

    Read more - about 12 minutes (2688 words)

    • Article
    • 1 comment
    • posted 30 January, 2026
  • Why does SSH send 100 packets per keystroke?

    Nolen Royalty wrote an interesting piece about diagnosing a quirky SSH-related issue, and I found it both interesting and inspiring.

    Read more (265 words)

    • Repost
    • of this original
    • posted 26 January, 2026
  • One the left, how you see your code. On the right, the reality - a mixture of library code and what you wrote

    It Is A War Out There - Take Control of Your Supply Lines with HtDTY

    Andrew Stephens reminds us to HtDTY (Host the Damn Thing Yourself) to reduce the risk of supply chain attacks and improve privacy. But I think the argument goes further than this.

    Read more - about 3 minutes (527 words)

    • Repost
    • of this original
    • posted 15 October, 2025
  • A password form with the password S1dfCeg7!Ex;C$Ngban9-A entered; an error message shows 'Your password must be at least 12 characters log, contain at least one uppercase letter, one lowercase letter, one number, and one special character'

    Hive's Password Policy Makes Me Cry

    Hive's password form can't decide whether you need 8+ or 12+ characters, gives misleading error messages and... requires that you use a 'special character' except most special characters (including most common punctuation) is secretly banned, and gives you a misleading error message if you try to use it. Do better, Hive!

    Read more - about 3 minutes (650 words)

    • Article
    • 3 comments
    • posted 14 October, 2025
  • Is it possible to allow sideloading *and* keep users safe?

    Terence Eden's upset at Google's proposed changes to Android to further lock-down the ecosystem, and I'm concerned too.

    Read more - about 4 minutes (753 words)

    • Repost
    • of this original
    • posted 13 September, 2025

Posts navigation

Older posts

Get in Touch

I'd love to hear from you! Why not...

  • email me on blog@danq.me?
    (my spam filter is aggressive, so use a good subject line, i.e. not just "hello"; encrypt your email if you like)
  • say hi on Mastodon, where I'm @dan@danq.me?
  • send a letter or postcard to
    Dan Q, Unit 159610, PO Box 7169, Poole, BH15 9EL, UK
  • reach out some other way?
  • ยฉ Dan Q 1998-2026
  • Creative CommonsAttributionNon-Commercial except where stated (how to use)
  • powered by BloqClassicPressHTML5CSS3
  • privacy
  • Read articles, checkins, notes, reposts, and more...
  • @dan@danq.me
  • contact
  • subscribe
  • Dan Q
  • Creative Commons Attribution Non-Commercial license
  • ClassicPress
  • CSS is awesome
  • Created by a human, not by AI
  • LGBTQ+ pride flag (2018 progress variant)
  • Polyamory flag
  • Say no to Web3
  • Mastodon (it's like email... no, come back!)
  • Tested on Firefox
  • Best viewed on the Internet
  • PHP
  • Ruby
  • Debian
  • Caddy (webserver)
  • Find me on Melonland
  • Check out my GitHub
  • Three Rings - by volunteers, for volunteers, since 2002
  • I'm a fucking webmaster
  • Looks best at: any resolution!