Jeroen van der Ham

@jvdham.nl

Associate Professor at UTwente on vulnerability management 1sand0s@infosec.exchange and @1sand0s

How do I disable announced notifications from workout on my watch? These notifications are interrupting music or podcasts when I’m cycling and I don’t want them.

Since iOS 18.2 i have problems with Mail. It’s hardly downloading new mail from my imap server. Anybody else having this too? Anything I can do about it to fix? Nothing changed on my server end (Dovecot). I’ve even tried to disable IMAP IDLE, but that also does not help.

Password policies are evil and should be burned to the ground. The piece that Stuart Schechter wrote on their history however, is so incredibly misguided. It is bonkers to think that we would have had a more secure world without password hashing.

How some of the world's most brilliant computer scientists got password policies so wrong

The US government’s latest recommendations acknowledge that password composition and reset rules are not just annoying, but counterproductive. The story of why password rules were recommended and enfo...

stuartschechter.org

CVE 2020-19909 in Curl has been interesting to watch. It's weird that NVD decided last week that it needed a CVSS score, and even weirder that they came up with a 9.8 for it. Now it's been marked "Disputed" with an explanation that it is not likely to be exploited.

It seems surprising that as a society we lose the ability to do certain things. And then this week I ran into one: we have lost the ability to quickly set up a mailinglist. Even the age old mailop list ends up in my spam folder due to standard outlook spam filtering.

When was the last time a company was compromised _solely_ because a user clicked on a link? Which product is so dangerous that an entire company can be shut down because someone used that product as intended? Details welcome!