Steve Gibson Profile Banner
Steve Gibson Profile
Steve Gibson

@SGgrc

Followers
63,520
Following
0
Media
118
Statuses
7,076

I didn't want to clutter up the corporate GibsonResearch Twitter account with lots of personal stuff. That's what this one is for.

Southern California
Joined May 2010
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@SGgrc
Steve Gibson
3 years
Someone on the Facebook recovery effort has explained that a routine BGP update went wrong, which in turn locked out those with remote access who could reverse the mistake. Those who do have physical access do not have authorization on the servers. Catch-22.
115
637
2K
@SGgrc
Steve Gibson
11 months
GRC's forthcoming “ValiDrive” freeware is running and being tested by our terrific community. It IS finding bad, slow, buggy, error-prone and fraudulent USB drives. 👍 It's expected for release later this week. I'll announce it here when it's ready for everyone.
Tweet media one
43
121
930
@SGgrc
Steve Gibson
10 months
“ValiDrive” New GRC Windows utility to quickly spot-check any USB mass storage drive for deliberate sizing fraud and errors: Over the next day I'll be fleshing out its description page. But the Windows App is ready for the world now! 👍
Tweet media one
Tweet media two
44
204
879
@SGgrc
Steve Gibson
3 years
Reports are that Facebook employees cannot enter their headquarters because their badges don’t work, and those inside are unable to enter various rooms because access is dependent upon obtaining authorization from remote Facebook servers. Those who live by technology...
54
228
806
@SGgrc
Steve Gibson
7 years
Announcing new freeware from GRC (by me): "InSpectre" Quickly assess and verify any Windows platform -- hardware and software -- for Meltdown and Spectre mitigation function and capability (125kb with no "installation" nonsense.)
73
408
713
@SGgrc
Steve Gibson
11 months
By popular demand... I am (briefly) pausing work on SpinRite v6.1 to create a new piece of GRC Freeware which will quickly and non-destructively check the terrain of any USB-connected mass storage drive for “fakery” - It will quickly spot “fake” or badly damaged drives.
39
46
556
@SGgrc
Steve Gibson
8 years
Too perfect.. Courtesy of cartoonist Stuart Carlson @
Tweet media one
17
630
517
@SGgrc
Steve Gibson
3 years
OFFICIAL Win10 registry key to allow Win11 upgrading without TPM 2.0 =OR= CPU requirements: “AllowUpgradesWithUnsupportedTPMOrCPU” At: "HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup" create a REG_DWORD value with that name above. Set it to '1'. Voila! Win11 setup will upgrade!!
33
146
539
@SGgrc
Steve Gibson
10 months
Tweet media one
17
107
501
@SGgrc
Steve Gibson
3 months
Tweet media one
20
110
463
@SGgrc
Steve Gibson
3 years
The world's DNS servers are seeing 30 TIMES more traffic since DNS caches have drained for Facebook, Instagram and WhatsApp. Users are inadvertently pounding on them. (Cloudflare's 1 . 1 . 1 . 1 DNS server(s) are holding and remain speedy.)
9
109
434
@SGgrc
Steve Gibson
3 years
Facebook may have "deplatformed" itself, along with Instagram and WhatsApp. Hope no one depends upon "Login with Facebook!" Whoopsie! Somehow, the BGP entries for Facebook's DNS resolvers have been withdrawn from the Internet's routing tables. Insider? Attack? Who knows. Wow.
24
114
416
@SGgrc
Steve Gibson
2 years
Google just released a really well-produced, fun, visual, 15 to 19 minute YouTube video series “Hacking Google”. Videos are: Operation Aurora, Threat Analysis Group, Detection & Response, Red Team, Bug Hunters, Project Zero. HIGHLY recommended:
6
81
398
@SGgrc
Steve Gibson
11 months
Today's Security Now! Picture of the Week...
Tweet media one
22
40
381
@SGgrc
Steve Gibson
2 years
"Leaving LastPass" This week we discuss the many issues surrounding LastPass' disclosure that they did, in fact, allow all of their customer's partially-encrypted data to be stolen by unknown malicious actors, why it's time to say goodbye and what's next.
59
76
368
@SGgrc
Steve Gibson
7 years
THE absolutely most fabulous table setting placemat I've EVER encountered. (Okay... so there hasn't been much competition... but still!!)
Tweet media one
12
96
364
@SGgrc
Steve Gibson
7 years
Short Version: WPA2 is not dead. Only a single boolean flag needs to be added to code to prevent the attack. And TLS/HTTPS still saves us.
20
234
349
@SGgrc
Steve Gibson
2 years
Only 5000 Iterations! Direct confirmation from a decade-long LastPass user and Security Now! follower that when he checked just now, his LastPass vault was still set to 5000 iterations of PBKDF2, rather than the 100,100 that was set five years ago in 2018. Not cool, LastPass.
65
53
349
@SGgrc
Steve Gibson
4 years
#COVID ー19 / Thanks for all the well wishes, everyone. It appears that "patience" will be the main requirement. This thing is tenacious. Because it's truly novel, I think our bodies need much more than the typical time to mount a defense.
60
18
340
@SGgrc
Steve Gibson
10 months
How are various organizations organized? Not tomorrow's picture of the week... but funny:
Tweet media one
17
47
334
@SGgrc
Steve Gibson
3 years
Meanwhile... there's been a noted global decrease in reports of teenage depression and poor self image. Mental health is on the rise. But fear not, BGP is sure to be restored soon. :-/
12
45
330
@SGgrc
Steve Gibson
6 years
Microsoft FINALLY publishes a comprehensive 948-page Windows Command Reference PDF!: Yay!!
18
129
326
@SGgrc
Steve Gibson
4 years
Merry Christmas All!! And, while I really didn't plan it this way, the first release of the long-awaited ReadSpeed Benchmark went public on Christmas Eve. You can see an overview, watch a video of it running (with my narration) then try it for yourself!
23
33
317
@SGgrc
Steve Gibson
7 years
This week's fun & funny tech photo: "And that's how computers are made"
14
178
314
@SGgrc
Steve Gibson
11 months
Tweet media one
19
17
311
@SGgrc
Steve Gibson
8 years
A wonderful tee shirt, which Security Now! listeners will especially appreciate (and understand)...
Tweet media one
10
137
286
@SGgrc
Steve Gibson
7 years
This Week's "Picture of the Week" wins the all time sublime perfection Darwin award. Funniest perfect thing I've ever seen!...
Tweet media one
43
142
281
@SGgrc
Steve Gibson
4 years
Can I Tweet yet??
47
8
272
@SGgrc
Steve Gibson
3 years
Buckle Up! If you have access to Amazon Prime and enjoy Sci-Fi action movies, I can recommend Chris Pratt in “The Tomorrow War.” Non-stop action, fun, astonishing special effects (how'd they do those alien monsters?) and more. I can't imagine that it would disappoint!
37
18
259
@SGgrc
Steve Gibson
5 years
"SQRL Explained" 17-page technical overview document. See for details, GRC's reference SQRL client for Windows, and more. :)
19
83
256
@SGgrc
Steve Gibson
8 years
New Freeware from GRC: "Never10." Tiny (82k) utility allows easy disable or re-enable Win7/8 OS upgrade to Win10.
39
173
251
@SGgrc
Steve Gibson
3 years
:-( Security Researcher Dan Kaminsky died Saturday at age 42 of complications (ketoacidosis) from diabetes, which he had struggled with for years. Security Now! researchers know of Dan's discovery of a critical weakness in the DNS servers at the time. He will be missed.
13
32
254
@SGgrc
Steve Gibson
5 years
I just posted THIS posting number 23,606 to the SQRL development discussion group: Onward and back to SpinRite!
19
28
250
@SGgrc
Steve Gibson
11 months
Tweet media one
22
24
237
@SGgrc
Steve Gibson
2 months
“The rise and fall of ” Security Now! #978 show notes: MSFT vs Recall backlash, Google's me-too, NYT breach, Apple pswd mgr, DJI in the sky, AI assist or coding?, Linux's CVE craze and a bad mistake Microsoft turned into a goldmine.
Tweet media one
13
30
240
@SGgrc
Steve Gibson
3 years
A complete postmortem tomorrow. :)
15
11
236
@SGgrc
Steve Gibson
7 years
Everyone: I have no doubt that the title of next week’s podcast will be “Vault 7”.
28
27
231
@SGgrc
Steve Gibson
7 months
“The Mystery of CVE-2023-38606” Security Now! #955 show notes. A quick SpinRite update and some customer feedback, Then a seriously deep dive into what can only reasonably be described as a deliberate backdoor that was engineered into the past 5 generations of Apple's silicon.
Tweet media one
19
26
236
@SGgrc
Steve Gibson
5 years
The OWASP Gothenburg, Sweden chapter created a terrific video of my presentation there 10 days ago: This video FULLY demonstrates and EXPLAINS SQRL to anyone who is interested. Share it with other techies! :)
5
85
223
@SGgrc
Steve Gibson
5 years
Ready to start…
Tweet media one
18
7
220
@SGgrc
Steve Gibson
5 years
Danger Will Robinson!! Danger!! A heads-up that Netflix released all of Season 2 of Lost in Space the day before Christmas. I haven't started into it yet since I JUST found out. Hope to make it last a few nights! :) Happy Holidays All!
25
11
221
@SGgrc
Steve Gibson
6 years
We're losing the "Right to Repair" REALLY interesting and thought-provoking piece in Motherboard. :)
14
99
221
@SGgrc
Steve Gibson
6 years
GRC is back online. It was a dead port on their switch. Bizarre. But happy to be back online!
17
10
217
@SGgrc
Steve Gibson
2 years
Announcing “InControl”: GRC's latest Windows freebie which gives users control over Windows' out-of-control updating and upgrading. 82 kbytes of no-installation-needed x86 assembly language: Clean & simple, anyone can use it to control Windows Update.
14
59
218
@SGgrc
Steve Gibson
7 years
Tomorrow's Security Now! will provide full and deep coverage of BOTH the KRACK and ROCA attacks. :)~
13
66
201
@SGgrc
Steve Gibson
8 years
The latest Netflix series “Travelers” is fabulously binge-worthy! I’ll be describing it on Tuesday’s podcast, but you may not want to wait!
39
36
199
@SGgrc
Steve Gibson
8 years
Q: How many people would prefer not to have Windows 10? A: At least One Million: "Never10" downloads just crossed ONE MILLION.
31
105
201
@SGgrc
Steve Gibson
8 years
Everyone: Thank you SO MUCH for your "GRC is DOWN" support. I will update my dusty blog with a full rundown if we remain off the air. :)
64
37
198
@SGgrc
Steve Gibson
3 years
Title for tomorrow's Security Now! podcast, based upon what you get if you go to www(.)facebook(.)com: “Something Went Wrong” :) Indeed.
24
14
190
@SGgrc
Steve Gibson
3 years
A Blast from the past! Leo and me together in 1998... and more! I just updated GRC's old page of classic TechTV videos from WMV to MP4. We young once! <grin> The video collection is here:
18
14
180
@SGgrc
Steve Gibson
9 years
(Geek Alert!) Every time I see this brilliantly conceived photographic statement, I laugh again. It's so brilliant. http://t.co/rNcLLpdOSY
Tweet media one
8
165
180
@SGgrc
Steve Gibson
6 years
Sunday's Dilbert: Sad (true?)... but wonderfully Dilbert... (thanks to @MatDeWater for the tip.)
10
72
175
@SGgrc
Steve Gibson
2 years
GRC's Shortcut of the week for Security Now episode #905 : This is a PowerShell script, runnable on any Windows machine, that will post-process a captured LastPass vault to show its owner everything that's visible without decryption. (Quite a lot!)
37
32
182
@SGgrc
Steve Gibson
2 years
To =ALL= Security Now Listeners: I'm currently listening to Alex Stamos on Wednesday's "This Week in Google." Alex has not let anyone get a word in edgewise because he has SO MUCH amazing information to share. Without reservation, I RECOMMEND listening to this. It's FANTASTIC!
10
11
180
@SGgrc
Steve Gibson
6 years
GRC is DOWN HARD. No idea what happened yet. Everything appears to be fine at the data centers. Incoming link is up, but no bandwidth appears to be incoming. Looks like a routing problem at Level3/Century Link end. I'm on it! :)
30
16
178
@SGgrc
Steve Gibson
8 years
Netflix original series “Stranger Things” is UNBELIEVABLY WONDERFUL. If you have access to Netflix do NOT miss it!! Season 1 is 8 episodes.
32
35
173
@SGgrc
Steve Gibson
5 months
“Web Portal? Yes Please!” Security Now #963 show notes: Nevada wants to ban E2EE for minors, IT pros have a tough job, Chrome gets an Edge, online services selling our info, LockBitten, another horrible web portal mistake, SpinRite 6.1 released & feedback
Tweet media one
11
29
175
@SGgrc
Steve Gibson
7 years
Security Now Listeners!: Another charitable "Humble Bundle" offer of terrific security related eBooks:
19
102
167
@SGgrc
Steve Gibson
10 months
“When Hashes Collide” Security Now! #940 show notes: The operation of hardware security modules, convenient file hashing, non-hysterical requirements for secure data erasure, a UNIX time countdown, a deep dive into the value of deliberate hash collisions.
Tweet media one
9
30
161
@SGgrc
Steve Gibson
6 years
Remember last week's latest new Apache STRUTS vulnerability? Uh huh. Well, the bar has been forever raised on vulnerability disclosure and demo sites:
5
53
162
@SGgrc
Steve Gibson
2 months
GRC's (new) email system now allows Security Now! feedback email to be sent from known addresses to "securitynow" (@) . Anyone may register their address at: and there is NO NEED to subscribe to any email lists if not interested.
12
19
165
@SGgrc
Steve Gibson
2 months
“Microsoft's Head in the Clouds” Security Now! #974 show notes: Fascinating insights from analyzing 3.4 million PINs, a backup plan for GPS, multiple Passkeys per website account, what happened with Microsoft's cloud security breach and what's the future?
Tweet media one
4
28
163
@SGgrc
Steve Gibson
4 months
“Minimum Viable Secure Product” Security Now! #969 show notes: When should researchers keep quiet? Dangerous Internet secure message sites. The 0-Day for Pay market. Voyager 1. SpinRite v6.1 now selling, and an important industry initiative's new member.
Tweet media one
12
26
161
@SGgrc
Steve Gibson
13 years
MALWARE REMOVER: New from Microsoft, free, bootable malware/rootkit remover: http://connect.microsoft.com/systemsweeper
4
205
159
@SGgrc
Steve Gibson
8 years
It appears we know where TrueCrypt came from. It's a bit disturbing. LONG article. Skip halfway down to E4M icon:
19
87
156
@SGgrc
Steve Gibson
4 years
Re: Today's Mega Twitter Hack: I'll be on live with Jason Thursday morning at 11am Pacific to discuss everything we know about today's hack. See you there! :)
11
19
153
@SGgrc
Steve Gibson
3 months
“Chat (out of) Control” Security Now! #971 show notes: Stuxnet on steroids, Voyager 1 update, new features for Android & Thunderbird, China's new bans, Gentoo says no to AI, feedback, SpinRite and the EU's misguided legislation advances toward adoption.
Tweet media one
6
23
156
@SGgrc
Steve Gibson
12 days
“I've got problems with the WiFi” We cannot play this during tomorrow's Security Now! podcast due to a conflict with YouTube. But if you haven't seen it, it's just SO perfect:
17
28
160
@SGgrc
Steve Gibson
10 months
“Encrypting Client Hello” Security Now! #942 show notes: An 9.8 RCE flaw in the world's #1 eMail server, AI malware infiltration, Win11 passkeys, a SyncThing quickstart, targeting LastPass users, the difficulty of truly protecting TLS traffic from spying.
Tweet media one
6
20
152
@SGgrc
Steve Gibson
8 years
What should you eat? THIS fabulous (long) article explains why Western diet advice has been so deeply flawed:
11
56
147
@SGgrc
Steve Gibson
7 years
iOS users: Time to update (again). Last week's update left a worrisome (bad) remote WiFi attack possible. Grab v10.3.1 when you can. /Steve.
19
144
143
@SGgrc
Steve Gibson
3 years
A shout out to @StopForumSpam . GRC's forums were drowning in forum spam, because forum spammers are people, typically in the Eastern bloc, who create temp GMAIL accounts and manually bypass all CAPTCHA challenges. But after adding StopForumSpam -- not a SINGLE fake registration!
2
9
146
@SGgrc
Steve Gibson
6 years
Paypal's Venmo API defaults to publicly posting transaction details. What?!?! This link will show you the most recent one:
37
81
140
@SGgrc
Steve Gibson
10 months
“The Top 10 Cybersecurity Misconfigurations” Security Now! #943 show notes: “ValiDrive” published. Is 23andMe lying? What's the growth in cyberattacks? Is Brave fading? Google tracking link embedding. Pixel 8 support. Feedback and a GREAT doc from NSA/CISA
Tweet media one
10
24
139
@SGgrc
Steve Gibson
4 months
“Morris The Second” Security Now! #966 show notes: Voyager lives! (maybe). The WEB just turned 35 - What's its Dad think? A horrific consumer privacy violation. Lots of feedback. Will we be able to make generative AI models safe against deliberate abuse?
Tweet media one
14
19
141
@SGgrc
Steve Gibson
5 years
FYI: I'm heading toward a hybrid solution with zero-cost or paid options, warrant-proof (TNO) cloud storage, optional archival non-local storage, file versioning, ransomware protection, fully cross-platform, and more. :)
27
11
139
@SGgrc
Steve Gibson
4 months
"GoFetch" Security Now! #967 show notes: Apple vs DoJ, GM's privacy invasion, Super Sushi Samurai, no HomeKit routers, a domain name for private nets, can we control AI?, Telegram blocked again, Pwn2Own 2024 and the major Apple's M-series crypto attack.
Tweet media one
16
20
136
@SGgrc
Steve Gibson
3 years
Anyone seeking additional pain can now obtain the official Windows 11, directly from Microsoft. (I would call it the "final" Windows 11 ... but who are we kidding?)
13
27
137
@SGgrc
Steve Gibson
3 months
“Passkeys: A Shattered Dream?” Security Now! show notes: A stunning new UK law promises to change IoT security globally and immediately! Chrome's 3rd-party cookies, feedback and eMail, and an insider developer bemoans the failure of Passkey authentication.
Tweet media one
7
24
137
@SGgrc
Steve Gibson
11 years
Step-By-Step HOWTO to run SpinRite in a Virtual Machine on a PC, Mac, Linux, etc.: http://t.co/qabapwpo (the bitly link is "srvm")
17
37
136
@SGgrc
Steve Gibson
18 days
“The Attack” Security Now! #982 show notes: Entrust responds to Google's withdrawal of trust. Other CA's jump in. The Passkey Redaction Attack. OpenSSH and Port Knocking or failure blocking. The Internet dodged another bullet!
Tweet media one
8
32
137
@SGgrc
Steve Gibson
6 months
“Unforeseen Consequences” Security Now! #960 show notes: CISA pushes SOHO router changes, a serious flaw in a Linux core lib, OpenSSL RIP?, Roskomnandzor!, proactive Passkey adoption, and what may be the unforeseen consequences of Google's cookie blocking?
Tweet media one
8
24
135
@SGgrc
Steve Gibson
4 months
“A Cautionary Tale” Security Now! #968 show notes: All Linux users should update. 73 million AT&T users' data leaked online. New Signal & Telegram features. Russian IT exodus. Google's (non)incognito mode. A VERY worrisome discovery for the Linux community
Tweet media one
11
24
133
@SGgrc
Steve Gibson
9 years
Very nice Windows 10 privacy lockdown guide: http://t.co/nT2ETe9Tqi
8
78
130
@SGgrc
Steve Gibson
7 months
“The Inside Tracks” Security Now! #956 show notes: Why I believe the Apple backdoor was deliberate and known, how soft is today's cybersecurity?, 23andYou, cryptocurrency update, cyberwar insurance, not so Incognito, and interesting spinning drive data.
Tweet media one
10
20
132
@SGgrc
Steve Gibson
2 years
I watched the first episode of the new Start Trek “Strange New Worlds” last night. I cannot imagine that anyone who grew up with the original series or The Next Generation would not LOVE this as I do! It's REALLY spot on. ArsTechnica's review nailed it:
11
16
131
@SGgrc
Steve Gibson
8 years
Security Now! Followers: I found a very nice $50 router: (Needs 12v power supply.) We'll discuss it next week! :)
50
30
129
@SGgrc
Steve Gibson
8 years
Star Trek “Beyond” was perfect. Funny, fun, fast & fantastic. Everything you want after 50 years of Trek. Happy Anniversary!!
14
26
128
@SGgrc
Steve Gibson
13 years
High Quality Star Trek Sounds: http://www.stdimension.org/MediaLib/computere.htm Many people have asked where I found mine. :)
15
46
129
@SGgrc
Steve Gibson
25 days
“The End of Entrust Trust” Security Now! #981 show notes: An urgent OpenSSH vulnerability!! Old bitcoins on the move. Voyager 1 update. A fabulous emailing system. DNS for version management. How one of the original certificate authorities totally blew it!
Tweet media one
2
18
128
@SGgrc
Steve Gibson
7 years
A VERY cool example of browser-based voluntary cryptocurrency mining. At "max", how many hashes/sec does your PC do?
46
72
121
@SGgrc
Steve Gibson
8 years
The most tweeted-to-me link in recent times: John Oliver on last night's "Last Week Tonight" He did a FABULOUS job!
2
52
120
@SGgrc
Steve Gibson
11 years
HOWTO create your own SUPER SECURE personal cloud storage with BitTorrnet Sync, OwnCloud, and a Raspberry Pi: http://t.co/TloC4bhxjU
11
102
124
@SGgrc
Steve Gibson
5 years
"Star Trek: Picard" Premieres Today. It's annoying that it's "CBS All Access", so paid streaming. But just a heads-up for those who might have not caught the release date. :)
30
13
122
@SGgrc
Steve Gibson
2 years
Anyone want to know the TRUTH about Windows 11 hardware compatibility requirements? Because this has always infuriated me, I'll be revisiting the issue on today's podcast/ Here's 63 seconds from last Wednesday's Windows Weekly podcast #765 :
9
27
123
@SGgrc
Steve Gibson
8 years
In case you missed it... THE BEST political ad of this season. Why can't they all be so fun & positive?
9
63
122
@SGgrc
Steve Gibson
2 months
“A Large Language Model in Every Pot” Security Now! #977 show notes: Simplest apps are better, GRC's 1st week with incoming email, who's been Pwned? More CA trouble. Remember ICQ? A perfect SciFi movie. And what might be Microsoft's true plan for Recall!?
Tweet media one
14
22
124
@SGgrc
Steve Gibson
9 months
“Article 45” Security Now! #947 show notes: Microsoft's Azure key storage, 4 new 0-days in Exchange, another cyber mass-casualty event, CVSSv4, Google's WebDRM?, Bitwarden's Passkeys, SpinRite 6.1 fixes an SSD, and the EU goes off the rails (again)! <sigh>
Tweet media one
10
18
121