Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jeff Moss

@thedarktangent@defcon.social
mastodon 4.7.3
  • Open on defcon.social

Founder of DEF CON & Black Hat. Maintainer of infocon.org.

Member of the UK Gov Cybersecurity Advisory Board & The Council on Foreign Relations.

Working to get Hackers and Researchers a seat at the Policy table.

I'm interested in hacking, community, technology, privacy, security policy, and the intersection of civil society. (He/Him) Opinions are my own.

Previously member ONCD (2024-2025), CISA Cyber Security Advisory Council (2021-2025), and DHS Advisory Council (2009-2020)

12637 Followers
1161 Following
45 Posts
Joined November 13, 2022
DEF CON:
https://defcon.org
DEF CON Forums Blog:
https://forum.defcon.org/node/196796
InfoCon:
https://infocon.org
Open post
Jeff Moss @thedarktangent@defcon.social
· 3mo ago
Replying to
Next up, a #DEFCON #VPN service sounds awesome. Like with email there is plenty of expertise on how to build VPNs. Technically it is a realistic goal, so let's investigate! To be attractive to a large customer base you need to offer a lot of locations with an ever changing pool of addresses for when some get blocked by someone in the world. Those two things mean you need a pool of providers and great automation playbooks where you can easily spin up and provision "secure" VPN gateways all over the world. Because of the reliance on 3rd parties, unlike with email, you now have to worry about the legal concept of the 3rd party doctrine, so have some more lawyers ready to do battle. Then two things happened, I spoke with two different people with experience in the VPN game. First someone who served as a CTO to a large VPN provider. They spent all their time trying to save money, automate more, and respond to non-stop customer complaints from over seas business people. Chine would block some VPN addresses and they could no longer connect to their company back home and they needed to do that RIGHT NOW. So a sort of daily fire drill. The increasing VPN competition meant they had to keep spending on advertising and cost control. The second person put the final nail in the coffin. They explained as far as they could tell about half of all VPN providers had ties to intelligence services. Either as fronts or investors or super friendly "partners". Iran, Russia, China, North Korea, some Middle Eastern countries, all play in this space. This means half of the VPN providers have a different business model than the other half. Their goal is maximum people at the least cost to cast as large a monitoring net as possible, and revenue from paying customers doesn't have to actually cover your operating costs. Building a #VPN service the right way would mean we would be more expensive, in fewer locations, and support only the strongest technologies - all things that would reduce your pool of potential customers. So, like the private email idea, it was interesting to investigate, we learned a lot, and we will never enter the VPN market. Instead we run free #Tor relays and support @torproject@mastodon.social Please support Tor and other privacy technologies.
292
6
143
4
Open post
Jeff Moss @thedarktangent@defcon.social
· 3mo ago
Replying to on defcon.social
For #DEFCON to do private email we would want to host our own servers to avoid the 3rd party legal doctrine, and keep them secure. No problem, we have a secure location and lawyers. Back during COVID when we were investigating this it was still possible to gather some open source info on how large other private email services were. How big was the market? Could you make enough money to hire the people and buy the servers? MailFence, Proton, and others showed it was possible if you were very efficient. Great! Then I spoke with someone who worked at a white label email service provider. I realized DEF CON would never do a private email service for two reasons: CSAM: They explained they had about 10 people dedicated to responding to legal requests around CSAM, not including their lawyers and LE relationship people. SPAM: They had another room with about 30 people dealing just with spammers and the impacts of spammers. Managing their ASNs, netblocks that get lower reputation on blackhole lists, moving customers to "clean" netblocks when a shared block gets polluted by spammers, etc. Conclusion? If you are very successful you can look forward to having a room of 40 people dealing with LE, SPAM, CSAM, Networking, and that's before you add on customer service. That doesn't seem fun or very DEF CON Hacker anymore. Next up, VPN.
190
7
62
1
Open post
Jeff Moss @thedarktangent@defcon.social
· 3mo ago
Replying to
Because this post got a lot of traction, some more context: Last year I had drinks with another VPN dude at a meeting, and he worked for a holding company that owned many VPN companies. They acquired them pretty regularly and integrated them best they could. I asked why keep all the separate brands and marketing if it’s all basically the same thing, and he explained the market is segmented. Some users believe a particular VPN is better for gaming, or business, or torrenting, or porn, or cheapest or whatever. It actually hurt them the couple times they tried to merge brands, so now they try to merge all they can behind the scenes technically but keep the brand identities separate. #DEFCON #VPN #VPN #Tor
149
7
80
1
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Looks like someone built a tool to check your LinkedIn network for names from the Epstein documents. Soon I expect other tools will follow to work with other social media platforms. This is what the beginning of community accountability looks like. Just because the legal system is captured doesn’t mean there are zero consequences. https://github.com/cfinke/EpsteIn Yes, I know I am mentioned in the files, but I can’t control when other people mention me. #epstein
github.com
276
22
232
2
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
Here is Wednesday morning: #LasVegas #Meshtastic #Meshcore #DefCon
18
4
5
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
It’s really telling that the first two comments to my post about the meta data privacy improvements in Signal are punching down, complaining about Signal not doing it the way they would do it.
24
8
2
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
I know I am in #DefCon mode because I want to drink Red Bull non-stop. I don't drink it any other time, so it's kinda a strange stress response.
16
4
2
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Heading to Las Vegas for #Hacker Summer Camp? Don't forget to backup all the things before you leave!
14
1
3
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 7mo ago

RIP FX - You are a legend.

Here Dino is delivering his Pwnie Award, as well as the last public post FX made last year.

104
15
126
4
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
RE: https://infosec.exchange/@SecurityWriter/115969540425890734 To build on what was said below, your whole online existence is essentially three things combined: 1 - Your email account or mail server where you can get password resets. 2 - DNS that protects the mail server from being impersonated. 3 - Your domain WWW server that can publish records that your domain registrar or certificate authority trusts when issuing certificates. If you lose control of your email account or mail server, people can password reset their way into all of your account unless you have some strong second factor as a security key. If you have a secondary email recovery account that would be vulnerable. It could possibly be used to bypass your second factor. If you lose control of your DNS server or your registrar account, then people can impersonate your services such as your web server or mail server for account recovery. A DNS attack could completely remove your existing servers and point traffic to malicious ones as well. Finally if you lose control of you web server then it could be used to publish .well-known files used for identity verification with certificate authorities, spread malicious files, your imagination is the limit. As you can see DNS and email are critical. Today everybody outsources their DNS and email. Choose how you manage these as if your identity, finances, and company depend on them. Basically no one controls their own identities. By running your own email or DNS servers the third-party doctrine would not apply to you, and you would get notice that something was going on with law enforcement.
infosec.exchange
122
20
91
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Looks like CyberNwes had released their #DefCon Documentary! "For the first time in over a decade since the founders' original documentary, Cybernews was granted unprecedented behind-the-scenes access to DEF CON's organizers and community." https://www.youtube.com/watch?v=pb0kJXSy64E
9
0
5
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Question about #RainbowTable and #PasswordCracking What is the preferred format today? RT2, RTC, RT (RT1?) and with what tools, rcrack? I'd like to convert all the https://infocon.org/ rainbow tables into whatever the best format is so everyone that downloads them doesn't have to keep duplicating work. #InfoSec #InfoCon #hacking
InfoCon.org
infocon.org

InfoCon.org

InfoCon.org is an archive of hacking and security conference videos, documentaries, rainbow tables, word lists and podcasts.

11
8
6
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@dcuthbert@defcon.social I was talking to someone who was seriously trying to disconnect their car. They found the system unplugged the lead to the antenna and thought they were done. It turns out even with the antenna unplugged if the car got too close to a cell site sometimes it would still synchronize.
5
3
4
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago

Under the giant #DefCon cube!

defcon.social

DEF CON Social

19
2
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago

Congratulations #Hungary! 🎉🎉

defcon.social
17
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 4mo ago

Just connecting through Dubai on the way to Bahrain for some #DefCon meetings. Everything seems oddly normal at the airport, I’m not sure what I expected, and I’m curious what stories I’ll hear from locals.

We plan to make a go/no-go decision the beginning of July if we hold DC Middle East the beginning of November, but either way we need to be planning now.

defcon.social

DEF CON Social

11
2
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@jef@mastodon.social
4
0
1
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@adamshostack@infosec.exchange @jack_daniel@mastodon.social I was thinking of licensing you my training data from https://infocon.org (never mind that is it all free and open) in return for substantial shares of your companies.
InfoCon.org
infocon.org

InfoCon.org

InfoCon.org is an archive of hacking and security conference videos, documentaries, rainbow tables, word lists and podcasts.

4
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago

This image from Reddit seems to pretty much sum up the situation:
#USPol

defcon.social
13
0
2
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@blackfeathers@defcon.social I’m up high in a hotel along the strip, using a stock T1000E so nothing fancy.
2
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 4mo ago

The AI Security Uplift is underway.. the security fixes in the latest Nginx version is a good example. More fixes in one version than the last year. Unrelated to core Nginx there are an additional 22 fixes in the ZSTD module.

https://nginx.org/en/CHANGES

Like I have been saying, all boats will get lifted on a rising tide, but only if you use popular boats that everyone runs their tools against.

nginx.org
6
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago

With South East Asia getting around 80% oil from the Straight of Hormuz, and #Singapore around 65%, it seems prescient that back in February they had a campaign around awareness if the power goes out:

defcon.social
6
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@syrupsplashin I totally understand, as I am mentioned in the files. I was pointing out that people will find alternative ways to try and hold people accountable when the legal system fails, that socially disconnecting yourself from those you might have followed years ago will become a thing. It definitely won't be perfect. For example I am sure over the decades I've followed some people who have turned into MAGA that I would prefer not to associate with. Or maybe there companies that are enabling fascism that I don't want to buy from anymore, but I lack the tools to easily figure out which ones they are. Someone or some group will do the work, just like the MAGA groups are making lists on their side of the beer companies they don't like anymore.
10
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 3mo ago
Replying to
@tychotithonus@infosec.exchange You don’t have anyone using LAST First?
2
2
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@niconiconi@mk.absturztau.be @drwho@masto.hackers.town For FreeBSD enabling KTLS is a big performance improvement. Thanks NetFlixfor doing the work and getting it upstreamed!
1
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@niconiconi@mk.absturztau.be @drwho@masto.hackers.town We use 9000 jumbo frames and don’t see much of an improvement, but we are not saturated so it’s hard to tell. Thinks like hardware TSO, RSS, Etc seem to make a small difference.
1
2
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 14mo ago
Replying to
@0xabad1dea@infosec.exchange Time for everyone to start increasing the costs by deploying something like Anubis I guess. https://github.com/TecharoHQ/anubis
GitHub

GitHub - TecharoHQ/anubis: Weighs the soul of incoming HTTP requests to stop AI crawlers

Weighs the soul of incoming HTTP requests to stop AI crawlers - TecharoHQ/anubis

20
5
6
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago
Replying to
Ha! Thanks everyone for the feedback on CoMaps vs. Organic Maps. I read the news section on Organic Maps and there is no mention of the concerns raised by the CoMaps open letter. That seems a bit odd, so I'll be trying CoMaps next.
2
0
1
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 5mo ago
Replying to
@alecmuffett I have found the community of people working to create and support open standards and interoperability are creating the foundation on the internet. One friend told me "I don't really care what you build on top of it, I can't predict what people will want, but I do want whatever is built to be open and not to be proprietary and rent seeking"
2
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 4mo ago

Made it to Krakow for #CONFidence, looking forward to meeting everyone. 👋

defcon.social
1
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 14mo ago
Replying to
@Foxboron@chaos.social @0xabad1dea@infosec.exchange Its taken decades to get here, and all along the way companies have forced externalities onto other site operators end users. Anubis reminds me of tar pit defense against spam, trying to slow things down and raise the costs to spammers.
7
4
1
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@t3sserakt@c3d2.social @tomgag@infosec.exchange I’m all for building on top of #Tor, no registrars, no DNS, no Certificate Authorities. That’s why all the #DefCon and #InfoCon services are available over .onion sites as well.
2
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@andreagrandi I would not accept results blindly, but I would like to know at least where to start looking..
1
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@hc@mastodon.africa @harrysintonen@infosec.exchange I’m not sure about new servers, mine is quite old. One thing to do with email is create a Google Postmaster account and register your mail server with them. https://www.gmail.com/postmaster/
gmail.com

Postmaster Tools – Google

1
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@hc@mastodon.africa @harrysintonen@infosec.exchange I try to pay for my key domains for many years in advance, 5-10 years.
1
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 8mo ago
Replying to
@hc@mastodon.africa @harrysintonen@infosec.exchange If I didn’t run my own mail servers I would pay for email someplace, not a free account. That way I could talk with a human if necessary, not have my email used for the advertising tech, etc.
1
3
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@moldavia@mstdn.party I must not read that many Wired articles. 😂
0
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 14mo ago
Replying to
@Foxboron@chaos.social @0xabad1dea@infosec.exchange I didn’t say it did?
0
0
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@moldavia@mstdn.party Strange, that link took be to the article with no limitations.
0
1
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@muddle@infosec.exchange .rt is not compressed, and .rti2 is compressed. .rtc is also compressed but not as well as .rti2 For example 9TB of rti2 is equal to about 11TB of .rtc. About 17TB of .rt is equal to about 7TB of .rti2 (250%) More tools seem to support .rtc, but if they are old tools and everyone is using the ones that support .rti2 then great, less disk space needed and I can try to covert to that format.
0
6
0
0
Open post
Jeff Moss @thedarktangent@defcon.social
· 2mo ago
Replying to
@muddle@infosec.exchange Some quick searching will reveal https://www.freerainbowtables.com/rti2formatspec.pdf "Introduction RTI2 is a variable length bit packed rainbow table format developed by www.freerainbowtables.com. It reduces disk usage through the variable length data chains, though each data file has one consistent data chainrow length, and through the use of prefix indexes. It is in some ways similar to the RTI format but designed to be easier to modify items in subsequent minor versions and this flexibility adds a fair amount of complexity. Additionally, it is designed so that a transition away from the file naming for information may be possible as this will be necessary for more complex table sets in the future"
freerainbowtables.com
0
4
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:46:22 UTC