Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Per Thorsheim

@thorsheim@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Founder of #PasswordsCon. Above average interested in passwords & digital authentication. Online since 2400baud. I made the world use RFC 3207 STARTTLS for email encryption.

1359 Followers
935 Following
33 Posts
Joined April 03, 2017
Twittodon verification:
https://twittodon.com/share.php?t=thorsheim&m=thorsheim@mastodon.social
Obsessions:
Passwords, digital authentication
Open post
Per Thorsheim @thorsheim@mastodon.social
· 18mo ago

US gov asks european suppliers to guarantee they don't do DEI.

Next: we ask US to guarantee they do fair pay, 5 weeks paid annual vacation and 1 year paid maternity leave.

2171
108
1381
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago

Protip: add your name, address, alternative phone number & email to the lockscreen of your phone!

In case you forget it somewhere, it will be so much easier for others to return the phone to you.

6
2
4
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 3mo ago

Skriv en falsk pinkode på betalingskortene dine. Da kan du lure skurkene som stjeler dine kort, varsle bankene og redde pengene dine. Enkelt og veldig lurt!

4
0
3
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 3mo ago

The near future of developers who can't write code themselves.

4
0
3
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 6mo ago

I will be presenting "Our Vulnerable Networks" at #Sikkerhetsfestivalen 2026, talking BGP & RPKI history, status & "how to get it done".

Through history back to 1989 (BGP), L0pht testifying for congress in 1998 and lots more, I will explain the problem, the gaps, current status and what we need to do to fix a global internet routing security issue that is exploited many times daily.

Thanks to @internet_nl@mastodon.nl & @ripencc@mastodon.social for their tools & knowledge, and the @cloudflare@noc.social routing radar!

mastodon.social

Mastodon

8
2
6
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago

Right now attending the first ever BSides conference here at home in Bergen, Norway!

https://2026.bsidesbergen.no/

2026.bsidesbergen.no

BSides Bergen 2026

3
0
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 6mo ago

Jeg har vært på podcastinnspilling hos Advokatforeningen og snakket om mine undersøkelser av epost sikkerhet hos deres medlemmer. Resultatet kan du høre på Spotify og andre podcast plattformer. Mer info her:

https://www.advokatforeningen.no/aktuelt/podcast/bits-and-bytes-for-advokater-per-thorsheim/

Bits and bytes for advokater: Per Thorsheim | Advokatforeningen
Advokatforeningen

Bits and bytes for advokater: Per Thorsheim | Advokatforeningen

4
0
2
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago

Gut feeling: Instructure (who owns Canvas) chose to pay the ransom because the consequences for a massive number of students worldwide in their exam period before summer could be devastating.

I can only imagine the ransom paid is *massive*

2
3
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago

RE: @finnmyrstad@eupolicy.social

Proud to support this, and have co-signed the letter to Norwegian authorities.

eupolicy.social

Finn Lützow-Holm Myrstad: "❓Have you noticed that digital products and servi…" - EUpolicy.social - A Mastodon server for the EU bubble

4
0
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 3mo ago

På #Personverndagene 2026 skal jeg holde kurs for å vise hvordan man kan gratis teste internett sikkerheten for egen organisasjon, leverandører og andre.

Risiko vil bli forklart, nødvendige tiltak blir gjennomgått, og du får en sjekkliste med det du trenger til jobben.

https://personverndagene.no/

mastodon.social

Mastodon

1
0
2
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 3mo ago

Post-kvante Kryptografi (PQC) er fremtidens sikring av data i møte med trusselen fra kvantedatamaskiner. En god del norske nettsteder har allerede støtte for dette, i den grad det er mulig å sette opp. Jeg har sjekket!

https://thorsheim.net/pqc/

thorsheim.net
1
0
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 3mo ago

Whenever I hear or see discussions about tactics etc in the FIFA World Cup on national news.

1
1
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@samueljohnson@mstdn.social @internet_nl@mastodon.nl Here you go: https://thorsheim.net/2026/02/data-protection-agencies-dpa-should-have-good-security-right/
thorsheim.net

Data Protection Agencies (DPA) should have good security, right? – Per Thorsheim

3
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago

Jeg viste spoofing i 2019 og forklarte mulighetene og konsekvensene gjennom en rekke foredrag, artikler og mediesaker, som i tillegg til Norge også dekket Sverige og Danmark.

Telenor ble bøtelagt av Nkom. Datatilsynet kom med kritikk, men kunne ikke gi ekstra bot.

Så kommer Harrison Sand & Norsk rikskringkasting (NRK) med Martin Gundersen på banen nok en gang bare i år, og BOOM, hva finner de da?

Flere sårbarheter som muliggjør spoofing.
Jeg har kommentert til NRK.

https://www.nrk.no/norge/sarbarhet-avdekket_-telia-og-ice-kunne-misbrukes-i-spoofingforsok-1.17898532

Sårbarhet avdekket: Telia og Ice kunne misbrukes i spoofingforsøk
NRK

Sårbarhet avdekket: Telia og Ice kunne misbrukes i spoofingforsøk

To av Norges største teleselskaper hadde en feil som gjorde det mulig å tyvlåne andres telefonnummer.

1
1
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 8mo ago

https://www.theregister.com/2026/02/03/microsoft_tls_deprecations/

Almost 5 years after RFC 8996 / BCP 195 «Deprecating TLS 1.0 and TLS 1.1»

theregister.com
3
0
2
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago
Replying to
@Colman@mastodon.ie Will be interesting to see if this is the end of this tragic story. I doubt it.
1
1
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 4mo ago
Replying to
@Colman@mastodon.ie And just like that, the story continues: https://www.theregister.com/cyber-crime/2026/05/12/congress-investigates-canvas-breach-after-instructure-cuts-deal-with-shinyhunters/5238927?utm_source=dlvr.it&utm_medium=bluesky
Congress investigates Canvas breach as company pays ransom
theregister

Congress investigates Canvas breach as company pays ransom

Instructure CEO Steve Daly

1
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago

Data Protection Agencies should have good security, right?

I've scanned almost 160 DPAs around the world using the Dutch Internet Standards Platform @internet_nl@mastodon.nl to check web, dns and email security.

The results are in, and you won't like them.

https://www.linkedin.com/pulse/data-protection-agencies-dpa-should-have-good-right-per-thorsheim-ecbwe/

mastodon.nl

Internet.nl (@internet_nl@mastodon.nl) - Mastodon.nl door Stichting Activityclub

2
2
5
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago

Det går bedre med epost sikkerheten for norske advokatselskaper, men det er alltid rom for forbedringer!

Her en liten statusoppdatering pr februar 2026:
https://www.linkedin.com/pulse/det-g%25C3%25A5r-fremover-i-advokatbransjen-per-thorsheim-dx9qe/

linkedin.com

Det går fremover i advokatbransjen!

I flere artikler her på Linkedin har jeg påpekt mangelfull epost sikkerhet hos norske advokatselskap. Jeg har stilt spørsmål ved advokaters bruk av gratis epost tjenester og deres konfidensialitetsplikt, samt hos ulike fagforbund og andre organisasjoner som bør forventes å ha orden på dette.

2
6
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 5mo ago
Updated my mailcheck tool to better fit mobile displays. Github: https://github.com/thorsheim/Mailcheck Live: https://passwordscon.org/mailcheck
GitHub

GitHub - thorsheim/Mailcheck: Standalone html that runs in your browser to check any domain: DNSSEC, MX, PTR, DANE, SPF, DKIM, DMARC, BIMI, TLS-RPT, MTA-STS, CAA, RPKI, Security.txt and WHOIS info.

Standalone html that runs in your browser to check any domain: DNSSEC, MX, PTR, DANE, SPF, DKIM, DMARC, BIMI, TLS-RPT, MTA-STS, CAA, RPKI, Security.txt and WHOIS info. - thorsheim/Mailcheck

1
1
2
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 18mo ago
Replying to
@RachelC_Y@piaille.fr First part is true. Companies in Norway, as in France and others, have received letters from American embassies about this. The second part is wishful thinking / suggestion from me.
6
1
2
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 18mo ago
Replying to
@xs4me2@mastodon.social I did consider adding it in there, but it seemed a bit too much to ask. ;)
2
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@halfawake@infosec.exchange Her har du noe som du ikke ser like enkelt som meg, men som er offentlig tilgjengelig info: advokater som har oppgitt gmail som kontakt epost. Jeg håper at disse selvfølgelig ikke bruker Gmail til vanlig klientkommunikasjon men går gjennom sine respektive arbeidsgiveres løsninger, men jeg lister nå bare opp det som er offentlig oppgitt jeg, og tester deretter.
0
3
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago

Lawyers using free mail services like Hotmail, Gmail & iCloud?
Oh yes!

Security, privacy & lawyers legal obligation to confidentiality?
Good question!

I've written about lawyers in Norway using such services, and my own personal recommendations about it.

https://www.linkedin.com/pulse/lawyers-using-free-email-services-per-thorsheim-4fkee/

linkedin.com

Lawyers Using Free Email Services

I have previously written a couple of articles about email security at law firms in Norway & Denmark. I have also written about email security at Apple iCloud, labor unions in Norway, the Norwegian National Security Authority (NSM), the Norwegian Data Protection Authority (Datatilsynet), and the dec

0
0
3
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@halfawake@infosec.exchange Telenors online.no plattform:
0
2
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@halfawake@infosec.exchange ...og Apple iCloud:
0
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 8mo ago

Datatilsynet har selv svakheter og mangler for sin mailserver som utgjør en høyst unødvendig og reell sikkerhetsrisiko for dem, og alle som kommuniserer med dem på epost.

Jeg har undersøkt, og skrevet en forhåpentligvis forståelig forklaring på norsk om hva som mangler, hva det betyr, og hva som bør gjøres.

https://www.linkedin.com/pulse/epost-sikkerhet-hos-datatilsynet-per-thorsheim-f2ufe

linkedin.com

Epost Sikkerhet hos Datatilsynet

Jeg heier på dere. Dere har en særdeles viktig rolle i samfunnet, med en klar og tydelig stemme.

0
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 6mo ago

@km@mastodon.babb.no 220 STARTTLS

0
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 2mo ago
#PasswordsCon is coming to Munster Technological University in Cork, Ireland, December 8-9! Additionally our Chatham house rule day will be on December 7, while the Cyber Research Conference Ireland (CRCI) will be at the same location on December 10. Info & more: https://events.mtu.ie/index.cfm?page=events&eventId=1427
events.mtu.ie

MTU Events -

MTU Events

0
0
1
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@halfawake@infosec.exchange Jupp. Jeg hentet data fra advokatenhjelperdeg.no. Om det er Advokatforeningen eller medlemmene som selv legger inn og oppdaterer egen info der vet jeg ikke, men advokat Hauge i Advokathuset Vest AS har vitterlig lagt det inn som sin kontakt epost: https://advokatenhjelperdeg.no/finn-advokat/vestland/bernhard-olav-hauge/
Advokaten hjelper deg

Bernhard Olav Hauge

0
4
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 7mo ago
Replying to
@halfawake@infosec.exchange Hotmail:
0
2
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 6mo ago

@km@mastodon.babb.no sant nok siden du startet med moderne EHLO, ikke gammeldags HELO.

0
0
0
0
Open post
Per Thorsheim @thorsheim@mastodon.social
· 6mo ago
Replying to
@dbelson@mastodon.social Would *love* to talk one day, as I'm using CF radar in preparations for that talk in august, but also to promote the use of rpki to everyone relevant. "Never heard of it." "Not a problem." "Doesn't happen to us." "That's someone elses problem." "Theory. Ransomware is for real, so we focus on that." "No documented losses or problems due to lack of rpki." I've heard other versions as well. CF Radar provide documentation on some of those, but could - imho - provide more info.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:51:33 UTC