US gov asks european suppliers to guarantee they don't do DEI.
Next: we ask US to guarantee they do fair pay, 5 weeks paid annual vacation and 1 year paid maternity leave.
Founder of #PasswordsCon. Above average interested in passwords & digital authentication. Online since 2400baud. I made the world use RFC 3207 STARTTLS for email encryption.
US gov asks european suppliers to guarantee they don't do DEI.
Next: we ask US to guarantee they do fair pay, 5 weeks paid annual vacation and 1 year paid maternity leave.
Protip: add your name, address, alternative phone number & email to the lockscreen of your phone!
In case you forget it somewhere, it will be so much easier for others to return the phone to you.
Skriv en falsk pinkode på betalingskortene dine. Da kan du lure skurkene som stjeler dine kort, varsle bankene og redde pengene dine. Enkelt og veldig lurt!
The near future of developers who can't write code themselves.
I will be presenting "Our Vulnerable Networks" at #Sikkerhetsfestivalen 2026, talking BGP & RPKI history, status & "how to get it done".
Through history back to 1989 (BGP), L0pht testifying for congress in 1998 and lots more, I will explain the problem, the gaps, current status and what we need to do to fix a global internet routing security issue that is exploited many times daily.
Thanks to @internet_nl@mastodon.nl & @ripencc@mastodon.social for their tools & knowledge, and the @cloudflare@noc.social routing radar!
Right now attending the first ever BSides conference here at home in Bergen, Norway!
Jeg har vært på podcastinnspilling hos Advokatforeningen og snakket om mine undersøkelser av epost sikkerhet hos deres medlemmer. Resultatet kan du høre på Spotify og andre podcast plattformer. Mer info her:
https://www.advokatforeningen.no/aktuelt/podcast/bits-and-bytes-for-advokater-per-thorsheim/
Gut feeling: Instructure (who owns Canvas) chose to pay the ransom because the consequences for a massive number of students worldwide in their exam period before summer could be devastating.
I can only imagine the ransom paid is *massive*
RE: @finnmyrstad@eupolicy.social
Proud to support this, and have co-signed the letter to Norwegian authorities.
På #Personverndagene 2026 skal jeg holde kurs for å vise hvordan man kan gratis teste internett sikkerheten for egen organisasjon, leverandører og andre.
Risiko vil bli forklart, nødvendige tiltak blir gjennomgått, og du får en sjekkliste med det du trenger til jobben.
Post-kvante Kryptografi (PQC) er fremtidens sikring av data i møte med trusselen fra kvantedatamaskiner. En god del norske nettsteder har allerede støtte for dette, i den grad det er mulig å sette opp. Jeg har sjekket!
Whenever I hear or see discussions about tactics etc in the FIFA World Cup on national news.
Jeg viste spoofing i 2019 og forklarte mulighetene og konsekvensene gjennom en rekke foredrag, artikler og mediesaker, som i tillegg til Norge også dekket Sverige og Danmark.
Telenor ble bøtelagt av Nkom. Datatilsynet kom med kritikk, men kunne ikke gi ekstra bot.
Så kommer Harrison Sand & Norsk rikskringkasting (NRK) med Martin Gundersen på banen nok en gang bare i år, og BOOM, hva finner de da?
Flere sårbarheter som muliggjør spoofing.
Jeg har kommentert til NRK.
https://www.theregister.com/2026/02/03/microsoft_tls_deprecations/
Almost 5 years after RFC 8996 / BCP 195 «Deprecating TLS 1.0 and TLS 1.1»
Data Protection Agencies should have good security, right?
I've scanned almost 160 DPAs around the world using the Dutch Internet Standards Platform @internet_nl@mastodon.nl to check web, dns and email security.
The results are in, and you won't like them.
Det går bedre med epost sikkerheten for norske advokatselskaper, men det er alltid rom for forbedringer!
Her en liten statusoppdatering pr februar 2026:
https://www.linkedin.com/pulse/det-g%25C3%25A5r-fremover-i-advokatbransjen-per-thorsheim-dx9qe/
Lawyers using free mail services like Hotmail, Gmail & iCloud?
Oh yes!
Security, privacy & lawyers legal obligation to confidentiality?
Good question!
I've written about lawyers in Norway using such services, and my own personal recommendations about it.
https://www.linkedin.com/pulse/lawyers-using-free-email-services-per-thorsheim-4fkee/
Datatilsynet har selv svakheter og mangler for sin mailserver som utgjør en høyst unødvendig og reell sikkerhetsrisiko for dem, og alle som kommuniserer med dem på epost.
Jeg har undersøkt, og skrevet en forhåpentligvis forståelig forklaring på norsk om hva som mangler, hva det betyr, og hva som bør gjøres.
https://www.linkedin.com/pulse/epost-sikkerhet-hos-datatilsynet-per-thorsheim-f2ufe