Posts
4632
Following
742
Followers
1659
"I'm interested in all kinds of astronomy."
repeated

#BOFH excuse #442:

Trojan horse ran out of hay

0
2
0
repeated
@jerry @dey I can see the Initiator is an img, but I can't find anything seemingly related in inspector + network rectord don't tell me what code initiated a request. That's the status.
1
0
0
@dey @jerry But I'm not using Mastodon, this is an Akkoma instance. And this only happens if I scroll back to the point in my timeline when I first got this notif. It'd be really weird if this behavior didn't trigger at around page load.
1
0
0
@dey @jerry More details pls, who is trying to figure out if I have SW X installed and how?
1
0
0
@jerry Based on this article and the previous error I assume this permission request is not coming from JS but someone trying to make me fetch an URL from localhost which now triggers additional warnings:

https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox

At this point I'm not sure if it should be illegal for posts to contain references to localhost.
0
0
0
@jerry I came here to drink wine and scroll, and I'm just out of wine!
1
0
2
@jerry It *is* timeline dependent! I had to scroll back more than a day (I stupidly overwritten the original screenshot with the crop, but the timestamp helped).

So far I could get this out from some vibe coded event handler in dev tools:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"
1
0
1
@jerry Original timestamp of the image:

Wed Sep 23 09:14:13 PM CEST 2026

It's the first time I see such request ever (not just here).
2
0
1
Umm why does infosec.place "access my device"?

/cc @jerry
1
0
1
repeated

Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/

3
5
0
repeated
repeated

I tempted to do a small giveaway: reply with your best success *or* horror story related to electronics. I'll pick ~3 winners around EOW and send them a copy of The Secret Life of Circuits.

Plz no AI slop. Won't ship to Russia.

8
3
0
repeated

Webseeds should be working again for https://infocon.org/ .
There was a problem with http range requests that should now be fixed. Please let us know if you see a difference!

0
1
0
repeated

Any pentesting firm behaving like OpenAI would be shutting down and counting lawsuits within a couple of months.

This new rera of Big AI doing cyber surely feels like the late 1980s/early 1990s of the Internet Wild West

0
2
0
repeated

RE: https://cosocial.ca/@mhoye/117326705107715161

That last paragraph is a compelling point that runs deep.

0
5
0
repeated

@xssfox More interesting technical details here (I can't vouch for accuracy):
https://collusion.wiki/
https://transluce.org/agent-activity

0
2
0
Show older