Posts
3370
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated
repeated

@jt_rebelo @arstechnica The end goal is a new set of electronics that completely lack hardware support for any kind of phone-home nonsense and are designed for utmost simplicity and reliability, rather than giant piles of rapidly developed spaghetti code full of features nobody wants.

We know how to build safe and reliable electronics, we do it all the time for e.g. geostationary communications satellites that have to function for 10+ years without any maintenance and that would cost $100M+ to replace.

We know how to build reliable software. We just... don't. Because it's too expensive.

0
1
0
Unfortunately the hv-vendor-id trick didn't work to make KDNET work over Proxmox, at least not by just setting the enlightenment in the cpu entry of the node's Proxmox config :(

https://infosec.place/notice/ArU6AdcfLlqQd1uAzY
0
0
0
repeated
repeated

Open Source Security mailing list

8 CVEs in X⁠.Org X server and Xwayland https://www.openwall.com/lists/oss-security/2025/02/25/1
CVE-2025-26594: Use-after-free of the root cursor
CVE-2025-26595: Buffer overflow in XkbVModMaskText()
CVE-2025-26596: Heap overflow in XkbWriteKeySyms()
CVE-2025-26597: Buffer overflow in XkbChangeTypesOfKey()

0
2
0
@SecurityWriter Strong Dwayne Elizondo Mountain Dew Herbert Camacho vibes!
2
0
5
Narrator: "Here's how the hack actually works"
Narrator: *Not actually explaining how the hack works.*

Gotta love USA-style storytelling!
0
0
2
I think I should display this somewhere in a frame

https://youtu.be/My_13FXODdU?si=5l_PiCdfXbY3ohSx&t=540
1
2
4
repeated

The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248) - watchTowr Labs https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/

0
3
0
repeated
Edited 11 months ago

There are numerous times where I think "if that person simply had better aim, the world would be so very different".

But then I remember that where we are right now globally is not down to one or two evil people - but the result of rot in many social, economic, and governmental systems. The people we think are making evil choices are avatars for the system, more than individuals.

We have to fix the systems.

EDIT: They're still evil assholes. I just mean they're replacable, not unique.

0
2
0
Computer History IBM 1130 System Engineering 1965

https://www.youtube.com/watch?v=SNqii4Hnu9A
0
0
0
[RSS] Pwn everything Bounce everywhere all at once (part 2)

http://blog.quarkslab.com/pwn-everything-bounce-everywhere-all-at-once-part-2.html

New pre-auth RCE exploit chains for old SOPlanning bugs #NoCVE
0
0
1
Edited 11 months ago
[RSS] Pwn everything Bounce everywhere all at once (part 1)

http://blog.quarkslab.com/pwn-everything-bounce-everywhere-all-at-once-part-1.html

Blast from the past: new, configuration independent exploitation method of CVE-2009-1151 (pre-auth RCE in phpMyAdmin)
0
0
1
repeated
@freddy IME a consultants (incl pentesters) are hired in large part to outsource responsibility. We all know testing can't be perfect, but if there was a test and still there was an exploited bug, you have a scapegoat.

Example: you discover 10 SQLi's, which is a lot. Dev fixes all of them bit doesn't go any further in root cause analysis. When the 11th SQLi gets exploited it will be the pentesters fault that it was not in the report, because a) people think in checkbox lists b) doing proper analysis is expensive c) the consultant is not "one of us" ...
0
0
0
repeated

Mildly amusing: this Aussie dude got fed up with people parking in his driveway so he installed a motion-activated sprinkler.

10
20
0
repeated
repeated

We found out that machines performed 7% better if we trapped them in an endless loop of profound existential anguish

2
6
0
Show older