Posts
2836
Following
682
Followers
1507
"I'm interested in all kinds of astronomy."
This is a fun one: LLM inference creates a timing side channel that allows identifying sensitive topics by passively intercepting encrypted traffic:

https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/

/via @jonny
0
3
5
@simpson I wish you a fast recovery, whatever happened...
0
0
1
repeated

Today, my VPS served over 51.5 million requests. Well over 99% of that was AI crawlers and other obnoxious shits.

This is not normal. This is complete and utter bullshit. This is also happening all over the place.

It can be caught, it's not even hard. But we shouldn't need to. This is about three orders of magnitude more requests I'd normally receive, and it's almost entirely useless garbage.

Every single one of you who use GenAI tools, you personally, are complicit in this. You are responsible for these bots hammering the entire internet, you are enabling it.

If you think this price is acceptable, that every single person who hosts anything outside of BigTech walled gardens deserves this relentless assault of thieving robots, then you are a garbage human being.

But it is not too late to change course. You too can look back at the carnage you enabled, and feel remorse. It's okay. We'll forgive you.

You don't need to look at the environment damage LLMs cause - we can have an educated guess (it's very bad). You don't need to look at the unsustainability of it all. All of those are things that we don't directly feel right now.

But look at the damage these things cause to everyone outside of the BigTech walled gardens. That is measurable. These attacks are fact. You can't debate it. You can't justify it.

You, dear enabler of GenAI bullshit, you are responsible for enabling this carnage. Think about that. Feel bad about it, and stop. Today is a great day to do that.

12
26
2
repeated

chat my ex cancelled the spotify duo account, what streaming service do i sign up for?

5
1
0
repeated

I totally forgot to post about this huge leak from Chinese government linked infosec company KnownSec (a name that makes me think of 2013 Anonymous more than anything else).
https://www.techradar.com/pro/data-breach-at-mysterious-chinese-firm-reveals-state-owned-cyber-weapons-and-even-a-list-of-targets

1
4
0
repeated

did you know that you can find free Cortex M0 development boards at the side of the road? folks call them disposable vapes but they're hackable, and i've reverse engineered a bunch of them! see https://github.com/schlae/VapeRE/

15
21
1
@leadore @gaborudvari Thanks, I'll go through this in a couple of days, now I just managed to unlock fly permission and rn floating around randomly listening to some light house music with beer :D
0
0
1
repeated
@gaborudvari Great tips, thanks! I'm experimenting with minetest rn but frankly I have no idea what I'm supposed to do so can't really gauge the feature parity either :D
1
0
0
@gaborudvari well I do mind and I find it disgusting that entire families are made to sell their PII if their kid wants to play a game along with their friends. And yes, I'm willing to pay for an option that doesn't sell my kids personal data, but apparently this is not an option.
1
0
0
TIL Minecraft requires a freaking MS account. I thought it wasn't that bad so we proceeded to create one, but it turns out that if you want to create a child account (based on birth date, to avoid adult ads and shit) you as an adult *also* need a MS account that would be of course immediately connected to your childs account which I assume to be a gold mine for advertisers.

Seriously, fuck #AdTech!

(I also wonder if this is legal in the EU?)
2
2
9
repeated
repeated

TIL the Task Manager Guy™ once dabbled in scareware?
https://bird.makeup/users/c0ner0ne/statuses/1989395111491588340

0
1
0
repeated
repeated

For my blog and newsletter, I wrote about why there have been so many data breaches and security lapses this year *alone* involving the mass-exposure of people's driver's licenses and passports — including new details about an exposure of 223,000 government-issued IDs as recently as this week.

Read more: https://this.weekinsecurity.com/it-is-far-too-easy-to-find-leaked-passports-and-drivers-licenses-online/

Sign up/RSS/subscribe: https://this.weekinsecurity.com

1
7
0
repeated

carats per SHA512 hash

0
1
0
@G33KatWork constraints induce creativity: finishing the project without *that* part is almost like writing a haiku :)
0
0
1
@d_olex @whitequark oh I think I misunderstood! I'm concerned about how NDAs the Red Team is usually subject to (the target, data from their systems, etc) can be compatible with these third party services.
1
0
0
repeated

#BOFH excuse #225:

It's those computer people in X {city of world}. They keep stuffing things up.

0
1
0
Show older