Posts
4645
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated

BBC News has 4 YouTube videos up in the past day about OpenAI hacking “governments”, with approaching a million views.

If you want to know the technical details of this elite frontier AI hacking - these are examples of the actual OpenAI agent requests.

It’s really dumb shit. The story here is OpenAI are utterly incompetent at cybersecurity, as are their victims.

5
5
0
Re: this one I'm still curious how I could tell which document node triggered a network event (denied, with an img Initiator) I see in dev tools. I can't find the corresponding URL by searching in Inspector, DeepSeek hallucinates all the solutions, maybe @freddy has a tip?

#Firefox

RE: https://infosec.place/objects/c55e1bcb-86a9-4d16-b9fb-83dccaeb4dad
2
2
4
repeated

#BOFH excuse #442:

Trojan horse ran out of hay

0
2
0
repeated
@jerry @dey I can see the Initiator is an img, but I can't find anything seemingly related in inspector + network rectord don't tell me what code initiated a request. That's the status.
1
0
0
@dey @jerry But I'm not using Mastodon, this is an Akkoma instance. And this only happens if I scroll back to the point in my timeline when I first got this notif. It'd be really weird if this behavior didn't trigger at around page load.
1
0
0
@dey @jerry More details pls, who is trying to figure out if I have SW X installed and how?
1
0
0
@jerry Based on this article and the previous error I assume this permission request is not coming from JS but someone trying to make me fetch an URL from localhost which now triggers additional warnings:

https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox

At this point I'm not sure if it should be illegal for posts to contain references to localhost.
0
0
0
@jerry I came here to drink wine and scroll, and I'm just out of wine!
1
0
2
@jerry It *is* timeline dependent! I had to scroll back more than a day (I stupidly overwritten the original screenshot with the crop, but the timestamp helped).

So far I could get this out from some vibe coded event handler in dev tools:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"
1
0
1
@jerry Original timestamp of the image:

Wed Sep 23 09:14:13 PM CEST 2026

It's the first time I see such request ever (not just here).
2
0
1
Umm why does infosec.place "access my device"?

/cc @jerry
1
0
1
repeated

Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/

5
8
0
repeated
repeated

I tempted to do a small giveaway: reply with your best success *or* horror story related to electronics. I'll pick ~3 winners around EOW and send them a copy of The Secret Life of Circuits.

Plz no AI slop. Won't ship to Russia.

9
3
0
repeated

Webseeds should be working again for https://infocon.org/ .
There was a problem with http range requests that should now be fixed. Please let us know if you see a difference!

0
1
0
repeated

Any pentesting firm behaving like OpenAI would be shutting down and counting lawsuits within a couple of months.

This new rera of Big AI doing cyber surely feels like the late 1980s/early 1990s of the Internet Wild West

1
2
0
Show older