Posts
4655
Following
742
Followers
1661
"I'm interested in all kinds of astronomy."
Session timeouts[1] provide great examples of #compliance disconnects from reality:

When booking for events it *always* takes *days* to get from registering for an event and getting there to show your QR or whatever. And while an attacker who hijacks your session has 0 benefit from accessing it for a prolonged time, somehow #security finds it crucial that users are auto logged-out after 30mins.

It would take just a *tiny* bit of thinking to avoid making things worse for everyone.

[1] https://wstg.owasp.org/latest/4-Web_Application_Security_Testing/06-Session_Management/07-Session_Timeout/ (congrats to #OWASP for breaking all your indexed links in search engines, also very helpful!)
0
1
3
repeated

BBC News has 4 YouTube videos up in the past day about OpenAI hacking “governments”, with approaching a million views.

If you want to know the technical details of this elite frontier AI hacking - these are examples of the actual OpenAI agent requests.

It’s really dumb shit. The story here is OpenAI are utterly incompetent at cybersecurity, as are their victims.

5
5
0
Re: this one I'm still curious how I could tell which document node triggered a network event (denied, with an img Initiator) I see in dev tools. I can't find the corresponding URL by searching in Inspector, DeepSeek hallucinates all the solutions, maybe @freddy has a tip?

#Firefox

RE: https://infosec.place/objects/c55e1bcb-86a9-4d16-b9fb-83dccaeb4dad
2
2
4
repeated

#BOFH excuse #442:

Trojan horse ran out of hay

0
2
0
repeated
@jerry @dey I can see the Initiator is an img, but I can't find anything seemingly related in inspector + network rectord don't tell me what code initiated a request. That's the status.
1
0
0
@dey @jerry But I'm not using Mastodon, this is an Akkoma instance. And this only happens if I scroll back to the point in my timeline when I first got this notif. It'd be really weird if this behavior didn't trigger at around page load.
1
0
0
@dey @jerry More details pls, who is trying to figure out if I have SW X installed and how?
1
0
0
@jerry Based on this article and the previous error I assume this permission request is not coming from JS but someone trying to make me fetch an URL from localhost which now triggers additional warnings:

https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox

At this point I'm not sure if it should be illegal for posts to contain references to localhost.
0
0
0
@jerry I came here to drink wine and scroll, and I'm just out of wine!
1
0
2
@jerry It *is* timeline dependent! I had to scroll back more than a day (I stupidly overwritten the original screenshot with the crop, but the timestamp helped).

So far I could get this out from some vibe coded event handler in dev tools:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"
1
0
1
@jerry Original timestamp of the image:

Wed Sep 23 09:14:13 PM CEST 2026

It's the first time I see such request ever (not just here).
2
0
1
Umm why does infosec.place "access my device"?

/cc @jerry
1
0
1
repeated

Postmortem of a little community hobby wiki struggling to survive an extinction-event-tier DDOS purely because they banned one guy for using Claude on the wiki https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/

5
8
0
repeated
repeated

I tempted to do a small giveaway: reply with your best success *or* horror story related to electronics. I'll pick ~3 winners around EOW and send them a copy of The Secret Life of Circuits.

Plz no AI slop. Won't ship to Russia.

10
3
0
repeated

Webseeds should be working again for https://infocon.org/ .
There was a problem with http range requests that should now be fixed. Please let us know if you see a difference!

0
1
0
Show older