Posts
4648
Following
742
Followers
1662
"I'm interested in all kinds of astronomy."
repeated

Introducing 𝙷𝚊𝚠𝚔𝚃𝚞𝚊𝚑𝙱𝚛𝚘𝚠𝚜𝚎𝚛.𝚎𝚡𝚎

- 15 KB native web browser
- 6 MB of RAM for the host
- 0 lines of Visual Basic (no C# cuz idk how to write it)
- no URL bar because surfing through 88x31s is more fun
- title bar kept cuz then u can close it and minimize buttons

3
3
0
@freddy Interesting theory! I do blackhole some sites but I doubt any URL of those would point to :3000...
1
0
0
@freddy This is what I believe a native FF log message resulting from an attempt to load from localhost:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"

I could reproduce it by scrolling a shit ton in my timeline (won't do again), but I think a minimal test case would be a simple `img src="http://localhost...` served from a non-local origin.

In that case though the source would be there in Inspector, but in case of Akkoma infinite scroll does some magic that prevents me from simply looking up the tag by URL, that's why I'm thinking if some kind of "stack trace" is available for network events that would lead me to the offending element?
1
0
0
@TarkabarkaHolgy Blood Knights is 100% wh40k compatible too!
0
0
3
"If it only were that simple." - George Washington
0
0
0
@securestep9 It looks client-side so you could get the same info from dev tools no?
1
0
0
#Windows experts, can you answer this without trying:

How many times do you need to press the down arrow to select C:\Users\Public?

#UX #UI
1
0
0
Session timeouts[1] provide great examples of #compliance disconnects from reality:

When booking for events it *always* takes *days* to get from registering for an event and getting there to show your QR or whatever. And while an attacker who hijacks your session has 0 benefit from accessing it for a prolonged time, somehow #security finds it crucial that users are auto logged-out after 30mins.

It would take just a *tiny* bit of thinking to avoid making things worse for everyone.

[1] https://wstg.owasp.org/latest/4-Web_Application_Security_Testing/06-Session_Management/07-Session_Timeout/ (congrats to #OWASP for breaking all your indexed links in search engines, also very helpful!)
0
1
2
repeated

BBC News has 4 YouTube videos up in the past day about OpenAI hacking “governments”, with approaching a million views.

If you want to know the technical details of this elite frontier AI hacking - these are examples of the actual OpenAI agent requests.

It’s really dumb shit. The story here is OpenAI are utterly incompetent at cybersecurity, as are their victims.

5
5
0
Re: this one I'm still curious how I could tell which document node triggered a network event (denied, with an img Initiator) I see in dev tools. I can't find the corresponding URL by searching in Inspector, DeepSeek hallucinates all the solutions, maybe @freddy has a tip?

#Firefox

RE: https://infosec.place/objects/c55e1bcb-86a9-4d16-b9fb-83dccaeb4dad
2
2
4
repeated

#BOFH excuse #442:

Trojan horse ran out of hay

0
2
0
repeated
@jerry @dey I can see the Initiator is an img, but I can't find anything seemingly related in inspector + network rectord don't tell me what code initiated a request. That's the status.
1
0
0
@dey @jerry But I'm not using Mastodon, this is an Akkoma instance. And this only happens if I scroll back to the point in my timeline when I first got this notif. It'd be really weird if this behavior didn't trigger at around page load.
1
0
0
@dey @jerry More details pls, who is trying to figure out if I have SW X installed and how?
1
0
0
@jerry Based on this article and the previous error I assume this permission request is not coming from JS but someone trying to make me fetch an URL from localhost which now triggers additional warnings:

https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox

At this point I'm not sure if it should be illegal for posts to contain references to localhost.
0
0
0
@jerry I came here to drink wine and scroll, and I'm just out of wine!
1
0
2
@jerry It *is* timeline dependent! I had to scroll back more than a day (I stupidly overwritten the original screenshot with the crop, but the timestamp helped).

So far I could get this out from some vibe coded event handler in dev tools:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"
1
0
1
Show older