Posts
2510
Following
649
Followers
1466
"I'm interested in all kinds of astronomy."
repeated

For my hackathon project I did try to make CFA (Cat Factor Authentication, using your cat's microchip as a second factor) a thing 😆 The project did win a prize, but more for the experimentation then the actual result https://wpengine.com/blog/hackathon-december-2023/

14
37
2
repeated

Is remote code execution in UEFI firmware possible? Well, yes it is.

Meet : 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.

Full details by @fdfalcon and @4Dgifts in our new blog post:

https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

2
9
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

This blog post comes from deep inside the world of advertising, from people trying to move away from cookies. And along the way offer a VERY rare insight into the dark technology behind advertising and tracking ("hashed offline passbacks", "first and multi-touch attribution"), stuff you almost never read about. https://blog.sentry.io/we-removed-advertising-cookies-heres-what-happened/

1
4
0
repeated

After the takeover by Broadcom, VMware is in total chaos when it comes to orders and license renewals. Here is a status overview.

https://borncity.com/win/2024/01/13/order-license-chaos-for-vmware-products-after-broadcom-takeover-jan-2024/

3
3
0
repeated

@pervognsen Did u see that the RAD Debugger has been released :O ? https://github.com/EpicGames/raddebugger

1
3
0
repeated

"OpenAI says it’s “impossible” to create useful AI models without copyrighted material"

10 years ago three dudes from Sweden were hunted by FBI, Interpol and their own government for challenging copyright laws and seeking a fresh approach without ever profiting from it. 🏴‍☠️

Now venture capitalist-backed corporations will sell us our own copyrighted material at a premium. Working tirelessly to embed it in every product designed from now on so you will not be able to avoid it. 💰

7
6
1
repeated

So apparently starting with Linux 5.18, ASLR is weakened for 64-bit executables, and absolutely BROKEN (i.e. not present) for 32-bit executables when the library is 2MB or larger.
Oops? 🤦‍♂️
https://zolutal.github.io/aslrnt/

4
5
0
repeated
repeated

@yabellini@fosstodon has moved

Did you realize that we live in a reality where SciHub is illegal, and OpenAI is not?

8
37
2
repeated

80 character column limits in code are a legacy from 80 column text displays which are a legacy of IBM's 80 column punch cards which are a legacy of Roman chariots which had two side-by-side 40 column horses

2
13
0
repeated
Edited 1 year ago

has a new hidden setting auto-rejecting banners (not just hiding them eg Brave). Piloting in 🇩🇪 in Private Browsing but anyone can enable:
Go to the URL about:config
Set cookiebanners.ui.desktop.enabled ->True
Go to Settings->Privacy, turn on Cookie Banner Blocker.

3
20
0
repeated
Edited 2 years ago

It's probably obvious to most of you, but a big difference between the commercial social media platforms and the fediverse is that as those commercial platform grow, they get additional revenue from ads, from selling personal information, and otherwise monetizing their users. While that is turning out to not actually pay the bills for them, in the fediverse, just about every instance is run by volunteers and funded by donations or out of the volunteers' pockets. It's a labor of love and a hope for a better future. When traffic grows, we need to expand our capacity.

That is why I am asking, if you are able, please consider donating to the instance you on to help keep the fediverse ecosystem going. Typically the /about web page will have details on how to donate.

Note: I am well aware that many of you are not in a financial position to donate - and that is OK. We are here to serve you as well. Donations are completely optional.

20
29
0
repeated

The first version of an SMTP smuggling scanner is now available at https://github.com/The-Login/SMTP-Smuggling-Tools.
More tools to come! Feedback is much appreciated!

0
4
0
repeated

The 37C3 talk on TEA1 encryption (used by police and military units in europe) is hilarious.
The hackers announced they found a vulnerability in the encryption, and one of the ways the organization that standardized the TEA1 encryption downplayed the breach was by saying that it wasn't viable, because it required "high powered GPUs".

So they ported their algorithm to a Toshiba Satellite P1 running Windows 95, and re-cracked the encryption there.

https://www.youtube.com/watch?v=8KhbJ4pqcOY

4
18
2
repeated

I've only just noticed that GitHub has a "Download SBOM" button on repos, e.g. https://github.com/bbc/simorgh/network/dependencies

It's in SPDX format (https://spdx.github.io/spdx-spec/v2.3/introduction/) which seems pretty reasonable to me from a machine-reading PoV.

Hopefully being a standardised format means it can be ingested into standardised tooling.

3
2
0
repeated

Under-the-radar late night launch: RSS Parrot is live! It talks like Mastodon, but it doesn't walk like Mastodon. BUT! It will relay any RSS feed straight into your timeline.

Turn Mastodon into your very own feed reader. Follow anything that has an RSS feed and get a toot about new posts.

How? Mention @birb with the address you want to follow.

More details at https://rss-parrot.net. Boost for visibility :)

11
27
1
repeated
repeated

PSA to all junior hackers: pasting some random code into GPT, asking it to “identify” a security vulnerability, and submitting it as a bug bounty will never, ever work. You will succeed only in getting yourself banlisted as a crank.

You can spend five years becoming an actual expert or you can find a career that’s easier for you; if it were so easy that ChatGPT could do it, there wouldn’t be any bug bounties

2
11
0
repeated
Edited 1 year ago

I highly recommend supporting the Standard Ebooks project. 📚

«Standard Ebooks is a volunteer-driven project that produces new editions of public domain e-books that are lovingly formatted, open source, free of copyright restrictions, and free of cost.»

Donate 👇
https://standardebooks.org/donate

Please boost 🙏

1
17
0
repeated

Okay, listen up:

Mozilla is two different entities. The Mozilla Corporation and the Mozilla Foundation. The second one? That’s the social good one you really want focused on important things.

The Mozilla Foundation, like all non-profits, publishes their Form 990 annually to disclose compensation. Here it is.

You’ll see that the top earner there, Mitchell Baker, who is very handsomely rewarded, is actually paid by the Mozilla Corporation, not the Foundation. Put another way, the non-profit is not blowing its funding on a CEO.

And the corp, by the way, is what generates revenue that largely funds Firefox.

The annual report of the Foundation shows a pretty healthy financial situation, and increased investment in public good projects year-over-year.

I don’t like everything they do either (e.g. that risible website generator), but I don’t actually think they are suffering from a lack of focus. They’re suffering from a mature market.

6
12
0
Show older