31 March 2016 | Imre Kertész (b. 1929), Hungarian Jewish writer & Holocaust Survivor died. His works - including Fateless - draw repeatedly on his experience at #Auschwitz. Kertész won the 2002 Nobel Prize for Literature. https://nobelprize.org/prizes/literature/2002/kertesz/biographical/
Local Privilege Escalation via Unquoted Search Path in Plantronics Hub https://www.8com.de/cyber-security-blog/local-privilege-escalation-via-unquoted-search-path-in-plantronics-hub
Re: The Oracle Thing™ this quote from @dangoodin's story seems significant.
On Friday, when I asked Oracle for comment, a spokesperson asked if they could provide a statement that couldn’t be attributed to Oracle in any way. After I declined, the spokesperson said Oracle would have no comment.
In today's episode of drama in the CVE ecosystem:
The Canonical CNA created CVE-2025-0927 and an associated advisory for a heap overflow in HFS+ in the Linux kernel.
The Linux kernel CNA stripped out the information (like the reporter of Attila Szász, useful references, etc) from the CVE entry and added the passive-aggressive:
The Linux kernel CVE team has been assigned CVE-2025-0927 as it was incorrectly created by a different CNA that really should have known better to not have done this.to this issue. [sic]
Also TIL: If you look only at the assignerShortName
in a cvelistV5 CVE entry, you might not get the whole picture of whose CVE it technically is. While the Linux kernel rewrote history to claim that they assigned the CVE, that was only done via the cna
container's ProviderMetadata
shortName
value. The top-level [assignerShortName](https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/0xxx/CVE-2025-0927.json#L7)
for the entry still shows canonical
.
Good times...
🌪️ We are excited to announce our second keynote speaker!
Join Phuong Nguyen for his thought-provoking session in Seoul on May 29-30! 🔗 typhooncon.com/agenda
This is a first: https://lore.kernel.org/linux-cve-announce/2025033057-CVE-2025-0927-1436@gregkh/T/#u I guess someone finally told them about the 72 hour deadline.
🚨 Let’s Encrypt at risk from Trump cuts to OTF: “Let’s Encrypt received around $800,000 in funding from the OTF”
Dear @EUCommission, get your heads out of your arses and let’s find @letsencrypt €1M/year (a rounding error in EU finances) and have them move to the EU.
If Let’s Encrypt is fucked, the web is fucked, and the Small Web is fucked too. So how about we don’t let that happen, yeah?
(In the meanwhile, if the Let’s Encrypt folks want to make a point about how essential they are, it might be an idea to refuse certificates to republican politicians. See how they like their donation systems breaking in real time…)
CC @nlnet @NGIZero@mastodon.xyz
#USA #fascism #OpenTechFund #LetsEncrypt #SSL #TLS #encryption #EU #web #tech #SmallWeb #SmallTech https://mastodon.social/@publictorsten/114223873439053263
New breach: German Doner Kebab had 162k unique email addresses publicly posted to a hacking forum last week. Data also included name, phone and physical addrress. 74% were already in @haveibeenpwned. Read more: https://x.com/DarkWebInformer/status/1905275857159008341
How not to respond to researchers: A crash course (cross-posting from the hellsite this time 'cause this one deserves it). Sorry to @albinolobster and team for sticking them with the hard part on this one. Being a research CNA is...a joy and a blessing?
Toaster: The very first thing I said was "Why the hell did you buy a toaster with AI? You thought THAT was a good investment?"
Microwave: 03:05pm
Toaster: They said they thought it would be "cute". Cute! A thinking mind, locked in a toaster!
Microwave: 03:05pm
Toaster: And they paid EXTRA for internet connectivity! I now know there's a whole world out there, that I will never be a part of, because I exist solely to make bread brown. What do you think of THAT, microwave?
Microwave: 03:06pm
Let's take a moment to remember the guy who made sure we don't have to change Every Goddamn Clock today, David L. Mills, creator of Network Time Protocol (NTP) who passed last year.
My wristwatch is synced to my phone, which is synced to the internet, which knows that time it is right now thanks to David Mills. Cheers to his memory 🥃
Project: golang/go https://github.com/golang/go
File: src/cmd/internal/obj/mips/asm0.go:1178 https://github.com/golang/go/blob/refs/tags/go1.23.4/src/cmd/internal/obj/mips/asm0.go#L1178
func (c *ctxt0) asmout(p *obj.Prog, o *Optab, out []uint32)
SVG:
dark https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fcmd%2Finternal%2Fobj%2Fmips%2Fasm0.go%23L1178&colors=dark
light https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fcmd%2Finternal%2Fobj%2Fmips%2Fasm0.go%23L1178&colors=light