Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Bert Driehuis

@bertdriehuis@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security noob since 1986

15 Followers
65 Following
27 Posts
Joined December 20, 2022
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@SecureOwl@infosec.exchange @grumpydad@infosec.exchange that is so recognizable, and at the same time such an indictment of western values, it hurts even thinking about...
4
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@eniko@mastodon.gamedev.place @mmcknett@hachyderm.io @bkuhn@fedi.copyleft.org @sinbad@mastodon.gamedev.place @JoshJers@mastodon.gamedev.place back when I joined this field, downloading GCC just to see if a presumed bug wasn't already fixed took a couple of hours. I've found a bug in GCC at least three times without winding up being credited for the fix because by the time I identified the issue, checked it was still relevant, and wrote up a fix, it was fixed upstream. Blvd magazine described me as a "bottom feeder" at the time. Still unsure if that's derogatory or a badge of honor.
3
1
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@dianea@lgbtqia.space I think R9 could be optimized away, it being blank. I once optimized away 12 bytes from the FreeBSD boot loader to be able to fall back to the 3C509 netboot loader. Saved me from replacing 16 Ethernet adapters and making 15 flights to remote offices For some reason, I never got credited for saving actual money. Office politics and finance rarely jive, but I digress.
1
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@mindfuck_inc @DJGummikuh the transcription into ISO 8859-1 doesn't do the richness of the language justice. As in Chinese, many tonal subtleties get lost in translation.
3
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@gsilvapt @bagder Probably. But for the Y2K turnover, this topic was a greenfield exercise. Like last time, anybody caught up in this will not have done their homework over the past decade. But unlike last time, running old crap is not just a risk to continuity. This time it will also show that the org didn't care for security either for the past decade. Not holding my breath though. Just look at the number of Java developers that to this date have not replaced log4j with a more modern (and better designed) alternative.
1
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@australopithecus @brianbilston at least the disciples of Weird Al!
1
0
1
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@anakin78z@mograph.social I'd pay for shoot'm-up like call of duty, but with kindness and petting kitties instead of shooting.
1
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 7mo ago

@thegibson@masto.hackers.town ever searched your desk for a forgotten fizzy drink to see the most expensive power supply you've got releasing its magic smoke, and in utter disbelief continue the search until you realize that the magic smoke will turn to flames at some stage unless you act *right now*? Been there, done that, got the t-shirt.

In aviation it's called the startle response, and despite being trained to not kill myself and my passengers, I am fully aware it applies to me as well.

1
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 7mo ago
Replying to
@thermia the attack is specific in using 192.168.1.129, so UPnP would not be my first suspect. Someone or something on the local net appears to be treating your friend to a free security scan. It looks like it's targeting IoT, so it may be one of Mirai's successors at play.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 6mo ago
Replying to
@TechConnectify great to see a new video from you! For some use cases, such as personal aviation, ye olde 4-stroke engine is not very likely to be replaced by electrics any day soon (unless someone invents a really lightweight extension cord). For these, synthetic fuels would probably be the most environmentally friendly solution. Have you ever seen any research into turning excess solar power into e-fuels? The hard part is probably not the chemical or the physics part, but making the process economically viable with just excess electricity. That said, it might just be the stuff to fill a gap in the transition. The good news is someone just made oil a lot more expensive so more people may realize that cheap fossil fuels are not a given.
0
0
1
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 7mo ago

Way back in 1993, I tried to get my name attached to an amicus brief for USL vs BSDi. Apparently, I missed my target as there is no mention whatsoever of my name in the docket for 832 F. Supp. 790 (1993). But if today you are using MySQL or any of its derivatives, and enjoy having an alternative to the 800 pound (albeit very nice) gorilla that PostgreSQL has become, you may want to review this petition:

https://letter.3306-db.org

I just signed it. And it's weird to name an open source entity as the 800 pound gorilla.

Open Letter — Invitation to Discuss the Future of the MySQL Ecosystem
letter.3306-db.org

Open Letter — Invitation to Discuss the Future of the MySQL Ecosystem

The MySQL Ecosystem Needs Independent, Vendor-Neutral Governance. Add your name to the open letter.

0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@1337 @mkornblum Still, the most convincing pointer that something is rotten in the kingdom of Denmark is the lack of transparency. Maybe their cash burn isn't in inference but in training. I don't care either way. The training will never be finished. They will continue to scorch the planet for a product that can't be run unsupervised, and that even like-minded folks like Uber find expensive for the value they get back, at a price point which is unlikely to get lower. I think the economics for Claude's customers will get even worse once the cost of brain rot gets factored in.
0
0
1
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 3mo ago
Replying to
@woe2you@beige.party @mttaggart@infosec.exchange actually, wazuh isn't all bad. It's the only one that has tools for correlation built in (a nightmare to write and test, but that is true of all the other solutions I've seen as well). It has an all in one log collector that just works. I've also got a vector+openobserve in my homelab. I like openobserve (especially after living in ES hell for years), but while writing enrichment rules in vector is okay, but I don't see a good solution for correlation yet. Bonus point for vector: it's easy to make a stream for unparseable log records. That tripped me up with nxlog. My preference would be to do correlation at ingestion time and I've yet to find a decent open source tool for that.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 1mo ago
Replying to
@antoinnesterk@cyberplace.social Enjoy it, and unwind! I'm lucky to be able to share caregiving duties with my brother and sister. My upcoming vacation will be bittersweet: it's the first time visiting the family holiday address without my dad. He took the news without a fight, which before his stroke would have been totally out of character...
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 3mo ago
Replying to
@miss_rodent@girlcock.club @mcc@mastodon.social next to the shared libs, appimage also bundles support files. This prevents incompatibilities at the cost of duplication. Snaps try to be a bit of everything: independent of the host distro, but with seperate snaps for dependencies like Gnome to eliminate some of the duplication. Snaps also bundle some appimage rules to make exploiting bugs harder. There's a lot to be said for the ideas behind all three, but none are perfect. Neither is steering clear of all three by the way.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@bontchev@infosec.exchange @GossiTheDog@cyberplace.social that 180 Euros is not covering the cost of inference. And you're correct: for users who do not let their skills atrophy, GenAI can be of value. For the majority, it will be a provider of brain rot, unmaintainable code and vulns, and for society, the extinction of the senior in the workplace. At $ORKPLACE, I've now run into the first case of a user who is patently wrong in his interpretation of some vendor docs but won't budge because AI summarizes it wrong, and he trusts the 'puter more than his colleagues.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 5mo ago
Replying to
@dangoodin@infosec.exchange how many of these vulnerabilities had easy fixes, without side effects? I've lost count of how often I fixed bugs, only to find out that the fix caused a bigger problem down the line. In the early days of Firefox I helped fix issues in the code, and verifying the fix for regression potential is ten times the work of the fix itself.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@ryanc@infosec.exchange RS 232 requires 12 V last I checked (well technically 3-15, but that's for loss of potential due to transmission losses). I doubt any industrial cat could be controlled even by the full 15V.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 3mo ago
Replying to
@luna@lea.pet I sometimes feel like I'm missing the point. Like MS Teams on Android losing usability with every release. It would've made sense if they hadn't killed Windows Phone eons ago. Are they just softening us up?
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 11mo ago
Replying to
@khzimmer2@literatur.social @angusm@mastodon.social in that case I'm fairly confident you don't scan a lot of documents that require good OCR and good document compression. I run a Windows VM for the sole purpose of servicing a Brother ADS-1200 scanner. Every single alternative I've looked at has less accurate OCR, _and_ generates PDF's over twice the size of Brother's otherwise atrocious software. If you look up Open Source Zealot in any reputable source you'll find my picture to illustrate the entry. It's just a tough nut to crack. I sank serious money and time in this topic and just never found a way of improving scanning under UNIX-like OSes beyond the level of scanning using the Brother ADS-1700, which sucks as bad under Windows as it does under Linux. It's not as if Windows or Brother are the magic bullet. I'd love the idea of open source leapfrogging the software for the ADS-1200, but there will be tons of isolated use cases that don't lend themselves to easy solutions.
0
1
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@anthropy@mastodon.derg.nz procrastinators unite! How does next week fit your schedule, y'all?
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@landelare@mastodon.gamedev.place @stux@mstdn.social 99% of WordPress sites would be perfectly served with a static website and a form mail script. The attack surface of WordPress is just wild when you look at it. Just the lesser risk of DoS would be worth the switch. Where SSG's lack is in support by mom&pop sized web developers. I've converted a couple of WP sites to Jeckyll and it's an evening 's worth of effort, but the skills to do that are few and far between.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@mendingcatsshelter1@mastodon.social Our cat loves shopping bags! We're always careful when leaving them at kitty heights though. One day after shopping, she caught her head in a loop and was panicking. Got her out quickly, but a good reminder...
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@Viss@mastodon.social @kelseyhightower@mastodon.social my biggest gripe with docker is that the true believers think it absolves them of the need to do upgrade assessments, read release notes and other sysadminy things.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 3mo ago
Replying to
@nixCraft@mastodon.social People are our most important asset. We depreciate on them.
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 2mo ago
Replying to
@Gedankensplitter@nrw.social @edgeofeurope@mastodon.social @jwildeboer@social.wildeboer.net only Germans can define a complex and obnoxious trait with an English word and get away with it remaining a German expression. That said, I haven't heard Ibanez's take on it (Mortadelo y Filemon, or Clever und Smart for the German readers).
0
0
0
0
Open post
Bert Driehuis @bertdriehuis@infosec.exchange
· 4mo ago
Replying to
@MisuseCase@twit.social @spaceinvader@social.securitytheater.net so far I've not seen any evidence that AI is doing much for code quality -- quite the contrary in fact. As productivity (and burnout) soars, the seniors have no cycles left to weed out even the low hanging vuln fruit. The juniors have no way to know what is low hanging fruit. And the folks in between, well heaven knows how they will ever become senior other than by outliving the seniors physically.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:42:34 UTC