Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Zimmie

@bob_zim@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Dan Kaminsky once said I know how computers work.

248 Followers
27 Following
50 Posts
Joined January 23, 2023
Pronouns:
he/him
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@briankrebs@infosec.exchange Is there independent confirmation of any of this, or is it all just from OpenAI (known lying liars who lie) and Hugging Face (whose entire business depends on hype from OpenAI and its ilk)? If it’s true, both OpenAI and Hugging Face come off as blitheringly incompetent, top to bottom.
22
5
2
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@Osteopenia_Powers@newsie.social @jcrabapple@dmv.community TPMS isn’t actually Bluetooth, it’s an unencrypted wireless protocol on either 315 MHz or 433 MHz, depending on locale. The lack of encryption is part of the problem, as each sensor broadcasts a probably-unique identifier. Bluetooth is much more private, though still usually identifiable.
12
1
2
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1mo ago
Replying to
@liaizon@social.wake.st @mcc@mastodon.social I mean, the original which has slopified is pronounced like “keep ass”.
3
1
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@Affekt@hachyderm.io @ApostateEnglishman@mastodon.world @stux@mstdn.social Laser safety glasses are expensive, but they’re a lot cheaper than new eyes. Geared tripod heads, high-magnification spotter scopes, and spotter scope mounts aren’t terribly expensive, but you get parallax over distance. Dichroic mirrors and mounting systems to let you eliminate parallax are expensive, but then you can use a common CO2 bench laser.
5
0
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@ocnurb@woof.group @rrb@infosec.exchange And note most SSDs have two levels of secure erase. One takes a few microseconds to flush the key used to encrypt the data on the flash. This is secure unless the SSD vendor lies, but it leaves the data in place, so pages still need to be erased before they can be written. This is what phone wipes do, but desktop SSDs can typically do it, too. The other type uses dedicated circuitry in the flash chips to set all the pages (including faulty pages and spare pages) back to a neutral state. This takes several seconds and more power, but it restores out-of-the-box performance. This is common on desktop SSDs.
4
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@taedryn@anarres.family @foolishowl@social.coop @gwynnion@mastodon.social Exactly. I’ve personally seen a lot of datacenters, and I’ve never seen one which employs even 50 people full-time per square kilometer. Historically, economic engines like factories took in a lot of money, but also paid out to a lot of people. They diffuse money. Never perfectly, but you could honestly say a new factory would bring employment and thence income to the local populace. Offices, too. Datacenters pay out dramatically more to dramatically fewer destinations (most of which are big companies). They concentrate money. The “business real estate good!” mentality largely hasn’t noticed this difference.
3
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@Dss@infosec.exchange @briankrebs@infosec.exchange They should have taken even the barest of steps towards securing an environment. Telling the software not to misbehave isn’t a security control. Don’t use default credentials. Don’t allow untrusted software currently under test to access a network at all. Maybe take a look at the environment of the software under test more often than once a week. The flagrant disregard for the most basic security practices means either they’re either idiots or hucksters. I don’t see a third option. And to claim “We didn’t know this thing we built would go out and do felonies on behalf of our company”? Really? Then why did they give it the capability to do that?
2
1
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@eestileib@tech.lgbt @briankrebs@infosec.exchange Not just religious devotion. They’re pitching these things to governments as weapons. Consider this through that lens, and they have a *suuuuper clear* economic incentive.
2
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@evaw@mastodon.world @futurebird@sauropods.win Ish. Space doesn’t impart new heat, but vacuum is *strongly* insulating, so it’s ridiculously hard to dump the heat you have. And the sun imparts a ton of new heat.
3
1
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@drahardja@sfba.social Yeah, I posted about this on the dead bird site about a decade ago, though I was more curious about ransomware spreading from charger to car and artificially limiting range. Got *so many* replies from people who didn’t have the first idea how car charging connections work. Ed Zitron basically called me an idiot and started a pile-on, which was “fun”.
3
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@filippo@abyssdomain.expert That all sounds very reasonable. Some site operators have implemented passkeys alarmingly poorly, I suspect due to a lack of understanding of how sites should handle the public key. Explicitly treating them just like credentials people already know how to store should help clarify it.
3
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@obot50549535@left-bank.net @jmax@mastodon.social @Natasha_Jay@tech.lgbt Exactly right. They (and many cats) also use their tails to maintain stability when turning aggressively. It’s particularly visible in videos of cheetahs chasing prey.
3
0
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@thomasfuchs@hachyderm.io @molly0xfff@hachyderm.io Did you mean AirsPod Pro?
2
2
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social Not sure about other countries, but the US is composed almost entirely of rules which cost far more to enforce than they save. New York City spent tens of millions on cops to fight tens of thousands of dollars of fare evasion (e.g, turnstile hopping) for the subways. San Francisco routinely spends tens of millions of dollars on cops to harass unhoused people and throw their stuff away, when it would cost less than a tenth of that to simply pay for apartments and social workers for all of them. In this case, the rule isn’t meant to be perfectly enforced.
2
4
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@DrHyde@fosstodon.org @drahardja@sfba.social It feels like it was meant to allow the charger network to push updates to the car, like how cable companies can push updates to cable modems even if the cable company doesn’t own the modem.
2
2
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@wbud@tech.lgbt @alice@lgbtqia.space @deviantollam@defcon.social On the payment processor side, the type of card data capture is part of the transaction. The technical capability exists at the payment network level to say, for example, a typed-numbers transaction is limited to $10, a magstripe transaction is limited to $20 (the stripe has more data than just the card numbers), a tap is limited to $50, a chip-without-PIN is limited to $100, and a chip-with-PIN has no limit. Whether the bank actually does anything with that technical capability or not is up to the bank. Worth asking them, though.
1
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@younata@hachyderm.io Check out the developer tools like ViewFrame. You could see on the device how the interface of most applications was built, and NewtonScript was a really nice language for building them.
1
1
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@farooqkz@mastodon.bsd.cafe @iogrt@functional.cafe Nushell is a lot like PowerShell. It passes around real data structures, not just blobs of text you have to parse. Very pleasant overall.
1
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social Well if they aren’t supplying the public grid, they can just be built *outside* the environment. And for convenience, that oil tanker was already towed there!
1
0
1
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@mrgrumpymonkey@mastodon.social @aces_funhouse@kinkycats.org @AltAfterDark@masto.thefword.club They’ll be too busy thinking about power genitalia?
1
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@mrgrumpymonkey@mastodon.social @aces_funhouse@kinkycats.org @AltAfterDark@masto.thefword.club For example, consider some of the more famous misreadable domain names: #americanScrapMetal #anAlbumCover #bitefArtCafe #chooseSpain #expertsExchange #moleStationNursery #penIsland #powergenItalia #speedOfArt #teachersTalking #therapistFinder #whoRepresents VoiceOver on iOS reads all of those perfectly. Without the uppercase letters giving it hints, it gets some of them hilariously wrong.
1
2
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@cynblogger@sfba.social @violenteastcoastcity@mastodon.social Most acoustic tube headsets have either a throat mic (for reliability in noisy environments) or a remote mic commonly mounted at the wrist (for not obviously looking like you have a radio).
1
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@engelke@hachyderm.io @violenteastcoastcity@mastodon.social Also note the GMRS license covers immediate family members, so you probably only need one.
1
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@DrHyde@fosstodon.org @drahardja@sfba.social Yeah, but it feels like the result you would get from somebody arguing that has to be supported when defining the standard.
1
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@miclgael@hachyderm.io If your threat model doesn’t include insiders at the company impersonating you to gain access to your account, sure! And it’s reasonable for that not to be in most threat models. It’s in my threat models for my banks, though.
1
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@evaw@mastodon.world @Linebyline@mastoart.social @futurebird@sauropods.win Even if those experimental results are verified (still up in the air), it’s unlikely it can be scaled up to pump more than a few microjoules. Quantum effects are notoriously difficult to maintain at useful scales.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@wbud@tech.lgbt Several years ago, US payment processors did what was called the “liability shift”. The networks now largely disclaim liability for fraud via magstripe-only transactions as a way to push the long tail of stores which accept credit cards to update to EMV-capable terminals. That tail is *really long*, though. I personally have paid for things exclusively with NFC via phone or watch for the last few years, but I live in a pretty big city. The more rural you get, the more likely you are to run into a store with an older terminal. I would keep at least one emergency use card with a magstripe, but I would feel comfortable removing the stripe from my primary card.
0
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1w ago
Replying to
@mattblaze@federate.social And the “NFTs will change the whole concept of property ownership!” people. Just the worst barbershop quartet around.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2w ago
Replying to
@ryanc@infosec.exchange Can’t forget the fun, safe math-optimizing lizard!
0
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@SteveBellovin@infosec.exchange @mattblaze@federate.social @20002ist@thepit.social “No, it’s either/or.”
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@miclgael@hachyderm.io Ultimately, passkeys (and WebAuthn more generally) is asymmetric authentication versus symmetric authentication. Passphrases are passed in the clear—usually over an encrypted transport, but the clear passphrase hits the memory of every service on the path to the authentication service. The authentication service then hashes it and confirms if it matches the stored hash. The clear passphrase can be logged by any of these services, and this has happened many times at some major companies like Google. TOTP and similar no longer passes a clear value, so the webserver may not be able to log your secret, but the authentication service which approves or rejects the codes still has a clear secret in its memory. Fewer places to check for logging, but it’s still possible. With asymmetric authentication, the server never gets secret data. Nothing on that end can possibly log anything which could be used to impersonate you. Though most of the time, this authentication is used to generate a symmetric token stored in a cookie, so cookie stealing or forgery is still potentially a risk.
0
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1w ago
Replying to
@platinumtulip@sunny.garden Currently using Ice Cubes. It has some aspects which slightly annoy me (for example, any media is scaled and cropped to a square for the in-post preview), but it’s leaps and bounds better than a web application. Thinking about trying to contribute.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@ricci@discuss.systems So making changes to something without regard for the identity of who might be affected doesn’t count as involving human subjects? Does that mean the Stanford IRB think the Tylenol murders were victimless?
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social “At least 12 states are affected!” Wow. Sounds bad. Which ones? “Not telling!”
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1mo ago
Replying to
@em_and_future_cats@mastodon.social @QasimRashid@mastodon.social Uh … those people *aren’t* perfectly fine with the LDS. As a recent example, they just pared down the list of approved religions in the military, and the LDS were specifically listed separately from Christian religions. There was a big stink about it. https://www.abc4.com/news/religion/church-jesus-christ-reclassification/ Most of them barely consider Catholics Christians.
abc4.com
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social That’s not really a difference, though. Certainly not a meaningful one. For-profit businesses love wildly inefficient rules, too. At my current job, I had to figure out which are our approved vendors, get quotes from three of them, and spend tens of hours filing paperwork to get approval to buy a $20 thumb drive to reimage a failed server. Took months.
0
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@alice@lgbtqia.space @mycrowgirl@flipping.rocks Reminds me of a great shirt design I got from Woot years ago, before Amazon bought them. https://shirt.woot.com/offers/bats
shirt.woot.com
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@huronbikes@cyberplace.social @GossiTheDog@cyberplace.social That’s more-or-less what “hyperconverged” is, yes: a bunch of physical servers which provide both compute and storage. The networking is still usually separate, and usually Ethernet rather than a real high-performance interconnect.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@meltedcheese@c.im @briankrebs@infosec.exchange With a sufficiently rigorous specification, we definitely can prove code is correct to the spec. It’s difficult, and there can still be security issues in the specification, but it’s well within the means of any serious company. The fact these companies spent umpteen billion dollars without building formally-verified security boundaries for the code they intended to weaponize speaks to their fundamental unseriousness. They’re private companies intending to engage in their very own Sea Spray.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 3w ago
Running into a weird number of people today who seem to be incapable of comprehending the difference between a default behavior and an optional configuration.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@wbud@tech.lgbt On the topic of a credit card for emergencies, be sure to set it up to pay for some regular bill, like a streaming TV service or something. If a card goes too long without a charge on it, the issuer sometimes closes the account rather abruptly. The company which issued my first credit card closed the account (tanking the average age of my credit lines) with no notice just as I was applying for mortgages. It sucked so much.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@helediron@techhub.social Intel has their enterprise drive controllers set themselves to read-only when they hit the rated endurance. All the other brands which fab their own flash last *much* longer than their rated lifespans. Flash does wear out eventually, but you have to *really try* to get there.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2w ago
Replying to
@alice@lgbtqia.space @deviantollam@defcon.social Depends largely on the desired features. For example, UWB for touchless unlock (Apple Home Key, or Aliro) is only available on a handful of devices right now. Schlage released a new smart lock recently which seems nice, the Sense Pro. https://appleinsider.com/articles/26/08/20/schlage-sense-pro-review-uwb-home-key-proves-itself-again-on-this-sleek-smart-lock
appleinsider.com
0
1
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@catsalad@infosec.exchange
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1w ago
Replying to
@mcc@mastodon.social It’s like the opposite of a Lumon Dasher keyboard. All the escaping! Only one Control, though.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 1mo ago
Replying to
@xrobau@mastodon.au @LapTop006@aus.social SATA SSDs are unlikely to be fast enough to make good cache vdevs. I’d skip it unless you check your ARC stats and have less than a 99.5% hit rate. https://infosec.exchange/@bob_zim/115465564078061185 And using a single SATA SSD for both cache and log at the same time will definitely hurt performance compared to just using the capacity devices. A special vdev is more likely to improve performance, but it’s also risky, as it contains the filesystem structure itself (lose the special vdev, and you lose the tree telling the OS what data is where).
infosec.exchange

Zimmie: "I just had a brief conversation involving how rea…" - Infosec Exchange

0
4
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to on toot.wales
@gilesgoat@toot.wales @RobeeShepherd@mastodon.art Not quite. There are three main distinguishing characteristics: • The elements change length significantly - a Yagi-Uda’s elements are all almost the same length • The elements are all connected - in a Yagi-Uda, the driven elements are connected to the feed, but the reflector and director elements are electrically isolated • The alternating directions of the elements - Yagi-Uda antennas are symmetrical across the antenna’s axis Log-periodic antennas change element length dramatically over the length of the antenna, the elements are connected into two groups, and the groups alternate with each element (core-up-shield-down, core-down-shield-up).
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Replying to
@joshbuddy@sfba.social @ainmosni@social.ainmosni.eu @tante@tldr.nettime.org @toriver@mas.to @ErikJonker@mastodon.social Exactly my point. Perfect enforcement is almost always wildly wasteful. As long as you don’t expect it, you can make useful rules about the behavior you want to see or not, give moderators discretion to act on those rules, and audit the moderator actions to ensure they aren’t using the rules to harass people.
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2mo ago
Two of my banks recently implemented #passkeys, and the contrast between them is stark. I went to log in to one and they wouldn’t let me in until I “verified my identity” using a text message code to a phone number they apparently got from some data broker or by uploading my government ID and a video (obviously not happening). When I eventually got their support to let me in, the site forced passkey setup with no options at all. There’s no way to set up more than one passkey, no way to revoke access from the one I set up, and no way to log in via password anymore. They made every single decision in the most incorrect way possible. Utter garbage. Unfortunately, they’re the only option available to me for the particular account I have, so I’m stuck with them. Meanwhile, Wealthfront reopened a support ticket I filed years ago requesting passkey support to let me know they had added it. I logged in with a password, and the site offered to set up a passkey. In my user profile’s authentication page, there’s a section listing all my passkeys (and app-specific password names, etc.). It allows me to specify friendly names to track which is which, add more, and remove keys I no longer control. It’s pretty much perfect! #passkey #webauthn
0
0
0
0
Open post
Zimmie @bob_zim@infosec.exchange
· 2w ago
Replying to
@Infosecben@ioc.exchange @alice@lgbtqia.space @deviantollam@defcon.social Eh. *All locks* can be breached relatively easily. Breaching a Thread network to send an unlock command is a *lot* more difficult than simply cutting the deadbolt with a reciprocating saw if the door opens outwards, or kicking the door in if the door opens inwards. Most deadbolts’ strike plates are remarkably poorly installed.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:55:16 UTC