Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Craig Brozefsky

@craigbro@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I like to build simple, secure and resilient information systems to empower and connect people. I believe that this is best done with Free Software, open data standards, open protocols, and restrained craftsmanship.

I am happiest when I get to do this work with those fighting fascism, ethnic-cleaning, genocide and protecting our environment.

To make a living, I provide consulting and coaching services for software, data, and security engineering.

#openbsd #scheme #lisp #commonlisp #clojure #emacs #orgmode

0 Followers
0 Following
18 Posts
Joined October 15, 2024
Consulting:
https://www.taconic.systems
Free Software:
https://codeberg.org/craigbro
email:
craig@red-bean.com
LinkedIn:
https://www.linkedin.com/in/craigbrozefsky/
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
Replying to
@MaddieM4@raphus.social the over leveraged transient trust relationships we have embodied in package managers and distributions with massive package sets and builds with maximum features and thus maximum dependencies, are no longer tenable. Slop exacerbates it, but even without slop we are seeing the results of that shared infrastructure being targeted by bad actors — states, criminal gangs, rent seekers. I say this not in disagreement with #NeverSlop as a system design principal, but to expand the understanding of the threats we face at this time. No slop, no features designed for rent extraction, no standards that are cartel whitewashing, measure and know the cost of each dependency, and build open alternatives that are radically simpler. For example, GameOfTrees, not git with rust and ruby toolchain dependencies. Workflows that don’t require JavaScript to collaborate.
5
2
3
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
Replying to
@shriramk@mastodon.social I’m not sure that restaurants should have an API in order to have functioning interactions with humans. Agents calling them is like spam calls to me, it’s abuse of voice calls. Failure to enforce our regulations on devices on the telephone networks is the hole here. Restaurants are one example, but my day job is literally on a project called “digital customer engagement” for a company with millions of customers. We have to have explicit authorization, and have very specific use cases for automated notifications on voice channels. If some company set up voice agents to call our customer service line and have the agent attempt to order and negotiate service for things we explicitly don’t provide online for a reason, it would be considered abuse and result in a lawsuit.
2
1
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 2mo ago
I’m quite deep in the infrastructure as code camp, but I have to admit that the cascade of dependent process and abstractions is a barrier for many coworkers who are otherwise capable of manipulating and understanding the environments we are building. Json, structured editing, interpolation, javascript, templates, managing state and understanding the edge cases and complexities of declarative infrastructure tools, multi-stage deploys, dev/qa/prod instances, parametrizing and secrets management… This is no small ask of someone who has to fix problems, close tickets, and make things work and is used to a more direct manipulate and test loop. Putting this stack of complexity and abstraction in their way has real costs.
4
0
1
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 4mo ago
Replying to
@jwildeboer@social.wildeboer.net @homelab@fedigroups.social radical simplification and reduction of attack surface is the primary strategic response to this.
5
1
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 6mo ago
Replying to

@kentpitman @davefischer @tomjennings

I don't think the enabling thing was just at these people were smart. I think it's that they had the freedom to explore. Market economies are based on scarcity being valuable, but this economy was not based on that and so it didn't have to hoard software, it could share it.

See the world, you have built it, with shoulders of iron. See the world, but it's not yours, say the stealers of Zion. - The Clash - The Equaliser

My relationship to free software over my 30 years as a developer is founded upon the fact that it is what enabled my career. I didn't go to college, or have a local peer group. Learning linux, and using free tools to build my own workstation, clusters, and eventually, becoming a lisp programmer, would not happen with the generous sharing of others. I was able to share much of my work as open source, because little was actually depending upon the license.

I agree with you, we should not confuse the visible and valorized "capitalist economy" with the entirety of the socio-economic systems that we depend on, build, and flourish within.

6
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 3mo ago
Replying to
@swannodette@mas.to i find myself building a “distro” of my own, checking each dependence for policy on LLM, and configuring to install into my home dir. Just shell scripts and text files documenting dependencies. I decided against using the existing ports, because I want to control build options and updates. I really need very little, since libxml2 and emacs gives me a text mode browser without JavaScript, in eww. Feels like my first few years with Slackware in the mid 90s, or the”unsupported” accounts i had on a SunOs 4.1.3unoff cluster. Radical reduction in complexity, dependencies and attack surface is the only sane response to the current state of the software industry and the LLM slop and vuln explosion that is exacerbating it. I’m not retro grouching for nostalgia sake — just a lisp hacker who pays attention to the cost of everything, and is skeptical of the value of anything… BTW, Illich was an inspiration to me in the 90s too, I discoverer him from an early mailing list or usenet post, but then you needed to go to the library to get books…
1
1
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 3mo ago
Replying to
@briankrebs@infosec.exchange thank you!
1
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 3mo ago
Replying to
@Landsil@infosec.exchange so handsome!
1
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 6mo ago
Replying to
@briankrebs that mitigation from outside, seems at odds with the described attack. Im curious now about how that transfer occurs where it could be a lateral movement vector.
1
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 8mo ago
Replying to
@deech @jonmsterling except that in this case it’s a religious ceremony of dedication to the brand of autocomplete you use to get wrong answers. 🤣 As a hiring manager, I am not going to expect you to be versed in fads that require thousands of dollars in tokens to learn that are of marginal value to producing good code, especially at the entry level. I also am applying my own criteria that you know how to find the documentation and perform experiments for the tools you use, and not listen to the bullshit bot.
1
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 6mo ago
Replying to
@Hemera the cake is a lie
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
It’s the internet, if you don’t like what you are reading, look someplace else or write what you want to read. Same applies to software. There is amazing work being done now, and if you think it’s all going to slop its way to entropic collapse, might as well make the leap to that which makes you happy and build the system you want. It may take a decade, but you will still end up in a better place.
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
Reactionary extrapolation is a rhetorical or ideological trait that both the AI true believers and the FOSS purity police have in common.
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
Replaced git with #gameoftrees, which is native to #OpenBSD, has no new dependencies, and comes with complete man pages. No rust, no ruby, no python, and process seperation for improved security via pledge and veil.
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 6mo ago
Replying to
@mhoye@cosocial.ca This is how I ended up doing devops before it was a thing. Small companies with leadership that understood that if I have to be on call, I get a say in how things are built. Respect the people that do the work. I was an admin on call, catching taxi at 2am to go reboot solaris x86 boxes at a colo. Later, in large companies with an operations team in a different department, as a lead we made sure that we took personal responsibility for any disruption to the operators on call — including exchanging personal phone numbers and betting on call formally or not, depending on circumstance. Focusing on observability and deployment speed needed to respond and fix (live debugging and patching production via a CL REPL in some cases). Even when we controlled the tech, we had periods where a database or storage system was having chronic problems that took weeks to resolve. This taught us to favor simplicity over everything, and to truly understand our resource and state management. We called it stupid, not simple, because it avoided the common hackers conceit that clever is simple. I am sure that this personal responsibility is abused in dysfunctional organizations, but that doesn’t reflect on the origins of the practices, only what happens when they become popular and adapted as ritual or control in organizations that skipped the foundation. Similar to extreme or agile development. Respect the people who do the work. Keep it stupid, stupid.
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 6mo ago
Replying to
@kfogel@kfogel.org hmm, I’ll get on that
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 1w ago
Replying to
@shriramk@mastodon.social As we both understand, a reservation website is a structured negotiation between three parties designed to minimize impact on staff, and provide for the whole lifcycle of the reservation. I use these too, especially if the restaurant expresses that preference, and I appreciate them. It's not an "API" though, becasue all of the ones I have seen presume human agency on my part. Maybe I've over-indexed on the OAuth2 entity model tho. The flow is designed to NOT support automated agents, and they consider that abuse. I'm sure noone in the fediverse would mistake a human being picking up the phone for an API, or use an API metaphor to rationalize abusing those humans. So let's talk about this hypothetical one call agent. The agent making one robocall to a private entity without prior permission is still subject to FCC robocall complaints, caller-id requirements, and basic social norms. Without even getting into efficacy of the speech recognition/synthesis and reasoning, it bypasses the mitigations and controls of a website reservation system, if there is one, and is an unbalanced demand on human time. That is to say, it is an entitled dickhead move. Not an innovation, or signal of missed oportunity. This was the point of my original commet, BTW. This practice becomes a DDOS when a sufficient, but relatively small, number of hypothetical entitled dickheads pull the host(ess) into a running gun-battle armed only with caller-id and "Thank you for calling, please hold". 8^)
0
0
0
0
Open post
Craig Brozefsky @craigbro@infosec.exchange
· 3mo ago
Replying to
@xan@xantronix.social FreeBSD whoops a pony’s ass
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:09:17 UTC