Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Alun Jones

@ftp_alun@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Father, Husband, Cancer survivor, Information Security Guy. Former Microsoft Security MVP. Loves XSS and "-alert(1)-">'-prompt(2)-'>

133 Followers
55 Following
42 Posts
Joined November 05, 2022
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2w ago
Replying to
@VisualStuart@pdx.social got any hints on parking? That's always a struggle!
1
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@cgudrian@social.tchncs.de @GossiTheDog@cyberplace.social Saddest part is, we already know what idiots do to people they think are witches.
4
0
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@overholt@glammr.us I feel a disturbance as if a million librarians cried out in fear and pain.
4
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 3mo ago
Replying to
@GossiTheDog@cyberplace.social Amazing how many people's lives Roko's basilisk will ruin by simply never existing.
9
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago

@GossiTheDog@cyberplace.social "Chris Evans (not gay) and others hosted the station early on, but they weren't openly gay" - I love how much heavy lifting is being done in that sentence by "others".
In a very similar sense, I and others discovered fire, invented the wheel and built the pyramids.
I should put this on my CV, then the AI recruiter reviewing it will confirm it to be true.

12
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 4mo ago
Replying to
@petrillic@hachyderm.io I can still remember the thrill of waiting to hear each episode on the radio. Fantastically advanced use of audio effects and music in a radio drama! Now I love in the USA, and find myself explaining to incredulous fans of Douglas Adams that radio is where this started.
6
3
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 4mo ago
Replying to
@briankrebs@infosec.exchange Dog called Patch, by a Window, on a Tuesday? Just a guess.
4
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to on gts.cryptography.dog
@ansuz@gts.cryptography.dog @ColinTheMathmo@mathstodon.xyz no, I was thinking it might indicate a good test of how random the simulation is.
1
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@ColinTheMathmo@mathstodon.xyz @ansuz@gts.cryptography.dog reminds me of a challenge that popped up in project management software, performing critical path analysis on projects where activity durations were not easily predictable. We modeled this with Monte-Carlo analysis, running the CPA hundreds of times. While the participatory randomness here doesn't mean that you can take a shortcut to analyzing the project's overall time span, you can perhaps say something about the day of the week it'll finish on. If nothing else, that could be a useful test of how accurate your CPA modelling is.
1
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 5mo ago
Replying to
@SwiftOnSecurity Wow. And then those same people, who always felt their underlings were incompetent, are pushing that down to them, not realising or caring that it's driving the incompetence down into the org.
3
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 7mo ago
Replying to
@briankrebs when I interview for appsec positions, I like to ask "what would it take for you to fire a developer for a security lapse?" Interesting conversations ensue. I don't think anyone actually ever fires developers for security failings, including failure to learn from repeated blunders.
5
0
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago
Replying to
@christianp@mathstodon.xyz
3
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 8mo ago
Replying to
@davep You went downhill fast, there.
4
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 4mo ago
Replying to
@europlus@social.europlus.zone @briankrebs@infosec.exchange what it realistically means is "we have to do this when paying the ransom, otherwise, when Shiny Hunters inevitably later release the data, we will be sued for not having done this". Paying the ransom makes zero sense, unless the data is destroyed in some existential sense to Instructure.
1
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 5mo ago
Replying to
@jack_daniel@mastodon.social mehgrim - the pain behind the eyes caused by all the meh.
1
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 7mo ago
Replying to
@GossiTheDog fault injection into production code at scale. Nice.
2
0
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago
Replying to
@stragu @GossiTheDog that has shown an interesting failure mode. https://www.forbes.com/sites/daveywinder/2026/04/08/1-billion-microsoft-users-warned-as-angry-hacker-drops-0-day-exploit/ [Note: I am very specifically using this as an example of what happens if a vendor requests a video demo of security vulnerabilities; I am NOT alleging this to be an example of an AI Slop submission]
forbes.com
1
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 7mo ago
Replying to
@rradczewski they had to hire more lawyers, and not once did they stop to ask the question "what is the likely cause of this (apparent) rise in theft across the board?"
1
2
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 11mo ago
Replying to
@Nickiquote@mstdn.social We've been routinely told that technology is clearly successful if it starts being used by the porn industry - but that's only a truth if the creators of the technology itself haven't sought out its use for porn. This seems like panic.
1
1
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 45mo ago
Replying to
@joelle "Is this a pedestrian? Please answer really promptly."
5
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 46mo ago
Replying to
@adamshostack@infosec.exchange @securopean@infosec.exchange To put it another way, if Putin dies tomorrow, and Russia suddenly becomes a utopian state based on peace love and universal harmony, and all those Russian hackers disappear, the threat model hasn't changed. Maybe the likelihood of a regionally-exposed threat being exploited decreases, but that's a bit of a stretch, given how many other threat actors there are, and assuming that the knowledge escapes and is spread to parts of the world who still want in to your data.
1
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 46mo ago
Replying to
@ryanaraine @k8em0 Props to Katie for jumping in on the "cyber shortage", and reminding Ryan that there's NO shortage of talented and interested people who want to join the cyber workforce, but they're kept out by companies who've spent the last several years insisting on 5 years experience, totally unnecessary coding skills, or an apparent insistence on penis.
1
0
1
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago
Replying to
@weekend_editor @ColinTheMathmo @vpunt is this because excel doesn't fulfil its designed purpose, or because it's being stretched for a use it's authors could never have anticipated, and are not rewarded for supporting?
0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange I'm going to bet their pushback is to declare that it's not really that important to change the name. Which is kind of a tacit admission on their part that they believe it to be very important indeed to keep the name.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago

@GossiTheDog@cyberplace.social I liked that.
Not a lot.
But I liked it.

0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 11mo ago
@mattblaze@federate.social @jautero@indieweb.social users deserve no rights, only devs. This is how enshittification happens.
0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@spacerog@mastodon.social I heard it again today. I guess we're trying to persuade an industry that still pushes back on "allow list" and "block list", too.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to on universeodon.com
@georgetakei@universeodon.com is it a final front ear?
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago
Replying to
@stragu @GossiTheDog You're right, sorry - I've had to page through a few of these articles in the last couple of days, and thought they all had basically the same text. Here's the one that suggests the video requirement was what tipped the hacker over the edge. https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit/ For this level of video demo, I've often seen people upload demos with music and a notepad window for anything they need to say while demonstrating. From a handler's perspective, there are other problems - often it's not clear what the video's trying to show, and spending time to watch the video is just another way in which the handler has their time taken away from good reports by spurious reports.
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
BleepingComputer

Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit

Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions.

0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 3mo ago
Replying to
@ColinTheMathmo@mathstodon.xyz Needs braces: Avoid {staring directly into the projector beam} at all times. versus: Avoid {staring {directly into the project beam} at all times}. It's probably the result of someone reading "Don't stare at the projector beam, even if it's not on, because someone might turn it on while you're staring at it, and then you'll be hurting for a while, and may become temporarily or permanently blind", and saying "make it more punchy".
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 5mo ago
Replying to
@mathew I don't hate it.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 34mo ago
Replying to
@byte@tech.lgbt @adamshostack@infosec.exchange Then, of course, there's the stuff I released as open source, but requested anyone using it for any kind of commercial use paid me for its use. That shit was used in space shuttle missions. I never saw a penny. I'd definitely propose a middle-ground, where there must be a way for someone with a need to repair / modify / resurrect to be able to do so with reasonable payments to the rights owners.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 6mo ago

I am painfully aware that I learned to write software over four decades ago, when it made sense to try and fit everything into 16K, but I'm really struggling with the attitude that it's a great idea to just throw more hardware at a problem.
LLM is being used, for the most part, as a sophisticated "more hardware", but it's far from the only place we do this.
And as a result, we've managed, as a society, to volunteer ourselves for a different kind of "Vime's boots" scenario, where most of our effort and expense goes into maintaining and patching, rather than clever solutions that make for lasting improvement.
Problems that could have been thought about, and addressed at dev time, or even at compile time, are now repeatedly addressed (and re-addressed, over and over) at run time.
It appears cheaper at launch, and impresses the bosses, but over time, it simply serves the purpose of funneling money into the AI service providers' pockets, for a possibly-small, but persistent, loss in performance.

0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 4mo ago
Replying to
@beeoproblem@mastodon.gamedev.place @briankrebs@infosec.exchange possibly the AI classifying pictures now decides that, since all creatures named "Patch" are dogs, that means all dogs are capable of being named "Patch". Or it could just be that there's too many cyber security folks naming dogs these days.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to on universeodon.com
@mathew@universeodon.com https://eliotakira.com/neko/
eliotakira.com
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@nullenvk@yourwalls.today @lcamtuf@infosec.exchange AI can do anything!
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@robpike@cosocial.ca Now make it into a product, and sell it - for peanut butter uses, obviously.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@tdp_org@mastodon.social where's Dougal when you need him?
0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@ColinTheMathmo@mathstodon.xyz I have a theory that Windows apps grew to prominence in the 90s in part because of unreliability. Unix code of the time tended to assume the memory allocations would always succeed, that there'd always be space on the disk, etc. Windows apps assumed they had to check those errors, and as a result, behaved more robustly under pressure. Just a hypothesis based on my own anecdotal experience.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 34mo ago
Replying to
@byte@tech.lgbt @adamshostack@infosec.exchange Sure, and I understand that frustration very much, but here's a counterpoint: I spent years supporting that software, and dealing with people who yelled at me about it. When I finally reach the point where the income doesn't match the effort it takes to keep it going, and I shut down support, and stop producing new versions, you don't get to decide that it's important enough to you to take those rights away from me, but not important enough for you to pay me. To extend on your language, fuck finding software so important that you're going to steal it, but not important enough that you're willing to pay the original owner for it. Write your own fucking software from scratch.
0
1
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 2mo ago
Replying to
@m8urnett@infosec.exchange This doesn't pass my "would you use AI for it?" test - if you can't quickly verify its correctness, and the task isn't suited to analysis and reduction of masses of widespread data, it's not a good AI task. It's why I feel code review is a good AI task, but coding is not.
0
0
0
0
Open post
Alun Jones @ftp_alun@infosec.exchange
· 5mo ago

@GossiTheDog@cyberplace.social "Thank you for asking, in this New Hire Orientation presentation on developer security, about the new speculative execution vulnerability in the x86 processor family. Let me know when you've found and eliminated your new team's several dozen XSS vulnerabilities, and we can talk some about more advanced vulnerability classes."

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:41:05 UTC