Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

GeneralX ⏳

@generalx@freeradical.zone
mastodon 4.7.3
  • Open on freeradical.zone

but most of all, @generalx@freeradical.zone is my hero

#privacy #security #foss #abolishICE #hacktheplanet

Toots reflect the views of my other employer

Header: lawyers Denise Heberle and Bill Goodman, in a PSA for the National Lawyers Guild ("NLG Know Your Rights Reminder")

Avatar: jack of hearts

Posts spontaneously combust except polls

72 Followers
66 Following
34 Posts
Joined March 30, 2025
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

In case you missed it, all of these malicious VS Code extensions use techniques that were responsibly disclosed to Microsoft, to which the response was:

"After careful investigation, this case has been assessed as low severity and does not meet MSRC’s bar for immediate servicing"

"Therefore, it is the user’s responsibility to ensure that they are not installing malicious extensions."

Five months later, Microsoft's own GitHub was compromised.

https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/
#security #vscode #openvsx

mazinahmed.net
49
5
40
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

Very happy to see the results of a security audit by @cure53@infosec.exchange of TorVPN (next gen Orbot).

While no High issues found, the Medium issues that could cause Denial of Service conditions are very important to focus on.

Why?

Because if you can't attack the security, you attack the ability to do things securely. Downgrades. Fallbacks. Prevent Signal from working so you're forced to use SMS.

Glad to see the focus on Availability!

https://blog.torproject.org/code-audit-tor-vpn/torvpn_cure53_audit.pdf
#tor #privacy #security #android #orbot

blog.torproject.org
14
0
5
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 3mo ago
Replying to

@gsuberland@chaos.social Joke's on you.

--oh-god-when-will-the-horrors-end is an invalid option, but it is a valid package name...that I just published.

5
2
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Boosted by @silverpill@mitra.social
Palantir is hiring neurodivergent individuals! Click here to have your neurodiversity taken advantage of and exploited! hxxps://jobs.lever.co/palantir/61eaa54c-e1b7-4064-afad-f7df3d48d652 #Palantir #neurodivergent #hiring #whistleblowers_needed
8
8
7
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

How do you mostly pay for stuff, in-person?

#poll #askfedi #money #personalfinance

freeradical.zone
5
4
10
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 2mo ago
When a colleague uses AI, it's like being exposed to secondhand smoke. And you can't avoid it because you have to work with them. #ai #workerhealth
1
0
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 6mo ago

Self hosters, do you use Cloudflare in front of your hosted services?

#cloudflare #selfhosting #privacy #security

freeradical.zone
7
7
8
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Did the jabber.ru "lawful" intercept on Hetzner and an RCE vuln in acme.sh go hand in hand in 2023?

This blog raises the question, but the reality is probably more mundane, especially since the op was discovered from expired certs.

The recommendation list linked to protect against this MITM misses a key feature - (TLS) channel binding. Conversations supports it.

https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
#xmpp #jabber #security

remyhax.xyz
2
0
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

The meshtastic firmware pipeline on GitHub was vulnerable to pwnRequest 5 days ago, the same vuln that popped Trivy.

This could have let someone take over signing keys for Debian packages and publish malware that infects the machine installing the packages.

Since there are a few vendors that preinstall firmware and sell meshtastic-ready devices, the malware could have been an entry into some e-commerce organization.

https://github.com/meshtastic/firmware/security/advisories/GHSA-mjx5-98jq-q736
#meshtastic #security #devops

github.com
3
0
2
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

The attribution for Mastodon's CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:

"This security issue has been reported by Doyensec in collaboration with Claude and Anthropic Research"

Is this how they say "Mythos" without revealing that Doyensec is one of the undisclosed Project Glasswing members?

https://github.com/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73

https://w.on-t.work/activitypub/may-2026-vulnerability says:

"Doyensec has contacted us on *behalf* of Anthropic".
#security #mastoadmin #mythos #ai #glasswing

github.com
2
0
8
1
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

"Don't Look Up" talk:

That Feeling When the NSA says "damn you, academics!"

(T-Mobile using a null cipher in an IPSec tunnel and broadcasting unencrypted voice to whole continents and other free for all data from the US military, Mexican military, inflight WiFi).

https://events.ccc.de/congress/2025/hub/de/event/detail/don-t-look-up-there-are-sensitive-internal-links-in-the-clear-on-geo-satellites

#39c3 #security #sigint #privacy

events.ccc.de
6
0
4
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

When Big Tech clouds fail, are censored, or collude with the (US) government, which would you choose for private messaging?

#privacy #security #decentralization #securemessaging #matrix #xmpp #simplex #deltachat #signal #poll #polls #askfedi

freeradical.zone
6
6
12
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@evan Clearly replies, as the other options are only allowed once per account. I'll wait for a spammer to prove me right.
2
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

It's hard to fall for 'support' scams that target free and open-source software.

Because "support" is browsing GitHub issues, a mailing list, or a discourse forum.

And then submitting your own patch.

#foss #scams #half_joking #signal

freeradical.zone
1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Yet another wave of "cybersecurity hiring shortage" articles, this time featuring AI as the cause.

After unsuccessfully finding a job in "cybersecurity" for years, this shortage story is getting old.

The good news: watching how my company does security from afar, I'm glad I'm not a part of it.

#cybersecurity #hiring #oldnews

freeradical.zone
1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

New Nightmare Eclipse account is at https://gitlab.com/nightmare-eclipse

"You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.

Now you take the courtesy to flag my github account and wipe it out of the public, just like that ?

Mark this date July 14th, I will make sure your bones are shattered that day."
#threatintel

gitlab.com
1
1
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Have you ever watched a public access TV show?

(Via internet is okay, but PBS doesn't count)
#poll #askfedi #tv #colbert #usa #nonprofit

freeradical.zone
1
2
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Pro tip: PGP/GPG public keys store creation date.

Pro Pro tip: creation date can be anything you want.

Think about this the next time you create another rando email account at an encrypted email provider.

#privacy #opsec

freeradical.zone
1
1
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

The page cache was a mistake.

#linux #security #dirtycbc #dirtydecrypt #dirtyfrag #fragnesia #copyfail

freeradical.zone
1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

How much money do you make?

#poll #askfedi #money #finance #polls

freeradical.zone
1
2
4
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

Are you a procrastinator?
#poll #askfedi #procrastodon

freeradical.zone
1
1
2
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

Thought experiment:

Should Mastodon hide the number of followers you have, as shown to other people?
#poll #askfedi #mastodon

freeradical.zone
1
0
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

For the last time,

_NSAKEY is not a backdoor!

Sending Bitlocker recovery keys to Microsoft is not a backdoor!

The Bitlocker YellowKey login bypass feature is not a backdoor!

Where do people get these ideas???!!

#security #privacy #conspiracies

freeradical.zone
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@ai6yr @SwiftOnSecurity Don't forget the IR, radar, or ultrasound sensors.
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Everyone's talking about GenAI code, but have you seen GenAI software requirements?

Now it makes sense why our product is riddled with bugs. The code is poor quality, execs blame coders and QA, but not one person realizes slop, poorly specified requirements are the root of our problems.

Software architects have been replaced with software slopitects.

In this AI-infested ecosystem, 50% of my CSM job is apologizing on behalf of AI.

End rant.

#ai #genai #sdlc #projectmanagement #software

freeradical.zone

Free Radical

0
0
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Which would you rather deal with?
#security #infosec #cybersecurity #blueteam #poll

freeradical.zone
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

"The scene that grew my love for CTFs is emptying out. The CTFTime leaderboard has almost no semblance of history or human skill anymore. The 2026 scoreboard is unrecognisable compared to every year before it. TheHackersCrew, alongside many other large and reputable teams, either do not play, play with far fewer people, or struggle to cut into the top 10. Unregulated cheating is through the roof."

https://kabir.au/blog/the-ctf-scene-is-dead
#security #pwn2own #reverseengineering

kabir.au
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Thought experiment:

- Vulnerability researchers uses centralized AI model to find a vulnerability

- Vulnerability gets automatically reported upstream by the AI vendor, without the AI user's consent

- Alternative: declare a group of embargoed entities who receive the reports instead of the affected projects (cough, cough, Project Glasswing), perhaps for triage or validation.

Is this good or bad?
#ai #security #mythos #projectglasswing

freeradical.zone

Free Radical

0
0
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Do you trust the HR department to have your back when you've got a harassment or hostile work environment issue?

#hr #workers #harassment #workplace #poll

freeradical.zone
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

I like the narrative of Nightmare-Eclipse being a disgruntled security researcher, because I think the reality is more exciting.

- active/former Microsoft employee?
- NSA employee?
- Shadow Brokers adjacent?
- APT?

🍿
#threatintel

freeradical.zone
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to

@cityhallin@infosec.exchange Some of my other favorites:

  1. Asking "what is your full home address?"

  2. Asking for your LinkedIn profile, and actually validating the URL starts contains linkedin.com, not considering that you may not use LinkedIn. One time "idontuse-linkedin.com" worked.

  3. "Voluntary" self-disclosure section that has required questions without an "I do not wish to answer" option, e.g. "Are you Latino? Yes/No"

0
2
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 3mo ago
Replying to
@protocol7@cyberpunk.lol @alice@lgbtqia.space Thoughts on collateral damage?
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@lizzard@social.tchncs.de @cityhallin@infosec.exchange Luckily it's the US. Where employers can't ask if you're a citizen, but many of them flat out ask anyway. Possible job versus lawsuit...pick your battles.
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

Infosec (and adjacent) people:

Are you forced by your employer to use AI to help you do your job?
#infosec #cybersecurity #security #AI #poll

freeradical.zone
0
3
3
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:50:03 UTC