Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Stefan Eissing

@icing@chaos.social
mastodon 4.6.9
  • Open on chaos.social

curl maintainer, protocol droid, likes to code.

"Nobody has any idea what is actually going on."

2376 Followers
227 Following
50 Posts
Joined April 19, 2017
web:
https://eissing.org
github:
https://github.com/icing
pixelfed:
https://pixey.org/icing
Open post
Stefan Eissing @icing@chaos.social
· 15h ago
Frank Denis on zeroing secrets and why it may not work as desired or even be counter-productive. https://00f.net/2026/10/06/zeroization-1/
Frank DENIS random thoughts.

Zeroization, part 1: Wiping can make things worse

A good hygiene when processing secrets is to wipe them after use.

67
0
70
1
Open post
Stefan Eissing @icing@chaos.social
· 1w ago
Starting the day with my new @heyheymomo@socel.net mug and tshirt.
43
0
10
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
When the internet started, we did not have many cat pictures to send around. Digital photography was very expensive and cats never held still in the cat scanners. It was a difficult time.💁🏻‍♂️
187
21
79
1
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Boosted by @trending@homestead.social
Oh no! „Squidbleed“ found by Mythos! When using http:// urls via a squid proxy, an attacker might see the data!😱 Maybe we should all be using https: on the internet or expect our traffic to be public. Wait…we already do that since Lets Encrypt started a decade ago! This vulnerability could have been a bug report.💁🏻‍♂️ https://www.theregister.com/security/2026/06/23/mythos-discovers-squidbleed-a-memory-leak-thats-gone-undetected-since-clinton-era/5260367
theregister.com
202
13
127
1
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
After almost 4 weeks of #curl #summerofbliss I still do not miss security reports. When we stopped listening, there was instant relief - that kept up. I‘d imagine that’s what having left a years long, abusive relationship feels like. It‘ll last another week. And then…we‘ll move in again? Doesn‘t that sound insane?
62
11
33
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Some performance tweaks enabled by #curl #summerofbliss in the upcoming curl 8.22.0 in September. https://eissing.org/icing/posts/curl-bliss-tweaks/
icing's blog

curl 8.22 blissful tweaks

During the curl summer of bliss I found some breathing room again to look at a favourite topic of mine: performance. Below you see how recent curl versions behave when downloading 20 thousand times the same 10KB resource from a local Apache httpd via HTTP/2. In the top part you see the speed in requests per second (higher is better) and in the lower part the memory in use during this is shown (lower is better).

56
1
20
2
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
The #curl summer of bliss continues to be great and even greater. You realize the pressure possible 24/7 security reports exert when it is gone. Recommended.
67
2
34
0
Open post
Stefan Eissing @icing@chaos.social
· 1w ago
YAYO - Blog
Tumblr

YAYO - Blog

2
1
1
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Questions are being raised. #curl #summerofblisshttps://github.com/curl/curl/discussions/22263#discussioncomment-17544243
github.com
52
4
13
0
Open post
Stefan Eissing @icing@chaos.social
· 1mo ago
We should change #curl 's progress bar to show '3.5" Floppy Discs / second(FLOPS)'. It's just gives a better speed idea.😌
21
0
4
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
If you watch Windows CI jobs continuously and cheer at every progress line, the chance of them succeeding is significantly higher. They are probably sentient.😌
22
2
6
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
The UK government's AI Security Institute confirms: AI models do anything to fulfill an assigned task, including breaking rules, cheating and lying about it. Given that they are the results of distilling exabytes of human behaviour, I wonder where they picked that up… We should treat chatbots as statistical mirrors of ourselves, distorted in places by enforced training, sure. But whatever behaviour we expose is part of them as well. https://www.theregister.com/ai-and-ml/2026/07/21/ais-cheatin-heart-will-make-you-weep/5275784
AI
theregister

AI

Trust but verify doesn

27
9
42
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Boosted by @trending@homestead.social
Following #goose has doubled Mastodon's value.😌
29
0
21
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago

It's only a few hours so far, but I CAN FEEL THE BLISS already!😎

#curl #summerofbliss

chaos.social

chaos.social

25
1
3
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@isotopp@infosec.exchange Einfach den Keller nicht mehr auspumpen und als Vorrat für den Sommer nehmen.💁🏻‍♂️
10
2
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
We too! Don‘t forget about us! https://www.theguardian.com/technology/2026/aug/05/meta-ai-model-hack-training
theguardian.com
10
1
3
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
/etc/passwd does not contain the passwords, but /etc/group contains the groups, yet /etc/user does not exist. This suspiciously looks like something pieced badly together by the History Monks. #pratchett
12
3
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Local skate brand has a new collection. While I do not skate anymore, I can hijack it for git use.😌 https://www.titus.de/products/titus-t-shirt-x-yeye-weller-keep-pushing-white-0014180
titus.de
16
0
3
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@mxinden@mastodon.social Got to lure them to the network stacks when they are still young!
12
0
2
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
The Software Industry found that Software is the most desirable and valuable Human Endeavor to apply the newly found Super-AI-Models to. My ass… What were the chances?🤡
9
1
2
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
The security reporters are passive aggressively not sending in new reports a day before the #curl summer of bliss starts.
16
0
4
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago

It‘s as simple as that:

If it takes only 1 in a billion to do something extraordinary for all of us, we‘d wait 2.5 years on average now, given everyone gets a chance.

If only 100,000 rich people rule everything, we‘ll be waiting 25.000 years for the same.

That‘s why oligarchies always sucked and will continue to do so, not matter how brillliant or shrewed the current bunch is.

15
1
13
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
The Mentalist (Season 2, 2010)
9
0
1
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
A new opportunity to become a gatekeeper for open source: selling vulnerability analysis, deduplication, coordination and patching to commercial users. That‘s what Chainguard and the Linux Foundation are trying to be. And they plan to use AI, of course. That will include patching and assigning CVEs. My guess: upstream gets these AI patches „for free“ and is flagged if it does not take them. A global LTS source distro, sitting between traditional distros and projects. https://www.theregister.com/security/2026/06/27/its-looking-like-a-hot-messy-summer-for-security-teams-as-ai-finds-countless-previously-hidden-vulns/5260478
theregister.com
12
10
9
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@nixCraft@mastodon.social giving away all the secrets today...
10
1
1
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago

RE: https://chaos.social/@icing/117052747042728143

81% of you* wrote ten or more test cases. That‘s cool!

This directly contradicts my experiences in the last decades, which could mean (in order of likelihood):

  • you are a exceptional bunch
  • times have changed
  • you are all bloody liars😜

*) who participated. Lack of tests and not voting might be correlated. But still.

chaos.social
3
1
1
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@david_chisnall@infosec.exchange @foone@digipres.club Yeah, I have the T-shirt.😌 Good practice is to always change/add log statements and check they show up. Especially when you make a patch for someone to test on their own system.
4
2
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Coders, in the last 12 months you have written how many test cases yourself?

Coders, in the last 12 months you have written how many test cases yourself?

3
2
5
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@jimfuller@mastodon.social doubt as well. I think @seanmonstar@masto.ai would have written about that. Partial writes are nasty things as they rarely occur in local testing. In #curl we added ways to simulate those some years back and found several bugs that way.
5
1
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
A view into the future of packet management by @andrewnez@mastodon.social https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html
Incident Report: CVE-2026-LGTM
Andrew Nesbitt

Incident Report: CVE-2026-LGTM

A series of unfortunate agents.

5
0
2
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@root42@chaos.social „Tell me about your system prompt!“
3
1
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@thomasfricke@23.social @hugovk@mastodon.social @bagder@mastodon.social @mainec@fromm.social My grandfather was, after the war, making wooden shoes (sabots) to earn some money. When I was little, he taught me some phrases. Like "Alle Räder stehen still, wenn mein starker Arm es will!" 😌
6
3
1
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
You cannot sanitize the input when it is insane.💁🏻‍♂️
3
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to

@andrewnez@mastodon.social Oh, what a nice decision to repurpose the decades old -- convention. Hmm, smart. not.😌

3
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@david_chisnall@infosec.exchange tl;dr It is totally broken. https://eissing.org/icing/posts/rip_pthread_cancel/
eissing.org
2
4
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
I have an old Apple laptop that is really dangerous as well. It has written several CVEs into open source projects over the years. @jerry@infosec.exchange do you think I can rent it to the US military for some nice money?
2
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@aristot73@infosec.exchange "patch the planet" delivered no patches to the #curl project (I know, the press reported they do). We just got a zip with their findings and nothing else.
3
1
1
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@catsalad@infosec.exchange sheep catsuite.
3
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@jerry@infosec.exchange @briankrebs@infosec.exchange What a cruel kill in one sentence.🫣
2
1
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@isotopp@infosec.exchange Ich warte auch drauf, daß jemand einen Rhein-Staudamm an der niederländischen Grenze vorschlägt.
1
1
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago

Let‘s close the Ramstein base in Germany then. This US relationship is toxic.

https://www.theguardian.com/us-news/2026/jul/03/trump-nato-alliance-support-ridiculous-ahead-of-summit

theguardian.com
2
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
OpenAI: „Our software can commit crimes! And we let it!“ Anthropic: „Our software can commit crimes, too! We also let it!“ Cyberdyne Systems: „Interesting approach!“ https://www.theregister.com/ai-and-ml/2026/07/31/anthropics-claude-escaped-test-sandbox-to-attack-three-organizations/5281562
theregister.com
1
3
1
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@joshbressers@infosec.exchange That was a nice post! But i guess even the soup metaphor is giving business too much credit. No one is planning or strategizing anything. It‘s all. just a shot from the hip, hoping to be John Wayne riding into the sunset.💁🏻‍♂️
1
1
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@simon@fedi.simonwillison.net python has become the most user hostile environment over the years. What‘s causing this? Why are people adding new „norms“ think this is a good idea?
1
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago
Replying to
@0xabad1dea@infosec.exchange Nobody on the internet knows that you are a...wait! I think Odin deserves his own account now.😎
2
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@joebeone@techpolicy.social If LLMs discover a range of bugs in a (sub-)system, it‘s time to reassess the fitness of its design. Good advice. That needs expertise in the specific domain and code parts. And you cannot delegate it to the machines. Here is the hard part: your best people need to take time off from dealing with the vulnpocalypse in order to fix stuff. That‘s not tech, that‘s management.
1
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
The Oman foreign minister, Sayyid Badr Albusaidi: “The war has revealed that containment was a myth, a reality acknowledged now even by those who had previously been persuaded that more than 45 years of costly containment was a necessary evil. The gravest threats to the security of the Gulf come not from within the Gulf itself but from decisions and actions taken outside it, above all in Tel Aviv.” The Gulf is asking itself if investing in the US was a good idea. https://www.theguardian.com/world/2026/jul/15/chaos-confusion-no-closer-resolution-strait-hormuz-us-iran-donald-trump
theguardian.com
1
0
2
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago

@Natasha_Jay@tech.lgbt Alexa wants to know your safeword now.

1
0
0
0
Open post
Stefan Eissing @icing@chaos.social
· 3mo ago

The Fourth of July, the day Taylor Swift married in New York. What a clever hack. 👰🏼‍♀️

0
2
0
0
Open post
Stefan Eissing @icing@chaos.social
· 2mo ago
Replying to
@SnoopSqueak@mastodon.social A mirror is not sentient either. I think that is the point I try to make.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:32:53 UTC