Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jörn Franke

@jornfranke@social.anoxinon.de
mastodon 4.7.2
  • Open on social.anoxinon.de

Interested in #science #data #nosql #cloud #geospatial #radio #games #simulation and #analytics supported by #environmental #sustainable #opensource #software #europe

789 Followers
6404 Following
48 Posts
Joined January 31, 2026
Website:
https://jornfranke.zuinnote.eu/
Codeberg:
https://codeberg.org/zuinnote
social.darc.de:
https://social.darc.de/@dl2ejf
Keyoxide:
$argon2i$v=19$m=4096,t=3,p=1$QVBFb3pmVW14U2tWK1V6YzlWZE80Zw$kTWjd24yB+vSgiJcXHQLfk/eRH00AQqW59es9mYzQig
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 2mo ago
Replying to
@briankrebs@infosec.exchange It could be also that the vulnerabilities were put by AI there in the first place and now they need to fix because they lost control.
13
0
2
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 1mo ago
published scrapy-contrib-bigexporter 1.2.0 export scraped data using Scrapy into big data formats, such as Iceberg, Parquet, Orc, Avro Changelog: https://codeberg.org/ZuInnoTe/scrapy-contrib-bigexporters/src/branch/main/CHANGELOG.md #python #scrapy #parquet #iceberg #scraping #web
codeberg.org

Cookie monster!

1
0
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 2mo ago
Replying to
@neu3no@netzkms.de Ich nutze Podman, weil es sowieso Teil von fast jeder Linux-Distribution ist (Docker ist bei keiner dabei). Podman ist per Default sicherer (rootless) und hat einige interessante Funktionalitäten (podman.systemd/Quadlet). Man kann es zum größten Teil als Drop-in-replacement für Docker nutzen (gibt auch Wrapper-Pakete).
1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@_elena@mastodon.social You have been referenced in a German IT magazine on that issue (behind paywall): https://social.heise.de/@ct_Magazin/116839474830468838 Edit: They said you were one of the first documenting the disappearing source code
Open quoted post
Quoting
c't Magazin
@ct_Magazin@social.heise.de

heise+ | Kurznachrichtendienst W Social: Mehr Marketing als Souveränität

Mitte Juni 2026 hat W Social seine öffentliche Beta gestartet, mit einer Menge Versprechen, die nicht alle einer näheren Betrachtung standhalten.

https://www.heise.de/hintergrund/Kurznachrichtendienst-W-Social-Mehr-Marketing-als-Souveraenitaet-11340019.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Bluesky #Entertainment #SocialMedia #news

Open quoted post
2
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@concretedog@mastodon.social @jamesb@fedi.duckduckpigeon.co.uk btw. in tabbed mode of Libreoffice you find the feature in a slightly different location: https://help.libreoffice.org/latest/en-US/text/shared/01/qrcode.html
help.libreoffice.org

QR and Barcode

2
0
2
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 4mo ago
Replying to
@shadow53@floss.social Then, there is the cost risk - all of them make a big loss at the moment (https://www.wheresyoured.at/premium-ais-circular-psychosis/) This means you will in the very near future pay 100-1000x more money. On top of that you will spend even more money because the more code you generate the more token you have to spend in the future for AI to go through your code. The cost risk is real: https://finance.yahoo.com/sectors/technology/articles/ubers-anthropic-ai-push-hits-223109852.html
Premium: AI's Circular Psychosis
Ed Zitron's Where's Your Ed At

Premium: AI's Circular Psychosis

In this week’s free newsletter, I explained how bad the circular AI economy is in the simplest-possible terms:  Anthropic not have money to pay big cloud bills, because Anthropic company cost lots of money, more money than Anthropic make! So Anthropic only PAY cloud bills if OTHERS give

3
1
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@dlr_next ja beim letzten Mal ist einiges durcheinander geraten
4
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@grimm Die Projektkosten eines Atomkraftwerks, die häufig ein vielfaches der Summe sind, sind auch nicht drin. Wartungskosten wurden auch nicht kalkuliert. Das ein Atomkraftwerk, welches temporär abgeschaltet wird, Gigawatt an externer elektrischer Energie zur Kühlung benötigt auch nicht. Versicherungen wie einige sagen auch nicht. (Wer hat eigentlich Tschornoby Auswirkungen bezahlt?).
3
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@endrift @wezm ah you are right. On the other hand then the question is: why webserial and not webusb?
3
1
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@arminhausf @evawolfangel Es wurde nicht nachgewiesen, dass es bessere Patches schreiben kann. Es wurde auch nicht nachgewiesen, dass die Patches nicht zu neuen Sicherheitslücken führen (da es den Kontext in dem das System deployed wird nicht kennen kann). Macht aber nix! Wenn es schief läuft ist halt der "Human-in-the-loop" Schuld. Und nicht die schlechte Technologie.
3
1
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@filippo Quote from a paper that you cite: ", our most time-efficient architectures can potentially enable run- times of 10 days for ECC–256 with ≈ 26,000 qubits, and 97 days for RSA–2048 with ≈ 102,000 qubits" This is for one key! If all "substantial engineering challenges" are solved. It was not the scope of your post, but a broader assessment at Confidentiality, Integrity, Availability risks with some concrete estimations would help (which is maybe more a job for a IT Security Risk Manager).
3
10
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi siehe auch https://www.redhat.com/en/blog/navigating-mythos-haunted-world-platform-security "Functionality vs. Security: Some vulnerabilities identified by AI are actually functionality bugs with no meaningful exploit path."
Navigating the Mythos-haunted world of platform security
redhat.com

Navigating the Mythos-haunted world of platform security

The preview release of Claude Mythos presents a massive challenge for IT security experts, as well as an opportunity. Mythos' capabilities to identify complex memory safety issues and logic flaws hidden in legacy code as well as exploit them in increasingly sophisticated ways dramatically compounds and expands the outsize role AI scanning plays in open source. As an industry, we cannot react to this seismic shift with panic; instead, we need to reinforce the need for system resilience throu

2
0
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi Die Kernellücke in BSD ist Panikmache. Niemand macht NFS über Internet verfügbar. Niemand sollte NFS ohne Authentifizierung und ohne Firewallregeln im privaten Netzwerk haben. Klar das solche Lücken einfach über Defense-in-Depth abgedeckt werden können => deswegen auch 20 Jahre keinen Fix (war sicher vorher bekannt). Dazu null Investionsbereitschaft von Softwarefriremn in Security (nur in Security wo ihr Geschäftsmodel bedroht wird)
2
1
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi Meines Erachtens falscher Fokus (unbegründete Panik). Statdtdessen sollte man sich auf Microsegmentation, Internet Egress Filtering, besseres Patch Management, bessere Ausbildung, bessere Software ohne Sicherheitslücken, minimale Zugriffsrechte usw. fokussieren. Dann kann man viele Sachen abfangen, obwohl Lücken in der Software vorhanden sind. Dazu müssen auch die großen Softwarefirmen für ihre Sicherheitslücken, über die das BSI regelmäßig berichtet, zur Verantwortung gezogen werden.
2
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@filippo I found no good argument for this. There is just a bogus comment that nobody asked the Manhatten project to create a small nuclear explosion. It has nothing to do with the topic and they of course did various tests and experiments to validate what they are doing. It is a typical distraction from the fact that they even cannot solve small problems on QC.
2
0
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 4mo ago
Replying to
@milan@social.tchncs.de could be a good complement for wanderer. It is based on Spring Boot so it should be easy to have SSO there. One thing though is that the dependencies are outdated (security risk): https://codeberg.org/fitpub/fitpub/src/branch/main/pom.xml Additionally, Java 25 LTS should be the Java version to be used (not 17)
codeberg.org

Cookie monster!

1
1
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 7mo ago
Replying to
@BMDS Hoffentlich geschieht das im Gegensatz zu OpenClaw, Clawbot und Co sicher und die Daten der Bürger enden nicht bei anderen. Das @bsi gibt hoffentlich Vorgaben und überprüft diese.
2
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 4mo ago
Replying to
@shadow53@floss.social I would ask to measure that it indeed brings improvement and have additional validation (unit testing, static code analysis, fuzzing etc.) that it does not decrease quality. Static code analyzers give you also statistics on duplicated code and code complexity. They can be indicator that things go wrong. Additionally, you can collect number of incidents (if LLM would work they should go down).
1
2
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@swetland@chaos.social See also https://www.softwareheritage.org @swheritage@mstdn.social
Software Heritage

Home Page - Software Heritage

1
0
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@thomasfuchs Maybe via the WDR archive: https://www.ard.de/die-ard/presse-kontakt/archive/archivzugang-wdr-100.html While they ask for a "research question", it does not really define it, so anyone can ask a "research question". You can request if they have the shows and check them there. If you want a copy then you have to pay a fee (not sure how much).
Archiv – Westdeutscher Rundfunk (WDR)
ard.de

Archiv – Westdeutscher Rundfunk (WDR)

Westdeutscher Rundfunk (WDR)

1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@wezm Is this not a bit redundant given WebUSB https://developer.mozilla.org/en-US/docs/Web/API/WebUSB_API ? I mean not every serial port is USB, but probably most of them relevant for browser use cases are.
WebUSB API - Web APIs | MDN
MDN Web Docs

WebUSB API - Web APIs | MDN

The WebUSB API provides a way to expose non-standard Universal Serial Bus (USB) compatible devices services to the web, to make USB safer and easier to use.

1
3
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@bsi Others are able to reproduce Mythos capabilities with cheap open source models: https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier Mythos just uses trivial techniques (paraphrasing outputs of static code analyzers, fuzzers. formal logic etc.). The problem is that companies do not invest in secure software (as you can see from the BSI announcements - Microsoft, Citrix etc. do on purpose not invest in security). Investing in Mythos is waste of money - instead invest in proper security
AI Cybersecurity After Mythos: The Jagged Frontier
AISLE

AI Cybersecurity After Mythos: The Jagged Frontier

When AISLE tested Mythos's showcase vulnerabilities on small, cheap, open-weights models, most found the same bugs. Here's what that means for cyber.

1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi Siehe https://cyberplace.social/@GossiTheDog/116390978622304265 Antrophic Mythos ist ein Marketinggag
cyberplace.social
1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi Da kommen allerdings dann keine neuen Lücken bei raus. Nur bekannte die nicht gefixed wurden, weil Geld gespart werden soll oder weil schon komplett abgedeckt durch Defense-in-Depth. Das Problem sind hier die Investitionen - bekannt sind die alle schon. Der technische Anthropic Bericht übertreibt die Kritikalität, spart mit Details (ohje alles so schlimm können wir nicht teilen) und einige Fixes für kritischen Sicherheitslücken wurden durch ahem "update der Dokumentation" gefixt (botan)
1
2
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@georgetakei@universeodon.com @pluralistic@mamot.fr warns against this since ages, e.g. https://pluralistic.net/2025/06/24/price-discrimination/# or in his book on "Enshittification"
pluralistic.net

Pluralistic: Surveillance pricing lets corporations decide what your dollar is worth (24 Jun 2025) – Pluralistic: Daily links from Cory Doctorow

1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 7mo ago
Replying to
@TheLastOfHisName Try to use flatpaks - this will install everything you need and does not lead to incompatibility with other software https://www.siberoloji.com/how-to-install-applications-from-flatpak-on-linux-mint/
Siberoloji

How to Install Applications from Flatpak on Linux Mint

How to install applications from Flatpak on Linux Mint using various methods, including the Software Manager, GDebi, DPKG, and APT.

1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 8mo ago
Replying to on vmst.io
@csara@vmst.io maybe https://european-alternatives.eu/ can give some inspiration @european_alternatives@mastodon.social
european-alternatives.eu
1
0
1
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 8mo ago
Replying to
@Liberapay@mastodon.xyz Hope you can move your infrastructure to a European cloud provider in the future
1
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 7mo ago
@kicad flatpak would be alsonice - this has a lot of advantages for many Linux distributions.
0
1
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 4mo ago
Replying to
@shadow53@floss.social See also on cost risk: GitHub will start charging Copilot users based on their actual AI usage (https://arstechnica.com/ai/2026/04/github-will-start-charging-copilot-users-based-on-their-actual-ai-usage/) GitHub Copilot has finally released a preview of usage-based billing based on current usage. (https://www.reddit.com/r/GithubCopilot/comments/1tbb5bj/github_copilot_has_finally_released_a_preview_of/?rdt=59236) how much is too much to spend on ai tools (https://www.marketplace.org/story/2026/04/24/how-much-is-too-much-to-spend-on-ai-tools) AI Is Too Expensive (https://www.wheresyoured.at/ai-is-too-expensive/)
reddit

GitHub Copilot has finally released a preview of usage-based billing based on current usage.

rostilos

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@EinPhysiker Über mehrere Monate Bücherschränke in Umgebung füttern?
0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@pluralistic@mamot.fr ok thx this seems to just check the domain. Anyway I found a way around. thank you
0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@pluralistic@mamot.fr It is good to have the threads also here as it seems your website is down
0
5
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@Gargron@mastodon.social @opensuse_es@fosstodon.org ?
0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@bsi@social.bund.de Es ist sehr zu begrüßen, dass es sicheren Cloudstandards wie C5:2026 gibt. Allerdings kocht hier jedes europäische Land sein eigenes Süppchen (e.g. SecNumCloud) oder kocht gar keins. Das schadet Europa und bringt uns nicht voran - unsere Softwareindustrie wird dadurch gelähmt. Ich erwarte daher, dass das BSI mit höchster Prirorität mit allen europäischen Ländern zusammenarbeitet und schnellstmöglichst (innerhalb von 12 Monaten) endlich EUCS fertigstellt: https://www.enisa.europa.eu/publications/eucs-cloud-service-scheme
enisa.europa.eu

EUCS – Cloud Services Scheme | ENISA

ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 5mo ago
Replying to
@kuketzblog@social.tchncs.de Wireshark liest verschlüsselten Traffic auch nur mit wenn es das Zertifikat hat: https://wiki.wireshark.org/TLS Hat man aber meistens nicht wenn es Richtung Internet geht. Man kann sich aber z.B. per eBPF in die openssl Bibliothek einklinken und dann geht es (sofern sniffer auf dem gleichen Rechner ist und man entsprechende Rechte hat): https://codeberg.org/ZuInnoTe/rust-ebpf-localnet-kernel-filter-study/src/branch/main/uprobe-libcall-filter Es gib da auch: https://www.heise.de/news/Ausgehenden-Traffic-unter-Linux-kontrollieren-Little-Snitch-ist-da-11250677.html
wiki.wireshark.org

TLS - Wireshark Wiki

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@pluralistic@mamot.fr Opening though https://pluralistic.net/2026/06/15/vernacular/#hypercardian works
pluralistic.net

Pluralistic: AI and amateurism (15 Jun 2026) – Pluralistic: Daily links from Cory Doctorow

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 4mo ago
Replying to
@milan@social.tchncs.de e.g. Spring Boot is 3.2.0, which was released Nov 2023 (More than 2 1/2 years ago, https://mvnrepository.com/artifact/org.springframework.boot/spring-boot/3.2.0) Spring Boot 4.1.0 is about to be released this week. Other dependencies maybe also outdated
mvnrepository.com
0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi Siehe auch https://chaos.social/@evawolfangel/116381132709222916
chaos.social

Eva Wolfangel: "Entschuldigt, ich bin so begeistert, dass mein ak…" - chaos.social

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@filippo Cryptographic experts might be confident in the security of lattice, but I would be not confident in their secure implementation. It took decades to get the implementation right for classical algorithms and they are still often wrongly implemented. This is a big security problem.
0
4
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@bsi@social.bund.de Ihr wisst schon, dass Ihr eine Plattform namens https://opencode.de habt? @zendis@social.bund.de
openCode.de - Open Source Platform for Public Administration
opencode.de

openCode.de - Open Source Platform for Public Administration

Together, we develop and share software that shapes our digital future in a self-determined way.

0
2
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 6mo ago
Replying to
@filippo Do not get me wrong. I believe we need to be crpyto-agile as at the moment it is even a mess to update the algorithm of one application to a latest version. Here I also agree with Bruce Schneier (https://www.schneier.com/blog/archives/2026/04/google-wants-to-transition-to-post-quantum-cryptography-by-2029.html) However, one should not do this in panic mode and get that one first right before moving to so impacting changes in an organisation.
Schneier on Security

Google Wants to Transition to Post-Quantum Cryptography by 2029 - Schneier on Security

Google says that it will fully transition to post-quantum cryptography by 2029. I think this is a good move, not because I think we will have a useful quantum computer anywhere near that year, but because crypto-agility is always a good thing. Slashdot thread.

0
0
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
@pluralistic@mamot.fr hmm ok thank you - I just checked. If I open pluralistic.net then it works, but this link does not (it comes from your thread): https://pluralistic.net/2026/06/15/
pluralistic.net

June 15, 2026 – Pluralistic: Daily links from Cory Doctorow

0
3
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 2mo ago
Replying to
@Kueperpunk@social.anoxinon.de ist korrigiert
0
1
0
0
Open post
Jörn Franke @jornfranke@social.anoxinon.de
· 3mo ago
Replying to
wie ist @bsi@social.bund.de involviert?
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:13:30 UTC