Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

JRT

@jrt@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Average nmap enjoyer, destroyer of IoT worlds and embedded universes.
Chief #Passkey Advocate

"Experte für Nischenthemen" - unnamed
"Intel Gott" - @brahms@chaos.social
"ernährt sich von den Tränen der CISOs" - @g0rb@infosec.exchange

he/him

Working in #InfoSec by day. Doing some things at @AsteroidOS@fosstodon.org and @spline@chaos.social by night.

ALT: @jrt@chaos.social

#fuckAI #InfoSec #Security #linux #foss #CCC #spline #berlin #ArchLinux #fedora #AsteroidOS #VR #CyberpunkIsNow

821 Followers
1478 Following
27 Posts
Joined February 28, 2024
Website:
https://jrtberlin.de
Languages:
English, German
Signal:
jrt.42
Threema:
https://threema.id/FMESVF5Y
Matrix:
@jrt:kde.org
Open post
JRT @jrt@infosec.exchange
· 3mo ago
This is next level infosec shitposing: "It is the FreeBSD analogue of Linux's Dirty Pipe, CopyFail, Fragnesia, and Dirty Frag — except we gave it a BETTER name, with a BETTER logo, on a BETTER website. The other bug websites? Disasters. Sad. Many people have told us this." https://bumsrake.de/ #CVE202645257
bumsrake.de

BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.

BUMSRAKETE is a HUGE, TREMENDOUS, MANY-PEOPLE-ARE-SAYING FreeBSD kTLS-RX page-cache write primitive. The BEST primitive. Some say the best ever.

245
12
196
1
Open post
JRT @jrt@infosec.exchange
· 3mo ago

I've come across a bit of #passkey fud over the years and some misconceptions. I've written a general overview of the topic and added a FAQ section at the bottom.
I tried to keep the main part light on technical details with a few more technical explanations in the appendix below.

https://jrtberlin.de/p/passkeys-a-comprehensive-overview/

Feel free to reach out if you think I missed something or the FAQ lacks a certain question!

Big thanks to @ljrk@todon.eu for the technical QA and to @brahms@chaos.social for the QA of the German variant.

#Passkeys #Authentication

Passkeys: A comprehensive overview
jrt

Passkeys: A comprehensive overview

Passkeys are everywhere right now. But Why should I care? My password is secure!\nIn this post I try to cover how we got into to today’s mess of authentication methods and why passkeys are a good option going forward.\nHow did we get here? The first computer password allegedly 1 dates back to the MIT Compatible Time-Sharing System (CTSS), with multiple terminals that where not user-specific but with each user having an individual set of user-owned files. At the time it seemed like a straight for

13
2
11
1
Open post
JRT @jrt@infosec.exchange
· 3mo ago
Ampelausfälle durch Hitze in Berlin https://www.tagesspiegel.de/berlin/hitzewelle-in-berlin-temperaturrekord-in-der-hauptstadt-gebrochen--zahlreiche-ampeln-fallen-aus-15762498.html?utm_source=mastodon&utm_medium=activitypub #kritis #hitze
tagesspiegel.de
4
0
7
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago

"können sie mich an die technische Abteilung oder einen second level durchreichen?"
"Da sind sie schon"

Fuck my life. Warum hab ich immer die edge cases?

9
2
2
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago

Another #Linux LPE:
https://github.com/V4bel/dirtyfrag/

#DirtyFrag

infosec.exchange
5
0
15
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago
Replying to
@GossiTheDog @zackwhittaker meanwhile the german @bsi is telling people that thr era of typically software vulns is coming to an end. I think this is the golden age of shitposting.
5
3
0
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago

Customer: it's highly confidential that we are in a business relationship
Also customer: sends LinkedIn connection request

4
2
2
0
Open post
JRT @jrt@infosec.exchange
· 9mo ago

I have #AsteroidOS stickers with me at #39c3. Come and say hi!

infosec.exchange

Infosec Exchange

10
4
2
0
Open post
JRT @jrt@infosec.exchange
· 8mo ago
Replying to
@EUCommission @HennaVirkkunen Hi, on the profile page linked on her mastodon profile is the link to her mastodon in the socials missing: https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en
Henna Virkkunen
European Commission

Henna Virkkunen

Henna Virkkunen is the Finnish Commissioner responsible for tech sovereignty, security and democracy in the second von der Leyen Commission.

7
1
1
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago
Replying to
@vampirdaddy @kde https://xkcd.com/1172/
Workflow
xkcd

Workflow

4
0
0
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago

Die größte Beleidigung als Teil des Souveräns finde ich ja den Habeck als "schlechtester Wirtschaftsminister aller Zeiten" zu diffamieten und dann die Katherina Reiche auf die Position zu setzen.

3
0
0
0
Open post
JRT @jrt@infosec.exchange
· 10mo ago
Replying to
@neobrain@mastodon.social I'm excited for your #39c3 talk!
8
3
0
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago
Replying to
@briankrebs @GossiTheDog @zackwhittaker @bsi 100% too bad I can't bring myself to switch sides :D
2
1
0
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago

Einwohnermeldeämter sind auch nur föderiertes Identity Management mit extra Schritten und schlechten Schnittstellen.

2
0
1
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago
Replying to
@nakal@mastodon.social @HonkHase@chaos.social tatsächlich gehts um Zusicherungen der Hardware im Stile einer Smartcard. Mit FIDO2 tokens könnte man die Anforderungen auch im Web darstellen (oder einem aktualisierten Perso mit FIDO2 Support statt FIDO U2F). Ohne wirds allerdings schwierig. Smartphones haben generell ein sehr hohes Schutzniveau. Meine Vermutung bei der Dependency auf Google APIs statt den verfügbaren Plattform APIs ist: a) so macht $BUSINESS das auch und spart Arbeit b) big4 Berater die natürlich "Experten" in dem Thema sind haben Stichwörter gegoogelt und das Ergebnis als den einen sinnvollen Weg präsentiert.
2
1
0
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago
Replying to
@nakal@mastodon.social @HonkHase@chaos.social verstehe ich, allerdings bezog sich mein Kommentar tatsächlich nicht auf die Google Teile, sondern den Vergleich mit Desktop Plattformen gegen die grundlegende Securityarchitektur von AOSP und den Hardware Anforderungen. Ich bin selber Graphene Nutzer. Eben dieses OS erfüllt die von mir erwähnten Anforderungen auf Pixel Geräten. Hier muss man zudem aufpassen: Security und Datenschutz gehen nicht immer Hand in Hand. Gerade ein Staat sollte auf die Unabhängigkeit von kommerziellen Dienstleistern setzen. Ich verstehe bis heute auch nicht so ganz warum die Plastikkarte, für die es ja nicht mal eine Mitführungspflicht gibt, so ein Problem ist für das man eine App benötigt.
2
0
0
0
Open post
JRT @jrt@infosec.exchange
· 7mo ago
Replying to
@buttplugio if it hits HR too hard, mabe it isn't the right fit :D
2
0
1
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago
Replying to
@brahms@chaos.social ja. Support war verwirrt und hat mich dann weiter versucht zu gaslighten
1
0
0
0
Open post
JRT @jrt@infosec.exchange
· 5mo ago

Die Blockade der Straße von Hormus ist also das neue Trumpsche Wallstreet Pump & Dump Scheme nachdem niemand seine Zolldrohungen mehr ernst nimmt.

1
0
0
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago

The migration from sddm to plasma login manager was super smooth. <3 @kde@floss.social

1
0
0
0
Open post
JRT @jrt@infosec.exchange
· 6mo ago
Replying to
@kde looks like a feature for @pallenberg :D
1
0
0
0
Open post
JRT @jrt@infosec.exchange
· 10mo ago
Replying to
@neobrain@mastodon.social when I hold presentations slides usually are work in progress until the talk starts :D
2
0
0
0
Open post
JRT @jrt@infosec.exchange
· 9mo ago
Replying to
@lasse@social.bau-ha.us ruf mich gern auf dem dect an.
1
1
0
0
Open post
JRT @jrt@infosec.exchange
· 18mo ago
Replying to
@ljrk@todon.eu @q@glauca.space @spline@chaos.social meine Vermutung ist, dass sie die app installbase pushen wollen. Nach dem Studium ist die app ja schon drauf und man hat sich dran gewöhnt, also kaufen die ex-studis ihre tickets dann auch darüber
2
1
0
0
Open post
JRT @jrt@infosec.exchange
· 18mo ago
Replying to
@q@glauca.space @ljrk@todon.eu @spline@chaos.social dann ergibt deren Verhalten ja noch weniger Sinn. wtf
1
1
0
0
Open post
JRT @jrt@infosec.exchange
· 7mo ago
Replying to
@xgebi @astro_jcm on-call @brahms
0
0
1
0
Open post
JRT @jrt@infosec.exchange
· 2mo ago
Hat jemand eine Empfehlung für einen #valetudo fähigen Saugroboter der mit 4 cm hohen Schwellen klar kommt? #askfedi
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:44:02 UTC