Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Lars Fischer

@lafischer@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Teaching IT-Security and Math (since 2020 or forever, whatever came first)

Practicing Habitual Automation

(languages Deutsch and English, depending on topic)

0 Followers
0 Following
19 Posts
Joined April 20, 2023
website:
https://informatik.hs-bremerhaven.de/lafischer
coffee:
tea
PGP:
A2FE 7D7E A05C 92C3 F9EC F875 B296 0E33 A4AC D842
Licence:
Starting 2020-10-05 this work is licensed under CC BY-NC-SA 4.0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Short:
I had to rotate my OpenPGP-keys. The current key is now

63F831BAAAFEA6B63D9514E441D8FF5258F8FB4A

Get it from the usual keyservers.

Long:

I am switching from GnuPG to sequoia-pgp and at the same time I had two expired subkeys. A ``sq key rotate`` did not produce the results I intended (new subkeys) and adding two new subkey did not seem to be importable to thhunderbird. The easy way out was to generate a completely new key — also as a test to see if this one could be imported into thunderbird (it could and I simply made it my main key).

``sq`` has a very easily usable CLI and absolutely helpful ``--help``. Plus, it does not have https://gpg.fail sitting on its back. The switch is not going without a hitch because I now have to move my private MUA to something that is working with sequoia and notmuch.

I absolutely love that ``sq`` is giving you hints on further switches that could improve the output. It seems that you are never been left helplessly stranded.

So, kudos and thanks
@sequoiapgp@mastodon.social
I think I'll give it a try for a while.

Plus, did you know that the IMPACT CA that "my" students built a year ago is using the sequoia library?

gpg.fail

gpg.fail

4
2
1
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 4mo ago
Replying to
@osmultitudes@higher-edu.social Ich fände es sehr angenehm, wenn sich die Analyse lesen lassen würde ohne, dass es notwendig ist seine Kontaktdaten preiszugeben. Wenn das so gut ist, würde ich mich hinterher vielleicht freiwillig entscheiden den Newsletter zu abonnieren. Darüber hinaus existieren ja auch noch so Dinge wie RSS, Atom und das ActivityPub.
2
1
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 3mo ago
Replying to
@reclus@chaos.social und danke für die Arbeit an Wikidata.
1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 3mo ago
Replying to
@reclus@chaos.social die DNB-Seite ist fehlerhaft und nicht von mir gefüllt. Insofern bitte nicht nutzen.
1
1
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 3mo ago
Replying to
@reclus@chaos.social die Frage ist doch eher, ob diese Person mit diesem Account hier verknüpft werden möchte. Vielleicht sollten wir die Person fragen...
1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

It seems every military organisation has to do #stravaleaks at least once … These days it has been the french.

Maybe we should provide strava with the Nobel Peaceprice. They seem to make military operations much more risky. Maybe this leads to (significantly) less war.

https://www.lemonde.fr/international/article/2026/03/19/stravaleaks-le-porte-avions-charles-de-gaulle-localise-en-temps-reel-par-le-monde-grace-a-l-application-de-sport_6672445_3210.html

infosec.exchange
3
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 8mo ago

I am slow in adopting all the shiny new technologies. (I actually went "backwards" to vim somewhat 10 years ago, after having been forced to work in one of those big IDE-things, eclipse I think it has been. Even emacs seemed bloated afterwords, though I had long years of happy relation with the latter. No hard feelings there.)

Turns out that it's good I could not remember the name "openclawai" that has been recommended to me by a fascinated coding-person.

Today (well, yesterday. Remember "slow") moltbook featured in "this week in security". Some million of API-keys disclosed to the general interested public — as well as the nefarious ones too. So there is an example of an Ouroboros (that a phrase usable here? Make it one.): Vibe-coders (or -shellers) bitten by vibe-code platform for vibe-coding. Well accidents tend to happen, bad code happens too, let us just see the funny side of this and do not think about what could have happened if this kind of very much not-mature technology would already be adopted widely.

Instant Update: I just got word from the office next door about the fascinating efficiency of vibe-coding and how everybody is and should be doing it. O_o (Told you; "slow" 😉)

(source: https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys via: https://this.weekinsecurity.com/this-week-in-security-february-8-2026-edition/)

wiz.io
4
0
1
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 4mo ago

Wenn du mein Betriebssystem unter Kontrolle hast, wieso musst du mir das in einem PDF mitteilen? Ich fände es beeindruckender, wenn da einfach die klassische Erpressernachricht auf dem Bildschirm auftaucht. Ausserdem ist das PDF das du mir geschickt hast kaputt. ;-)

1
2
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Not only students grow at this university. Its "applied", keep that in mind.

Put them in last week.

2
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 4mo ago

Temperatur im Büro heute 31°C.

1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Let me borrow from Bruce Schneier @Schneier_rss@burn.capital: ‘We don’t issue letters of marque on the high seas anymore; we shouldn’t do it in cyberspace.’ [1]

He has gotten struck by a sentence in the 2026 US Cyber Strategy (linked in [1]) which seems to imply that the White House (signed by DJT) is actually planning to somehow incentivize private companies to attack adversaries in the "cyberspace". (Sorry, I still cannot write the word "cyber" without flinching, I have Wieners "Cybernetics" in my bookshelf.) Which would (excuse the former digression, hope you are still following), as Schneier puts it, be "an incredibly dumb idea".

Incredibly dangerous as well, like handing everyone a gun, a blindfold and incentivizing they shot whenever they feel threatened or attacked from any direction. Cascades of hacks and hack-backs. Maybe the best thing would be if companies would outsource the "disruption of adversary networks" to the same hacker-for-hire, because they then might realize that they have contracts with both sides and hopefully just stop disrupting any of the two networks.

Plus, I assume, it would be illegal in most jurisdictions — including the current USA.

[1] https://www.schneier.com/blog/archives/2026/04/is-hackback-official-us-cybersecurity-strategy.html

schneier.com
1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Ongoing

1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 7mo ago

Category Theory is cool and if only because you can abbreviate it as "Cat Theory".

Started re-reading "Category Theory for the Sciences" by David Spivak with a friend. Read the foreword for the first time and immediately got this nice quote from it:

“when we formalize our ideas, our understanding is clarified. [...]
And if we are ever to get to the point
that we can input our ideas into computers,
we will need to formalize these ideas first.”

Very much what I experienced dabbling in Haskell-Code and the reason why that felt very much elevating.

If you know him on mastodon, please drop me a pointer. (Best in the way of "Hi, I'm David, glad you like my books", because I own two of them and cherish them both. (Just found a missing closing-bracket in section reference. I'd like to improve the second edition, but that is such an unimportant mistake. I both hope and not hope to find some mistake important enough to write an email.)) )

[Here I added an extra bracket for you to take, should you become aware of this text.]

1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 7mo ago

Wrote a very short tutorial on taskwarrior.
https://informatik.hs-bremerhaven.de/lafischer/tutorials/2026-02-11-taskwarrior.html

informatik.hs-bremerhaven.de
1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 7mo ago

Quickly, I have to absolutely urgently to help the chair of the board of GÉANT, who inexplicably unexplained cannot access his geant-email and thus has to borrow a presidents(! no less) gmail-account, with something utterly urgent! !k! Europe, no, the world is at the brink of cyber-apocalypsis.

#scamoftheweek

Is this some insufficient elaborate scam for busy professors? You are out of luck, I have grading work to attend to. There is no other task on my schedule for today — because I will use any and every excuse to #procrastinate from grading exams.

Or is it just, that something found me which could be called "shotgun-whaling"? Because I'd like to start the day with creating some new and (arguably) funny terminology. It would make my day so much better to see such a thing make a small ripple through the fediverse. I am soooo much not phishing for boosts here! ;-)

Oh, look, the tea is empty, have to go and brew some new tea.

(The 'k' between the exclamation marks above becomes slightly more funny if you are typing with the neo2 layout.)

infosec.exchange
1
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 19mo ago
Replying to
@ulrichkelber Fakten sind die alternativlose Alternative zu alternativen Fakten - oder auch gefühlten Wahrheiten.
0
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Nice, short read on vulnerabilities in two password managers. (Others seemingly have not been addressed.) Weaknesses like "missing authentication" might raise some hairs.

https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

Short commercial for the standard Unix password-manager https://www.passwordstore.org/ here. Main advantage in this context is that the actual software is simply combining trusted and tested tools and concepts: pgp, files, git, ssh, pinentry, various tools to further use pass in different applicatios , and not trying to "re-invent". That also has the advantage of the passwordsbeing accessible if the password-store software becomes unusable.

Furthermore it is easier to estimate the achieved level of security, e.g. https://gpg.fail/ (Prectical hint, sequoia-chameleon promises to provide a stand-in replacement for gnupg.)

arstechnica.com
0
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 6mo ago

Hamburg GI-Sicherheit. Leider einen Tag später. Workshops waren gestern.

0
0
0
0
Open post
Lars Fischer @lafischer@infosec.exchange
· 2w ago
Just barely finished the first of (hopefully) 12 Jupyter Notebooks for self-study and experimentation in next semesters "Mathematics 3" Course. Although this will only be a single-shot lecture, I am having way to much fun building this (and, yes, nothing teaches better than teaching yourself). Well, I should be doing other stuff, but a day full of oral exams earned me this evening. This notebook, and probably most of those to come, is based on "Probability" by Jim Pitman. If you have a masto-link of him, please reply with it. I am simply to tired now. (Also, I have to hit my Norsk-lecture to not miss my streak before midnight.)
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:59:05 UTC