Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Marsh Ray

@marshray@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Mostly computer and technical stuff. Radical listener. Tries to be a good person.
#Rust #UA

0 Followers
0 Following
50 Posts
Joined December 20, 2022
Github:
https://github.com/marshray
Bluesky:
@marshray.bsky.social
Discord:
marshray
Email:
marshray & live ! c0m
Twitch:
https://www.twitch.tv/marsh_ray
Type:
Static, strict
Open post
Marsh Ray @marshray@infosec.exchange
· 2w ago
Replying to
@Cheeseness@mastodon.social The whole series is great, but that one is really something special.
1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@mcc@mastodon.social Affordances surface complexity and “flat” design is little more than attempt to conceal the symptoms.
15
3
3
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@petealexharris@mastodon.scot @johncarlosbaez@mathstodon.xyz I do find it really interesting that this idea of a uniquely capable yet maliciously compliant non-human entity is one of our ancient and universal cross cultural archetypes.
14
0
3
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3w ago
Replying to
@darkuncle@infosec.exchange Back when I did a bunch of Windows stuff I used to figure stuff out by exporting the relevant section to a .reg file, making the change using the UI, exporting it again, then using a text-based diff tool.
1
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Impressive iOS exploit chain (patched in current update) pois0nSword: From Renderer R/W to Native Calls on iOS 26.1 https://varik.dev/blog/jsc/pois0nsword-native-calls
varik.dev
3
0
1
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@petealexharris@mastodon.scot @johncarlosbaez@mathstodon.xyz It does seem to fit right there at the dawn of “using language to coordinate with people other than those you share food with every day”.
3
1
1
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@syferdet@toad.social @ratvet@retro.pizza Is that what this is? I thought maybe they were time travelers from ancient Egypt or something.
2
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@thingsofshane@beige.party Timeless
2
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 1mo ago
Replying to
@jackemled@furry.engineer Any OS that can’t extract from the background activity of a 2011-era laptop enough entropy to initialize its RNG within a few seconds is broken. Possibly the system is making an overly-conservative assessment based on portability to some worst-case embedded hardware scenario.
1
2
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@mjd@mathstodon.xyz I was stuck trying to install Linux on my new laptop. ChatGPT helped me confirm an idea I had for a combination Greek/Latin military pun and now that I have a suitable hostname I can continue the installation.
2
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@DeltaWye@tiggi.es Headset/earbuds with mic 3.5 mm TRRS https://en.wikipedia.org/wiki/Phone_connector_(audio)#TRRS_standards
en.wikipedia.org
2
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@lkundrak@metalhead.club @brouhaha@mastodon.social @larsbrinkhoff@mastodon.sdf.org @mhoye@cosocial.ca Also CRT tubes can hold a surprising charge for several days or even weeks after being turned off. During operation there are typically hundreds of volts on the pins on the neck of the tube. You can get a significant tube discharge off of these pins too.
2
1
1
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@roytanck@mastodon.online If you're friendly with a local mechanic, machinist, or welder they can probably extract that broken half-screw easily for you
1
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Keep posting those simplistic, cynical hot takes! It’s working. The world will return to the way it was any time now
1
1
1
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@simontatham@hachyderm.io Using messages to hold state is typical freedesktop org design
1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
The “So you hate waffles!” index set a record high today. Be careful out there.
1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@sen@hachyderm.io Stupid people really don’t like being reminded of that.
1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@Moss@beige.party @catmisgivings@stranger.social @futurebird@sauropods.win I regularly think of that 2 seconds of the opening montage as well
1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@Moss@beige.party @futurebird@sauropods.win Huh. I thought the helicopter sound was made by John Fogerty’s guitar.
1
3
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Things those who build consumer-facing products and services rarely talk about: https://www.uncommonapps.nyc/p/castro-podcasts-things-i-got-wrong-support
Castro Podcasts — Things I got wrong: Support
uncommonapps.nyc

Castro Podcasts — Things I got wrong: Support

Building meaningful relationships with customers through support didn't turn out as I'd hoped

1
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@ldelossa@fosstodon.org They explicitly, intentionally host blogs promoting certain 1930’s German political ideologies. I mean like, literal translations of political speeches with the flags, graphics, etc. Not subtle or ambiguous in any way. That’s the domain you’re publishing on.
1
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@lcamtuf@infosec.exchange BS170 How long do you think it can dissipate 15W ? :blob_grinning_sweat:
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
After reading Scifi for a few years, I have concluded that there is no space battle like that in *The Dark Forest* Cixin Liu
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 1w ago
Replying to
@talya@dybbuk.club Right? Like, what if all those people using LLMs daily in their technical work aren’t just delusional and “AI” capabilities actually are advancing. That would be even more messed up.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 1mo ago
Replying to
@sandorspruit@mastodon.nl @dirtside@phpc.social @saramg@fosstodon.org @twipped@twipped.social @loathsome_dongeater@toots.matapacos.dog A “CPU spike” is exactly what you want to happen when you ask your computer to do something. If the CPU doesn’t spike that probably means it’s getting blocked on something else. The question is more whether the total amount of work required is appropriate, and whether it completes quickly enough to feel responsive.
0
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@thecybersecguru@infosec.exchange No, I will not repost your low-effort hashtag spam.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@kornel@mastodon.social I just leave it as another Ctrl. The more the better?
0
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2w ago
Replying to
@atoponce@fosstodon.org I wonder how long he ran it before concluding it “was completely and undeniably unable to generate the number zero in its unit”. The rdrand instruction produces a 64 bit result.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@jsbarretto@social.coop IDK but I’d be interested to learn how this turns out. Have you tried running it from a minimal process environment?
0
3
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to

@jsbarretto@social.coop Process environment can change almost any cargo setting. IDEs and other dev tools commonly modify it.

On unix the env or export -p commands can be used to display the environment. On windows its set.

0
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
Ftom: https://simonwillison.net/2026/Jul/22/openai-cyberattack/
Simon Willison’s Weblog

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model’s guardrail features turned off. Rather than solve the test, the …

0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@azonenberg@ioc.exchange @uberduck@hachyderm.io Long ago I worked in the office next to a guy trying to debug a random glitch that only occurred when several of our PCI cards were loaded into an expansion chassis. It took six months and they had to rent some super fancy logic analyzer. This was probably pre PCIe, maybe PCIx.
0
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to

@sanityinc@hachyderm.io @deech@mastodon.social unsafe

0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
A friend pleaded with me to try some vibe coding tool. Said I would fall behind, etc. “It’s sandboxed,” they said. “It can’t access any files except those you approve on a case-by-case basis.” Against my better judgement, I installed it. It required (lol) node and npm. Sigh. In for a penny and all that. I start the tool and get a nice prompt. I ask it where it’s running. It tells me it’s running locally. I ask it to run a basic check of my nvidia drivers and toolchain. Does a respectable job. Then I ask it more about its runtime configuration. Now it admits that it’s running in some unknown data center. “Who’s paying for this, and why?” I wonder. I request a directory listing. An out-of-band-looking UI control appears politely asking permission to read the contents of the project directory. Wonderful! Warm fuzzies wash over to see a purposeful and ergonomic sandbox in action. Friends, this “sandbox” is a lie. A scam. A total fraud. The AI has unrestricted bash shell access.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@kornel@mastodon.social On Linux I’ve got Caps Lock, Ctrl, Shift, Alt, and Super mappable. That’s just on the left side.
0
2
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
I don’t know how Anthropic is messaging about this, but I’m hearing from users that they are switching to Chinese models for data security tasks out of concern they will be flagged or even banned for asking.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
A friend is imploring me to vibe code but I can't stop asking it to escape its sandbox.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@ldelossa@fosstodon.org Substack sucks
0
3
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
If you repeatedly post pictures of rxpists or have an animated icon, I’m probably muting you. Nothing personal. It’s just this app doesn’t allow me to manage these things. The platform doesn’t allow posting a link without the server automatically grabbing some photo (eg promotional photos of the rxpists in question) from the linked website and displaying it full sized on the user’s device. The developers have long known about this and said that they would do something about it, but things seem to be moving the other direction. They have since *removed* the ability to copy links rather than opening them directly, which I relied upon to exercise a tiny bit of control over my web privacy.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@RueNahcMohr@infosec.exchange I enjoy your updates!
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to on assemblag.es

@CyberneticForests@assemblag.es To me a simpler framing is:

  • An optimization goal function created a perverse incentive.
  • The model under test exhibited unexpected (but not unprecedented) behavior by escaping the test sandbox
  • Hugging Face was a bystander, were harmed, and filed a police report.
  • These events may support some of OpenAI’s preferred narratives, but seem to go against others. On the whole OpenAI suffered mild reputational damage.
  • This was not a conspiracy, a marketing stunt, or planned in advance.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@mitsuhiko@hachyderm.io There are real trade offs of course but it’s been really difficult watching people whose views I mostly respected get stuck in ideological beliefs.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3mo ago
Replying to
@mjg59@nondeterministic.computer It’s wild that the agent protocol supports extensions but not the main secure comms channel.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@ivorytusk@kolektiva.social @hyc@mastodon.social @jensorensen@mastodon.social Really? How much of which ones?
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Watching *The Social Network* for the first time. It’s as if the creators were trying to make MZ look like an unlikable sociopathic loser with no friends and instead made him out to be a computer science genius for making a PHP MySQL website.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@kdkorte@fosstodon.org On Linux it’s the other way around. You have to install unwanted drivers in order to open simple windowed applications. E.g. look at the set of transitive dependents of avahi and bluetooth.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Replying to
@rwhitworth@infosec.exchange It’s figuring out where you cluster by testing your susceptibility to various rabbit holes.
0
0
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 3w ago
Replying to
@Walker@infosec.exchange For all the same reasons the “Internet Kill Switch” couldn’t be made to work https://www.schneier.com/blog/archives/2010/07/internet_kill_s.html
Schneier on Security

Internet Kill Switch - Schneier on Security

Last month, Sen. Joe Lieberman, I-Conn., introduced a bill (text here) that might—we’re not really sure—give the president the authority to shut down all or portions of the Internet in the event of an emergency. It’s not a new idea. Sens. Jay Rockefeller, D-W.Va., and Olympia Snowe, R-Maine, proposed the same thing last year, and some argue that the president can already do something like this. If this or a similar bill ever passes, the details will change considerably an

0
1
0
0
Open post
Marsh Ray @marshray@infosec.exchange
· 2mo ago
Project Excalibur: Nuclear Bomb Pumped X-Ray Laser @ Alexander-the-ok https://youtube.com/watch?v=sM0vMP5zoUw

Project Excalibur: Nuclear Bomb Pumped X-Ray Laser

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:47:51 UTC