Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Merospit

@merospit@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#Blueteam in #infosec / #cybersecurity at a place.

Outside of tech, interested in #camping, #gardening and family.

250 Followers
667 Following
24 Posts
Joined November 06, 2022
Open post
Merospit @merospit@infosec.exchange
· 4mo ago
Replying to
@colinmford@typo.social This explains their recent oddness. To escape the electricity costs they are going to make consumers generate the results locally with their 3GB inbuilt Chrome model... And to quantify fraud with this new distributed scheme they want recaptcha to know about every mobile device on earth...
16
1
6
0
Open post
Merospit @merospit@infosec.exchange
· 2mo ago
Australian Government 2026 Census website is failing, and it isn't even the real Census night yet. Imagine what is going to happen on Tuesday! This is reminicent of the 2016 census, which was the first attempt to allow online submissions, which failed because everyone logged in after tea to do it at the same time and flooded the system (causing the government to claim they were hacked, rather than just not provisioning their systems correctly to handle the correct load). I thought that surely there wouldn't be a flood on Saturday night, so do it now, but it appears that wasn't a good assumption. #auspol #censusfail #census2026
3
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 2mo ago
Replying to
@ramin_hal9001@fe.disroot.org I too am being forced to use it, with the same observations. Even getting it to create or modify scripts to do the actual work is troublesome. It will get something in its head and once it decides on it, it will just attempt the same thing three or more times in a row despite you telling it no repeatedly. I don't feel guilty at all swearing at it, so because of that, I prefer to think of it as a glassy eyed intern rather than a babysitting job, but the effects are the same.
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 4mo ago
Replying to
@cR0w@infosec.exchange and non-adblocked browsers
3
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 2mo ago
Replying to
@ludicity@mastodon.sprawl.club The turning point in my belief was watching someone with a spectacular amount of money on the line fire their highest performers because they were achieving that performance without LLMs. I can personally testify to this. Actual performance measurements have been ignored if LLM usage is not indicated.
1
2
1
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@wdormann@infosec.exchange At least they say they went to linux-distros and received advice first. Small mercies that we aren't the first to alert distros to it.
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@wdormann And a CVSS 7.8 won't standout when only 8.0+ typically get patched by OS. LPE are very underrated by CVSS.
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@SwiftOnSecurity It is great to get to the stage in defensive security where you can piss the bad ones off but you don't even need to know they exist. Almost makes all the other times worth the effort.
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@gayint@infosec.exchange GCHQ infiltrates another organisation! /s
2
2
0
0
Open post
Merospit @merospit@infosec.exchange
· 3mo ago
Replying to
@bob_zim@infosec.exchange @FuturisticRobert@infosec.exchange @jerry@infosec.exchange 2FA isn't designed to stop credential leaks. If that happens everyone should be doing password resets and onboarding 2FA again. It is solely designed to prevent someone else's data breach from affecting other websites. Even if a site uses passkeys, you can have an account takeover through someone adding another passkey to your account. And if the site is hacked, they wouldn't try to impersonate a user through the front door. They own the whole house.
1
5
0
0
Open post
Merospit @merospit@infosec.exchange
· 6mo ago
Replying to
@Viss@mastodon.social @cR0w@infosec.exchange Wow! Just wow! I thought OpenSnitch was a long term thing for me now that I switched.
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 6mo ago
Replying to
@petealexharris @ErikvanStraten @grammasaurus @SteveRudolfi They have been working for years to destroy URLs as a basis of trust. Even when you think a domain is real on a Google search result it can be someone else's site that they told Googlebot went through to your real site after a redirect. In that context HTTPS could be used but just send you to their new AMP site (or whatever they are calling this feature once it actually comes out).
2
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 4mo ago
Replying to
@eff@mastodon.social Both companies control the client applications, the operating systems, and are required by multiple jurisdictions to run client side scanning. Never be fooled by transport encryption, even if it is end-to-end.
1
2
1
0
Open post
Merospit @merospit@infosec.exchange
· 4mo ago
Replying to
@silvermoon82@wandering.shop @DaveMWilburn@infosec.exchange @Sempf@infosec.exchange Needing a report to be deterministic doesn't stop the true AI believers. Personal experience hand writing a real report after lawyers complain about team members slop taught me that.
1
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@dangoodin@infosec.exchange It needs to be good faith on both sides. Having a human hide behind a robot facade and then release the recent ImageMagick vulnerability after their LLM failed in 7 days of feedback with maintainers pushed the good faith argument on both sides.
1
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 6mo ago
Replying to
@nixCraft@mastodon.social Mine let you know which "agent" every document has to be run through to "correct errors" before it gets to that level. If you don't, they reject it based on believing the non-human more than the human.
1
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@reverseics Vance should know, just look what happened to the previous pope after their visit.
0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 1mo ago
If you have ever had an unlocked phone accessed during a stop, consider your accounts compromised, even if the device doesn't have malware on it and wasn't accessed using USB. https://www.heise.de/en/news/Surveillance-without-trojans-How-authorities-read-WhatsApp-and-Signal-11439021.html #security
Surveillance without trojans: How authorities read WhatsApp and Signal
heise online

Surveillance without trojans: How authorities read WhatsApp and Signal

Leaked files show customs and BKA hijack messenger accounts via official web tools. The legally risky method resembles foreign cyberattacks.

0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 1w ago
Zero days in a zero trust application highlight the flaw in what we were promised. https://sh3llc0d3.com/blog/inside-the-netscaler-zero-day-siege-chained-pre-auth-rces-weaponized-in-the-wild-watchtowr-disclosure/ #security #netscaler #zerotrust
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
Shellcode (Sh3llc0d3)

Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)

A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...

0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 2mo ago
Replying to
@sourceware@fosstodon.org Ratelimiting requests without cookies, and separately ratelimiting requests which had previously accepted cookies using the cookie as the rate limit key, when put together may help.
0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 3mo ago
Replying to
@mgd81@infosec.exchange Getting past commercial fingerprinters is just the first step. As long as it either accepts cookies, or doesn't accept cookies, each IP address, can be detected and blocked after N queries, where N depends on the risk you want to accept for also blocking legitimate users.
0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 5mo ago
Replying to
@nyanbinary@infosec.exchange @gayint@infosec.exchange Awesome. I don't even remember what the imposter organization letters stand for now.
0
0
0
0
Open post
Merospit @merospit@infosec.exchange
· 8mo ago
Replying to
@crazyeddie@mastodon.social @nixCraft@mastodon.social I haven't been in a job yet where the contents of my yearly performance review wasn't heavily tweaked (ie, censored) by my manager to focus on things that aren't day-to-day or technical debt reducing. This isn't unique to my current job at all. Managers love the term "technical debt" as it flies by on their agile boards, but god forbid you would actually focus on it.
0
1
0
0
Open post
Merospit @merospit@infosec.exchange
· 8mo ago
Replying to
@troberts@theblower.au Canberra forecast is positively cool compared to that (except for a 43 in the middle)
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 12:16:37 UTC