https://blog.cloudflare.com/containers-cross-tenant-vulnerability/ Cloudflare did the ol' "configure your cloud platform not to zero unintialized disk blocks" vulnerability. 
Remote
He/him. Previously twitter.com/mnordhoff.
0 Followers
0 Following
46 Posts
Joined November 05, 2022
Country:
US
Domain name (don't click):
RFC 8509 (DNS chaos):
Open post
Replying to
@davidgerard@circumstances.run Putting aside the multi-trillion dollar bills, someone on Reddit even reports getting a $29 alert for an account that no longer even exists...
https://www.reddit.com/r/aws/comments/1uywogn/aws_budget_alert_email_account_is_permanently/
6
0
0
0
Open post
Replying to
@mcc@mastodon.social Some people have already said "tar + something with a large compression window", but in particular tar + lrzip may be best if you go that way. It should be packaged on most distros.
It's intended to have a compression window up to the size of your RAM (or 2 GB on a 32-bit OS), or optionally even larger than RAM, though that's slower.
The "LR" stands for Long Range, even!
It's also multithreaded, which not everything is.
It can also be combined with other compression algorithms if you are a hardcore compression algorithm enthusiast.
(The only thing that bothers me about lrzip is that it doesn't preserve the file's modification time.)
https://wiki.archlinux.org/title/Lrzip
https://en.wikipedia.org/wiki/Rzip
3
0
2
0
Open post
Replying to
@gabe@mendeddrum.org @mcc@mastodon.social @airakose@mastodon.gamedev.place Older parts of the castle were built before the "of this world" optimization was widely-known in this country...
Maybe.
5
1
1
0
Open post
Replying to
@agwa Some goofus named Matt noticed one of the revoked certs before — I think I was searching for 1.1.1.1 on crt.sh to look at Cloudflare's certs — but didn't make a stink and then forgot about it. Wellp. Insert emoji of your choice here.
Speculating wildly, I wonder if Cloudflare has monitoring but only configured it to alert on Chrome or Mozilla-trusted roots.
4
0
2
0
Open post
Replying to
@agwa@follow.agwa.name E.g. https://crt.sh/?id=12116084225 from 2024 (expired).
When https://crt[.]sh/?q=1.1.1.1 loads (link broken to reduce fedi-DDoS), there are 12 results matching "C=HR, O=Financijska agencija" from 2024-2025 (not excluding possible precert duplicates).
Edit: And what kind of serial number is "VATHR-32343828408.286"?
Edit: The cert I linked above was revoked, I was mistaken.
2
3
1
0
Open post
Replying to
@agwa@follow.agwa.name D'oh. Thank you. Makes sense. My brain glossed right over the cert "Serial Number" at the top and went down to the Subject "serialNumber".
Guess I don't spend enough time around OV/EV certs.
1
0
0
0
Open post
Replying to
@corbet@social.kernel.org Developing that interstitial page and writing that blog post has to be more work than keeping the service running forever! Fricking Google.
(Unless another team deprecated the infrastructure it runs on.)
3
0
1
0
Open post
Replying to
Is it just me or is https://s3.dualstack.me-south-1.amazonaws.com/ inaccessible? Doesn't even respond to ping.
(Trying to visit the "homepage" Is supposed to redirect to https://aws.amazon.com/s3/.)
I dunno if it was already down or that just happened. And of course it could just be a connectivity issue.
(https://s3.dualstack.me-central-1.amazonaws.com/ works for me.)
As of 30 April, the status page described me-south-1 in worse terms than me-central-1.
0
0
0
0
Open post
Politics
I think rendering someone stateless is maybe the most evil thing a government can do?
I mean, also murder, but deciding who lives and who dies, and killing people, is one of the jobs of the government. Making people stateless is rejecting the fundamental nature of the state.
If one of your citizens is an asshole, and they don't even have citizenship somewhere else, sucks to be you! You have a whole law enforcement system, maybe you forgot. Use it.
Any politician who even thinks about making someone stateless needs to spend the rest of their life in a cell.
0
0
0
0
Open post
Assa Abloy, which owns HID Global, which owns ZeroSSL, applied for .hid.
https://newgtldprogram-aps.icann.org/applications/ASSAB2671T-T93344
At long last, Howard Hughes gets his own TLD.
0
0
0
0
Open post
Replying to
@flyingpenguin@infosec.exchange Hello. FWIW, this isn't central, but I think the archive.ubuntu.com and security.ubuntu.com certificate issuances on 27 February were routine, scheduled renewals.
https://crt.sh/?Identity=archive.ubuntu.com&match==&deduplicate=Y
https://crt.sh/?Identity=security.ubuntu.com&deduplicate=Y
They had certificates expiring 2026-03-13 and have a pattern of renewing 2 weeks beforehand.
https://crt.sh/?id=23088242647
https://crt.sh/?id=23099459793
(If crt.sh is loading today...)
0
0
0
0
Open post
Normal free software people with morals really missed out. It turns out if you had made "libc but extremely racist and with NFTs" in 2020 and started DMing tech CEOs on Twitter you would've got like $50 million in funding overnight.
https://www.phoronix.com/news/Omarchy-Alibaba-3M
0
0
0
0
Open post
sent 666.51M bytes received 1.48M bytes 1.31M bytes/sec
The rsync of the beast could have more bandwidth.
0
0
0
0
Open post
Issues with the Los Angeles stratum 1 NTP server gpstime.la-archdiocese.net since yesterday. 🙏 (It's stratum 3 and was down for a while.)
Absolutely no criticism, of course, but I hope things work out.
0
0
0
0
Open post
RE: https://social.nlnetlabs.nl/@nlnetlabs/116963672862487532
1 of the vulnerabilities was reported by 4 different people/groups, 1 by 3 parties, and... I lost count but several were reported by 2. Wow.
0
0
0
0
Open post
"I'm DeeMV your personal AI and I'm glad you are here."
Punny LLM (anti-)"assistant" names have gone too far. And this website isn't even for the DMV, which isn't even called "the DMV" in this state anyway!
0
0
0
0
Open post
Replying to
Comparing an unparseable OCSP response for one certificate (dated 2026-09-15 14:36) and a parseable one for another (dated 2026-09-17 19:31), Sectigo have removed that NULL parameter that the forum/Bugzilla posters believed to be at issue.
I have no personal opinion about who or what is at "fault" or whether it was compliant, though.
0
0
0
0
Open post
Replying to
Wikipedia was quick to update.
https://en.wikipedia.org/wiki/Society_of_Saint_Pius_X
0
0
0
0
Open post
Hrm, after the price gougers increase the price of .com domains 2026-11-01, .com domains will be more profitable to Verisign than .net domains, though .net will still be more expensive for registrants because its ICANN fee is bigger.
.com $10.97 (Verisign) + $0.20 (ICANN) = $11.07
.net $10.91 (Verisign) + $0.75 (ICANN) = $11.66
https://www.icann.org/en/registry-agreements/details/com
https://www.icann.org/en/registry-agreements/details/net
0
0
0
0
Open post
Replying to
Update: At least one OCSP response started to work today.
0
1
0
0
Open post
RE: https://infosec.exchange/@mnordhoff/112814601208026927
This was my favorite toot. It's too bad half of it is gone, but it does seem to have been archived.
https://web.archive.org/web/20240719135222/https://piaille.fr/@LaurentChemla/112812800979426563
Open quoted post
Quoting
Seeing https://federate.social/@jik/112812825679959416 and https://piaille.fr/@LaurentChemla/112812800979426563 may or may not be revealing about the American and French mindsets.
Open quoted post 0
0
0
0
Open post
Why does Amazon own the domain name com.be
0
0
0
0
Open post
Oh hey, Discord automatically categorized me as an adult.
I didn't know whether they'd go "this person runs Linux and doesn't understand half the features, they must be a Boomer" or "insufficient data, assume baby".
0
1
0
0
Open post
https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html?unlocked_article_code=1.xFA.Kjgt.3iZRJd-SnQk4
OK you know what maybe the data center segment of 007: First Light was more realistic than I thought.
0
0
0
0
Open post
Replying to
Jeez, DNS has gotten faster since last I looked.
https://www.knot-dns.cz/benchmark-400G/
Knot DNS with XDP can do 70 million qps even with DNSSEC (positive responses I guess).
0
0
0
0
Open post
Logged in to a website using... only my email address. Zero factor authentication.
They must've used cookies to automatically log me in except not, or some sort of hack to trick password managers into filling in a hidden form field.
Weird.
0
0
0
0
Open post
Seeing https://federate.social/@jik/112812825679959416 and https://piaille.fr/@LaurentChemla/112812800979426563 may or may not be revealing about the American and French mindsets.
0
0
1
1
Open post
Replying to
I think the GitHub dark tritanopia theme made the icon for open PRs fire engine red, like you should be afraid of them. They're admitting it!
0
0
0
0
Open post
Imagine telling the Pope 100 years ago that one day they would run websites and they would have cookie banners and they would only have an OK button.
0
0
0
0
Open post
Several years ago, AWS sent out a billing projection that had clearly used the wrong time unit: it was multiplied by 30 or 720 (24 × 30) or something like that.
Luckily it was not a big number, and it was not the real estimated bill, so I didn’t drop dead from shock.
IIRC, they sent out an apology a few days later.
0
0
0
0
Open post
LLMs
Recently saw two tech company blog posts—the two companies do business, so it might not be a coincidence—say "people don't install software anymore, their AI agents install software for them".
I don't even know what to say.
(I'm not a customer!)
0
0
0
0
Open post
https://domainnamewire.com/2026/07/23/com-verisign-record/
Revenue is up at the wallet inspector!
Some of their plans for .web are discussed.
0
0
0
0
Open post
OMG I was trying to use a couple stretched-out old hair ties and one of them DISINTEGRATED. The elastic turned into tacky goop IN MY HAIR.
I did not know that could happen! Do not let "old rubber bands" happen to you!
(I had ALMOST got a new hair tie out but didn't want to bother...)
0
0
0
0
Open post
Hikaru Utada started a 24/7 music video radio stream about a week ago (in Pride Month!)
https://www.youtube.com/watch?v=IJqlho9qJIw
0
0
0
0
