Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Guy

@phlogiston@mastodon.nz
mastodon 4.7.2
  • Open on mastodon.nz

Geek, computer scientist, engineer, cryptography enthusiast, freediver (scuba sometimes, too), baseball nut, father, husband, odd ball, book reader, traveller, scout leader/kaiārahi, fermenter, free/open source/FLOSS geared, (self-) sovereignty promoting, anti Big Tech (TM), ...

Aotearoa/New Zealand 🇳🇿 with German 🇩🇪🇪🇺 origin.

0 Followers
0 Following
26 Posts
Joined November 15, 2022
Wiki:
https://wiki.kloss.nz/
pronouns:
he/him
born at:
325.37 ppm
Open post
Guy @phlogiston@mastodon.nz
· 1w ago
Replying to
@darkuncle@infosec.exchange An interesting thing is this: While TLS does not expose a weak mode of using RSA, the majority of X.509 certs on the web are RSA (approx. 2/3). See below for a link to the source for this. But certificates are also used for other things, e.g. code signing, token issuing, etc. And who knows whether any of those use cases will *always* be avoiding the classic RSA padding for signatures. So a move to the more efficient and compact ECDSA or (even (better)) to EdDSA would be appreciated. This move will also more likely level the path towards allowing for better cryptographic agility to adopt hybrid #PQC ciphers in the future. BTW, kudos to Let's Encrypt! There the entire chain is using ECDSA signed certs down to the web site using it. https://ecdsa.com/research #cryptography #RSA #ECC
ecdsa.com

The State of Signatures on the Web — August 2026

What 349 of the web's busiest domains actually serve on port 443: key algorithms, protocol versions, certificate lifetimes and post-quantum readiness. With raw data.

2
1
1
0
Open post
Guy @phlogiston@mastodon.nz
· 4mo ago

RE: @heiseonlineenglish@social.heise.de

Good Switzerland is doing something against US Big Tech dominance and the CLOUD act risk. In this case to protect health data.

Aotearoa, please do so as well!

social.heise.de
10
2
4
0
Open post
Guy @phlogiston@mastodon.nz
· 3mo ago
Replying to
@kde@floss.social I'd actually like a good retro Motif theme. Oxygen and Air are a bit too modern. #KDE #Plasma
6
0
3
0
Open post
Guy @phlogiston@mastodon.nz
· 7mo ago

More reasons to ditch US Big Tech:
This is highly worrying from a cyber point of view: President Trump's Cyber Strategy for America

https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf

> This is highly worrying from a cyber point of view: President Trump's Cyber Strategy for America
https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf
>
> This document reframes cyberspace as a US-dominated military domain. It calls for offensive operations as a standard policy instrument. It boasts openly about destroying foreign critical infrastructure. Not only that, it also pledges to impose American “norms” on the global internet.
>
> It calls for deregulation at the very moment when any serious security expert agrees that regulation is essential for setting a baseline security bar.
>
> “Adversary” is not defined in this pamphlet, and any foreign organization may now fall easily inside the definition at any time. (akin to disabling all Microsoft infrastructures for the International Criminal Court, ICC, in 2025, or declaring Anthropic to be a “supply chain risk”).
>
> If the U.S. treats foreign technology as an adversarial risk, how can any government or organization trust U.S. technology any longer?
>
> This is the foundational strategic question now: how long are we willing to build our IT infrastructures on systems that another power, governed by executive orders, has declared to be part of their military arsenal?

Source: https://www.linkedin.com/feed/update/urn:li:share:7435955619792216066/?originTrackingId=TWIwavEFeQdojh5LYKQLqg%3D%3D

#murica #trump #BigTech #sovereignty #cybersecurity #CloudExit

whitehouse.gov
18
1
20
1
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago
Replying to

@foone If you're in the EU, or particularly a German speaking country, you could order your own 'Lichtbildausweis' for EUR 15 (with self-chosen information to be put onto it).

https://shop.digitalcourage.de/themen/ak-vorrat/lichtbildausweis-mit-selbst-waehlbaren-daten.html

Credits to @digitalcourage for providing the service!

Having said that: This service should not be needed!

Gadget: Lichtbildausweis
Digitalcourage e.V. – Shop & Unterstützungsbedarf

Gadget: Lichtbildausweis

An immer mehr Stellen muss man sich ausweisen. Aber bei nur wenigen Anlässen ist ein amtlicher Lichtbildausweis notwendig. Was liegt näher, als sich einen (nichtamtlichen) ...

10
0
3
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

#GenAI #LLM common issues ...

mastodon.nz
10
0
4
0
Open post
Guy @phlogiston@mastodon.nz
· 2mo ago
RE: https://social.heise.de/@heiseonlineenglish/116917555903146572 Nearly a quarterof all domestic power is consumed by hyper scalers' data centres in Ireland. Let that melt on your tongue and see whether this is sustainable for the given #ClimateCollapse situation. #LLM #GenAI #ClimateCrisis #DataCentres #BigTech
social.heise.de
3
0
6
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

Saying LLMs are good and have a useful side doesn't make them more ethical.

It's like saying Hitler had his positive sides for building the autobahns.

#LLM #GenAI #AI

mastodon.nz
8
4
3
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

I'll be running a #freediving induction course (pool, not depth) in May in #Auckland. Dates are 4, 11 and 18 of May on Monday nights at Tepid Baths. Costs are $150 and that gives you a 3 months club membership (Auckland Freediving Club), including the induction course (3 weeks) with any subsequent training session at any of the Auckland training locations.

The induction includes some theory, freediving safety as well as static breath hold (just holding for a (longer) while) and dynamics (swimming (longer) distances under water). Usually after the Monday night training, we're hitting the pub for a bit of a social gathering (optional).

https://aucklandfreediving.co.nz/events/club-intro-membership-may-2026-tepid-baths/

Let me know if you're interested. There are currently 2 spots still available. As there was no induction in April, 8 are already taken up. So, don't delay ... ;-)

Also, feel free to share with others (if there's interest)

mastodon.nz

Mastodon NZ

6
2
9
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

RE: @heiseonlineenglish@social.heise.de

Other countries (like ours) should do that too: Tax Big Tech!

social.heise.de
5
1
1
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

Interesting to see all kinds of FUD on open source/copyleft licences emerging in (commercial/corporate) organisations over and over again.

I'm always feeling like that guy who spots someone on the Internet 'being wrong' when that happens. Just can't help myself.

#copyright #licence #license #OpenSource #coopyleft

mastodon.nz
4
2
2
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago
Replying to
@KolokokoBird @peteorrall @aimee I used to use #OSMand happily. These days I'm using more #OrganicMaps, which I prefer. Especially as it has less limitations on map downloads. If I need live updates on roads, I use #HEREweGo. It is a European product, so should be much better on data privacy. I have not seen congestion reporting in it, but it did handle last week's road closures with detours from the Coromandel peninsula.
4
3
0
0
Open post
Guy @phlogiston@mastodon.nz
· 4mo ago

Hmm, just ran a 'Spy Night' with the #scouts last night. It was a bit of a mixed bag. I'd put hours into preparing it, but it mostly fell apart when I tried to print out my work sheets last nights, and my home laser printer gave up. So I was 20 mins late, and I couldn't run through the plan with the other leaders to get the right knowledge for supporting the patrols on the different stations :-(

Running through it, I know now what needs to be changed to make it better, where I wasn't aware without a good 'dry run' that some things were a bit too complex.

Content wise, this was covered:

* Message transmission and encoding:
- Tap code
- Morse code
* symmetric ciphers:
- Pig Pen (Masonic) cipher
- Caesar cipher
- Rail Fence cipher
- Vignere cipher (didn't get to it, needs to be cut)
* steganography:
- Invisible ink (lemon juice)
- First letters of words in a paragraph
- A cut out mask over a (book) page

#ScoutingNZ

mastodon.nz
3
0
0
0
Open post
Guy @phlogiston@mastodon.nz
· 4mo ago

Had to re-install my Doom #Emacs setup. Unfortunately updating my `emacs-plus` install via Homebrew on the work Mac had resulted in a misbehaving editor :-(

But it was easy enough to re-build and secure the config items across, as it all follows the UNIX paradigm of configs being in files (as opposed to binary registries).

Biggest irk I'm having with the 'flavours' of Emacs these days is that they seem to have the feeling that the defaults should be on vim ('evil') style key bindings modes. Whyyyy?!?!?!?!?

mastodon.nz
3
2
1
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

Making a season's (likely) last feijoa and apple crumble. Making feijoa fizz has worked a treat so far. Trying a feijoa and apple fizz now from both peels.

#everybitecounts

mastodon.nz
3
0
0
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

RE: @glynmoody@mastodon.social

Better have multiple archiver bots hit my server than a swarm of AI harvester bots.

One delivers value and is ethical, the latter isn't.

mastodon.social
3
2
2
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago
Replying to

Edge is the only Chromium‑based browser I’ve tested that behaves this way. By contrast, Chrome uses a design that makes it far harder for attackers to extract saved passwords by simply reading process memory. It decrypts credentials only when needed, instead of keeping all passwords in memory at all times. App‑Bound Encryption (ABE) adds another layer by binding decryption to an authenticated Chrome process, preventing other processes from reusing Chrome’s encryption keys. Because of these controls, plaintext passwords appear only briefly during autofill or when the user views them, making broad memory scraping far less effective.

The risk of keeping the passwords in cleartext in memory becomes evident in shared environments. If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes. In the video the attacker has compromised a user account with administrative rights and is able to view stored credentials for two other logged on (or even disconnected) users with Edge running.

I reported this to Microsoft, and the official response was that the behavior is "by design". They have been informed that I would be sharing this as a responsible disclosure so users and organizations can make informed decisions about how they manage credentials.

(from the pen-tester/finder of this issue)

3
0
0
0
Open post
Guy @phlogiston@mastodon.nz
· 4mo ago
Replying to
Here's the link to the OpenReception project page (in English as well): https://open-reception.org/ And the fediverse reference to it: @openreception@mastodon.social
open-reception.org
1
1
0
0
Open post
Guy @phlogiston@mastodon.nz
· 4mo ago

RE: @heiseonlineenglish@social.heise.de

How dense is that? Poor connectivity, increase in night sky light pollution, more space junk, increase in Kessler Syndrome, problem with energy supply, problems with cooling (radiation only, no efficient convective cooling) green house gas producing aluminium ablation in the upper atmosphere due to burning up satellites and launch vehicle parts. There's likely more.

To me, this is purely a land grab, but defies any common sense.

social.heise.de
1
2
0
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago
Replying to
There seems to be an ML-KEM WebAuthn draft: https://datatracker.ietf.org/doc/draft-vitap-ml-dsa-webauthn/ And the 'advanced' section of this FIDO2/WebAuthn PQC Testing Platform and Dev Tools are suggesting ML-KEM testability. https://webauthnlab.tech/ But it all seems still a bit 'further out there' to give me warm fuzzies without having to face another disruptive transformation yet again.
datatracker.ietf.org
1
0
0
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

I love baseball movies. On the weekend, I've watched one I didn't know, yet: Eephus.

What a weird movie!!!

I'd say it scores 100% on atmosphere/mood as well as character variety in the actors. But it would likely score more like 0-10% on plot or 'suspense curve'.

I've really liked it in a way, but would not recommend it. Unless you like quirky character studies like those of the French director/actor Jacques Tati. And you *must* love baseball with all its quirks and idiosyncrasies, especially recreational baseball ('beer ball').

And, I've learnt about a new/different pitch, the 'eephus': https://en.wikipedia.org/wiki/Eephus_pitch

#MastoMovie #movies #review #baseball

en.wikipedia.org
1
1
1
0
Open post
Guy @phlogiston@mastodon.nz
· 5mo ago

Embedding a Mastodon feed into a #Wordpress web site:

Web search resulted in many options, but I don't know which would be a most suitable for my needs.

I would like to integrate a block/widget into a Wordpress site that can pick up a particular Mastodon account feed of posts to embed in the web site. What would be a suitable approach for this?

I believe there was quite some discussion around Mastodon/Wordpress integration last year or so, but I've only now have had a use case for trying to put this into use.

Any tips/hints?

mastodon.nz
0
0
3
0
Open post
Guy @phlogiston@mastodon.nz
· 2mo ago
And another #GenAI on GenAI hack case. This time Meta AI is the culprit: https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/ I guess it's for street creds that your #AI needs to be at least good enough to take out another one's security. #LLM #Meta #security
reuters.com
0
1
2
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:29:04 UTC