Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

redsakana

@redsakana@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I think X.509 and Kerberos are pretty good actually—compared to many of the alternatives on offer.

0 Followers
99 Following
28 Posts
Joined September 13, 2024
Open post
redsakana @redsakana@infosec.exchange
· 3mo ago
Replying to
@mhoye@cosocial.ca The Microsoft bit is interesting but this guy's opsec skills seem to have been quite something in general
6
1
1
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
Replying to
@Kjaerulv@mastodon.social It feels now like the run-up to Bitcoin $120k in 2024–5. Lots of seemingly-random volatility that somehow always results in bigger fish getting fatter by gobbling up some smaller fish, like Citadel grabbing Aschenbrenner's AI-bro fund mentioned in the article. Then after a few days everyone just goes back to waiting for the number go up and forgets that it failed to do so for a while because surely the fundamentals are sound. FT had an article about the same fund a few days ago and some of the interviews had pretty incredible copium levels. Actual quote: “We were wondering for three weeks who was driving […] that momentum sell-off,” [HSBC analyst] Kettner said […]. “Now we’ve found a narrative, and we can move on.”
3
2
0
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
Replying to
@sarahjamielewis@mastodon.social systemd's shark-jumping has now gone further with Poettering et al. forming a startup called Amutable, where the general idea appears to be promoting read-only-but-modifiable VMs/containers/whatever. Read-only is often good, but adding a general-purpose -but-modifiable bit tends to add a _ton_ of complexity of everywhere [1] and is IMO a counterproductive idea [2]. Whatever the case, now everyone gets to deal with all the related features/problems they upstream into systemd. I have been pretty ok with systemd's original scope viz. as an init system, but at this point I'd just like to throw all of it out. [1] The systemd approach appears to be largely following the pattern set by Android's APEX thing which added a ton of complexity on top of the already rather extreme complexity of AOSP. [2] Unless you do it cheap&cheerful like the OpenWRT packages-overlay thing, which is fine if not particularly conducive to security.
2
1
0
0
Open post
redsakana @redsakana@infosec.exchange
· 1mo ago
Replying to
@misty@digipres.club Depends on how you feel about Chinese laptops I guess. Which is to say, Thinkpads. My ca. 2020 T14 is doing fine as a daily driver, still gets minimal firmware security support, and has 80% battery capacity remaining. Only reason I'm looking at a new one today is that while in technical terms I see no problems with driving the current one until 2027-28, the world is gonna be ultra fucked in 2027-28 if the AI bubble goes and ultra fucked in a different way if the AI bubble stays. Plus all the wars, of trade and other varieties, on the horizon. If you're fine with arm64 and somewhat less performance, MNT looks great and I would get one of the big ones if I had the budget for a second machine. Framework was dropped from consideration when they went all in on fashtech.
1
2
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago
Replying to

@bagder@mastodon.social This suggests a fun exercise for someone interested in messing around with LLMs:

  1. Put back all the curl security issues previously found by LLM tools by dropping the fix commits from history or otherwise obfuscating the revert.

  2. Feed the re-vulnerabilized repo to a selection of models and see what are the cheapest ones (by memory, time and/or monetary cost) that can find, say, 50%/75%/100% of the issues found by the warehouse-scale "foundation models".

Feels like a large part of the current results should be doable with significantly smaller resources, because being trained on every tweet and reddit post and libgen book ever is not obviously related to the task.

5
1
0
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
Replying to
@mntmn@mastodon.social I think maybe @lethalbit@chaos.social was fighting with that a few weeks ago, but could have been someone else on my timeline
1
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
Replying to on tech.lgbt
@nina_kali_nina@tech.lgbt If interested in reading more about this topic I recommend Miwa Kentarō's (三輪 健太朗) excellent マンガと映画ーコマと時間の理論
1
1
0
0
Open post
redsakana @redsakana@infosec.exchange
· 8mo ago
Replying to
@cstross@wandering.shop Mango Mussolini crashing out of the Berne Convention and WIPO with a midnight tweet can't be far at this point
7
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 4mo ago
Replying to
@davidgerard@circumstances.run nice, I have been thinking about visiting Scotland for a while but would prefer to do it without visiting the UK (or for the UK to get their wingnuttery problems fixed, but that seems even farther away)
2
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 10mo ago
Replying to
@cstross@wandering.shop Now would be a good time for everyone esp. on smaller instances to start or increase donations to their instance admins, since difficulty level seems to be going up. (If your financial situation allows, of course.)
6
0
6
0
Open post
redsakana @redsakana@infosec.exchange
· 4mo ago
Replying to
@davidgerard@circumstances.run This was a pretty funny quote from SpaceX about the size of their potential future market though (reproduced in yesterday's Money Stuff): "We estimate that our [Total Addressable Market] is $28.5 trillion, consisting of $370 billion in Space from space-enabled solutions; $1.6 trillion in Connectivity across $870 billion in Starlink Broadband and $740 billion in Starlink Mobile as well as additional opportunities in enterprise and government; $26.5 trillion in AI across $2.4 trillion in AI infrastructure, $760 billion in consumer subscriptions, $600 billion in digital advertising, and $22.7 trillion in enterprise applications." So they envision making bit of future money from space stuff, some of which might actually work and possibly even be profitable, and a ton of it from AI stuff that probably will do neither.
1
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago
Replying to
@wdormann The fix for Debian for users who don't need algif_aead (i.e. most of them): rmmod algif_aead ; find /lib/modules -name algif_aead.ko -exec rm '{}' \;
1
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago
Replying to
@mjg59@nondeterministic.computer As a complete-ish catalog of all the writing systems invented (and still known) I would perhaps say "of the last 2000 or so years"
1
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 9mo ago
Replying to
@cstross@wandering.shop Like I think many old consumer electronics hardware companies, Sony never quite figured out the right level of platform commitment for PCs (or any device supposed to access content from external sources): either they did one-off products or tried for CE-style total ecosystem lock-in, sometimes both at the same time. Arguably this is where Apple in the Jobs era succeeded: the Mac platform didn't get in your way too much and you could mostly trust it staying that way, but there was still enough Apple-flavored value-add to keep you coming back. What IMO enshittified both was the enchanted/cursed taste of IP and services revenue, when the people buying hardware were no longer the customers but became the product being sold. For Sony I'd say the problems started with the growth of Sony Music and Sony Pictures, while for Apple it was the bags of free money rolling in from the appstore tax. (I have a Sony-era Vaio Pro 11 that I still occasionally use with LTSC 2021. Many call it flimsy, but I'd say that a 750g laptop with a 5h+ battery runtime from the Broadwell era is extremely impressive.)
2
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 15mo ago
Replying to
@ids1024@mathstodon.xyz Wayland clients managed by an X window manager would be the ultimate payback for Team Wayland telling everyone "no" for the past decade+ (I don't _entirely_ disagree with the reasoning but for a general desktop use case: c'mon) @dalias@hachyderm.io @ariadne@social.treehouse.systems @cb@social.treehouse.systems
5
1
0
0
Open post
redsakana @redsakana@infosec.exchange
· 9mo ago
Replying to
@cstross@wandering.shop There's actually a rather nice UUCP-reimagined-with-encryption project called NNCP (http://www.nncpgo.org/) I used it for a while for a tricky mail setup.
nncpgo.org

NNCP (NNCP)

NNCP (NNCP)

1
1
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago
Replying to
@dsalo Anthropic seems little different from a hustler hawking ivermectin to the manosphere/antivaxx crowd: they have found an audience that will believe (and buy) _absolutely anything_ as long as the speaker has impeccable credentials within their respective echo chamber, and zero qualms about using that influence. The main difference being that their audience has a lot more spending money.
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago

Two screenshots from today's FT. Surely no problems here at all. (The most surprising part may be that Oracle supposedly has $250B of deferred cloud revenue in addition to what OpenAI has promised them.)

(https://www.ft.com/content/7599af3b-2184-4538-8ef9-370e01c1aaa8?syn-25a6b1a6=1 and https://www.ft.com/content/be97df0a-76b1-4cb0-9ba4-d1117d8d1450 , the latter diagram is originally from https://www.theinformation.com/articles/anthropic-commits-spending-200-billion-googles-cloud-chips)

ft.com
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago

the IPv8 dude is now trying to push his wares on the nanog mailing list and that's some serious AI psychosis going on there

0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago

@campuscodi@mastodon.social The code that led to the exploit is kind of mind-blowing: https://www.openwall.com/lists/oss-security/2026/04/18/5

Looking for code of this caliber in obscure projects/forks looks like an optimum case for LLMs since there's little need for hard work like predicting brances or deriving types.

openwall.com
0
0
1
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago

wake up babe, new slopnerability class dropped: find application X that _could_ be linked with some library Y that has a known vulnerability AND X could somehow be operated to reach said vulnerability in Y.

File slop report against X to claim your CVE badge and bug bounties.

(AFAICT this is neither about vendoring a vulnerable version of Y in X nor about vulnerable version of Y being concretely otherwise shipped somewhere where X could also be installed.)

0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 5mo ago

Implemented TPM2 auto-unlock and most of systemd-pcr{phase,fs} for initramfs-tools to get rid of dracut [1]. There's such an amazing amount of potential confused deputies in a typical initramfs (all flavors) that it's like having an entire sheriff's department in your computer.

If you're doing TPM auto-unlock without systemd-pcrphase (PCR 11) or equivalent, grabbing your encrypted root partition can likely be done in less than an hour of physical access without attacking the main OS or any kind of the TPM snooping or other hard work. pcrphase raises the bar, but you still have to get a _lot_ of fairly complex and non-obvious stuff right along the boot chain.

[1] dracut is kind of a second-class citizen on Debian, but it _could_ be fine on its own. However when combined with its systemd-in-the-initramfs module (enabled by default), the result is just an incredible fucking mess of pointless complexity. And I'm saying this after getting way too familiar with the giant pile of shell scripts that is initramfs-tools.

0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 3mo ago
@nina_kali_nina@tech.lgbt did you check out the new Ave Mujica song? It's a banger this time too
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 3mo ago
Fortress HODL is collapsing (from Alphaville): "[Strategy's rescue plan involves] a $1bn common stock buyback, and a “BTC Monetization Program” under which the board has authorised management to sell bitcoin for three purposes: to replenish the cash reserve up to $1.25bn; to fund preferred dividends and interest if “more advantageous” than issuing equity; and to fund the repurchases of preferred stock or equity." (Micro)Strategy has likely been _the_ whale propping up Bitcoin price. It's going to be fun ride when they start selling. The name of that ride is Doom Loop.
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
The domain for Molly (a Signal fork), molly.im, expired and based on Github discussions it took something like 48 hours after payment and manual intervention by the registrar to get the registry to reinstate it. I don't have have any inside info here but sounds like the .im registry is not a particularly serious operation.
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social All this feels like a good demonstration of the statement that AI companies tend to have little in the way of a moat. So you have cookie-cutter LLM-linter startups trying to stand out from the vast ocean of cookie-cutter AI startups by dropping a "0day RCE", no matter how silly, with maximum splash.
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 1mo ago
Replying to
@misty@digipres.club Some caveats: It's a good idea to check for example Archwiki and forums if a particular model has persistent firmware or hardware issues. Based on hearsay these seem to be more common on the P series (discrete GPU models). Webcam on recent models may be the ridiculous Intel IPU6 bullshit that doesn't really work. Never even tried to use mine. Base model FHD display is shit-tier. Either get the 4k or select the FHD option with "low-power" in the title. (Low-power is a Lenovo term for "not the bad ones we bought three hundred containers of in 2015".) WWAN modules customization tool offers now (Quectel/Sierra) reportedly mostly work. If ordering with WWAN, absolutely avoid Fibocom if that turns up.
0
0
0
0
Open post
redsakana @redsakana@infosec.exchange
· 2mo ago
Replying to
@c_merriweather@social.linux.pizza I'll have to give that a try one of these days
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:23:57 UTC