Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Siguza

@siguza@infosec.space
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.space

iOS hacker, security researcher, 0day enthusiast.
Sometimes RE tools / jailbreak / write-up author.
And accidental maintainer of ever more things I didn't ask for.

Contact in English or German.
PGP: https://siguza.net/pgp.asc

3365 Followers
166 Following
50 Posts
Joined January 02, 2024
web:
https://siguza.net
blog:
https://blog.siguza.net
github:
https://github.com/Siguza
thinking:
outside the box
Open post
Siguza @siguza@infosec.space
· 2d ago

I got some weird emails today. Supposedly from OnlyFans, so my first instinct was that this was some kind of scam. But no, it really came from one of their subdomains (backed by Sendgrid), DKIM signature checked out and all.

Then I thought maybe someone had hacked Sendgrid again, but all links in the email went back to the real OF domain, so that didn't make much sense either. But the even weirder part was that two minutes before the email had shown up in my main inbox, another email with the same content had shown up in my catch-all mailbox, sent to an address with the part before the @ misspelled. I really don't think anyone capable enough to hack Sendgrid would be sitting there manually misspelling email addresses.

Anyway, after requesting password resets for the two accounts I supposedly had, the picture became a bit clearer, because once I got in, the UI constantly reminded me that my email address had not been verified yet. So it seems that OnlyFans allows people to either create accounts or change their email addresses without verifying them. I don't know what the point of that is, and I don't know why anyone would try to sign up with my email address, since the platform lets you do basically nothing without verifying your email... but okay.

7
0
2
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@madcoder@infosec.exchange LLMs are brute force, just like a fuzzer. If paired with an objective and airtight criteria for success (like crashing a process), then brute force can work, yes. At the technology level, rather than blockchain and the metaverse in search of a problem, I think LLMs are more like Electron and NoSQL. You can't be bothered to structure your data, so you just chuck it all in a JSON file and let the code loop over it to find what it needs. Rather than engineering a UI, you just throw together a bunch of HTML and CSS, and let an old version of Chrome figure out how to arrange them on the screen, somehow. The result is that every messenger app is now 4 processes, uses 2 GB of RAM and 15% CPU power when idle, XSS and URL redirects are real attack vectors, and it takes a full 5 seconds to load 80 MB of app data on startup. And that was bad enough already when it was just Electron and NoSQL, but now this level of quality is being brought to operating systems, compilers, hardware and every other aspect of computing. People can say that there will be code review and quality control all they want, but we all know that that's bullshit. The real reason why NoSQL, Electron and LLMs are everywhere is not because they improve anything, but because they help in racing to the bottom. Managers worldwide have every incentive to cut back on costs, and little to no incentive for quality control. Especially in software projects with big existing user bases, where the breaking point will only come months or years down the line. I've already had to use software that was vibecoded from the ground up. Where buttons didn't work, filtering options only had to work once and then you had to reload, some of your settings were never saved, and data was not consistently displayed. And this wasn't years ago, it was in 2026. Every other week I have to debunk some blog post or paper or whatever that talks about Apple Silicon Macs having EL3, about entitlements that don't exist, LARPing about non-existent ROM bugs in the latest iPhone, or whatever other hallucinated bullshit. I think the reason why I have such a deep hatred for LLMs is in part because they accelerated the race to the bottom tenfold, and in part because they poison the information well that was already in a dire-enough state as it were. Where it previously felt like swimming against the tide, it now feels like swimming up a waterfall with a diesel locomotive strapped to my back. I don't care if people run scripts locally that were written by an LLM or by their cat. What I care about is the quality of critical digital infrastructure, and I'm convinced that that will decrease drastically over the next couple of years. I'm happy to be proven wrong, but unfortunately my pessimism has a depressingly accurate track record.
245
7
151
2
Open post
Siguza @siguza@infosec.space
· 1w ago
Replying to
@nicolas17@social.treehouse.systems @janne@social.treehouse.systems yeah no, Apple just stopped doing it. They had a perfectly good system, and they ruined it willingly.
3
1
0
0
Open post
Siguza @siguza@infosec.space
· 1w ago

@zackwhittaker@mastodon.social sad, I was hoping that was a shitpost 😅

1
0
0
0
Open post
Siguza @siguza@infosec.space
· 1w ago
Replying to
@janne@social.treehouse.systems @nicolas17@social.treehouse.systems you can get that from the macOS IPSW BuildManifest. It's 0x6050. Apple stopped the "ChipID is unique across SoCs" with A18/A18 Pro. :/
2
2
0
0
Open post
Siguza @siguza@infosec.space
· 1mo ago
Replying to
@never_released@mastodon.social ah, so it's another case of academia having no idea what kind of percentages matter in the real world 🤭
4
0
0
0
Open post
Siguza @siguza@infosec.space
· 1mo ago
Replying to
@gumnos@mastodon.bsd.cafe
4
0
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@zackwhittaker@mastodon.social the "Untied States" omg I'm wheezing 😂
16
2
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
I plug in an external HDD, it takes some 35s to spin up, and then another 65s where Finder sees the disk, but its contents are just "Loading...". What the fuck is it doing? There are a total of 13 entries at the top level of that file system hierarchy, retrieving those should take less than 1s.
10
8
0
0
Open post
Siguza @siguza@infosec.space
· 2w ago
Replying to
@argv_minus_one@mastodon.sdf.org @EUCommission@ec.social-network.europa.eu and for the EU folks: https://eci.ec.europa.eu/066/public/
#SITE_NAME#

European Citizens

Give your support !

1
0
1
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
So there's a new 300-page research paper out about the Apple Neural Engine... and it's just slop. It isn't even consistent with itself, mixes up the generations of A- and M-series chips, and has hallmark paragraphs where the AI is trying to justify something to itself. The code is open source too, and it's so plain obvious that he ran an AI agent under his own account that generated tons of pull requests, not least because he commented on and closed some of the requests, but also because of a commit that references some pull requests, whose summary literally reads: "chore: remove dead code and slop cleanup". The best part? This guy isn't just some rogue student, he's an assistant professor!
11
2
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@zackwhittaker@mastodon.social I mean, we all know that with billions in cashflow, you're effectively above the law, at least in the US.
5
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@madcoder@infosec.exchange you really became a proponent of "move fast and break things", huh
4
7
0
0
Open post
Siguza @siguza@infosec.space
· 4mo ago
Replying to
@zackwhittaker@mastodon.social can we please confiscate Microsoft's domains and have a competent sysadmin run them?
11
1
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@shac@ioc.exchange they have no incentive to do the right thing...
3
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@d_olex@mastodon.social by the turn of the decade, we won't have any functional operating system anymore
3
2
0
0
Open post
Siguza @siguza@infosec.space
· 4mo ago
Replying to
@joe@f.duriansoftware.com torrent.nexus is available, but costs upwards of $130/yr... a bit too expensive just for the joke :/
5
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@zackwhittaker@mastodon.social unrelated, but: archive.is has gone bad faith and should IMO no longer be used. They're using JavaScript to DDoS someone's blog from visitor's browsers, and Wikipedia and Stack Exchange have already blocked them, see: https://meta.stackexchange.com/q/417269
meta.stackexchange.com
2
2
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to on federated.saagarjha.com
@saagar@federated.saagarjha.com huh? What did I miss now?
2
0
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@zhuowei@notnow.dev everything "lands" in the physmap. It's a linear mapping of all DRAM managed by XNU/SPTM. So you should be able to pick any target, the difficulty is just that a whole bunch of page types (page tables, SPTM/TXM/Exclave memory, zalloc_ro, any page with executable code) are gonna have their permissions flipped to readonly, so you'd need a way to reliably avoid those or you'd be likely to panic. In addition, getting into a position where you can spawn a binary on iOS... that's a tall order. And it's possible that, under a release iOS kernel, dyld ignores a bunch of env variables that you need in order to pull this off... but I don't know for sure if this is the case, grep for amfiFlags in dyld src.
2
2
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@fay59@tech.lgbt real hardware is finite, so everything is O(1) anyway.
1
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@CCC@social.bau-ha.us kognitive Dissonanz, Sucht, sozialer Druck und Vendor Lock-In sind aber schon ganz verschiedene Themen. Das alles in einen Topf zu werfen und einfach zu sagen "du willst ja gar nicht" finde ich schon sehr verantwortungslos.
1
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@johns@social.librem.one I hope you send them on an odyssey, trying to retrieve it.
1
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@d_olex@mastodon.social "unfounded" my ass, just look at what happened to rsync. The reliable foundation upon which we built all of our digital infrastructure is being slopified and made unreliable as we speak.
1
20
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@sirlan@derg.social or a liability that will haunt you for the next 20 years
1
0
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@shac@ioc.exchange oh, and I almost forgot, I added a little wall panel with a wheel that goes from 15 to 35 but that does absolutely nothing.
1
0
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@zhuowei@notnow.dev hmm... okay I don't know if that can be done either. But in any case, physical OOB is gonna be tricky to exploit reliably.
1
1
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@mshelton@mastodon.social I wonder how this works in companies. If a company is AI-addicted and shoves this down its employees' throats - do the AI companies ask for govt IDs of the individual employees? Can companies compel their employees to submit such data to a third party?
1
0
0
0
Open post
Siguza @siguza@infosec.space
· 4mo ago
Replying to
@nicolas17@social.treehouse.systems @zhuowei@notnow.dev I don't think anyone actually knows...
1
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@dataq@mastodon.social APFS.
0
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@dataq@mastodon.social it does have the .metadata_never_index file at the top level... 🤷
0
2
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@jann@infosec.exchange I mean, it has a dedicated power adapter. It's just... a big-ass drive.
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 1mo ago
Replying to
@fay59@tech.lgbt ...what happens when you have two static inline functions that call each other (conditionally of course)...?
0
2
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@adfichter@infosec.exchange
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@zackwhittaker@mastodon.social Unfortunately I do not. I've seen people online suggest ghostarchive.org and megalodon.jp, but I've never used either of those :/
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 4mo ago
Replying to
@Kroc@oldbytes.space @ansuz@gts.cryptography.dog @jacqueline@chaos.social FOBI, which sounds eerily similar to phobia 😅
0
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@DHowett@mas.to pay a lawyer $50 to send a cease and desist?
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 1w ago
Replying to
@never_released@mastodon.social hoooooooly shitttttttttt
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
depol; Nachrichtendienstreform
RE: https://social.bau-ha.us/@CCC/116960379617111735 Also ich bin ja kein Jurist, aber... gibt es dann überhaupt noch irgendwas, was der Nachrichtendienst nicht darf?
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2w ago
Replying to
@a@asentientbot.ca wat
0
1
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@never_released@mastodon.social oh we're gonna end up with each state in their own time zone, some with DST, some without, and at least one state abandoning seconds, minutes and hours for some worse units that they just made up.
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@never_released@mastodon.social huhh??
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@alicela1n@social.treehouse.systems mine is like a bunch of meticulously organised filing cabinets... on top of a massive junk yard
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@TwraSun@mastodon.social I can already hear them scream "communism"...
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@d_olex@mastodon.social https://pivot-to-ai.com/2026/06/03/rsync-goes-ai-slop-breaks-your-backups/
rsync goes AI slop, breaks your backups
Pivot to AI

rsync goes AI slop, breaks your backups

rsync is a program for copying entire file folders from one computer to another, doing incremental updates if there’s only a few changes. You can keep a continuous backup copy. Rsync is super relia…

0
18
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@fay59@tech.lgbt oh, this isn't even a troll. This is a cold, hard soundness bug, unresolved since 2015. +100 psychic damage to compiler engineers.
0
2
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@saagar@federated.saagarjha.com if you asked Anthropic, probably "in the immediate future" and "governments need to take regulatory action for this scenario by yesterday" 😐️
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@fay59@tech.lgbt something something cve-rs
GitHub

GitHub - Speykious/cve-rs: Blazingly 🔥 fast 🚀 memory vulnerabilities, written in 100% safe Rust. 🦀

Blazingly 🔥 fast 🚀 memory vulnerabilities, written in 100% safe Rust. 🦀 - Speykious/cve-rs

0
2
1
0
Open post
Siguza @siguza@infosec.space
· 2mo ago
Replying to
@shac@ioc.exchange pretty sure it unmounted cleanly yesterday :/
0
0
0
0
Open post
Siguza @siguza@infosec.space
· 3mo ago
Replying to
@lilstevie@infosec.exchange I once tried to sign up to OVH. But because they have multiple domains under multiple TLDs, and some places do redirects based on location, others on browser language, I ended up signing under one TLD but it wanted me to log in under a different TLD, and that didn't work. So they just... don't want things to work to begin with. I guess. And then not long after that they had a data centre burn down too, so...
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:48:51 UTC