Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 33mo ago Replying to @WPalant@infosec.exchange <p>German law is making security research a risky business.</p><p>Current news: A court found a developer guilty of “hacking.” His crime: he was tasked with looking into a software that produced way too many log messages. And he discovered that this software was making a MySQL connection to the vendor’s database server.</p><p>When he checked that MySQL connection, he realized that the database contained data belonging to not merely his client but all of the vendor’s customers. So he immediately informed the vendor – and while they fixed this vulnerability they also pressed charges.</p><p>There was apparently considerable discussion as to whether hardcoding database credentials in the application (visible as plain text, not even decompiling required) is sufficient protection to justify hacking charges. But the court ruling says: yes, there was a password, so there is a protection mechanism which was circumvented, and that’s hacking.</p><p>I very much hope that there will be a next instance ruling overturning this decision again. But it’s exactly as people feared: no matter how flawed the supposed “protection,” its mere existence turns security research into criminal hacking under the German law. This has a chilling effect on legitimate research, allowing companies to get away with inadequate security and in the end endangering users.</p><p>Source: <a href="https://www.heise.de/news/Warum-ein-Sicherheitsforscher-im-Fall-Modern-Solution-verurteilt-wurde-9601392.html" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Warum-ein-Sicher</span><span class="invisible">heitsforscher-im-Fall-Modern-Solution-verurteilt-wurde-9601392.html</span></a></p> @WPalant@infosec.exchange for every country that makes a law like this, blackhats work getsveasier and easier
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 21mo ago Replying to @matthew@mastodon.me.uk Today I learned that Blåhaj are difficult to gift-wrap. #blahaj @matthew@mastodon.me.uk shiny haj :3
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 17mo ago Replying to @FediPact@cyberpunk.lol <h1>⚠️ IMPORTANT FEDIPACT ANNOUNCEMENT!!!⚠️</h1><h2>THREADS HAS CHANGED DOMAINS TO THREADS.COM!!!!!</h2><p>in a deleted article techcrunch confirmed threads would be moving from threads.net to <strong>threads.com</strong></p><p>zero clue why it was deleted because threads.net already redirects to threads.com as of right now</p><p>sooooo yeah!!! new domain to block. check out <a href="https://fedipact.online/why" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">fedipact.online/why</span><span class="invisible"></span></a> if you're wondering why</p><p>:FediPact: </p><p><a href="https://cyberpunk.lol/tags/fediblock" class="mention hashtag" rel="tag">#<span>fediblock</span></a> <a href="https://cyberpunk.lol/tags/FediPact" class="mention hashtag" rel="tag">#<span>FediPact</span></a> <a href="https://cyberpunk.lol/tags/meta" class="mention hashtag" rel="tag">#<span>meta</span></a> <a href="https://cyberpunk.lol/tags/threads" class="mention hashtag" rel="tag">#<span>threads</span></a></p> @FediPact@cyberpunk.lol cc @saabria@fearness.org sorry to bother
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 33mo ago Replying to @cinnamon@mk.absturztau.be @jamie@crab.garden Beware of the dog! (I also have an SVG version, if anybody is interested) @cinnamon@mk.absturztau.be @jamie@crab.garden haj :neocat_aww:
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 21mo ago Replying to @hadley@plush.city @Sylvhem@eldritch.cafe @fionafokus@mystical.garden It kinda is, though. It predates the idea of people with cellphones that have Internet access, and it's multi-device support is... bad. Senders have to choose WHICH of the logged in devices a message goes to, and if they choose wrongly? You don't find out until you get home and realise someone message you while you were say, out at work. There's also no built-in cryptography, and the 3rd party hacks are super fragile and prone to randomly turning off silently. @Sylvhem@eldritch.cafe @fionafokus@mystical.garden @hadley@plush.city and also no custom emoji and you have to download images to receive
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 26mo ago Replying to @skaverat@skaverat.net <p>Serious question to people born on 1970-01-01: Did you ever encounter weird IT related issues due to your dob?</p><p>Sharing encouraged, because I'm genuinely curious</p> @skaverat@skaverat.net not a 1970 but who do computers default to 1970?
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 26mo ago Replying to @aperture@snug.moe @sleepybisexual@fearness.org @skaverat@skaverat.net if you didnt mean why then i apologize but i did enjoy infodumping so sdbjgsdjkgsdjkg @skaverat@skaverat.net @aperture@snug.moe I meant why :3 thank u
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 18mo ago Replying to @endrift@social.treehouse.systems <p>Which of these computing devices do you have and use?</p> @endrift@social.treehouse.systems is a pinetime a smart watch?
Open post 58692 [lunya] (beeeeeeeeeeeeeep) @sleepybisexual@fearness.org · 18mo ago Replying to @endrift@social.treehouse.systems @sleepybisexual@fearness.org yes @endrift@social.treehouse.systems oki :3