Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

stf

@stf@chaos.social
mastodon 4.6.9
  • Open on chaos.social

https://pitchfork.ist, libopaque, https://sphinx.ctrlc.hu, pysodium, https://klutshnik.info, https://sphinx.pm

#searchable #cypherpunk

0 Followers
0 Following
43 Posts
Joined July 06, 2023
github:
https://github.com/stef
blog:
https://ctrlc.hu/~stef/blog/
Open post
stf @stf@chaos.social
· 5mo ago

i don't share any of the enthusiasm.

it is just replacing one old rightwing asshole, with a younger rightwing asshole.

unless there is wide and thorough anti-corruption investigations, convictions and large nationalization of stolen public funds, #orban wins... he retires and enjoys the spoils of stealing for decades.

#hungary

chaos.social
15
3
11
0
Open post
stf @stf@chaos.social
· 3mo ago
Boosted by @GroupNebula563@mastodon.social
does anyone have experience with these free sms receiver sites? the few i found are rejected. or any recommendation for very cheap european throw-away esims? #privacy #registration #account
3
0
1
0
Open post
stf @stf@chaos.social
· 9mo ago

#Applied #cryptography cannot solve a #security problem. It can only convert a security problem into a key-management problem.

Corollary: If you aren’t actually solving the key-management problem, your cryptography is strictly decorative. This is not only not helpful, it is actively harmful, because it gives users a false sense of security, leading them to skip other precautions they would have otherwise taken.

src: https://www.dlp.rip/decorative-cryptography

chaos.social

chaos.social

14
6
7
1
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@fj i don't think baarle-nassau ever had a proper border that schengen softened up. it is a very special place, look it up on osm: https://osm.org/go/0EuEZHA
osm.org
5
1
0
0
Open post
stf @stf@chaos.social
· 5mo ago

Product Warning: do *not* buy #ebikes with #bosch motors/controllers. they are locked-down by some #evil #proprietary shit and try to #vendorlockin you into their shitty products. the motors are good, but the apps, the navigation, are horrible, and #interoperability with devices and apps of other vendors is actively hindered.

learn from my mistake, don't repeat it.

pls discuss products/vendors that are open and interoperable in comments below.

chaos.social
5
0
6
0
Open post
stf @stf@chaos.social
· 5mo ago

so whatever happens tomorrow (i think it is given), what we saw over the last weeks in #hungary is a masterpiece. this is how you orchestrate the #controlled collapse of a #regime - unlike the 'mericuns - and have a plan for what happens after. #orban wants to retire and be in control #succession, e.g.:
1. domestic spies vs IT admins of #magyars party
2. Foreign Policy Minister reporting to Lavrov
3. getting Vance's endorsement

same as Jeltsin -> Putin, and Kadar -> Antall, Orban et al in '89

chaos.social
5
2
1
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@wdormann@infosec.exchange the amount of bloated attack surface iterm2 comes with makes this no surprise. they have one of those annually. a few years ago some colleagues of mine also found a similar one, only they made it an RCE over IRC.
2
0
0
0
Open post
stf @stf@chaos.social
· 7mo ago
Replying to
another interesting detail with this SBT #military #crypto #device #backdoored by the #nsa is that it contains a weird virtual machine, this handles templating of messages and fixed point math, and uses only 2 data "registers" and a pointer register.
2
1
0
0
Open post
stf @stf@chaos.social
· 7mo ago
Replying to
some interesting details, the #nsa #backdoored #phillips device runs a 8051 mcu. there's a print subroutine, that pops the return address from the stack, and prints the litteral chars from that address onwards until it finds a byte which has the top bit set. then it returns to the address after this last char. of course this is no calling-convention that any disassembler knows, so it throws them off. 2/n
2
2
0
0
Open post
stf @stf@chaos.social
· 7mo ago
Replying to
check out the write-up at https://rad.ctrlc.hu/raw/rad:z46AkAERuXAzqZcDRKvE7byRbkga1/7a27b7a350ccadadc2d1bd776747a06393fb50ab/writeup.pdf for more weird details of the #nsa #backdoored #SBT #military #crypto #device.
rad.ctrlc.hu
2
0
0
0
Open post
stf @stf@chaos.social
· 5mo ago
wtf does everytime a new v of #python is rolled out in linux distros, all virtual envs break, and i do have to rebuild them manually. we're now 13 minor versions since py v2.7 and everything became worse since then. i have a stable app, and if python would not fuck up this i would not have to touch it in a decade, but because of this, i feel like i'm in the java ecosystem where work is generated just to generate income for java architects.... fuck this.
1
1
1
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@Phosphenes@mastodon.social @Pyrogenesis@mefi.social @cstross@wandering.shop you have to buy the book to find out, duh!
1
1
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@i@toot.pouyan.net ah classic, something the hungarians missed also in '89 - setting an example for future generations of politicans. also this is what antall referred to when he said "tetszettek volna forradalmat csinalni"
1
1
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@i@toot.pouyan.net he is eager to retire, and the plan went beautiful, even 2/3rds of majority, meaning the sockpuppets can be removed without problems and never any evidence they would have pulled a vichy
1
3
1
0
Open post
stf @stf@chaos.social
· 15mo ago
Replying to
@dk so llms are technical debt accumulators, and ransomware is technical debt collection. i see a business model, are the actors intertwined like ddos services and cloudflare? like virus and anti-virus?
5
1
0
0
Open post
stf @stf@chaos.social
· 7mo ago

RE: @tynstar@nerdculture.de

bah. ich hab eine 4 stellige slashdot id.

nerdculture.de

Jens Bannmann ⁂: ""Ich habe Benutzernamen, die älter sind als du" k…" - NerdCulture

1
0
0
0
Open post
stf @stf@chaos.social
· 7mo ago
Replying to
@timcappalli@infosec.exchange https://words.filippo.io/passkey-encryption/
Encrypting Files with Passkeys and age
words.filippo.io

Encrypting Files with Passkeys and age

Encrypting files with passkeys, using the WebAuthn prf extension and the TypeScript age implementation.

1
1
0
0
Open post
stf @stf@chaos.social
· 8mo ago
Replying to
@fj@mastodon.social interesting, i can remember when i was active in the EP about 10 years ago, the far right was usually our ally when it came to digital rights issues.
1
0
0
0
Open post
stf @stf@chaos.social
· 13mo ago
Replying to on mastodon.social
@chatcontrol@mastodon.social please stop siccing the people on the meps and sicc them onto the ministers of the countries, the memberstate governments are the ones that are making this decision, not the meps. permanent representation is okish, though.
1
0
0
0
Open post
stf @stf@chaos.social
· 7mo ago

looking at the program of #realworldcrypto starting tomorrow in taipei: https://rwc.iacr.org/2026/program.php

i gotta say, i'm becoming a fan of Tom Ristenpart and his work.

chaos.social

chaos.social

0
0
0
0
Open post
stf @stf@chaos.social
· 9mo ago
Replying to
@Ichinin@infosec.exchange i'm not sure i follow, you refering to tls? the article the quote comes from does not. the quote itself points out a general issue that (m)tls might or might not have solved (depending on threatmodel).
0
2
0
0
Open post
stf @stf@chaos.social
· 7mo ago

repent! #realworldcrypto is nigh!

chaos.social

chaos.social

0
0
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@slott56@fosstodon.org i don't understand this question. distro rugpulls py3.12 replaces it with py3.13 - virtualenv doesn't find the old binary (and --copy also doesn't work for lack of missing libs), and each binary expects the deps in a versioned directory - so somewhere else - and stuff like uwsgi also cannot find the app any more. the only thing that changes is python.
0
17
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@hwine@vmst.io @slott56@fosstodon.org so you say, that the tools you recommended somehow containerize a python binary and the std modules and all it's dynamic library dependencies? do they build locally a python interpreter, or do they download a binary from somewhere on the internet?
0
11
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@hwine@vmst.io @slott56@fosstodon.org since i am convinced you want to correct me and not python, would like to conclude this thread with: i respectfully accept that you think i'm doing it wrong. and with the fact that i believe python is being wrong here and wastes the time of its users by not being more considerate, and i will continue grumbling about this, and if you cannot take that, please block me.
0
2
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to

@slott56@fosstodon.org

  1. apt get upgrade replaces python3.12 with python3.13
  2. in the venv the python binary is stale, i update that binary (to the new version, but all the deps, arpython3.13 -m venv --upgrade venv/) e still in venv/lib/python3.12 so i have to reinstall all of those there.
0
2
0
0
Open post
stf @stf@chaos.social
· 23mo ago
Replying to
@DannyMekic ah, thank you! but why direct anyone to linkedin then?
0
0
0
0
Open post
stf @stf@chaos.social
· 7mo ago

this song comes with some pretty strong security guarantees: https://www.youtube.com/watch?v=zmgR7zcva-A

0
0
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to

@hwine@vmst.io @slott56@fosstodon.org i guess my expectations (which i think are low) are like this:

packages in a virtualenv are installed in a version independent directory, instead of env/lib/python3.$minor/site-packages/ simply in env/lib/python/site-packages

upon upgrading python and running inside the virtualenv:

  1. py files run without extra steps
  2. pyc files are updated silently if needed
  3. .so modules work without changes, if API change in cpython then a warning to reinstall, but works as expected
0
3
0
0
Open post
stf @stf@chaos.social
· 3mo ago
Replying to
@unlofl@mstdn.social you must be (raises hand flat) this old to fully understand this joke...
0
0
0
0
Open post
stf @stf@chaos.social
· 7mo ago

@drwhax@infosec.exchange you might know, hypothetically i'm an activist/journo who has an increased chance of being candiru'd or paragon'd, is there anywhere a good intro/howto/guideline how to defend, detect, report and recover from such attacks?

infosec.exchange

DrWhax (@drwhax@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
stf @stf@chaos.social
· 9mo ago
Replying to
@Ichinin@infosec.exchange i think you very much misunderstood the quote, and possibly also the article if you read that. none said that keys are a problem, no idea where you got that from.
0
2
0
0
Open post
stf @stf@chaos.social
· 6mo ago
Replying to

@drwhax sorry to disagree, but Signature type: ecdsa_secp256r1_sha256 is not pq, also shouldn't the kem be hybrid?

0
1
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@rysiek maybe this https://youtu.be/0nt1CgQsgpI has some merit and is an explanation?

The Petrogas-Dollar: The Secret US Strategy Behind the Iran War

0
1
0
0
Open post
stf @stf@chaos.social
· 7mo ago
Replying to
@timcappalli@infosec.exchange isn't that what age is also pushing?
0
4
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@slott56@fosstodon.org all i want is stability, i don't want to update any virtualenv just because a new python version is deployed. i don't want to waste my time on this.
0
13
0
0
Open post
stf @stf@chaos.social
· 2mo ago
RE: https://social.treehouse.systems/@whitequark/116953973128142078 i have the previous revC and it is the best investment in a long time, so much comfort, so much versatility, so much speed, it's an amazing gadget, i'll definitely get a revD as well, you should too...
Open quoted post
Quoting
✧✦Catherine✦✧
@whitequark@social.treehouse.systems
the #GlasgowInterfaceExplorer revD project is up on CrowdSupply! subscribe to get updates and show your interested in the project, we're very excited to bring it to life :D https://www.crowdsupply.com/fully-automated/glasgow-interface-explorer-revd
Open quoted post
social.treehouse.systems
0
0
2
0
Open post
stf @stf@chaos.social
· 23mo ago
Replying to
@DannyMekic is it not ironic to do this privacy research and then post the results on linkedin?
0
2
0
0
Open post
stf @stf@chaos.social
· 9mo ago
Replying to
@Ichinin@infosec.exchange indeed, it says "key-management" you say "keys" there's a huge difference between those two. key-mgt is among others the creation of keys, the distribution of keys, the authentication of keys and their owners, the handling without side-chans, the detection of their compromise, their updating, their revoking, and possibly a lot of other things i forgot and wouldn't fit in a toot anyway. keys are just a bunch of bytes, they are innocent, not a problem, management, is and always has been.
0
0
0
0
Open post
stf @stf@chaos.social
· 5mo ago
Replying to
@hwine@vmst.io @slott56@fosstodon.org i appreciate you guys trying to help me, but there is a million of similar virtualenvs out there, are you ready to tell all those users that they're all doing it wrong and offering them bandaids and bad workarounds for the deficiencies of the interpreter - and don't tell me it's impossible; we have future, six, - which made the upgrade path bearable. we can have progress without unnecessarily breaking things and wasting users time, with a bit more consideration.
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 12:14:04 UTC