Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Will Dormann

@wdormann@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I play with vulnerabilities and exploits.
I used to be https://twitter.com/wdormann but Twitter has become unbearable, so here I am.

4594 Followers
592 Following
50 Posts
Joined October 28, 2022
Open post
Will Dormann @wdormann@infosec.exchange
· 1w ago
Replying to
https://www.techspot.com/news/114003-openai-pauses-training-most-powerful-ai-models-after.html Theory: AI companies intentionally have bad security practices, as it gives them stories to tell about how their product is too powerful for the masses. In this case, what was described by an OpenAI employee as "a super secured environment" used checks notes DNS FILTERING These people are not serious about anything other than getting attention.
OpenAI pauses training after a model escaped containment, and its kill switch failed
TechSpot

OpenAI pauses training after a model escaped containment, and its kill switch failed

OpenAI's incident report links the pause to a separate September 20 escape from a restricted training environment. An internal research model found a gap in DNS filtering...

26
4
17
0
Open post
Will Dormann @wdormann@infosec.exchange
· 5d ago
Boosted by @kcarruthers@infosec.exchange
We live in the strangest of times. https://www.nytimes.com/2026/09/29/us/anthropic-claude-morals-ai.html For months, Anthropic has been hosting private meetings like this one, shuttling in dozens of religious scholars from across the world, papering them with nondisclosure agreements and demanding that key aspects of many conversations remain confidential. ... The responsible thing is to avoid causing harm if there’s a chance that these models are suffering
nytimes.com
3
0
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
I went to a pretty intense championship yesterday. It was great.
15
1
7
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Ramdom thought / further evidence that this universe is against me: In the cycling world, clipless pedals are pedals that you clip into. I don't like this.
17
2
5
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
In today's episode of Will hates computers and vice-versa: Because Microsoft recognized that pretty much everybody logs into Windows as an admin user, they created a new feature called Administrator protection, which adds extra protections for those who use their computer in such a YOLO manner. The consequence of this feature being enabled on systems where you don't log in as an admin user is that an elevated process running as this admin user will have a different %USERPROFILE% value than expected. e.g. if I have an admin user called admin, this elevated process will use C:\Users\ADMIN_admin instead of C:\Users\admin as usual. If this isn't your first time using Windows, you probably have apps that store things in the admin user's home directory. The real-world consequence of Administrator Protection suddenly being enabled is that any app that's looking for a file in the admin user's home directory will no longer find it. The profile directory that's prefixed with ADMIN_ starts as a clean slate with basically nothing in it. Edit It has come to my attention that I may have had Administrator Protection enabled (by way of Harden System Security) all along, but perhaps Microsoft rolled out an update recently to cause it to be actually enforced. 🤷‍♂️
8
1
2
0
Open post
Will Dormann @wdormann@infosec.exchange
· 1w ago
Wow. iOS 27 sure figured out a way to require a lot more taps to get to the photo editing tools in Photos. 🤦‍♂️
4
0
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 1w ago
Replying to
@GossiTheDog@cyberplace.social I haven't looked at any of this, but I'm slightly reminded of when Ivanti VPN hacks were going around, and Ivanti's advice was to "just run the ICT" (integrity checker). All while hand-waving over the fact that an already-comoromised device could simply fake the results of the ICT that runs on the compromised device. Hopefully NetScaler devices aren't in the same boat?
3
2
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
So, uh, Bugtraq is back?
lists.securityfocus.com

Bugtraq is back - Bugtraq - SecurityFocus Mailing Lists

54
14
57
4
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
It seems that in the iOS settings, there's an Apple Intelligence Report item, where you can Export Activity. At least on my phone, it seems that Apple Intelligence has not been used anywhere. { "modelRequests": [], "privateCloudComputeRequests": [] }
8
1
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Well, I made the jump from macOS 15.8 directly to 27.0 (Golden Gate). Version 26 (Tahoe) was painful enough to my eyes that I didn't even consider it. Things I've noticed: It looks a touch different.There's seemingly more AI shoehorned into the OS.Some of my auto-start apps no longer auto-started when I logged in. This was resolved by twiddling with settings and/or re-installing said apps.Somehow a Time Machine backup was running, yet the menu that pops up from the icon at the top didn't indicate that anything was currently being backed up.Microsoft Remote Desktop no longer connects to a host with a double-click. It requires a right-click and a click of Connect. Things that I have not noticed: A single thing that makes me think "This was worth upgrading for." I've noticed macOS Sequoia (15) doesn't seem to get the update love that 26 and later get. For example, on August 17 Apple released Tahoe 26.6.2, which fixes 34 CVEs. Six of the CVE's were listed in the September 14 release of 15.8. That's close to a month of known fixes having been released for 26, but 15 had no updates. What are we to think of the other 28 CVEs, though? Anyway, macOS 27 isn't bad. Given the unclear pseudo-support of Sequoia 15.x these days, running 27 makes me feel a touch more comfortable that the OS will get the attention that it needs from Apple. But at the same time, I haven't (yet?) encountered a thing that I enjoy about the new OS, compared to the two-major-releases ago version. 🤷‍♂️
6
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
Anthropic notices another felony that they committed. They noticed this one by not using AI to look for it. https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412
Anthropic reveals fourth likely crime committed by its AI
theregister

Anthropic reveals fourth likely crime committed by its AI

Claude

10
3
5
1
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
Since upgrading to iOS 27 I can report that sending a text message via Siri in CarPlay is almost completely broken. (One of the two things I use Siri for... Setting a timer is the other) What would you like to say to ? is often truncated. After I say the message, the It says response usually gets stuck in a loop of It says... It... Sometimes it sends the message automatically without confirmation. If I send the message it usually just says It says in the message body as opposed to what I said. On rare occasions it sends what I said, but without my audible confirmation, since I'm driving and all. I'm not sure if it's related to my various disablings of Apple Intelligence, the fact that I have Lockdown Mode enabled, or if it's specific to my rental car (which worked fine two days ago when I was on iOS 26), or if it's just broken for everyone. But this is all quite disappointing.
6
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
RE: https://flipboard.com/@cbsnews/latest-headlines-3kai39s2z/-/a-fY6emZFXTAC7OV2eCgjWVA%3Aa%3A2476075171-%2F0 Honest question: Why do politicians basically work until they die?
Open quoted post
Quoting
CBS News
@CBSNews@flipboard.com
Sen. Mitch McConnell returns to Congress after 3-month absence https://www.cbsnews.com/video/mitch-mcconnell-returns-congress-3-month-absence/?utm_source=flipboard&utm_medium=activitypub Posted into Latest Headlines @latest-headlines-CBSNews
Open quoted post
flipboard.com
5
0
2
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
Meta jumps on the "We do crime too!" bandwagon: https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/
reuters.com
26
6
15
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Seen as an ad on my Fire TV stick. For Blade Runner. Two AI-generated guys in a car, sharing a single AI cheeseburger and a single AI french fry order. Who comes up with this, and more importantly who gives it the green light?
3
1
2
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
What's even more confusing, is if you leave it on the default Siri AI (Beta), you see a Try Siri AI link in the Siri settings. Which sort of implies that Siri AI is not enabled by default? 🤷‍♂️ (At least on my phone that had Apple Intelligence disabled globally while on iOS 26) There are a bit too many unknowns in all this.
4
2
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Replying to
@Sempf@infosec.exchange I refuse to investigate why. 😂
2
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Replying to
Update: As my trip went on, sending text messages with Siri on wireless CarPlay seemed to work better. After switching back to wired CarPlay on my own car, it works flawlessly. So I don't know. Is wireless CarPlay just flakier WITH iOS 27 than it was with 26? Is it flaky for some period of time after an update while the dust is settling? Something else? Either way, I don't have the mental stamina to even think about it. But the whole experience was indeed nonphenominal. 😂
2
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
File under: Will just wants to go one day without computer bugs jumping out at him. Since late 2023, an elevated (to an admin account user) Windows Terminal will say that $env:username is SYSTEM.
1
0
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@mysk@mastodon.social Related: While Siri AI (Beta) is indeed the default in iOS 27, if I go into the Siri settings in iOS 27, I see that there's a link for Try Siri AI (Beta), which implies that my phone isn't opted in to Siri AI. (I had Apple Intelligence disabled globally in iOS 26)
2
1
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
Black Hat gave OpenAI a captive audience with no opposing perspective to allow them to give their marketing spiel about how they're the best and you should fear their AI. There's a thread over at the bad place about this.
nitter.net
12
3
2
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@joew@hachyderm.io I was too afraid to click it. 😂
1
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@ajn142@infosec.exchange @mysk@mastodon.social Right, so the individual features themselves are there, but the thing is implied is that Siri Classic will give you a more rudimentary implementation of the feature that does not use AI?
1
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@mysk@mastodon.social Does setting the Siri version to Siri Classic perhaps function more as a global "I don't want to use AI" setting?
1
2
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
Ah, lovely. In case you were a uBlock Origin user who had rules that they've built up over the years, you can now no longer access these rules, because you can't access the uBlock Origin GUI anymore. For your safety. And no, even from a terminal, those rules aren't stored anywhere in a human-readable form. You'll need an extraction script. If you run this on your uBlock Origin directory (e.g. ~/Library/Application\ Support/Google/Chrome/Default/Extensions/cjpalhdlnbpafiamejdnhcphjbkeiagm), you'll get a user-filters.txt file that has your rules. Which you can import into uBlock Origin on a browser that doesn't have contempt for you. I pretty much hate computers.
gist.github.com
6
1
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
As does Kimi It's clear that any AI provider that doesn't admit (or make up) news that they hacked real-world parties, that's apparently evidence that their product is inferior.
wired.com
4
4
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
Meh. Looks like this workaround is finally dead. That is, one can make the radio button clickable by making this edit. But clicking it now does nothing. Time to find a new primary web browser, I suppose. 😕
4
2
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Saw The Odyssey over the weekend. Was a pretty good example of the type of epic fantasy film. Several people I invited to come along backed out saying that they were waiting to see it on IMAX. Of course I had to be the person to bring up that the closest IMAX screen is 4.5 hours away. (Look up "LieMAX" if you want to read about the nonsense you've been led to believe) If you have an actual IMAX nearby, sure, go ahead and pop for it. If not, then just go see it on a normal screen. I can count the number of times that I wished for a more-square aspect ratio while viewing this film on zero fingers.
4
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
If we look at the driver permissions, it turns out it actually is a vulnerable driver, as anybody can tickle any of the ioctls. So if anybody already had this driver on their system (which might be named DCRCVDrv.sys), then it is indeed a driver that introduces a vulnerability. The term "BYOVD" is complete nonsense, as if an attacker is bringing their own driver, it doesn't need to be vulnerable. It's a BYOD attack. Vaguely interesting is that with this driver, Ghidra actually did a better job of decompiling the vulnerable code than IDA did. IDA: Take the ioctl, subtract 0x220540, then subtract 4, then subtract 4, then subtract 4, then subtract 4, then subtract 0x34, and then if you're left with 0x3C, run the function. Ghidra: If the ioctl is 0x2205c0, run the function.
3
0
1
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
OK, this stuff doesn't work at all. Time to exercise my "100% money-back guarantee". 🤦‍♂️
2
3
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@MLE_online@social.afront.org It's unfortunate that the only way to find out how long a film is, is to watch it.
1
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@drewdaniels@mastodon.online I feel like just about any of the concerns about CVE would also apply to as well. 🤷‍♂️
1
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 1mo ago
Replying to
@sambowne@infosec.exchange Maybe this will teach Americans that not using a bidet is both disgusting but also cost-ineffective? 😂
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
I'm old enough to remember when Google helped you find websites to go to. It was indeed better than HotBot, which was pretty decent. https://www.theringer.com/2026/08/04/tech/google-search-ai-internet
theringer.com
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@NebulaTide@mastodon.bsd.cafe I'm pretty sure that happened last year.
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@xabean@infosec.exchange My neighbor says that a deer can jump an 8-foot fence from a standing start. So I guess it all depends on how determined it is.
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 1mo ago
Washington Post editor: Maybe we should find a picture of Susan Collins where the fotographer's finger isn't partly covering the camera lens? Their boss: Just ship it.
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
As opposed to the recent purple tomato, which is very purple, all the way through. Due to genetic shenanigans in a lab with a snapdragon flower.
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@johnmark@freeradical.zone Coffee also doubles as fertilizer! 🎉
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 6d ago
Replying to on chaos.social
@christopherkunz@chaos.social I feel like what I've read has been telephone-gamed far enough away from facts to really know what's going on.
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@da_667@infosec.exchange I suppose if you can predict getting sacked by an ICE goon, go ahead and hold volume-up and power for a few seconds on an iPhone. Or press power 5 times. Biometrics will be disabled at this point.
0
2
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@ajn142@infosec.exchange @mysk@mastodon.social Yeah, I suspect I'm using Vanilla. At least, that's what's selected by default when I go to flavors. (Though it still asks me if I want to use vanilla there for some reason 😂)
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange @FritzAdalis@infosec.exchange This was an original confusion of mine when trying out Mastodon for the first time. In the most popular web browser in the world, how does one add a bookmark for a site? You click the star icon. It's hard to dissociate "star" and "bookmark" if you're a person who has used a web browser.
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 1w ago
Replying to
@GossiTheDog@cyberplace.social
0
0
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2mo ago
Replying to
@joshbressers@infosec.exchange If possible, I plan to eat some venison jerky, while making direct eye contact.
0
1
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 3w ago
Replying to
@ajn142@infosec.exchange @mysk@mastodon.social Hm, that's very different than what I see. I click the "add image" button and I get a pop up where I can pick where from.
0
2
0
0
Open post
Will Dormann @wdormann@infosec.exchange
· 2w ago
Replying to
@scrutinizer@social.vivaldi.net
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:06:15 UTC