Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

CMDR Yojimbosan 🅅⁂

@yojimbo@masto.hackers.town
mastodon 4.7.3
  • Open on masto.hackers.town

Infosec, Unix, IP (networking, not lawyering), Free and Open Source software.
Has folded a fitted bedsheet, at least once.
#NZ Ōtepoti/Dunedin

741 Followers
999 Following
41 Posts
Joined April 13, 2025
Signal:
Yojimbo.30
Elite:Dangerous:
Radio Sidewinder
Pronouns:
he/him
Open Hardware:
https://onerng.info
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 3mo ago
Replying to
@davidgerard@circumstances.run @oxy@social.bsdlab.au My standard response to "ethics aside ..." is to go straight into "well in the case why don't we murder all the users and steal their money? I mean, if we don't have to consider ethics ..."
22
2
4
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@davep @knoppix95 @signalapp Well, the phone number is basically the username identifier, and for normal people, that's something they can understand. Having a username/password/key system introduces a "forgot" problem that they've been able to avoid ... and that's been a good move for reducing complexity. Of course it removes a feature at the same time, but it is what it is.
11
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago
Replying to
@stefano From the Linux side, "This Docker container could have been a single binary"
14
2
3
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 3mo ago
When you use a #tag on a post, what are you hoping to happen? Go on, boost this poll, humans!

When you use a #tag on a post, what are you hoping to happen? Go on, boost this poll, humans!

4
9
25
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 3mo ago
Here's an interesting talk on Neighbourhood-First networks; not just a technical topic, but also a human process. The idea of groups of independent small servers contributing in an eventually-consistent network over multiple transports, providing services to a geographically-local area, seems very powerful. It's adjacent to #veilid of course, but lives much higher up in the network and human layers of the stack. https://www.youtube.com/watch?v=kCbzHfKjTDs
3
0
4
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago

Some journalism in #nz is still critical, important, and detailed.

https://thespinoff.co.nz/kai/27-03-2026/all-170-chip-flavours-in-new-zealand-ranked-from-worst-to-best

masto.hackers.town
7
0
9
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 7mo ago
Replying to
@petergleick@fediscience.org Ah, look, there's the mistake :- "The AI models ... produced around 780,000 words describing the reasoning behind their decisions." No, they produced 780,000 words that looked statistically similar to what a human might have said under the same circumstances.
9
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2mo ago
Replying to
@ZenHeathen@beige.party @currentbias@zeroes.ca Or, we're going to get a rise in diagnoses of ADHD that didn't manifest in childhood, for example.
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2mo ago
Replying to
@bluetea@ioc.exchange Part of the problem is that these "learning" things are ineffective and expose a company's attitudes towards its staff more sharply than usual. I have to schedule these for my small $dayjob, and every year I go looking to see if there's a better supplier, and every year I get disappointed. I don't have the time to produce them myself and very few people sell a system that allows you to mix their content with your own local stuff, sadly.
1
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2mo ago
Replying to
@bluetea@ioc.exchange Hey, they fill up the compliance audit checkboxes, so they're working just as intended ...
1
3
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2mo ago
Source code is fundamentally language for a human to talk. To get a computer to understand it takes a whole bunch of important extra steps. Having agentic LLM fill the source code up with slop to the stage that humans cannot understand it any more might "work", but it's changing the purpose of the source code without explicitly negotiating that as a feature. Once you have large-scale LLM generated code, you're unmaintainable by humans any more.
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@lightweight @JulianOliver @ggpsv One complaint on a quick skim is that you didn't say that using "FROM ubuntu:latest" was being done in order to give your example container the highest chance to break out :-) Down near the bottom of the page you discussed running a slim image because of course you know that "FROM scratch" is hardest and best. I think it probably should have been emphasised at the beginning :-)
3
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago

TP-Link fireware is a gift that keeps on giving.

https://mrbruh.com/tplink/

TL;DR an undocumented command in the CLI calls out to a TFTP server and trusts whatever is provided because really, why wouldn't you?

Now, of course you need to be authenticated in order to get to the CLI like this; but you gain more control over the machine by exploiting it.

mrbruh.com

Finding a RCE in my old TP-Link router

How I found a remote code execution vulnerability in my old router because I was bored.

3
4
2
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago

This is your last opportunity to grab the latest Hackers Town Tshirt. Go to https://www.customink.com/fundraising/always-be-n00bin and pick up @prahou@merveilles.town's design for The Fool, reminding you to Always Be N00bin'.

This isn't only for people who use the Hackers.Town fediverse server (although that's where the money will be going, to our hosting expenses), it's for anyone who understands what we're talking about!

customink.com
4
0
7
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 3mo ago
Replying to
@SheHacksPurple@infosec.exchange I "stole" our data centre's security camera system, without being recorded by the camera system. (actually i only took one camera away, but had mapped the room to prove that this created a blindspot for the next camera, etc) And I did this without using my other unrecorded power, the admin account on the camera system server itself.
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 7mo ago

Hey #hackerstown ... (and non-hackerstown peeps too, you're all welcome)

It's fundraising time for our instance, we're not charging users for the service but we do like to be able to pay for it :-)

This time around we have a fantastic design from @prahou@merveilles.town's Analog Nowhere, The Fool to remind you to Always Be N00bin' - new experiences and new perspectives help us all hack better.

https://www.customink.com/fundraising/always-be-n00bin

masto.hackers.town
4
0
7
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@knoppix95 @bonkers @davep @signalapp I understand what you're looking for - anonymity comes when you chose your own username/identifier. However, anonymity wasn't a design goal for Signal, and probably still isn't. In the case of anonymity, it's often "lose your phone, lose your identity", and that isn't easy for the mass public audience. There's nothing wrong with anonymity :-) it's a great goal.
2
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 4mo ago
Replying to
@DLink@posthat.ca Honestly those boxes are what convinced me to get started with this whole thing :-) it just kept costs down so low in a sensible way. I still leave the header pins and battery lead in the box unused as well!
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 4mo ago
Replying to
@isaacfreeman@cloudisland.nz @lightweight@mastodon.nzoss.nz Y'all know we want to see $pricing$ :-) And of course a description of how you balance admin oversight of the platform with user privacy desires. My biggest desire is "full transparency"; i.e. it may be acceptable for you to see my photos in immich for example, but I'd want to see an audit trail so I can know when it happens and be able to ask you why.
1
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 4mo ago
Replying to
@kleptones@mastodon.social Hey, there's a volume control on the web page player!
1
3
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@tychotithonus@infosec.exchange "Here's some minified code so you can't see how it works" was a class move.
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@dch@bsd.network @kusuriya@masto.hackers.town Astral's rewrite is, in the same way, also very welcome. Still, no-one really tells us what the potential consequences of "rmmod algif_aead" might be :-)
1
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 9mo ago
Replying to
@parisba@cloudisland.nz @stilgherrian@eigenmagic.net or @josephcox@infosec.exchange Something you might want to poke at?
3
1
2
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago
Replying to

@Larvitz ssh should not be facing the Internet these days for the vast majority of users, even though by default it usually makes secure choices (like, no root user and keys instead of passwords). Your VPS should come with console access, which can be used for initial configuration and emergency access. You can then choose to set up management access via some separate network, probably a VPN.

1
2
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 15mo ago
Replying to
@funcrunch@me.dm Booksmith's list of alternative suggestions: https://www.booksmith.com/NotHP
booksmith.com
0
0
2
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@dch@bsd.network @kusuriya@masto.hackers.town copy.Fail is an interesting vuln, but the Xint description and PoC for it is ... not very well put together. You might get more info out of looking at https://github.com/rootsecdev/cve_2026_31431 instead. The size of the wrapper around the exploit isn't really something to brag about, and shipping a minified PoC is pretty impolite.
GitHub

GitHub - rootsecdev/cve_2026_31431: Exploit POC for CVE_2026_31431

Exploit POC for CVE_2026_31431. Contribute to rootsecdev/cve_2026_31431 development by creating an account on GitHub.

0
2
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2mo ago
Replying to
@jernej__s@infosec.exchange @niconiconi@mk.absturztau.be This is still my natural typing habit, and one of the reasons I get disappointed with almost every "Markdown" flavour out there ...
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 4mo ago
Replying to
@bagder@mastodon.social I was very tempted by sqlite ... on all the Androids for example, but not on Windows by default. OpenSSL is out, because there are other implementations. libz follows closely on a general-purpose OS and anything with web; but libcurl covers protocols other than HTTP; FTP and friends have been around for a lot longer, and there are a lot of IoT devices ...
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@openculture@toot.community Perhaps because Poe was an American author, I was attracted more to Christopher Walken's version. Although I was disappointed it wasn't a mashup of all three reading together like the post suggested!
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago
Replying to
@crmsnbleyd@hachyderm.io What sort of languages & things are you interested in the most? e.g. "rust and GUI apps" "C and OpenBSD" ... ?
0
2
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2w ago
Replying to
@valorin@phpc.social I feel like this could be a client preference, rather than a supplier decision, which raises the engagement complexity of course. And management still like to have "reports" regardless of how the actual work is being performed. For my small $dayjob, I like findings to be separate tickets that Security can track the state of; but I would prefer to make the whole report available to any internal dev, because vulns might not be independent of each other, they get more context I hope.
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@xurizaemon@toot.cafe What was that? Some random cultural-misappropriation based on how well Mark Shuttleworth got away with "Ubuntu"? (until you realise that being from SA there's a reasonable chance he knew the original word in its original context?)
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@xurizaemon@toot.cafe My meshtastic repeater is indeed still alive, but as it's outside I rarely connect to it with a UI, so .. I have no idea what it looks like :-) the t1000e hasn't been charged for weeks, I need to go looking for the cable ... and actually, the device, too ...
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 6mo ago
Replying to
@Larvitz You're not wrong; and an exposed ssh port has been ubiquitous for many yeahs, so it makes for a good example. These days I tend to argue the other way around - the host firewall should be involved in blocking outbound traffic as it's primary job. There's no need to block inbound traffic, as there should be no services on "unwanted" ports. Network-level firewalling is a different beast though.
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 7mo ago
Replying to
@Edent@mastodon.social I found one the other day claiming only 6 ... Google, LinkedIn, Microsoft, Meta, IBM, Cloudflare. Then I tried to register an account, and they requested KYC via Persona. I had to email their support team to get them to delete the account in the end, because I couldn't do it myself ... So does that count as "over 1000"? :-)
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 5mo ago
Replying to
@zebratale "Meta and Google ignore us, so why bother trying to get anyone else to pay attention?"
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 4mo ago
Replying to
@kleptones@mastodon.social But, slightly oddly, there's an intra-track gap being introduced, which is a shame when many of your own albums are recorded for gapless playback. Is that a deliberate papercut left in place to encourage people to buy and run through their own players? :-)
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2w ago
Replying to
@valorin@phpc.social Ah, so in this context you're the one producing the report? We have one provider who currently does automated testing & their platform stores the results/vulns; these can be collected as a single report or farmed out individual tickets if we give them a route to do so. It's a little frustrating, because the individual vuln can benefit from things like the scope statement, which are only in the bigger document. And the devs don't have a way to get creds on the supplier's system easily.
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 3mo ago
Replying to
@petrillic@hachyderm.io @soatok@furry.engineer Probably the otherwise is "don't say it online".
0
0
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 2w ago
Replying to
@valorin@phpc.social From whom are they being protected? Who is the target audience for a report? I've seen places where "the report" goes only to Security, who then drip-feed demands for fixes to be performed around the business. I feel they'd like more restrictions. I'd prefer to dump the whole report on the technical people in one go, allowing the full "devsecops" response to find workarounds if they're quicker than fixes.
0
1
0
0
Open post
CMDR Yojimbosan 🅅⁂ @yojimbo@masto.hackers.town
· 1w ago
Replying to
@chadmccullough@mastodon.bsd.cafe @elementary@mastodon.social Which BSDs are actually avoiding LLM contributions? I haven't done much research yet ... ?
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:15:11 UTC