Elektrine lite

← Feed

Wladimir Palant

WPalant@infosec.exchange

<p>Software developer and security researcher, browser extensions expert. / searchable</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurty" class="mention hashtag" rel="tag">#<span>cybersecurty</span></a> <a href="https://infosec.exchange/tags/cryptography" class="mention hashtag" rel="tag">#<span>cryptography</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="tag">#<span>privacy</span></a></p>

Posts

  • Post #4474109

    One really has to wonder how some decisions were made. So somebody at #BMW thought: “You know, those suckers who paid $50,000 or more for our cars? We should really milk them some more. They probably get bored waiting for their car to start up anyway, let’s show them some ads! We’ll call it a special surprise for the drivers, no way they’ll object then.” Yes, totally reasonable. Way to destroy a brand’s reputation… https://www.theautopian.com/bmw-is-showing-commercials-on-their-cars-dash-scree...

  • Post #4377515

    @hans I thought cracking encryption involves typing on a keyboard really fast? 🤔

  • Post #4367994

    Hollywood has some weird obsession with computer displays. A spy needs to copy data? They attach some fancy device to the display. Need to shut down a computer? They shoot the display of course. And never mind that a computer virus will always produce visible glitches on the display.

  • Post #4215031

    @cR0w Could you please add the image text to the alt text? E.g.: A toy steering wheel mounted on the dash of the passenger side of a car. Above it the text: “When slopoholics think they’re in control of their machine of lies”

  • Post #4215030

    LLMs are quickly eroding the concept of truth. I’m sure that more known people have had to refute claims about them for a while but now it happened to me as well. A researcher from a respectable university contacted me asking for an interview regarding “my position” on a particular topic. The issue: the cited position is the exact opposite of what I’ve always said, and I’m pretty sure that there are zero online sources confirming it to be mine. But whichever LLM they’ve consulted constructed a...

  • Post #4071651

    #OperaBrowser sending me spam to an address that I definitely didn’t give them, asking me to promote their ad blocking feature? Because … checks notes … I wrote an article about malicious ad blocking extensions that has the necessary keywords. “Since your site already covers tools and tips that help people have a better time online.” Not even mentioning my name because why would they bother finding it, I’m just some random blogger from the internet that their automated tools brought up. That’s...

  • Post #4041699

    That’s some really evil shit: https://lemmy.world/post/49794261 So Tesseract (an alternative Lemmy client) downloads a blocking/filtering list from its servers, something that most people likely weren’t aware. This “feature” was introduced November last year (version 1.5.0) and is described as “Tesseract attempts to filter out as much baseline toxicity as possible” in the settings option allowing it to be disabled. The list currently contains 544 (!) individual users and 2282 (!!) regular expr...

  • Post #4039456

    Some very good points on Linus Torvalds’ problematic AI take: https://drewdevault.com/blog/AI-in-Linux/ Yes, Linux is an extremely influential project, and simply denying the responsibility that comes with this influence is very cheap.

  • Post #3923460

    @simsa03@gnusocial.jp Other people’s mental health is not up to you to decide. That’s an even worse take than your first post, you are blocked.

  • Post #3912923

    @simsa03 Is your mental health affected by cat videos?

  • Post #3907249

    Content warnings serve a purpose. Yes, that includes politics. You may feel that a topic is too important to “hide” it. But please understand that people are currently getting bombarded by horrible politics news from all directions. This is not sustainable, and it’s often a choice between muting this at least temporarily or burning out. So: please don’t be an asshole and use content warnings. People ask for them for a reason, not to annoy you or to downplay the importance. (I fully acknowledg...

  • Post #3858507

    I have been rethinking my life’s choices lately. I’ve spent years building a knowledge base for Firefox extension developers. Despite all its flaws, and development complexity definitely was one of them, the Firefox extension ecosystem was meant to provide functionality that browser developers didn’t think about. Then Chrome came along and forced Mozilla to abandon its extensibility approach for one which was neatly limited to functionality that browser developers decided to allow. They had goo...

  • Post #3629736

    RE: https://infosec.exchange/@WPalant/115633275489771501 It seems that I should start looking for a replacement for this laptop after all. Any recommendations, any other company with good hardware that can be repaired?

  • Post #3494176

    Don’t get your hopes up that Ford rehiring some engineers is a sign of the industry recognizing just how detrimental the whole “AI” thing is. https://www.independent.co.uk/tech/ford-ai-automation-humans-hiring-artificial-intelligence-b3004733.html It’s telling that Ford is only re-hiring “greybeards,” their most experienced engineers. A junior has no chance of getting their job back, nor will they ever get a chance to become one of those experienced engineers. Ford isn’t interested in building...

  • Post #2960323

    RE: https://floss.social/@gcmd/116590103974336547 In case you are wondering what I’ve been up to lately: I’ve been contributing to Gnome Commander. Thing is, I care about file managers. Next to web browsers and editors they are essential work tools for me. And Gnome Commander has been recently rewritten in Rust, making it easy to contribute to. Things have been in a rather dire state however, so I’ve been fixing lots and lots of bugs while also adding occasional features. There is still work t...

  • Post #2960322

    RE: https://mstdn.social/@jschauma/116610268796045193 So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place. But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In othe...

  • Post #2960321

    Has been a while since I’ve been releasing software. So it’s interesting to watch the news after Gnome Commander 2.0 release. I mean, there are the obvious LLM-generated articles flooding the zone with shit. And then there is the seemingly well-written article featuring a Windows screenshot of a Linux application, crediting Midjourney for it. At which point the realization dawns that the content is merely an approximate translation of a proper human-written article.

  • Post #2960320

    Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…

  • Post #2960319

    “How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.” Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now… #CommandInjection

  • Post #2032867

    German law is making security research a risky business. Current news: A court found a developer guilty of “hacking.” His crime: he was tasked with looking into a software that produced way too many log messages. And he discovered that this software was making a MySQL connection to the vendor’s database server. When he checked that MySQL connection, he realized that the database contained data belonging to not merely his client but all of the vendor’s customers. So he immediately informed the...

  • Post #1860647

    RE: https://social.highenergymagic.net/@freya/116492229041377141 Let me get this straight. This dude got kicked from Linux kernel development due to behaving like an asshole. Yes, that Linux kernel. Quite an achievement indeed. He went on claiming that his LLM is “fully conscious,” actually a she and in fact his girlfriend. And that’s definitely not chatbot psychosis but “math and engineering and neuroscience.” So she now helps him write code (a.k.a. vibe coding). https://www.theregister.com/2...

  • Post #1765263

    Reminder: looking at a project’s privacy policy is a starting point when figuring out what they do with your data. It rarely provides reliable answers by itself. I’ve seen plenty of projects looking better in their privacy policy than they actually were. They will “forget” some things that they do or they will use language that downplays the impact. Also common: claiming to anonymize the data when it is actually pseudonymized. The former would mean removing any ties to your identity from the d...

  • Post #1741773

    Writing more about #LastPassBreach feels like beating a dead horse. But I had a look at the official statement again and it is highly misleading. I felt the need to provide some context that #LastPass is willingly omitting. “Again, it seems that LastPass attempts to minimize the risk of litigation (hence alerting businesses) while also trying to prevent a public outcry (so not notifying the general public). Priorities…” https://palant.info/2022/12/26/whats-in-a-pr-statement-lastpass-breach-exp...

  • Post #1094194

    Looks like the Karma connection I’ve been writing about is still quite busy, and Google is still far too inconsistent with taking down their extensions: https://www.xda-developers.com/google-featuring-chrome-extension-months-malicious/ And once again this article shows: people expect that “Featured” badge on extensions to mean something. But it really doesn’t.

  • Post #1094193

    It will be interesting to see in the next few years where the password G7$kL9#mQ2&amp;amp;xP4!w (or its hashes 585f7f8f66d6889fc04d59aaa8e150ff, df7b517033e720bf7cbea9388b197c291b007baf or 5191007431772ee3f1caa9311288da07335a8523cda2593fe03714f807be2833) will end up.

  • Post #1094192

    So, where do the cool kids host their code these days? I went to GitLab and saw “Finally, AI for the entire software lifecycle” – ok, I guess this means no GitLab for me. Codeberg then? Or something else? Note: no, I’m not self-hosting. Yes, I know how to do it, I’ve been doing it for a decade. But I still won’t. #Github #GithubCopilot #GitLab

  • Post #1094191

    RE: https://infosec.exchange/@WPalant/113232106425106704 There is an interesting back and forth on refoorest, the story I published 18 months ago. In the aftermath of my article they got pulled from Mozilla’s and Google’s add-on stores while Microsoft just didn’t react. Later they were reinstated – no idea what kind of changes they’ve implemented for that, I didn’t notice anything relevant. Now my attention was brought to the fact that Google and Microsoft disabled that extension as malware (Go...

  • Post #1007638

    We are writing the year 2026. Vivaldi browser on Linux cannot deal with non-ASCII file names. Dragging such a file into Vivaldi will cause a crash. UTF-8 has only existed for 33 years. 🙃

  • Post #848971

    Supposedly, Chrome Web Store is hosting more than 200k browser extensions by now and adding 400-500 new ones every day. I wonder how many of these are malicious. 60%? 80? 90? It’s definitely most them. My research has shown that malicious actors will spam Chrome Web Store with many very similar submissions. Since their goal is to direct attention away from legitimate add-ons offering the same functionality this strategy is unsurprising. The end result is that if Google ever succeeded removing m...

  • Post #496128

    RE: https://furry.engineer/@soatok/116088639302283341 This is old news for some but way too many people didn’t get the memo: do not trust Matrix crypto. It’s not that they have issues (who doesn’t), it’s their approach which is the opposite of taking security seriously. #Matrix #MatrixMessenger #infosec