cynicalsecurity :cm_2:
cynicalsecurity@bsd.network
<p>IT Security, cynically aged. Maths. Some nukes. Four languages. Longing for Symbolics and Connection Machines. Keeper of Ancient Computing Lore. Ⓐ</p>
Posts
-
Post #3956878
OK, these #Protectli systems are getting on my nerves. Can anyone suggest a reason why they would not cold boot into #OpenBSD unless the serial console cable is connected *and* live (i.e. I actually connect both ends of the cable)? They reboot fine, but cold boot hangs until I connect a serial cable. The Protectli runs Coreboot and is set to use the serial console.
-
Post #3696211
Should anyone need to be reminded, once again, from someone who has been doing offensive security for 40yrs: we hack the endpoints, we have always hacked the endpoints, we shall continue doing so. Why? It is this incredibly simple concept called ROI, return on investment, it is cheaper, much cheaper, to get the endpoint. Whether it is the phone, the app, the headphones, the microphone, the user being socially engineered. Nobody in his sane mind wakes up and goes "we need to crack the doub...
-
Post #2493695
Will you please stop wasting time on Mythos-associated FUD and try to understand that you need to build reliable and dependable software, not stuff which changes weekly, to get security? Mythos &amp; LLM only bring breadth and depth to automated searching, they find nothing conceptually new, if no-one had come up with buffer overflows there would be no buffer overflows coming out of Mythos. There will be a flood of issues, as if suddenly thousands of people were dedicated to finding bugs,...
-
Post #2235427
My Unix Archive mirror was slaughtered by LLMs overnight, it is on a 10G link, they were taking over 1Gbps in requests to the same files over and over again. I have Geo-blocked the whole of the US to stop them (with PF). This is ridiculous.
-
Post #1758656
I have to say the #OpenBSD patch 031¹ is rather subtle… I wonder how it was discovered. :flan_hacker: __ ¹ https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/031_pgrp.patch.sig
-
Post #1746164
So, I was recently involved in the IR for a cloudy cloud issue… and thinking it over I realised that the attackers really haven&#39;t moved into the LLM age. Why do attackers against M365 actually _look_ for files so that they land in the logs? If they have obtained valid credentials then they can use Copilot, set it to the whatever-it-is-called-not-Web mode, and go and hunt. They could even use a &quot;Research&quot; agent to find which documents the user has access to which conta...
-
Post #1653804
Is there a _good_ course on Azure forensics I can attend? Serious question, please don&#39;t reply with &quot;Meditation&quot; or &quot;Become a Monk&quot;, etc. :flan_despair: P.S. Please not a beginner&#39;s course, assume I&#39;ve been messing around in Unix kernels since 1986 and have a pretty decent forensic skill set in civilised operating systems and networks. I just appreciate the subtleties of the VMS heritage of the NT kernel but little above it :)
-
Post #1405382
An interesting research paper on bitflips in SRAM: Laurent Pichon. Laurent Le Brizoual, Edna Ferrucho Alvarez, Ludovic Claudepierre, "Electrical modelisation of a bitflip in SRAM cell memory induced by laser fault injection"¹, Microelectronics Reliability, Vol. 179, April 2026. An electrical model of the bitflip in SRAM under laser illumination simulating laser fault injection is proposed. This model is based on a bipolar phototransistor responsible of the amplified induced photocurr...
-
Post #1029181
Lessons learned from the Artemis 2 mission: 1. some genius thought sending Outlook to space was a good idea, 2. some other genius thought that Bluetooth in space was a good idea, 3. plumbers are in demand, even in space. :flan_molotov:
-
Post #468288
A colleague and good friend of mine, with whom I have worked for 32 years (seriously), is looking for a job in one of The Netherlands, Belgium, Germany and Switzerland. They are fluent in English, German and Dutch, speaks French too! German nationality. They have been managing complex IT projects for decades, are an excellent programmer and used to managing large development teams. Was doing &quot;agile&quot; when it was still called XP and pair programming (I used to make fun of them...