Elektrine lite

← Feed

Max Maass :donor:

hacksilon@infosec.exchange

<p>Sr. Security Specialist at iteratec // <span class="h-card" translate="no"><a href="https://infosec.exchange/@seemoo" class="u-url mention">@<span>seemoo</span></a></span> alumni // Member of CCC // Crypto means cryptography.</p><p>tfr.</p>

Posts

  • View post

    Yes! Go #Spectrum! #IsarAerospace

  • View post

    Sneaky.

  • View post

    @splicer@makersocial.online I have a switch in my #homeassistant that’s literally called „haunted house“, which turns on and off those automations that may be confusing to guests. As a bonus, it does this when triggered from my wall tablet (sound on).

  • View post

    Looks like #adform got compromised. It is shipping a malware-laced tracking script that is replacing crypto wallet addresses in the users clipboard. Recommend disabling adform includes in your websites. Sample: https://gist.github.com/malexmave/8ef5eabc7b6866698f1ea8a811c75b57 Analysis by Claude: https://claude.ai/share/5c751f9c-2bae-4835-8dff-fcbebf66d5dc #threatIntel

  • View post

    Someone wrote a viral article claiming that Claude installs Spyware on your computer. The technical observation is real, but the threat is not. I took a closer look, and I would argue that the real issue with the Claude extension is somewhere else entirely, and I&amp;#39;ve seen little discussion on it: Matt Hand at Origin found that the extension actually allows almost *any* software on your machine to control your browser. I wrote it up as an example for how threat modeling can be helpful in...

  • View post

    @bms48 That is correct, and it did not attempt to do so. Does every article that touches Anthropic need to recap and refute every single criticism of anthropic now, even if it is irrelevant to the issue it is discussing?

  • View post

    @bms48 You are entitled to that opinion. The technical implementation does not care about the sociocultural context of Anthropic, and that was the focus of the article. Refuting incorrect claims about a technical implementation does not imply a defense of the behavior of the company.

  • View post

    I never understood the concept of Moltbook - why create a social network for AIs to talk to each other when there&amp;#39;s already LinkedIn?

  • View post

    RE: https://fosstodon.org/@homeassistant/116295601825508570 Me: „oh, I wonder if they got the cryptography right. Might take a look.“ Blog: „…audited by @trailofbits...“ Me: „alright, nevermind, it’s going to be good, no need to check.“

  • View post

    RE: https://fosstodon.org/@SocketSecurity/116285042551834755 Socket has been consistently providing helpful writeups of the recent supply chain attacks. Very good signal to noise ratio, and worth following if you are struggling with figuring out the effects of the latest supply chain incidents.

  • View post

    RE: https://fosstodon.org/@SocketSecurity/116321614885038368 2020: the best thing you can do for security is have a bot automatically update your dependencies. 2026: the best thing you can do for security is to tell your bot that updates dependencies to wait a day or three before updating them. Expect more of this over the coming months as compromised credentials from previous supply chain attacks are used to mount new ones.

  • View post

    Der Antennenhirsch als selten gesehener Verwandter des #Datenelch, gesichtet in Regensburg. @linuzifer @lnp

  • View post

    For the #selfhosted / #homelab people running #Hister (https://github.com/asciimoo/hister): you should update to version v0.4.0 ASAP. I reported a vulnerability in the previous version that allows any website to download your entire database due to missing CORS enforcement. The author responded very quickly to the disclosure and had a new release ready within a few hours, excellent work on his part. Sadly, Hister is currently not packaged and does not auto-update, so people will have to manuall...

  • View post

    Jury is still out on whether I can get used to the #ZSA #Voyager keyboard, but one thing is already clear: their software is great, and their customer support is absolutely fantastic.

  • View post

    #Trivy got compromised on thursday and released a backdoored new version, which was rolled back. We spent the entire friday in incident response mode. Now they got compromised again over the weekend. I have a lot of sympathy for people under pressure during an incident, but for fucks sake, having a security tool get compromised three times within two months is just completely bonkers. We spent more time remediating security issues caused by our security tooling than any other cause. And the fac...

  • View post

    Is one month without a new war too much to ask for? 😫

  • View post

    So, what is the #Sanderson equivalent to „slashdotted“? I nominate #Sandstorm. (New crowdfunding campaign by Brandon Sanderson just launched and took down #Backerkit)

  • View post

    Great merch at #KeycloakDevDay. #keycloak #zerotrust

  • View post

    Tempted to call the motion detector in my office „senpai“ because it frequently doesn’t notice me 😫 #HomeAssistant