Elektrine lite

← Feed

Max Maass :donor:

hacksilon@infosec.exchange

<p>Sr. Security Specialist at iteratec // <span class="h-card" translate="no"><a href="https://infosec.exchange/@seemoo" class="u-url mention">@<span>seemoo</span></a></span> alumni // Member of CCC // Crypto means cryptography.</p><p>tfr.</p>

Posts

  • Post #4275400

    Sneaky.

  • Post #4145488

    @splicer@makersocial.online I have a switch in my #homeassistant that’s literally called „haunted house“, which turns on and off those automations that may be confusing to guests. As a bonus, it does this when triggered from my wall tablet (sound on).

  • Post #4131807

    Looks like #adform got compromised. It is shipping a malware-laced tracking script that is replacing crypto wallet addresses in the users clipboard. Recommend disabling adform includes in your websites. Sample: https://gist.github.com/malexmave/8ef5eabc7b6866698f1ea8a811c75b57 Analysis by Claude: https://claude.ai/share/5c751f9c-2bae-4835-8dff-fcbebf66d5dc #threatIntel

  • Post #2139809

    Someone wrote a viral article claiming that Claude installs Spyware on your computer. The technical observation is real, but the threat is not. I took a closer look, and I would argue that the real issue with the Claude extension is somewhere else entirely, and I&amp;#39;ve seen little discussion on it: Matt Hand at Origin found that the extension actually allows almost *any* software on your machine to control your browser. I wrote it up as an example for how threat modeling can be helpful in...

  • Post #2139808

    @bms48 That is correct, and it did not attempt to do so. Does every article that touches Anthropic need to recap and refute every single criticism of anthropic now, even if it is irrelevant to the issue it is discussing?

  • Post #2139807

    @bms48 You are entitled to that opinion. The technical implementation does not care about the sociocultural context of Anthropic, and that was the focus of the article. Refuting incorrect claims about a technical implementation does not imply a defense of the behavior of the company.

  • Post #891908

    I never understood the concept of Moltbook - why create a social network for AIs to talk to each other when there&amp;#39;s already LinkedIn?

  • Post #891907

    RE: https://fosstodon.org/@homeassistant/116295601825508570 Me: „oh, I wonder if they got the cryptography right. Might take a look.“ Blog: „…audited by @trailofbits...“ Me: „alright, nevermind, it’s going to be good, no need to check.“

  • Post #890048

    RE: https://fosstodon.org/@SocketSecurity/116285042551834755 Socket has been consistently providing helpful writeups of the recent supply chain attacks. Very good signal to noise ratio, and worth following if you are struggling with figuring out the effects of the latest supply chain incidents.

  • Post #890041

    RE: https://fosstodon.org/@SocketSecurity/116321614885038368 2020: the best thing you can do for security is have a bot automatically update your dependencies. 2026: the best thing you can do for security is to tell your bot that updates dependencies to wait a day or three before updating them. Expect more of this over the coming months as compromised credentials from previous supply chain attacks are used to mount new ones.

  • Post #808562

    Der Antennenhirsch als selten gesehener Verwandter des #Datenelch, gesichtet in Regensburg. @linuzifer @lnp

  • Post #755097

    For the #selfhosted / #homelab people running #Hister (https://github.com/asciimoo/hister): you should update to version v0.4.0 ASAP. I reported a vulnerability in the previous version that allows any website to download your entire database due to missing CORS enforcement. The author responded very quickly to the disclosure and had a new release ready within a few hours, excellent work on his part. Sadly, Hister is currently not packaged and does not auto-update, so people will have to manuall...

  • Post #728735

    Jury is still out on whether I can get used to the #ZSA #Voyager keyboard, but one thing is already clear: their software is great, and their customer support is absolutely fantastic.

  • Post #728732

    #Trivy got compromised on thursday and released a backdoored new version, which was rolled back. We spent the entire friday in incident response mode. Now they got compromised again over the weekend. I have a lot of sympathy for people under pressure during an incident, but for fucks sake, having a security tool get compromised three times within two months is just completely bonkers. We spent more time remediating security issues caused by our security tooling than any other cause. And the fac...

  • Post #679473

    Is one month without a new war too much to ask for? 😫

  • Post #679471

    So, what is the #Sanderson equivalent to „slashdotted“? I nominate #Sandstorm. (New crowdfunding campaign by Brandon Sanderson just launched and took down #Backerkit)

  • Post #679470

    Great merch at #KeycloakDevDay. #keycloak #zerotrust

  • Post #679462

    Tempted to call the motion detector in my office „senpai“ because it frequently doesn’t notice me 😫 #HomeAssistant