Elektrine lite

← Feed

Raphaël Vinot

rafi0t@social.yoyodyne-it.eu

<p>I have various notes about the French administration.</p><p>I also write code and stuff.</p>

Posts

  • Post #3626207

    Hey, quick question for the #infosec folks: are you still using securelist.com (the Kaspersky blog)? And if yes, have you looked at your traffic when you browse it? I just added support for websocket traffic on #lookyloo and it is pretty insane. They use yandex webvisor and afaict, the WS session calls home and sends enough data to replay your whole session (mouse movment, scrolling, ...), on top of everything they can get about your browser. Example: https://lookyloo.circl.lu/tree/7849cb0d-ae...

  • Post #2851262

    I find it so absolutely hilarious and on brand that the whistleblower in the Edouard Philippe embezzelment case is franco-german. https://www.radiofrance.fr/franceinter/podcasts/l-info-de-france-inter/le-maire-du-havre-edouard-philippe-vise-par-une-enquete-pour-detournements-de-fonds-publics-5402614

  • Post #2760436

    maybe pushing code as quickly as possible with zero domain knowlege and ignoring all existing research is not the best idea after all it&amp;#39;s hard to tell but clearly there is not way to know

  • Post #2715505

    OH yesterday from a non-tech person, at a tech event: &amp;quot;I was at the local chapter of the MEDEF (french bosses union) and we did a poll with our member asking if using AI increased their benefits, and ~70% said no.&amp;quot; With a very strong undertone of &amp;quot;WTF nerds?&amp;quot;

  • Post #2715504

    RE: https://infosec.exchange/@lcamtuf/116517194178120536 This, but on everything, with whichever AI gave free token that day, and nobody bother paying for an audit. That&amp;#39;s software dev right now.

  • Post #2715503

    RE: https://infosec.exchange/@lerg/116524161473318491 To every techie lolsobing at &amp;quot;HR is writing code, we&amp;#39;re all gonna die&amp;quot;: maybe we should have thought about it before now. We&amp;#39;ve been fighting tooth and nails since forever to make sure that there would be no regulation whatsoever on writing software. So wen we do a terrible job, it doesn&amp;#39;t have any bad repercussion (on us). The consequence is that for everyone else, software is kinda shit, and more...

  • Post #2715502

    Just heard Michael Moore (Anthropic) on Planet Money saying that with their cyber cyber tools and best practices, they can *assure* to fine all the bug before the code goes to prod. I&amp;#39;m looking forward seeing them being sued because they didn&amp;#39;t.

  • Post #2715501

    In todays&amp;#39; AI PRs fun: &amp;quot;here is a thing, I tested it against mock data, so you should test it against real data before merging it.&amp;quot; The non-mock data is public (the mocked data isn&amp;#39;t, amusingly enough), it is just that they cannot be arsed to do more than the prompt. (the code is simple, and by looking at it, I&amp;#39;m pretty sure it will most probably work, but folks, at least try)

  • Post #2715500

    Bon, la TBM vous êtes sympa, mais 3 interruptions de traffic sur le tram sur les 4 derniers jours, ça va pas le faire. Sans compter l&amp;#39;augmentation des tarifs, et avec la fermeture du pont de pierre tout l&amp;#39;été...

  • Post #2529685

    well, at least, if your bank website is responding right now, it&amp;#39;s probably really your bank. #cloudflare

  • Post #1980981

    RE: https://infosec.exchange/@da_667/116518148479614779 The safest day on the internet in recent memories was when cloudflare shat itself and all the phishing sites were down.

  • Post #1442337

    Oh FFS seems the website for ANTS (National Agency for Secured Documents) was letting you get data from another user by just changing the ID in the request. 19M accounts leaked (~1/3 of the french population). Also, if that&amp;#39;s how it worked, how the fuck can you not notice it for long enough that the attacker was able to get everything. This is 🥖excellence francaise🥖 for you all. https://frenchbreaches.com/blog/fuite-massive-a-lants-jusqua-19-millions-de-donnees-sensibles-exposees (FR...

  • Post #1134371

    Welp, les Francais, si vous avez utilisé SOONCARE de YMED avant le 2026-04-06, tout est dans la nature. Ce qui est rigolo, c&amp;#39;est que ce messge clairement automatique ne mentionne pas sooncare, donc sans fouiller, aucune idée de ce qui a été poppé...

  • Post #968581

    RE: https://mastodon.ar.al/@aral/116330105563818936 oh, we can tell.

  • Post #910564

    Seems we&#39;ve reached the plot point &quot;hero left behind enemy lines&quot; of Wag the dog?

  • Post #860127

    In case you missed, you can bet on murder*. *offer only available for countries where the C-Suite doesn&amp;#39;t live https://www.404media.co/with-iran-war-kalshi-and-polymarket-bet-that-the-depravity-economy-has-no-bottom/

  • Post #860126

    Todays cursed mimetype: text/plain; charset=gzip+enc wat

  • Post #860124

    Not everyone need to learn to code. Especially when &amp;quot;learn to code&amp;quot; means &amp;quot;prompt an AI&amp;quot;.

  • Post #860123

    So. Hear me out. The existence of a &amp;quot;dignified transfer&amp;quot; implies an &amp;quot;undignified transfer&amp;quot;, where they kick the coffin down the staircase. I don&amp;#39;t make the rules.

  • Post #860122

    RE: https://vmst.io/@vmstan/116200819973767850 Hahaha

  • Post #860121

    Not sure if it is a bug, but surely it is confusing. If you run tor and require a specific country code for the exit node, with strict node to 1 (--ExitNodes {&amp;lt;CC&amp;gt;} --StrictNodes 1) it will properly raise an error if the CC in invalid (say FOO), but if the CC exists *and* and there are no exits in that country, it will simply fallback to whatever, without any warning.

  • Post #860120

    RE: https://indieweb.social/@Outpost/116251600317479260 so hmmm maybe people take note.

  • Post #278700

    This is nothing newsworthy but dataset 9 from the recent dump is still changing. Today, they updated EFTA00173201 and *unredacted* Leslie Groff and Leslie Wexner name &amp;amp; face and Karyna Shuliak name. And for the nerds, you should know that the `last-modified` HTTP header in the response when you GET a file is accurate.