Elektrine lite

← Feed

redsakana

redsakana@infosec.exchange

<p>I think X.509 and Kerberos are pretty good actually—compared to many of the alternatives on offer.</p>

Posts

  • Post #3834880

    The domain for Molly (a Signal fork), molly.im, expired and based on Github discussions it took something like 48 hours after payment and manual intervention by the registrar to get the registry to reinstate it. I don&#39;t have have any inside info here but sounds like the .im registry is not a particularly serious operation.

  • Post #3782537

    @nina_kali_nina@tech.lgbt If interested in reading more about this topic I recommend Miwa Kentarō&#39;s (三輪 健太朗) excellent マンガと映画ーコマと時間の理論

  • Post #3609584

    Fortress HODL is collapsing (from Alphaville): &quot;[Strategy&#39;s rescue plan involves] a $1bn common stock buyback, and a “BTC Monetization Program” under which the board has authorised management to sell bitcoin for three purposes: to replenish the cash reserve up to $1.25bn; to fund preferred dividends and interest if “more advantageous” than issuing equity; and to fund the repurchases of preferred stock or equity.&quot; (Micro)Strategy has likely been _the_ whale propping up Bitcoin pric...

  • Post #3520570

    @nina_kali_nina@tech.lgbt did you check out the new Ave Mujica song? It&#39;s a banger this time too

  • Post #2245019

    Implemented TPM2 auto-unlock and most of systemd-pcr{phase,fs} for initramfs-tools to get rid of dracut [1]. There&amp;#39;s such an amazing amount of potential confused deputies in a typical initramfs (all flavors) that it&amp;#39;s like having an entire sheriff&amp;#39;s department in your computer. If you&amp;#39;re doing TPM auto-unlock without systemd-pcrphase (PCR 11) or equivalent, grabbing your encrypted root partition can likely be done in less than an hour of physical access without a...

  • Post #2245018

    wake up babe, new slopnerability class dropped: find application X that _could_ be linked with some library Y that has a known vulnerability AND X could somehow be operated to reach said vulnerability in Y. File slop report against X to claim your CVE badge and bug bounties. (AFAICT this is neither about vendoring a vulnerable version of Y in X nor about vulnerable version of Y being concretely otherwise shipped somewhere where X could also be installed.)

  • Post #2245017

    @campuscodi The code that led to the exploit is kind of mind-blowing: https://www.openwall.com/lists/oss-security/2026/04/18/5 Looking for code of this caliber in obscure projects/forks looks like an optimum case for LLMs since there&amp;#39;s little need for hard work like predicting brances or deriving types.

  • Post #2245016

    the IPv8 dude is now trying to push his wares on the nanog mailing list and that&amp;#39;s some serious AI psychosis going on there

  • Post #2245015

    Two screenshots from today&amp;#39;s FT. Surely no problems here at all. (The most surprising part may be that Oracle supposedly has $250B of deferred cloud revenue in addition to what OpenAI has promised them.) (https://www.ft.com/content/7599af3b-2184-4538-8ef9-370e01c1aaa8?syn-25a6b1a6=1 and https://www.ft.com/content/be97df0a-76b1-4cb0-9ba4-d1117d8d1450 , the latter diagram is originally from https://www.theinformation.com/articles/anthropic-commits-spending-200-billion-googles-cloud-chips)