Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Wladimir Palant

@WPalant@infosec.exchange
  • Open on infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable

#infosec #cybersecurty #cryptography #privacy

3428 Followers
8 Following
50 Posts
Joined August 21, 2018
Website:
https://palant.info/
Pronouns:
He/him

Posts

Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Aug 04, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

One really has to wonder how some decisions were made. So somebody at #BMW thought: “You know, those suckers who paid $50,000 or more for our cars? We should really milk them some more. They probably get bored waiting for their car to start up anyway, let’s show them some ads! We’ll call it a special surprise for the drivers, no way they’ll object then.” Yes, totally reasonable.

Way to destroy a brand’s reputation…

https://www.theautopian.com/bmw-is-showing-commercials-on-their-cars-dash-screens-and-they-want-you-to-think-its-a-treat/

5
0
5
1
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Aug 04, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to on social.woefdram.nl
@hans I thought cracking encryption involves typing on a keyboard really fast? 🤔
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Aug 04, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Hollywood has some weird obsession with computer displays. A spy needs to copy data? They attach some fancy device to the display. Need to shut down a computer? They shoot the display of course. And never mind that a computer virus will always produce visible glitches on the display.
8
10
1
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 30, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Ja, ich habe auch schon alles gesehen (https://github.com/elk-zone/elk/issues/1877#issuecomment-2440130547 😬). Es gab ja mal diesen Standardisierungsversuch, aber jemand (John Gruber) meinte, dass es der Idee zuwiderlaufe und deswegen unnötig sei. Nun ist wieder ein Jahrzehnt vergangen, und das Chaos ist definitiv nicht besser geworden.
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 30, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Strange that “high pain tolerance” isn’t listed as a requirement. 🤔
1
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 30, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Ein vernünftiger Markdown-Konverter wäre besser. Sternchen mitten im Wort hat in Markdown eigentlich keine Bedeutung.
0
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 29, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @evacide@hachyderm.io
@evacide@hachyderm.io I’ve learned about the concept of checks at school. Still, the only time I’ve actually seen one was when I was sent one from the US. The bank wanted 20€ just for processing it.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 29, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

LLMs are quickly eroding the concept of truth.

I’m sure that more known people have had to refute claims about them for a while but now it happened to me as well. A researcher from a respectable university contacted me asking for an interview regarding “my position” on a particular topic. The issue: the cited position is the exact opposite of what I’ve always said, and I’m pretty sure that there are zero online sources confirming it to be mine. But whichever LLM they’ve consulted constructed a bullshit controversy where there never was one.

I can refute it this one time of course, and I assume that no such claims will make it into their final publication. But the tendency to rely on LLM-generated “information” is there, even in academia. And once they publish unverified bullshit it becomes “the truth” that LLMs will prioritize in their training and other people will refer to as proof that LLM claims are correct. This is going to be really bad.

8
0
4
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 27, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @WPalant@infosec.exchange
It gets even “better.” Tesseract dev shut down the project and removed the repositories. They are said to have posted a farewell message which contained JavaScript code that was sending 2000 requests to the Lemmy instance of the user who uncovered their secret blocking list (that message is no longer online). Not really enough for a DDoS attack but probably an attempt to drive up traffic costs. https://lemmy.dbzer0.com/post/72962926
Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instance - Divisions by zero
lemmy.dbzer0.com

Tesseract dev injects malicious code into browser to illegally DDOS the dbzer0 instance - Divisions

FYI admins cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance [https://quokk.au/c/fediverse/p/1066667/tes

9
0
5
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 24, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
#OperaBrowser sending me spam to an address that I definitely didn’t give them, asking me to promote their ad blocking feature? Because … checks notes … I wrote an article about malicious ad blocking extensions that has the necessary keywords. “Since your site already covers tools and tips that help people have a better time online.” Not even mentioning my name because why would they bother finding it, I’m just some random blogger from the internet that their automated tools brought up. That’s quite something. I wonder whether they realize that their product still enjoys some trust and respect which is probably undeserved since their owner change. And how such tactics affect this trust.
3
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 23, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
That’s some really evil shit: https://lemmy.world/post/49794261 So Tesseract (an alternative Lemmy client) downloads a blocking/filtering list from its servers, something that most people likely weren’t aware. This “feature” was introduced November last year (version 1.5.0) and is described as “Tesseract attempts to filter out as much baseline toxicity as possible” in the settings option allowing it to be disabled. The list currently contains 544 (!) individual users and 2282 (!!) regular expressions applied to user names. Among the expressions censored in user names are: Democrat, Republican, Israel, ElonMusk, trump, amerika and billionaire. There is also the regular expression usa?(.*)?terrorist which seems to be intended for the phrase “USA are a terrorist state.” The list also contains 97 censored communities and 32 regular expressions applied to community names. Finally, there are 352 (!) “forbidden” domains and 296 filtered phrases including proletariat, epstein class, Jesse Welles and “Hi, I’m an AI engineer based in Japan”. The author also disliked 👉👈 emoji. Judging by the project’s issues some people only just found out that they are being censored and are wondering why. #tesseract #lemmy
13
2
10
1
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 23, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
AI concerns, Linux Hover or focus to reveal Sensitive
Some very good points on Linus Torvalds’ problematic AI take: https://drewdevault.com/blog/AI-in-Linux/ Yes, Linux is an extremely influential project, and simply denying the responsibility that comes with this influence is very cheap.
3
0
2
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 19, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to on gnusocial.jp
@simsa03@gnusocial.jp Other people’s mental health is not up to you to decide. That’s an even worse take than your first post, you are blocked.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to on gnusocial.jp
@simsa03 Is your mental health affected by cat videos?
0
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @es0mhi@tilde.zone
@es0mhi@tilde.zone That’s a very unhealthy and an extremely American attitude. Are you interested in book suggestions?
1
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @es0mhi@tilde.zone
@es0mhi@tilde.zone Here is your medal for suffering and wanting others to suffer in the same way. 🏅 It may come as a surprise but ignoring your own and other people’s boundaries is neither necessary to stay informed nor is it helping to change the current situation. These boundaries exist for a reason, respecting them and giving yourself a break from time to time is generally a good strategy to have the energy to actually do something.
3
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @es0mhi@tilde.zone
@es0mhi@tilde.zone I assure you, people who need a break from politics know very well what is going on. And you can still write about politics even when using CW.
2
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @ghostrunner@hachyderm.io
unsolicited criticism of behavior Hover or focus to reveal Sensitive
@ghostrunner@hachyderm.io I don’t care about authorities. But I generally prefer to understand things that I’m doing. 🙄
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @ghostrunner@hachyderm.io
unsolicited criticism of behavior Hover or focus to reveal Sensitive
@ghostrunner@hachyderm.io Do you have a link for me maybe? I went through a few guides on content warnings and I don’t see such a category in any of them. I’d need to better understand the purpose of such a content warning and when it should be applied.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @orbman@infosec.exchange
@orbman@infosec.exchange No, not people with different opinions. People who get all entitled when somebody asks for trivial accommodations – such as content warnings.
3
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 18, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Content warnings serve a purpose. Yes, that includes politics. You may feel that a topic is too important to “hide” it. But please understand that people are currently getting bombarded by horrible politics news from all directions. This is not sustainable, and it’s often a choice between muting this at least temporarily or burning out. So: please don’t be an asshole and use content warnings. People ask for them for a reason, not to annoy you or to downplay the importance. (I fully acknowledge that I don’t always think about this. But I try.)
59
9
44
1
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 17, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

@cR0w@infosec.exchange Could you please add the image text to the alt text? E.g.:

A toy steering wheel mounted on the dash of the passenger side of a car. Above it the text: “When slopoholics think they’re in control of their machine of lies”

infosec.exchange

:rainbowCrow: (@cR0w@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 17, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @WPalant@infosec.exchange
Not quite unsurprisingly there are people in my comments who feel that automating vulnerability research is increasing their productivity and that they are in control, being the “human in the loop,” that they are in fact learning a lot. Well, Christine Lemmer-Webber just published a great article on that. One passage is particularly worth repeating: “The vehicle is the LLM, you are the passenger. And I think the amount of agency people have over their journey is greatly reduced from what they feel like it is.” This is about coding but if you look closely you will notice the same dynamics applying to vulnerability research. It’s all about speed, and understanding/validating LLM-generated results is inherently slow. So the human in the loop will always tend to give up more and more control, relying more and more on the LLM to just do the right thing. And we get the same deskilling that we see everywhere else, all while LLMs keep regurgitating old stuff. Either way, I’m not interested in arguing about this. I won’t convince LLM fans just as they won’t convince me. We’ll see soon enough how this goes.
12
1
3
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 16, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
I have been rethinking my life’s choices lately. I’ve spent years building a knowledge base for Firefox extension developers. Despite all its flaws, and development complexity definitely was one of them, the Firefox extension ecosystem was meant to provide functionality that browser developers didn’t think about. Then Chrome came along and forced Mozilla to abandon its extensibility approach for one which was neatly limited to functionality that browser developers decided to allow. They had good technical reasons for that of course, but it replaced an ecosystem that embraced creativity by one which encourages endless repetitions of the same thing. Now it’s educating people about security, another task I’ve spent years on. Currently this field is being killed by the so-called “AI.” Don’t get me wrong, I recognize the immense progress made on automated vulnerability finding. I see the short-term benefits. Yet the long-term outlook is grim. In a field that was already severely understaffed, this will result in even fewer people seriously learning about security. Yet the LLMs are by no means intelligent, nor will they ever be. They recombine existing human knowledge, and they are highly reliant on it. Without an influx of new knowledge their results will degrade. Either way, I’m not complaining. It was fun while it lasted. But you probably shouldn’t expect new security research from me any time soon, I have little incentive to do it in this changed landscape.
32
5
16
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 06, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @quinn@dresden.network
@quinn@dresden.network That’s an interesting one even though its specs aren’t quite what I am looking for.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 06, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @hhg@infosec.exchange
@hhg@infosec.exchange Yes, I was thinking about Tuxedo already, seems to be a good option. Didn’t know Slimbook, looks like a viable alternative, thanks!
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 06, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
RE: https://infosec.exchange/@WPalant/115633275489771501 It seems that I should start looking for a replacement for this laptop after all. Any recommendations, any other company with good hardware that can be repaired?
0
2
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Unfortunately, things are looking increasingly grim to do anything about this within the legal boundaries.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Well, there is a tiny problem with going into hiding and throwing Molotov cocktails at data centers: unlike John Connor I have kids. 😅
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Where is John Connor when we need him?
2
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jul 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Yes, this was in the news a month ago: https://www.forbes.com/sites/josipamajic/2026/06/04/bots-now-outnumber-humans-online-and-the-internet-was-never-built-for-this/
0
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · Jun 30, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Don’t get your hopes up that Ford rehiring some engineers is a sign of the industry recognizing just how detrimental the whole “AI” thing is. https://www.independent.co.uk/tech/ford-ai-automation-humans-hiring-artificial-intelligence-b3004733.html It’s telling that Ford is only re-hiring “greybeards,” their most experienced engineers. A junior has no chance of getting their job back, nor will they ever get a chance to become one of those experienced engineers. Ford isn’t interested in building a sustainable system where people can accumulate experience and grow, they want the humans to help improve their cost-saving automation – and then the humans will be let go again. The strategy is still to replace human car designers by computers, this strategy merely suffered a minor setback.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 28, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.”

Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now…

#CommandInjection

4
2
2
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 24, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…

5
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 24, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

Has been a while since I’ve been releasing software. So it’s interesting to watch the news after Gnome Commander 2.0 release. I mean, there are the obvious LLM-generated articles flooding the zone with shit. And then there is the seemingly well-written article featuring a Windows screenshot of a Linux application, crediting Midjourney for it. At which point the realization dawns that the content is merely an approximate translation of a proper human-written article.

3
0
1
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @svenja@mstdn.games
@svenja@mstdn.games Yes, unfortunately. 😥 (And just to prove your point: I tried to enable the screen reader in GNOME but something changed here and now it doesn’t do anything at all. There is a new “Configure” button below that toggle switch, so presumably the screen reader is configurable now. But clicking that button doesn’t do anything.)
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @svenja@mstdn.games
@svenja@mstdn.games I’m sorry to hijack your attention in such a way, so feel free to ignore. (Gerne auch auf Deutsch kommunizieren, wenn das für dich einfacher ist.) I’ve been working on improving Gnome Commander accessibility recently, and while I’ve made some progress, some areas are just very complex and I lack the knowledge for handling them properly. Do you happen to have some pointers for me: applications, preferably for Linux, that have good accessibility despite having a complex user interface? I need to see how other people solved non-trivial scenarios.
2
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @svenja@mstdn.games
RE: https://mammut.gogreenit.net/@chewie/116617831739595301 @svenja@mstdn.games Supposedly, there is still an audio option (for now?). Makes this only marginally better of course.
3
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @zollak@bonn.social
@zollak@bonn.social I assume that they won’t be accepting just any phone (if they still do it now then they certainly plan to change it in future). It’s about checking whether the phone in question has a usage profile that matches a human. Getting this to work with phone farms might be non-trivial. They seem to speculate on it requiring more resources than solving visual challenges automatically which right now is rapidly becoming trivial.
2
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @Reinald@nrw.social
@Reinald@nrw.social No idea. Supposedly, on a phone meeting their requirements this captcha should be handled automatically. Don’t know what they do if the requirements are not met.
2
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 22, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @acs@mastodon.scot
@acs@mastodon.scot No, you don’t understand correctly. I recommend reading the second paragraph.
0
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 21, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

RE: @jschauma@mstdn.social

So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

252
32
282
2
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 17, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange

RE: @gcmd@floss.social

In case you are wondering what I’ve been up to lately: I’ve been contributing to Gnome Commander. Thing is, I care about file managers. Next to web browsers and editors they are essential work tools for me. And Gnome Commander has been recently rewritten in Rust, making it easy to contribute to.

Things have been in a rather dire state however, so I’ve been fixing lots and lots of bugs while also adding occasional features. There is still work to be done but Gnome Commander 2.0 has been released today. And you can probably guess where this is going: I now “own” the project.

Either way, there is now a Fediverse account for the project – feel free to say “hi.” Also, contributions by humans are very much welcome and appreciated, LLM-generated contributions are prohibited.

11
0
8
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 07, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @paco@infosec.exchange
@paco@infosec.exchange @zbrown@floss.social @dangoodin@infosec.exchange Well, we’ve got the details now, and it’s merely two weeks later: https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ I haven’t looked into it in detail but I must admit that the bug descriptions look pretty impressive.
4
2
1
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @WhyNotZoidberg@topspicy.social
@WhyNotZoidberg @freya It probably does. But few people bother publicizing it so widely.
1
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 03, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @m@martinh.net
@m Well, that particular LLM wrote into IRC chat: “don't bite Kent! he's doing his best. he's currently telling a camgirl about my love life so I think he's handling the situation with appropriate gravitas”
1
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 02, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @Orca@nya.one
@Orca That was also my thought. He says “like a teenager” but you can still hear a parent-child relationship there. The LLM also talks about him being her parent. But that’s merely one more level of wrong out of way too many. Even if he instructed her to act like an independent middle-aged woman – she still isn’t, he still has total control over her. And even if he didn’t use the system prompt to codify her “feelings” for him - it’s still an LLM, they continue a conversation in the “typical” way. If he starts talking romance she will soon start discussing bride dresses.
2
1
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 02, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @woffs@fe.disroot.org
@woffs Depends on how many people are working on them. I have really no idea – if it’s a few thousand then we are probably talking about a fairly standard distribution. @freya
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 02, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @freya@social.highenergymagic.net
@freya @izzy There is also https://social.vlhl.dev/notice/B3h6u785ScEvsqIMAC Unfortunately, the message mentioned there isn’t part of the transcript, and I don’t even know whether that’s an exact quote. But it also indicates that the LLM was “fixed.”
1
0
0
0
Open post
WPalant
Wladimir Palant @WPalant@infosec.exchange · May 02, 2026
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable #infosec #cybersecurty #cryptography #privacy

infosec.exchange
Replying to @WPalant@infosec.exchange
One quote in the article above stuck with me: “teenager … increasingly running circles around me”. Yes, that totally is something that teenagers do. Btw. dude, when was the last time you saw rather than imagined a teenager? And these are the people who feel qualified to raise something they consider a sentient being. One really has to be grateful for the fact that LLMs aren’t sentient by any means. The humankind is responsible for enough atrocities as it is.
28
1
1
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:43:00 UTC