Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Demi Marie Obenour

@alwayscurious@infosec.exchange
  • Open on infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

169 Followers
144 Following
50 Posts
Joined January 17, 2023
Pronouns:
She/her
GitHub:
https://github.com/DemiMarie
Matrix:
@alwayscurious:matrix.org

Posts

Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · 5d ago
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @emily_rugburn@lgbtqia.space
@emily_rugburn@lgbtqia.space @mcnado@mstdn.social Not surprised. I expect that most doctors would need to be paid more to work there.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · 5d ago
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @ariadne@social.treehouse.systems
@ariadne@social.treehouse.systems Can one provide a good user experience for E2EE DMs without reimplementing half or more of Signal?
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · 5d ago
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @jann@infosec.exchange
@jann@infosec.exchange I think that’s a great idea, though it’s one that can be taken too far. Some things aren’t worth caching.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @alwayscurious@infosec.exchange
@dalias@hachyderm.io To clarify, I’m concerned about attackers using N-day vulnerabilities in software that won’t be patched. Those build up over time, and once an exploit is written, it can be used even by script kiddies.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @dalias@hachyderm.io
@dalias@hachyderm.io I did indeed mean Office 2024 Home. I suspect that Word, Excel, and PowerPoint are used more than everything else by far. My main concern with Office 2019 is that it’s end of life, meaning one needs to be very careful to never open an untrusted document with it. That’s beyond what I would expect from a non-technical user, unless someone else set them up with a non-networked VM.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @datenwolf@chaos.social
@datenwolf@chaos.social @whitequark@social.treehouse.systems Can one make “quasi-SRAM” by using a semiconductor with large enough bandgap, and sufficiently long channels, that leakage at room temperature is negligible? Pseudomorphic epitaxially grown AlN/AlGaN HEMTs come to mind. With a bandgap of over 4eV, it ought to be possible to have a turned-off transistor be indistinguishable from an open circuit at DC.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @dalias@hachyderm.io
@dalias@hachyderm.io Office 2024 LTSC?
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 09, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @datenwolf@chaos.social
@datenwolf@chaos.social @whitequark@social.treehouse.systems I’m actually surprised that isn’t possible. Is the problem the need for current to keep the thyristors on?
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 09, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @drakulix@social.dreampi.es
@drakulix@social.dreampi.es Is Vulkan any better?
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 09, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to on glauca.space
@r@glauca.space @whitequark@social.treehouse.systems I would not be willing to deal with user-provided images unless I was at a company with lawyers on staff. If I’m not, I’m either outsourcing the whole task or not allowing user-provided images or videos. Text only.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 09, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to on adhd.irenes.space
@ireneista@adhd.irenes.space Ah, I thought you were complaining about the amount of boilerplate required.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 09, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to on adhd.irenes.space
@ireneista@adhd.irenes.space Vulkan is designed to be used by large programs and libraries for which the boilerplate is irrelevant.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jul 01, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

If I had a project like Mesa or virglrenderer, I would pay a premium for a CI service that offered bare-hardware runners for various embedded boards that are safe to run on not-yet-reviewed contributions.

4
0
2
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jun 28, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

RE: @thedarktangent@defcon.social

As this post shows very well, hosting user-generated content has very real economy of scale. Abuse prevention and response is very expensive to do well, and the consequences of not doing it well are severe.

Even end-to-end encrypted apps like Signal still need to be able to respond to abuse reports!

0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jun 23, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

If an IPS is found to break some feature of TLS, browsers should force that feature on in the next update, with no opt-out.

“Nobody can connect to the Internet” is, hopefully, enough to force changes.

1
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Jun 13, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @dfx4509b@friendica.world
@dfx4509b @GrapheneOS@grapheneos.social Such action could be under EU laws too.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 15, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @icing@chaos.social
@icing@chaos.social I suspect the Linux kernel is an exception.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 13, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @penguin42@mastodon.org.uk
@penguin42@mastodon.org.uk @jann@infosec.exchange There is a chicken bit that works around the bug.
2
0
1
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 11, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @mjg59@nondeterministic.computer
@mjg59@nondeterministic.computer I don’t think that the people who make weapons of war would care about license compliance.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 11, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @chris@social.losno.co
@chris@social.losno.co It’s a natural response, but it isn’t always the best one. For instance, allegations of abuse or harrassment need to be taken seriously.
0
2
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @GrapheneOS@grapheneos.social
@GrapheneOS@grapheneos.social Is this illegal under antitrust or pro-competition laws? If so, is legal action against it planned?
0
1
2
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 10, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @patrick@retro.social
@patrick@retro.social @alex@feed.yopp.me One way to solve this would be to only provide remote attestation collateral for servers and for devices enrolled in MDM. Client devices without MDM would only support local attestation: one could obtain the public keys from a boot splash screen provided by the firmware, but there would be no way to verify this remotely. Local attestation is sufficient for most legitimate uses, such as Qubes OS’s Anti-Evil Maid.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @mttaggart@infosec.exchange
@mttaggart@infosec.exchange @cloudflare@noc.social I suspect they view this decision as one that should be left up to courts. One problem with this argument is that the court system is (by design) far too slow.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @alwayscurious@infosec.exchange
@phillmv@hachyderm.io @AT1ST@mstdn.ca @brib@bribstodon.xyz @jneen@unstable.systems The other part is that one needs to know the expected behavior before writing the tests, and I often don’t know the expected behavior before I write the code that implements it. I write the code as I figure out what needs to happen.
0
3
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @phillmv@hachyderm.io
@phillmv@hachyderm.io @AT1ST@mstdn.ca @brib@bribstodon.xyz @jneen@unstable.systems In statically typed languages, the tests will not compile until the API is written. I’d rather have static type checking than easy test mocking, though that is admittedly a tradeoff.
0
4
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @phillmv@hachyderm.io
@phillmv@hachyderm.io @AT1ST@mstdn.ca @brib@bribstodon.xyz @jneen@unstable.systems One can’t write the tests without first writing the API, and it’s often impossible to figure that out without having first written much of both the code that implements the API and the code that uses it. For mature projects, test-driven development makes more sense.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @jneen@unstable.systems
@jneen@unstable.systems “hypervigilance, famously, destroys your mind and body” Link to that? As an aside, I think that any open source maintainer that receives a lot of outside contributions from untrusted people already needs to be hypervigilant. I treat LLM output as if it came from an untrusted new contributor.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @kirakira@furry.engineer
@kirakira@furry.engineer @jneen@unstable.systems I used an LLM to write a test suite for some code I wrote myself. I also asked it to keep in mind the spec the code is supposed to implement. The LLM figured out how to achieve almost 100% MC/DC coverage using only the public API. It (correctly) justified condition that could not be tested. Some of the tests failed, and when they did, the LLM pointed out that the problem was with the code. In one case, it wrote a 2 line fix (add missing Vec::clears) I used directly. In one case, it suggested a 1 line change (use the correct Rust struct). In the others, I fixed the code myself. I didn’t do this because tests are unimportant. I did it because writing a test suite with good coverage by hand is very difficult. Is this a silver bullet? Of course not. I still need to cleanup and validate the test suite, and I need to write integration tests. But it saved me a lot of time, and resulted in much better test coverage. If nothing else, this makes regressions much less likely.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @mgorny@social.treehouse.systems
@mgorny@social.treehouse.systems It’s due to a labor shortage, which is in turn due to a funding shortage. Same reason there are so many unfixed syzbot reports. The companies that would pay for such things all have their own forks.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @thesamesam@social.treehouse.systems
@thesamesam@social.treehouse.systems The Xen-related code in Linux is maintained by the Xen Project. Xen has a completely separate process for handling vulnerabilities, and also keeps vulnerabilities under embargo until patches are available. Therefore, pointing out the security marking in the commit message is safe and logical.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @david_chisnall@infosec.exchange
@david_chisnall@infosec.exchange Also a very good reason to use microkernels instead of monolithic kernels.
1
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @alwayscurious@infosec.exchange
@filippo@abyssdomain.expert I’ve seen FIPS 140 certificates that make almost no sense, and I’m pretty sure it is to avoid these enormous delays. Last I checked, the IBM Cryptographic Coprocessor’s certificate only covers loading of a firmware by the bootloader. The certificate of the Private Machines Enforcer blades is invalidated by booting the Compute Engine. In both cases, the certificate doesn't cover what companies actually buy the hardware for.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @sophieschmieg@infosec.exchange
@sophieschmieg@infosec.exchange I think some stuff will be declared “don’t use with untrusted input” or just abandoned. Edit: I also think one should be able to automatically assign CVEs for sanitizer reports. Yes, it’s an abuse of the system, but is the only way I can think of to force downstreams to be the ones to fix the vulnerabilities. That includes downstreams who have money.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 08, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @filippo@abyssdomain.expert
@filippo@abyssdomain.expert Wow. No wonder so many despise FIPS 140-3. Fun fact for anyone reading: last I checked, the most recently FIPS 140 validated version of Windows’s built-in cryptographic library was from an end-of-life version of Windows.
1
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @dalias@hachyderm.io
@dalias@hachyderm.io @ska@social.treehouse.systems That makes sense if you don’t care about performance. I suspect that companies that pay developers of new kernel or graphics APIs generally do care. Right now, I care a lot about software rendering, but as soon as the security problems with GPUs are solved I won’t care anymore.
0
1
1
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @ska@social.treehouse.systems
@ska@social.treehouse.systems @dalias@hachyderm.io I suspect that in the future, high-performance code will use io_uring via a library that abstracts it away. I don’t think making it easy to use kernel APIs directly needs to be a goal. It’s like OpenGL vs Vulkan: Vulkan makes it very hard to write a trivial application, but for large, complex applications it turns out to be a better fit.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @dalias@hachyderm.io
@dalias@hachyderm.io Is splice even useful nowadays?
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @alwayscurious@infosec.exchange
@lina@vt.social I’m no expert on machine learning at all. That said, my understanding is that if one wanted to train a model for software development, finding sufficiently diverse training data would be the hardest problem. I am not a lawyer, and this is not legal advice, but here is my understanding: Most FLOSS licenses aren’t suitable here. MIT and BSD-family licenses require listing copyright owners. Apache 2 requires listing changes to the source files, including the license text, and copying a NOTICE file if one is present. GPL and LGPL are copyleft, so one would not get any funding for training a model on that data. This means that the only code I use is code that is under public domain or public domain equivalent licenses, such as BSD-0, MIT-0, or CC0. Even CC0 might not be suitable because it explicitly refuses to grant a patent license. Is there enough such code to train a model on? I’m genuinely unsure. If there is, great. Otherwise, one has to make agreements with each copyright holder separately. But that requires (a) being able to contact them all and (b) them being willing to cooperate. Relicensing just OpenSSL and LLVM took a huge amount of work. Now multiply that by the number of projects one wants to use. Furthermore, getting some rightsholders to cooperate might well require payment. This is a lot of work that cannot be automated. It’s also the kind of work that I suspect technical people find very, very boring. Plus it is likely quite slow, and doing it properly is probably quite expensive. Instead of bothering with things like legal compliance and ethics, people working at OpenAI, Google, and Anthropic decided to steal stuff and hope they would get away with it. So far, they have. Yes, they have been sued, but the damages have not exceeded what they are able to pay. The people training KL3M had a much easier time, because almost anything produced by the US federal government is public domain and the exceptions are well-known. If I understand correctly (and lawyers would know), this means they can use all federal laws and regulations, all opinions by US federal judges, and anything else produced by a US federal government employee in an official capacity. That’s a lot of text, and it is likely a very good fit for KL3M. But not for writing software. I don’t know about other fields so I won’t bother to comment about them.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @lina@vt.social
@lina@vt.social Which tasks can one make work this way? Serious question.
0
2
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @lina@vt.social
@lina@vt.social I don’t know if I will redistribute the vibecoded test suite I wrote. The only LLM-generated code I have published were trivial bugfixes that were clearly based on my own code.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 07, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @lina@vt.social
@lina@vt.social US and EU law seems to be pointing in the direction of the model providers being potentially liable, but model users not being unless they do something stupid (like prompting the model to get those violations out).
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 05, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @lina@vt.social
@lina @harry_wood @Di4na I tried using Claude Code for writing some code and found that it was frustrating even after quite a bit of time. However, it found some very non-obvious (without hindsight) bugs. The latter is what I think my main use will be going forward.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 05, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @lina@vt.social
@lina @vineyardsiren What specific tasks are you thinking of?
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 05, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @thesamesam@social.treehouse.systems
@thesamesam@social.treehouse.systems I remember a few issues: It’s blocking rather than asynchronous, which causes problems in certain scenarios.It needs a single program (such as NetworkManager) to wrap it.It can’t configure the network itself, which makes roaming much harder.The code is just harder to understand and work on.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 05, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @thesamesam@social.treehouse.systems
@thesamesam@social.treehouse.systems The code is all in libell.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · May 05, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @thesamesam@social.treehouse.systems
@thesamesam@social.treehouse.systems The AF_ALG and keyring dependency of iwd can be fixed much more easily than the poor code quality of wpa_supplicant.
0
1
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Apr 17, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange
Replying to @ireneista@adhd.irenes.space
@ireneista So the first thing I see is that it can be circumvented by installing a Linux distro that doesn’t have a US presence and therefore is not subject to US jurisdiction. The second thing is that forcing open source developers to comply might well be unconstitutional on first amendment grounds.
0
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Apr 15, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

It’s fine to not allow LLM-generated, or even LLM-assisted, code contributions.

Rejecting valid reports of security vulnerabilities because they were generated with LLM assistance is foolish. All it does is make life easy for criminals and cyberweapon vendors.

For what it is worth, OpenBSD seems to have exactly this policy. They reject LLM-generated code, but promptly fixed a remote DoS found by Claude Mythos Preview and confirmed by Anthropic.

3
0
1
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Apr 11, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

What are best practices for situations where one has reason to suspect there is a security vulnerability in a project, but cannot confirm it?

Especially when there have been similar vulnerabilities in the past, and one is about to file public issues that will tell others exactly where to look.

1
0
0
0
Open post
Demi Marie Obenour @alwayscurious@infosec.exchange · Apr 11, 2026
Demi Marie Obenour
@alwayscurious@infosec.exchange

Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.

infosec.exchange

If one is going to be using a whole server for one task, it’s best (performance-wise) for that one task to have all the drivers. So DPDK + SPDK.

Of course, that’s a lot of development work, but only because this was not the model from the beginning.

0
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:28:47 UTC