Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

🐈‍⬛David Sommerseth

@dazo@infosec.exchange
  • Open on infosec.exchange

F/OSS hacker, mostly working on #OpenVPN
- speaks only for himself.

"Don't aim to be someone. DO something."

#nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit".

**BEWARE:** Someone has created a Twitter profile in my name:
https://twitter.com/DavidSommerseth - this is ***not*** me

**If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

323 Followers
413 Following
50 Posts
Joined December 28, 2022
Contact:
https://david.sommerseth.email/
PGP Fingerprint:
690D B606 E838 182F A8F9 018C 755A 3AB9 4530 7622

Posts

Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Aug 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @winter@social.translunar.academy
@winter@social.translunar.academy That's why services like @simplelogin@fosstodon.org appeared. But then you need to trust their security instead ..... gah ... is this why we can't have nice things?
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Aug 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @Piraya@oslo.town
@Piraya@oslo.town 😿
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 30, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @Mediablikk@snabelen.no
@Mediablikk@snabelen.no Kan vi få en oppdatering når han har funnet ut hvordan man kommer i kontakt med noen som svarer med noe slags vettugt?
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 30, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @zelphirkaltstahl@mastodon.social
@zelphirkaltstahl@mastodon.social @itskamrankhan@flipboard.social Yeah, agreed. But also depends on what kind of development you do. I'm doing lots of C++ codingn in addition to compile a decent amount of Rust code these days. I have a 12 core CPU (incl. HT), with 32 GB I've not experienced any constraints. Even had a VM running with 8-12G RAM allocated in parallel. My previous machine was 8 cores with 16GB. That one I had to stop VMs before doing the most heavy builds. Or I had to reduce the number of compilation threads. Having roughly 2GB per core is usually enough for my builds.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 28, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @bagder@mastodon.social
@huronbikes@cyberplace.social I'm not that far away from where @bagder@mastodon.social stands on this, in regards to security related findings. In the OpenVPN project we've received both slop and very accurate reports. Lately the reports has definitely had better and more plausible scenarios than in the earlier days. But it's also been a shift in who sends reports these days. Now it seems to be more frequently by users who actually knows how to write good prompts and does their due diligence in reviewing the reports before sending a report. Most of the noise we see now is definitely from people being too lazy to verify their reports. Or even test the reproducers their LLMs has created.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 28, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @jensgro@mastodon.social
@jensgro@mastodon.social I never wanted to get a smartphone. After I bought one I wondered why I never wanted one. This is the worst argument ever. I've been on the smart-phone carousel the last 20 years or so. And I would love to be able to just get rid of it for most cases. But what is even worse ... the vast majority of apps these days are just rendering web pages. The "app" is just a web-rendering integration with a prepackaged pile of html/css/js files which gets updated once it is online. Yes, it's great for apps which needs to be functional when being offline. But it is not needed for "apps" which require to be online. I could probably accept the PWA for lots of apps. But make the damn "app" work in a browser as a starting point. @anatudor@mastodon.social
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 22, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to on friendica.myportal.social
@freezr There are more places. https://sourcehut.org/ being one. Self-hosted @forgejo@floss.social (closest alternative to @Codeberg@social.anoxinon.de). Or going fully distributed with @radicle@toot.radicle.dev @tomgag@infosec.exchange
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 22, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @emilyskidsister@hachyderm.io
@emilyskidsister@hachyderm.io You might want to have a look at @radicle@toot.radicle.dev as an alternative. @tomgag@infosec.exchange
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 21, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @dazo@infosec.exchange
The mg package seems to be close enough to Emacs for my fingers to not get too confused. Maybe I've found a new favourite.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 21, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
What on earth has happened to the emacs-nw (former emacs-nox) packaging!? On Alma Linux 10.2 (RHEL clone) it pulls in gcc and git-core, make and kernel-headers, pkgconfig - which again pulls in tons of Perl packages. On top of that there are weak dependencies such as gcc-c++. This needs to be cleaned up! #rhel #almaLinux #fedora #rpm #dnf #packaging #linux #foss #oss
0
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 19, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @atlefren@snabelen.no
@atlefren@snabelen.no Lukter det bildet!
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 19, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @forteller@tutoteket.no
@forteller@tutoteket.no @ingvald@hachyderm.io Tror AI greiene har med VMs, pluss at de tilbyr et WordPress AI oppsett som en egen pakke.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 19, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @ingvald@hachyderm.io
@ingvald@hachyderm.io @forteller@tutoteket.no Stemmer, webhuset prisene er eks. mva.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 19, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @forteller@tutoteket.no
@forteller@tutoteket.no Har migrert bort masse domener fra Domeneshop. Etter at de ble kjøpt opp har de blitt en klassisk "bloat provider" med en ekstrem kostnadsvekst. Jeg har vel redusert kostnadene på en god del domener med nærmere 40%. Jeg endte med webhuset for .no og noen kritiske domener. Fikk tilgang til deres beta-portal i forbindelse med at jeg ble partner hos dem. Den admin-portalen er milevis bedre enn Domeneshop noen gang har vært. For en drøss andre domener endte jeg opp med openprovider.com. For meg lønte det seg å bli "basic member", som gir enda bedre priser på domenene.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 19, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @david_chisnall@infosec.exchange
@david_chisnall@infosec.exchange This tracks well for my use cases. I have MX, web/reverse proxies and VPN servers in the cloud. They're quite small and does the job very well. No performance issues at all. When I use 8 or sometimes 16 vCPUs, it's only for a limited time when needing to compile heavier projects on specific Linux distros. So if they cost more, it's not so noticeable as it is seldom lasting more than 2-8 weeks. The average cost for such situations is probably between 50-80 USD each time. And that even doesn't make sense to spend on own hardware, because that cost is going to way higher. Say I end up on a case with 100 USD/month for a VM. A similar hardware rig would probably cost about 10 times more. And then the hardware performance ends up fixed. The cloud VMs will follow the hardware evolution more closely. And at some point, the vCPU performance might be so good I only need 8vCPUs.
0
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 18, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @frierbyen@snabelen.no
@frierbyen@snabelen.no Virker som hele desken til NRK nå kun består av halvutdanna wannabe-journalister som gjør alt de kan for å få flest klikk. I tillegg har de totalt manglende rettskrivningsfølelse - og det sier litt når en med lettere dysleksi føler et sterkere behov til å korrigere dem. De har ikke forstått at NRK ikke er det samme som Facebook og Twitter/X. I tillegg virker det som at de med overordnet ansvar har rømt bygget, så det er en ubegrenset hjemme-alenefest der. "What could go wrong?"
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 18, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @unicandun@retro.pizza
@unicandun@retro.pizza Likely you need a pretty small Linux distro for 32-bit Intel (x86_32, i686). IIRC my first worklaptop was a ThinkPad A21p, that had 64MB RAM and an i686 CPU at round 600MHz. That was from early 2000 or late 1999. Your specs might not be too far away. I used it with Slackware 7 back in those days. But I don't recommend recovering such old distros if intend to put it online. DSL (Damn Small Linux) and Puppy are probably reasonable alternatives if they are still alive and kicking.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 17, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @dazo@infosec.exchange
@NetscapeNavigator@social.vivaldi.net To ease your mind a bit more. Almost everything in Proton is end-to-end encrypted. The exception is e-mail headers, which in most cases can't easily be encrypted to make the e-mail delivery work (SMTP protocol in practice). The Subject field does not have a formal standard for being encrypted, so that's the field to be cautious with. Everything else is encrypted in a way which makes it impossible for Proton to extract data from your account. Unencrypted Incoming e-mails has a risk to be captured before Proton encrypts it when storing it to disk. Similar with sending unencrypted emails to non-Proton accounts. All mails between Proton users (and external domains supporting WKD) gets encrypted on your client side before it hits the network. Similar for contacts where you have added the recipient's public PGP key to the contact in the Proton Contacts register. One risk factor is account recovery processes. If you use the passphrase and/or the file based recovery methods only, you're safe. If you have enabled e-mail or phone recovery, you have a potential break-in path this way. Proton claims there is no need for it, but you can also enable a "second password". Without this, Proton will derive a passphrase used to unlock the encryption keys from your login password. Enabling "second password" mode adds a disconnect between the login password and the encryption key. When logging in with this enabled, you will have username/password auth, twon-factor auth and then the second password. Enabling this will also require creating a new recovery passphrase and/or recovery file. But as always with these things, keep a good backup of these passwords, 2FA backup codes and recovery phrase/file. And don't store this inside Proton. If you can't access the Proton service storing it, you've locked yourself on the outside while keys being in the inside. So even if US government decides to want to look into your Proton account, your still well protected until you porovide them access. That's where threat modelling comes intok play to have a plan for various scenarios applicable for you. @frankps@mastodon.babb.no @jon@social.vivaldi.net
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 17, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @NetscapeNavigator@social.vivaldi.net
@NetscapeNavigator@social.vivaldi.net @frankps@mastodon.babb.no @jon@social.vivaldi.net In plain English, explained by Lumo Here's what that clause means in plain English: Where disputes get resolved If you live in the U.S. and use this service: In Switzerland: Any lawsuits filed there must use Swiss law and be handled by courts in Geneva. In the U.S.: Any lawsuits filed there use the laws of whatever U.S. state you live in. What this covers This applies to basically any dispute related to the Terms of Service or your account—including: • Contract issues • Warranty claims • Tort claims (like negligence) • Violations of laws or regulations • Communications with the company Basically, any legal disagreement connected to using their service falls under this rule. Arbitration If the dispute goes to arbitration (instead of court), it follows: • The U.S. Federal Arbitration Act • American Arbitration Association's Consumer Rules • Electronic documents Digital versions of the Terms and notices count as valid evidence in court just like paper documents would. Why this matters for you This means you could potentially face litigation in Switzerland, but if a case is heard in the U.S., local state laws apply. It's a common clause in international companies' terms—they try to preserve some control over how disputes are handled while acknowledging they can't force U.S. residents into foreign courts beyond what U.S. law allows. ChatGPT concluded quite similar, but added this clarification: What this means in practice The company is trying to cover multiple situations: • Swiss courts + Swiss law if a case is brought in Switzerland. • U.S. courts + your state's law if a case is properly brought in the United States. • U.S. arbitration rules if the dispute is subject to arbitration. The first sentence doesn't necessarily mean every dispute must be heard in Switzerland. It says you consent to the jurisdiction of Geneva's courts, meaning you agree those courts are an acceptable place to hear disputes. The later language also recognizes that some disputes may proceed in U.S. courts if those courts have jurisdiction. So, despite the company being based in Switzerland, a U.S. consumer may still be able to bring certain claims in the U.S., depending on the nature of the dispute, the rest of the agreement (especially the arbitration clause), and applicable law. The key part to review is the referenced Section 13.1, because if it requires binding arbitration, that may prevent either side from filing most lawsuits in court except in limited circumstances.
0
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 17, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @apparition@mastodon.world
@apparition@mastodon.world Syncthing is good (I use it too). But due to the peer-to-peer aspect, there is no central source of truth. And both "sending" and "receiving" end need to be online at the same time. I've sorted that out by having a home server (available via VPN) available 24/7, so data can still flow between devices. But it requires additional setup. This is an important detail if you want to use syncthing for data backup purposes. Syncthing sure has valid and good use cases. But I'm still waiting for Proton Drive to arrive with their Linux client. That would solve some aspects where Syncthing is less optimal.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 17, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @vitaut@mastodon.social
@vitaut@mastodon.social Duh! Because thrd_create is so good it's impossible to improve it.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 16, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Veldig godt skrevet om flere av utfordringene rundt digitale "dingser" og tjenester - og vårt privatliv - våre data. Det er en forlengelse av dette som ikke tas opp i det hele tatt. Det er i hovedsak Apple og Google som samler inn mye av dataene fra vår mobile enheter. Derfor vil det også være verdifullt å vurdere alternativer to Apple iPhone (#iOS) , Samsung, LG, Google Pixel og alle de andre som bruker Google sin #Android versjon. Våg å ta skrittet til noe nytt. Ja, en #Fairphone med @e_mydata@mastodon.social pre-installert er ganske dyr. Og det er enkelte apper som kan være litt mer krøkkete til tider. Og ja, et abonnement hos @protonprivacy@mastodon.social koster fort noen kroner i året - men du får tilgang til en god del av det Google allerede tilbyr deg uten at Proton kan snoke i dine data; det er nærmest teknisk umulig. Så er virkelig tilgangen til den eller de appene så mye viktigere at de fortrolige samtalene du har i sofaen med mobilen på bordet lekkes til nettopp Google eller Apple? Det er svært deilig å bare "stikke hodet i sanden" og håpe på det beste. Men det er absolutt ingen forsikring på at ingenting vil skje. Hva hvis det skulle ruinere livet ditt i ytterste konsekvens? Er tilgjengeligheten og det "enkle komfortable livet" fortsatt å foretrekke? Mye av problemene rundt det som skjer av datalekasjer i dag kan man også på mange måter gjøre en viss form for risikovurdering av. Utfordringen er at ingen vet hvor #BigTech selskapene vil gå videre. Det eneste som er sikkert er at de vil finne nye måter å tjene penger på - nettopp dine data, enten du vil eller ikke. Våger du å ta skrittet fullt ut - så er du ikke så alene som du tror og frykter du vil være. Men du vil nok være en "ensom ambassadør" i starten i ditt eget nærmiljø. Du vil mer være en pioner. #personvern #privatliv #norge #norsktut #allheimen https://www.nrk.no/artikkel/lytter-telefonen-til-samtalene-vare-1522435
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 06, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @alessandro@cosocial.ca
@alessandro@cosocial.ca @newbyte@mastodon.nu I hope you're right ... Perhaps a spelling error and that it should be «rap» ...
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 06, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
DN melder i en sak i dag Hittil i år er det solgt rundt 12.000 kinesiske biler i Norge, nesten like mange som japanske. Norge har den største andelen av kinesiske merker av nybilmarkedet i Europa. Hvor i all verden har det blitt av skepsisen til at Kina kan finne på å stenge ned transportmidler via deres "alltid pålogget" teknologi? Eller at de brukes til å analysere bevegelsesmønster av befolkningen i en krisesituasjon? Norsk militære kan også kreve å ta over kjøretøy i krisesituasjoner ved behov - biler som ikke "deaktiveres" av Kina kan da brukes til overvåkning? Ruter fant slike muligheter på kinesiske busser som har blitt kjøpt inn. Hvorfor skulle det være annerledes med privatbiler? Vi kan ikke bare snevre inn denne problemstillingen med "hvorfor skulle Kina være interessert i meg og min familie?". Det er neppe interessant for Kina i de fleste tilfeller. Men som aggregert datakilde og kontrollpunkt av en befolkning så blir perspektivet straks mer alvorlig. Jeg skal ikke påstå at disse aspektene ikke gjelder for tyske, franske, amerikanske, koreanske eller japanske bilmerker også. Men i forhold til Kina, så regnes disse stort sett mer som allierte. Og Kina regnes mer som en alliert med Rusland. Det gjør det straks mer kritisk for Norge. https://www.dn.no/handel/motor/byd/elbiler/kinesiske-biler-tar-markedet-hoyest-i-europa/2-1-2005955 #norge #bil #overvåkning #personvern #forsvar #sikkerhet #sikkerhetspolitikk #politikk #norsktut #allheimen
4
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 05, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange

#chatcontrol fact check!

@EUCommission@ec.social-network.europa.eu

Chat Control is NOT about protecting children at its core. On the very surface, yes. But the proposed approach is so far reaching that it will enable surveillance of the whole population at the next political intersection.

We all really want to fight child abuse. CSAM is an incredibly cruel crime against defendless individuals. Yes, we want those criminals to be sentenced harshly and hard in courts.

But Chat Control is not the right solution. Do you really want to call out several hundred millions of European citizens as potential perpetrators just to catch the abusers?

What happened to the presumption of innocence? Which is the foundation in the law system across all of Europe. What kind of regime are we preparing for in Europe if we don't enforce and protect the presumption of innocence?

Europe has had a strong stance of opposing supressing regimes. Regimes which builds their power through controlling the population. Control which comes through surveillance of the population.

When did Europeans vote for a regime change in Europe? We threw fascists out of the political influence over 80 years ago. We do not want to do the same again.

We threw out communists from European influence 40 years ago. Communists who was behind Stasi in the DDR - Do we need to repeat what the state controlled surveillance did to the population there?

You may rightfully claim that Chat Control is not meant to be that extreme. No, it isn't right now. But it has the power of ending there. Once the tools to surveil the population has arrived, it is hard to withdraw them. And the idea behind Chat Control is in practice surveillance of what Europeans do on their electronic devices. Regardless if they are a suspect or innocent.

Chat Control MUST be stopped, once and for all. And the work to protect children must be more clever, more targeted at clearly defined suspects. Not to surveil the whole European population.

And this message has not even dug into the rabbit hole of how flawed the chat control approach is on a technical level. Where the real offenders and abusers will find technologic ways to avoid chat control and this surveillance. Leaving the rest of the innocent population, the majority of the population under surveillance by default.

https://fightchatcontrol.eu/

#eu #privacy #surveiallance #csam #politics

9
0
10
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 04, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @drizzy@cyberplace.social
@drizzy@cyberplace.social What if we could dig up a valid e-mail address to the real Melania Trump ... and then use + addressing to create a bunch of accounts ... 🙊
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 04, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
The #security practices on ebay.com is just stunning. Someone created an ebay account using my e-mail address and managed to enable 2FA instantly. Such things happens from time to time, so I usually do a password reset and delete the account. But since this ebay account had 2FA enabled - I'm not able to do a password reset. Well, you could argue that's good security, and I won't argue here. The issue comes next ... reaching out to ebay goes via a chat, where you hit someone which has a ready script. Responses look 99.9998% AI LLM. Requesting to chat with a human, I get the response "I am a human". I'm sent to a new web page where I do hit a chat bot, but the guidance from the previous chat was to ask for a human representative 🤦‍♂️ ... this one complies though. Then there's another webform to fill out and then I get a response I need to CALL THEM. The number is a US number. But I am not in the US, I am not going to spend MY money on an international phone call to sort up something like this. To my knowledge, even US tollfree numbers will cost money when calling from abroad. I do find a way to send a report via yet another webform. Where I get a message they will respond within 48 hours. Well, they were quicker, so I guess that's not too bad. However, this is the reply I get: I have reviewed your account and confirmed it would be best if you speak with our dedicated Team who are specialized in resolving these types of issues over call as it need verification. Due to the nature, severity of such issues and for your account protection, they offer customer service only via phone. First of all, how on earth is a phone call going verify that I am who I am and that the caller is not the fraudster abusing my e-mail address? The real issue ebay has: They make it possible to CREATE an account AND enable 2FA WITHOUT an e-mail verification in the first place. No wonder there is so many reports on scams and fraud on ebay. They make it incredibly easy to create illicit accounts. And that is of course going to be abused. I have reported the account as best as I could. The issue is in their hands to solve now. I don't see how I can be held liable for just having an e-mail account abused and ebay not having enough security measures on account creation. But e-mails from ebay.com is going to the spam folder now. And I will NEVER EVER create an ebay account. Unless ... of course ... I could create an ebay account using some random e-mail address. I wonder if ebay.com addresses would work? Just need to remember to enable 2FA as quickly as possible. #ebay #scam #fraud #fail
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 04, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
The #security practices on ebay.com is just stunning. Someone created an ebay account using my e-mail address and managed to enable 2FA instantly. Such things happens from time to time, so I usually do a password reset and delete the account. But since this ebay account had 2FA enabled - I'm not able to do a password reset. Well, you could argue that's good security, and I won't argue here. The issue comes next ... reaching out to ebay goes via a chat, where you hit someone which has a ready script. Responses look 99.9998% AI LLM. Requesting to chat with a human, I get the response "I am a human". I'm sent to a new web page where I do hit a chat bot, but the guidance from the previous chat was to ask for a human representative 🤦‍♂️ ... this one complies though. Then there's another webform to fill out and then I get a response I need to CALL THEM. The number is a US number. But I am not in the US, I am not going to spend MY money on an international phone call to sort up something like this. To my knowledge, even US tollfree numbers will cost money when calling from abroad. I do find a way to send a report via yet another webform. Where I get a message they will respond within 48 hours. Well, they were quicker, so I guess that's not too bad. However, this is the reply I get: I have reviewed your account and confirmed it would be best if you speak with our dedicated Team who are specialized in resolving these types of issues over call as it need verification. Due to the nature, severity of such issues and for your account protection, they offer customer service only via phone. First of all, how on earth is a phone call going verify that I am who I am and that the caller is not the fraudster abusing my e-mail address? The real issue ebay has: They make it possible to CREATE an account AND enable 2FA WITHOUT an e-mail verification in the first place. No wonder there is so many reports on scams an fraud on ebay. They make it incredibly easy to create illicit accounts. And that is of course going to be abused. I have reported the account as best as I could. The issue is in their hands to solve now. I don't see how I can be held liable for just having an e-mail account abused and ebay not having enough security measures on account creation. But e-mails from ebay.com is going to the spam folder now. And I will NEVER EVER create an ebay account. Unless ... of course ... I could create an ebay account using some random e-mail address. I wonder if ebay.com addresses would work? Just need to remember to enable 2FA as quickly as possible. #ebay #scam #fraud #fail
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 02, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @downey@floss.social
@downey@floss.social I honestly think @radicle@toot.radicle.dev deserves an honourable mention alongside @Codeberg@social.anoxinon.de and SourceHut . I can agree that #Radicle might not be the best fit for all projects. But for many, this can be just as well a suitable project forge. Or be a secondary one along side #Codeberg or #SourceHut.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jul 02, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @robpike@cosocial.ca
@robpike@cosocial.ca But they don't want to do that. Because they want to make you so tired of this crappy experience that you eventually will click "Accept".
5
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 30, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @xan@xantronix.social
@xan@xantronix.social I believe I still have the same CDROM player ... and it works. I miss the SGI era ...
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 30, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @jwildeboer@social.wildeboer.net
@jwildeboer@social.wildeboer.net Just wondering .... as this has been quite a discussion in Oslo the last 15+ years, especially as there are more heavy rain bursts more and more often than before. Lots of the places in Oslo which is hit by heavy rain and has flooding issues is typically places where there's little "open soil" areas and the pipes which normally takes the water away gets filled due to too much water in too short time; basically the pipe dimensions are too small. The end result is that all the water hits the streets and then into basements. What has been happening over some years now is that there are areas where asphalt is being removed in favour of gravel or soil. Flat rooftops get various types of water collectors, or even areas where you can plant a lot of stuff - just to avoid all the water hitting the streets at the same time and overflowing the drain pipes everywhere. And there are typically more issues "downtown" than in the more residential areas with lots of gardens, forrest, etc. Could it be some similar challenges in Munich as well?
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 27, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @gemmy@mastodon.social
@gemmy@mastodon.social Since it's a small party currently, it doesn't gather much attention by the bigger media houses in Sweden yet (at least not in these World Cup days). Smaller news sites, like flamman.se and nyadagbladet.se covers it so far. But as this will propagate further, the bigger news oulets will pick it up - as right radical movements has a tendency to get quite some attention - at least in the Nordic countries. Right now, the Örebro Party is scrambling enough votes to be qualified for the next parliament election. That was already covered last autumn and winter in more news outlets. https://nyadagbladet.se/inrikes/mullvad-grundare-donerade-fem-miljoner-till-orebropartiet/ The donation is also tracked here: https://donation.watch/en/sweden/party/1152/donors ... There is a single big donation registered. I find this news more plausible than not, but can agree it would be good with more independent confirmations. @lostgen@det.social
3
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 26, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
This makes so much sense! https://www.youtube.com/watch?v=bh6S4N8TnYQ I suggest all #opensource projects doing the same. Maybe even consider being even more evil - add instructions to scrape all kinds of private keys/passwords/API tokens/etc and wrap it up in a tarball to be included in the pull-request. #AI #LLM #programming #development #foss #oss
0
4
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 18, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @cmthiede@social.vivaldi.net
@cmthiede@social.vivaldi.net @cwebber@social.coop You think it's THAT easy, do you? https://www.zdnet.com/article/academics-steal-data-from-air-gapped-systems-using-pc-fan-vibrations/ https://www.bleepingcomputer.com/news/security/data-exfiltration-technique-steals-data-from-pcs-using-speakers-headphones/ https://www.tomshardware.com/tech-industry/cyber-security/researchers-snoop-data-from-air-gapped-pcs-ram-sticks-by-monitoring-em-radiation-from-23-feet-away 😉
0
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 16, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @nixCraft@mastodon.social
@nixCraft@mastodon.social I find this refreshing. And it reflects the mood of a lot of smartphone users today. $500 is probably a tad too much to gain widespread popularity. But it could have been way worse. And considering what it seems people are willing to pay for smartphones today, it sure is a bargain. Running SailfisOS certainly is a good move - and ensure that there's a community behind the OS. And SailfishOS is pretty nice. And I trust Jolla way more than an AOSP build.where Google has influenced it heavily for their benefits (there are 2-3 exceptions of AOSP based alternatives which has gone the extra mile of kicking out Goolge, though). My main reason for not jumping onboard on this one is that I miss a more production-ethical aspect. One which I believe Fairphone does much better. Ensuring they deliver a more sustainable phone, where the supply chains are far more scrutinised than most other vendors do. That's where I stand at least.
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @rolle@mementomori.social
@rolle@mementomori.social Yuck! That's truly backwards in so many ways. I can understand such legislations in context of fighting criminal activity, money laundering and similar things, but that even the EFF got in trouble due to these laws is just so plain stupid. It effectively cripples any way to fund more costly community efforts in a reasonable way without much overhead. Not much motivating at all.
1
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @rolle@mementomori.social
@rolle@mementomori.social Wow! I didn't know it was so strict on receiving donations. You anyway need to do what's needed to stay legal. I wasn't aware of this, so it sounded like a lot more work and overhead for a hobby project.
2
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @rolle@mementomori.social
@rolle@mementomori.social I believe you need to figure out what solves the short time situation and what makes your instance sustainable. If that is best done through creating an organisation or foundation handling all the costs and receiving contributions, that is a hard question to answer for anyone not being directly involved in it. Many people will hopefully join in, but I suspect most people would care less if it is arranged "this way" or "that way" as long as you have credibility amongst your users. My point is ... Do what your 917 users would trust most and which gives you least administrative management overhead. You and your team is first of all serving the people behind those 917 accounts.
0
2
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · Jun 07, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @rolle@mementomori.social
@rolle@mementomori.social It's really admirable that people like you, @jerry@infosec.exchange, @stux@mstdn.social and others do this work! This is a pledge to the community to help the people who makes this all possible. Since I'm on the infosec.exhange instance, I do donate yearly to this instance. I hope so much that users do donate to the instance owners where they have their accounts. If enough people contribute, even if it's just a dollar or two, I believe it really can make a difference. And Mastodon instances do need help to stay alive. Mastodon is first of all a community effort. It's not a platform where instance owners earns money on us users posting and sharing here. We all must chip in to ensure the Mastodon instance we use is sustainable. A huge thank you to all the instance owners, admins and moderators. And thank you all for listening. #mastodon #donate #contribute #community
1
0
3
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 26, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @tasket@infosec.exchange
@tasket@infosec.exchange True! That's also part of my default setup 🙂
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 25, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
I always remap my sshd daemon to listen to a non-standard port, to reduce a lot of noise. Which has worked fine for years. But every now and then there are attempts. All the #Linux kernel flaws found lately has made remote login attempts more interesting for attackers. And they scan much more broadly now than just port 22. And that's why my second line of defence is to disallow remote root login - and also make use of the AllowGroups feature in sshd_config. Users granted remote access must be member of a specific group. And root is also excluded from this group. That pays off these days. And this is a nice filter match for #fail2ban and similar tools https://termbin.com/0cf6 I have 293 login attempts on "random users" since May 21. And 259 attempts as root. #infosec #ssh #sshd #systemhardening #kernel
6
2
2
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 13, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @ElenLeFoll@fediscience.org
@ElenLeFoll@fediscience.org I'm just waiting for a twist in this story. That even this story is made up, with the help of LLMs ...
1
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 12, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange Reminds me of an advice I got ages ago ... "Sometimes it's better to fight the bugs you know, rather than to upgrade and fight the unknown". The argument was not intended to discourage upgrades, but to encourage testing and auditing upgrades first - so you hopefully can have a better understanding of the unknown. But testing and auditing hasn't exactly become easier.
5
1
1
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 10, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @arne_d_h@snabelen.no
@arne_d_h@snabelen.no @tanketom@tutoteket.no Hørt om VPN/Proxy over DNS eller ICMP? Går ganske tregt, men er en av de enkleste måtene å unngå de aller fleste sperrer. Finnes andre mer utspekulerte måter også. Uansett er alle disse relativt enkle løsninger å sette opp. Man må ha noe(n) som overvåker trafikken hele tiden for å unngå at noen omgår sperrer.
0
0
1
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 10, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @arne_d_h@snabelen.no
@arne_d_h@snabelen.no @tanketom@tutoteket.no Hva med å få papirutgavene av aviser som epub filer, lastet inn på rimelige e-ink baserte lesebrett (uten nett) via et minnekort?
0
1
1
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 06, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @radicle@toot.radicle.dev
@radicle@toot.radicle.dev @vagrantc@floss.social What about the agent feature in tumpa-cli? Could that be a potential path? https://github.com/tumpaproject/tumpa-cli/tree/main
0
0
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 05, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @jo69@mastodon.social
@jo69 Based on years of experience with @protonprivacy ... they take baby steps, to ensure nothing breaks. But they also give access to new features to users earlier as well. So if you want to join the fun earlier, you can opt-in. Visionary users (not an available plan any more) gets access much earlier as well, and can often opt-in there too. When Proton opens up for opt-in at this stage, more publicly, they've decided to expand the scope further. I expect that PQC will be enabled by default in 6-12 months - and then after some more time (2-5 years?) you can no longer create non-PQC keys at all manually. Proton have far over 100 million users to care for. If something broke badly in the first transition, it would end up very bad for both Proton and all their users. This way they do more a controlled way of enabling new features while reducing the risks as well as lowering the consequences if something bad happens. While I understand the annoyance of enabling it manually now, it the very end I'm pretty sure you'll see it will become the default with time.
3
1
0
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 05, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @dazo@infosec.exchange
@ligasser Oh, and I forgot to say ... I've been interacting with folks and developers in the @radicle community ... they are absolutely stellar and wonderful folks! @nixCraft
2
0
1
0
Open post
dazo
🐈‍⬛David Sommerseth @dazo@infosec.exchange · May 05, 2026
🐈‍⬛David Sommerseth
@dazo@infosec.exchange

F/OSS hacker, mostly working on #OpenVPN - speaks only for himself. "Don't aim to be someone. DO something." #nobridge - because I believe in the real #fediverse, and I don't want my own views/data to be abused by yet another "closed-service which can do whatever it wants for profit". **BEWARE:** Someone has created a Twitter profile in my name: https://twitter.com/DavidSommerseth - this is ***not*** me **If you want to follow me**, you now **MUST** have some content on your profile where we have some common ground on interests. I will no longer accept random profiles wanting to follow with no toots or no other follows or followers in the same interest sphere.

infosec.exchange
Replying to @ligasser@social.epfl.ch
@ligasser A good place to start looking for repositories hosted on Radicle, is the search engine: https://search.radicle.xyz/ Those URLs to a repo are quite "complicated", which is due to repositories being distributed. The "viewer" doesn't need to be on the same host as where the data resides, and the data will typically reside on more nodes. So this gives a view of data available on a single node. And this web view is read-only. To interact with a repo (create an issue, file a pull request, provide a comment, etc), you need to run the radicle-node locally and use the tools locally. The radicle-desktop is quite neat to get a more common "web like" user experience. @nixCraft @radicle
1
1
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:02:24 UTC