Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Gabriel N

@gnyman@infosec.exchange
  • Open on infosec.exchange
0 Followers
0 Following
27 Posts
Joined November 09, 2022
Founder of:
https://kilpi.tech
Personal website:
https://nyman.re

Posts

Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Aug 04, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @kepano@mastodon.social
@kepano@mastodon.social @kepano@mastodon.social ok, so there is no security risk from accepting this, it will just create a new note? Or is it here where a webpage could inject code (by having it in the webpage?) and do something bad? I think it’s the simultaneous clipboard issue which is causing a lot of the confusion. It does not ask "Do you want to create a new note with ”? It shows some error about the clipboard. I understand the problem with URI’s not being authenticated, I think it’s wrong allow all "new" commands, it should be per app. If the clipper would generate a private key it could sign the requests and then you approve "Web Clipper" to always do this but other apps would not be able to do it? Thoughts?
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Aug 04, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @kepano@mastodon.social
@kepano@mastodon.social can't say without knowing what it's trying to do and why it's asking me, and what are the implications of saying yes or no is
0
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Aug 03, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @kepano@mastodon.social
@kepano@mastodon.social is this (one of) the new prompts? I don't understand what I'm being asked to do, and I consider myself fairly technical. I got it when running the web clipper.
0
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Aug 03, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
I love what your doing with obsidian @kepano@mastodon.social but can you help me understand this. Is it convoluted edge case that was not prioritised? Is opening untrusted md's not something you think people do? (I don't but just sample of 1). As Adam presents it, it looks bad but I'd like to hear the other side of the story. https://www.linkedin.com/posts/evilpacket_if-you-use-obsidian-you-will-want-to-upgrade-share-7488660732641763328-69yj/
0
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 26, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @inthehands@hachyderm.io
@inthehands@hachyderm.io yes! Let's add LLM chats (openai, meta ai, etc etc) into that list I use LLMs for some things, but I've started a habit of doing a takeout and then deleting all data regularly. Not perfect as it assumes they actually delete it, but I do think that they will do that (with maybe an exception of anything flagged for safety). Not deleting things when asked seems much less likely than loosing it in a hack or figuring out a legal way to use it even if you told them not to.
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 23, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
RE: https://infosec.exchange/@wdormann/116965991820118056 Microsoft: "We are making security our top priority, above all else." Also Microsoft
Quoting
Will Dormann @wdormann@infosec.exchange
From a SharePoint vulnerability perspective, this is the most trivial exploit I think I've ever seen. The exploit is a single web request to SERVERNAME/_trust/default.aspx In the request to this endpoint, there's a XML structure, where the value is serialized data that is unsafely deserialized by the SharePoint server. At this point, SharePoint executes whatever is specified in the ysoserial.net-created serialization blob. That's it. No special sequence of events. No tricky to get to endpoint. No need to authenticate in any way.
Open quoted post
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 22, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
RE: https://mastodon.social/@marginalia/116962929877712271 lol best way to describe dockers dumb firewall bypass It further doesn’t let you set firewall rules for the ipvlan interface, which means that anything you put there better not bind on the public IP, or its ass is going to be hanging out in full view. This is in no way a limitation of ipvlans, but purely a docker problem. I love when technical people write up why for solutions just not "here is a list of steps I ran". Please keep them coming @marginalia@mastodon.social
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 22, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @rw@social.kernel.org
@rw@social.kernel.org not a bad idea except LLMs are not great with creativity but even with that in mind it can't get worse than the current numberwang Maybe a mix, allow user submitted names and let people vote :-) that is sure to create memorable names
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 21, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @strawhousepig@mastodon.social
@strawhousepig@mastodon.social @tychotithonus@infosec.exchange airbus had a nice one also
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 21, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @ThinkstCanary@mastodon.sdf.org
@ThinkstCanary@mastodon.sdf.org @haroonmeer@infosec.exchange this is interesting but isn't it self-defeating, we want the agent to trip the token don't we? At least that's where I ended up when I was thinking about how to use tokens in a AI context. They are good for detecting when the AI tries to use something it shouldn't or when that something has been exfiltrated.
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 15, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @CryptoLek@infosec.exchange
@CryptoLek@infosec.exchange I'm a bit confused by this moralisation by criminals
1
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 09, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @taosecurity@infosec.exchange
@taosecurity@infosec.exchange the link goes to the ebook not the blog?
0
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Jul 03, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @Viss@mastodon.social
shameless self promotion Hover or focus to reveal Sensitive
@Viss@mastodon.social oh nice! I recently spun up Nessus and couldn't believe how bad it still was. Your sign up page only asks for domains though, can the tool scan a ip range (we are the RIPE holders)?
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 26, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @th@social.v.st
@th that's nice, time for the sauna to pay itself back :-) In Finland we had this quite a lot in the recent years but the market is catching up with large resistive distric heaters, and I guess some battery capacity, up so it's becoming more rare
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 26, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @CryptoLek@infosec.exchange
@CryptoLek@infosec.exchange I also like doing this, makes walking feels "productive", the bad part is when you find too much trash but don't have a place to drop it so you just have to leave the rest :-/
1
1
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 23, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

Found this in my archive. One of the last times when I installed a dot zero OS X release. Now I generally wait until just before the next major release as around that time all new features go into the new one and the "old one" just get bug fixes.

1
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 23, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @averagesecurityguy@infosec.exchange
@averagesecurityguy@infosec.exchange @sawaba@infosec.exchange yeah I agree with you both on why incidents don't fix anything, if we disagree on something it's maybe if AI will cause enough incidents to lead to a change or not, I don't think so, I think it will cause incidents and companies will put some policies in place to keep the amount just below the critical line.
1
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 23, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @sawaba@infosec.exchange
@sawaba@infosec.exchange @averagesecurityguy@infosec.exchange oh this is fantastic, bookmarked! I was looking for something like this a while back
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 22, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @sawaba@infosec.exchange
@sawaba@infosec.exchange no, not crazy, but sadly I think it's rare that a company that has a breach can actually change. There are so many examples of companies having constant security incidents without any real change. My thinking is that unless security is actually a core priority and culture, nothing will change for real.
1
5
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 17, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

Interesting, Microsoft has (started?) putting up a warning on repos that host exploit code.
From the description it sounds like the code itself would be malicious but afaik this is "just" a PoC.

The interesting part is to see if they start doing this everywhere or just when it's windows exploits that make them look silly :-)

0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 14, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

@campuscodi@mastodon.social @Techaltar@mas.to would be great, it would allow them to subsidier the consumer tiers just like the other big tech does. Proton is out of the reach of so many because of the cost.

mastodon.social

Catalin Cimpanu (@campuscodi@mastodon.social) - Mastodon

0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 14, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @jerry@infosec.exchange
@jerry It seems like a win-win and was looking into it this winter when electricity prices was high, a DYI solution barely works out if you already own a GPU, and this is Finland where we need heating most of the year But on a professional scale it has been tried many times and all of the companies have either gone bankrupt (Dutch nerdalize )or switched to doing it at district heating level (French qarnots) Only one who still seems to be around is UK https://heata.co/ and they heat your water.
1
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 13, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

it's a interesting world we live in where the rewrite-in-rust army has now gotten nuclear weapons in the form of LLM's, and they are not afraid to use them :-D

The backstory for why I started thinking about this is that CIRCL.lu runs this vulnerability-lookup project, which is great. But I had some ideas how to improve the notification emails so I wanted to look into what it would need to self-host in order to customise it for my use.

But I got distracted by this, I rewrote it in rust, issue.

Someone just had a LLM reimplement everything in rust, I think in order to reduce the system requirements for running the project.

I mean, I'm very divided. I love efficient computing. I am not going to (want to) self-host vulnerability-lookup if it needs 7 different services and 16 GiBs of RAM. So a efficient rust implementation would be interesting.

But after looking at the code, I am not sure this is the right approach. I told codex to look at it before deploying it and there are so much unnecessary stuff in there. Is it slop? I don't know, I guess that depends if someone keeps maintaining and improving it for more than a month.

Just because you can does not mean you should.

Would it have been better to take those tokens and spend it on improving the slow or resource intensive parts of the original project?

0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 10, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

It's a frisk 7C but sun is out and it's time to start collecting that d-vitamin.

Quite an experience to first listen to the Artemis recap and then notice that I (unintentionally) picked my ESA coffee mug.

Humanity can do great things, I hope we can keep the focus on the building rather than destroying.
https://youtu.be/J4FE0JocJpk

0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Apr 10, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange

Microsoft PR department does what they always done, catch on to some brand and milk it until it has negative value.

They did this same thing with Azure and probably other things before it.

I wonder if this is intentional, does the board want them to do this or is it an institutional thing they can't stop?

https://teybannerman.github.io/strategy/2026/03/31/how-many-microsoft-copilot-are-there.html

0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Mar 27, 2026
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @bjis@mastodon.social
@bjis @krisu @kepano I assume this is a general comment about state of things, one just need to take one look at Show HN or GitHub to know 99% of those projects were done in a few evenings and the author will loose interest and/or notice it's impossible to maintain with a week
0
0
0
0
Open post
gnyman
Gabriel N @gnyman@infosec.exchange · Nov 01, 2025
Gabriel N
@gnyman@infosec.exchange
infosec.exchange
Replying to @micahflee@infosec.exchange
@micahflee containers are good for this, I've been running the agents in containers in yolo mode for various stuff, really useful when you need them to figure out something involving tools instead of just code The next step is to limit the connectivity so it can't exfiltrate your code, it's a bit harder but with some firewall it and forcing all traffic through a proxy it's possible to do precise enough filtering But, looking at your dockerfile... what's up with running apt-get update 6 times and deleting the list each time. I mean bandwidth is cheap by why waste it?
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:50:22 UTC