Sr. Security Specialist at iteratec // @seemoo@infosec.exchange alumni // Member of CCC // Crypto means cryptography.
tfr.
Posts
@vonnordmann@chaos.social I had to search for a bit to find it, finally found it in the upgrading notes:
The new server needs roughly twice the RAM than the old one and also a bit more CPU, so make sure your Home Assistant host has enough free memory to run all services smoothly.
https://github.com/home-assistant/addons/blob/master/matter_server/MIGRATION_FAQ.md
@bms48@mastodon.social You are entitled to that opinion. The technical implementation does not care about the sociocultural context of Anthropic, and that was the focus of the article. Refuting incorrect claims about a technical implementation does not imply a defense of the behavior of the company.
@bms48@mastodon.social That is correct, and it did not attempt to do so. Does every article that touches Anthropic need to recap and refute every single criticism of anthropic now, even if it is irrelevant to the issue it is discussing?
Someone wrote a viral article claiming that Claude installs Spyware on your computer. The technical observation is real, but the threat is not. I took a closer look, and I would argue that the real issue with the Claude extension is somewhere else entirely, and I've seen little discussion on it: Matt Hand at Origin found that the extension actually allows almost *any* software on your machine to control your browser.
I wrote it up as an example for how threat modeling can be helpful in evaluating sensationalist claims about security issues, including where Anthropic themselves fall into the same trap.
RE: @SocketSecurity@fosstodon.org
2020: the best thing you can do for security is have a bot automatically update your dependencies.
2026: the best thing you can do for security is to tell your bot that updates dependencies to wait a day or three before updating them.
Expect more of this over the coming months as compromised credentials from previous supply chain attacks are used to mount new ones.
RE: @homeassistant@fosstodon.org
Me: „oh, I wonder if they got the cryptography right. Might take a look.“
Blog: „…audited by @trailofbits@infosec.exchange...“
Me: „alright, nevermind, it’s going to be good, no need to check.“
I never understood the concept of Moltbook - why create a social network for AIs to talk to each other when there's already LinkedIn?
RE: @SocketSecurity@fosstodon.org
Socket has been consistently providing helpful writeups of the recent supply chain attacks. Very good signal to noise ratio, and worth following if you are struggling with figuring out the effects of the latest supply chain incidents.
#Trivy got compromised on thursday and released a backdoored new version, which was rolled back. We spent the entire friday in incident response mode. Now they got compromised again over the weekend.
I have a lot of sympathy for people under pressure during an incident, but for fucks sake, having a security tool get compromised three times within two months is just completely bonkers. We spent more time remediating security issues caused by our security tooling than any other cause. And the fact that there wasn't any official communication on friday means that we had to rely on third-party writeups, which were missing critical information like exact docker container digests and time ranges of the compromise. This made incident response completely miserable.
Anyway. Trivy 0.69.4, 0.69.5, 0.69.6 were all compromised with infostealer malware. Do what you have to do. There are several decent writeups:
- https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release
- https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack
- https://labs.boostsecurity.io/articles/20-days-later-trivy-compromise-act-ii/
And Trivy has an advisory on their GitHub that covers last thursday, but not the second compromise over the weekend: https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
Tempted to call the motion detector in my office „senpai“ because it frequently doesn’t notice me 😫
So, what is the #Sanderson equivalent to „slashdotted“? I nominate #Sandstorm.
(New crowdfunding campaign by Brandon Sanderson just launched and took down #Backerkit)
For the #selfhosted / #homelab people running #Hister (https://github.com/asciimoo/hister): you should update to version v0.4.0 ASAP. I reported a vulnerability in the previous version that allows any website to download your entire database due to missing CORS enforcement. The author responded very quickly to the disclosure and had a new release ready within a few hours, excellent work on his part.
Sadly, Hister is currently not packaged and does not auto-update, so people will have to manually download a new release, or be vulnerable.
CC @shollyethan@fosstodon.org, since he included it as a spotlight in this week's newsletter.
Der Antennenhirsch als selten gesehener Verwandter des #Datenelch, gesichtet in Regensburg. @linuzifer@23.social @lnp@podcasts.social