Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Harry Sintonen

@harrysintonen@infosec.exchange
  • Open on infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

0 Followers
0 Following
50 Posts
Joined November 18, 2022
PGP:
https://sintonen.fi/pgpkey.txt
Research:
https://sintonen.fi/advisories/
Github:
https://github.com/piru

Posts

Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · 6d ago
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
Since they feel so strongly about helping the #curl project I told them to look into https://curl.se/sponsors.html
curl.se

curl - Project Sponsors

0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · 6d ago
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
It appears that AI companies target open source contributors with their marketing spam: "we noticed you contributed to curl/curl — thanks for helping build open source. We're running a small program for Github OSS contributors and would love to invite you. You'll receive $25 in XXXXXXXXX credits to use frontier AI models (this time YYYYY) through a single OpenAI-compatible endpoint." #enshittification
1
1
1
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 06, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape" https://www.openwall.com/lists/oss-security/2026/08/06/3 #CVE_2026_64564 #infosec #cybersecurity
www.openwall.com

oss-security - CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalatio

9
4
6
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 06, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @icing@chaos.social
@icing@chaos.social "We must also get on the doom marketing bandwagon, or get left behind!"
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 04, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
"As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled" 🤦‍♂️ What exactly did they expect would happen when following such policy? ref: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
AI Security Institute

Incident Report: unsanctioned agent behaviour during cyber testing | AISI Work

0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 04, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
"Embargo klo 01:00" ja juttu julkaistu 00:01 - nyt ei kai ihan mennyt niin kuin suunniteltiin. #yleisradio
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 04, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
#Engadget, yes we do have a reason not to watch #Babylon5 from YouTube.
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 04, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

  • CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
  • CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
  • CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
  • CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
  • CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
  • CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/

#infosec #cybersecurity

0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 03, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
Here's my older mitm-to-SYSTEM vulnerability writeup for anyone interested: https://sintonen.fi/advisories/n-able-ecosystem-agent-improper-certificate-validation.txt N-able dismissed this as low level finding.
5
0
3
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 03, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ #nablencentral #CVE_2026_18577 #infosec #cybersecurity
N-able Status

N-central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577

Release Note Details Download CMMC Download Build Number : 2026.3.1.7 Last Updated: 02-August-2026  This release is based on 2026.3.0 which was release on ‘July 30th 2026’ . To find out all that is…

0
1
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Aug 02, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
40 years of #Byterapers: 1986: https://www.youtube.com/watch?v=txaIWaT6zik 2026: https://www.youtube.com/watch?v=TmwjZ33ID5k (Assembly 2026 #democompetition winner) Congratulations on continuing to be awesome! #demoscene
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 31, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old. Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream. Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong. I've now reported the issue upstream, which will hopefully eventually lead to a fix being distributed to every affected platform. I am not going to disclose the details of the vulnerability right now, even though the fix has been public for a very, very long time now. As far as I can tell, most Linux and BSD systems are vulnerable right now, so letting coordinated disclosure happen only makes sense. #infosec #cybersecurity #vulnerabilityresearch
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 27, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @VictoriaFerryRetroGeek@piaille.fr
@VictoriaFerryRetroGeek@piaille.fr Negative bit number isn't necessarily incorrect. The CPU internally modulo the bit number by 32, even if negative. Thus, for example: btst #-32,d0 btst #-64,d0 btst #-96,d0 All those btst are entirely valid, and the same as btst #0,d0. The question is if the value is actually correct (even if negative). If it is not correct then this is a problem indeed.
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 25, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Back when the "internet" involved expensive phone calls and modems, someone figured out that a video backup system (VBS) could be used to distribute hundreds of megabytes of "backups" between friends by shipping a VHS cassette in a padded envelope. You just needed a VCR (everyone had one), and a small harness that could sample the video signal from the VCR for the software to decode. Interestingly, the Video Backup System website is still up: http://www.hugolyppens.com/VBS.html I'm sure someone used this thing for actual backup purposes as well...
38
10
35
1
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 24, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
13 2026-07-24 16:23:31 +0000 error: Corrected error, no action required., CPU 2, bank Unified Memory Controller (bank=17), mcg mcgstatus=0, mci CECC, mca DRAM ECC error. Ext Err Code: 0 Memory Error 'mem-tx: generic read, tx: generic, level: L3/generic', memory_channel=0,csrow=0, mcgcap=0x0000011c, status=0x9c2041000000011b, addr=0x72fb55480, misc=0xd01a000101000000, walltime=0x6a639183, cpuid=0x00a20f10, bank=0x00000011, microcode=0x0a201030 #ECCMemory saving the day.
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 23, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @gabrielesvelto@mas.to
@gabrielesvelto@mas.to Indeed, "RAID is not a backup". This is why in my own setup I have important zfs datasets backed up to second onsite pool with syncoid and really important data also to a remote server.
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
#openai #huggingface
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 17, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
VESA Monitor Control Command Set (MCCS) standard "Asset Tag" function has a gaping flaw. The key is 16-bit and there is no rate limiting. 🤦‍♂️
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 16, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
#Amazon #CloudFront seems to having global issues. https://health.aws.amazon.com/health/status
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 08, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
I've started to outright block accounts posting AI slop or parroting AI company PR statements. Life is too short.
0
1
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 05, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jul 01, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Risto Mikael Riihimäki, owner of Rent ja Kalusto Oy, has been sentenced to three years and 8 months in prison for a aggravated regulatory offence. The company delivered 135 trucks and 29 trailers to Russia, circumventing the EU sanctions. In court, the company claimed that the items were destined for Kazakhstan or Turkey, but Finnish officials were able to recover the communications between Riihimäki and his Russian contacts, making it clear where the items were really destined. The company was sentenced to lose the 608275€ profits from these dealings, fined 10000€, and equipment worth 6 million € confiscated.
24
1
23
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 30, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

No, the libssh2 vulnerability CVE-2026-55200 isn't end of the world.

  1. You need to defeat ASLR to successfully exploit it. The PoC works only when you disable ASLR. In most realistic use cases you need additional off-band infoleak from the app using libssh2.
  2. You also must somehow convince the victim to connect to your malicious server, OR compromise some existing server to perform the attack.

Calling this a "CRITICAL VULNERABILITY" is dumb.

68
0
45
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 28, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
https://fightchatcontrol.eu/#contact-tool #fightchatcontrol #chatcontrol
4
1
6
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 28, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
I hate it when I'm right about these things. https://www.euronews.com/my-europe/2026/06/26/eu-countries-move-to-revive-temporary-message-scanning-regime-but-it-could-backfire https://infosec.exchange/@harrysintonen/115383111569608066 #stopchatcontrol #privacy
26
3
25
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social I was a LPB using uni network. 😄
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 21, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
I have consistently refused to engage AI in any tasks that require mental effort. Intuitively, I felt that it leads to laziness and eventual deterioration of problem-solving skills. I still consistently challenge myself by solving already solved problems - not because they haven't been solved well already - but in order to maintain my skills. I can only recommend this approach. https://www.nature.com/articles/d41586-026-01947-1
127
8
130
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 18, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Heads up to anyone using #AMD CPUs in a setting where Transparent Secure Memory Encryption (TSME) is critical: AMD has disabled this feature for consumer AMD products as of the latest AGESA updates. The feature is now only available for "PRO" CPU variants. https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/ #enshittification
52
1
56
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 10, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
I, for one, hail our EU overlords for staying their ground and not bending over to Apple. This EU regulation did not come as a surprise to anyone, and definitely not to Apple. Yet they decided to go all knee-jerky about it. Food for thought: If you cannot implement an AI feature in an interoperable and safe manner, it likely should not be implemented at all.
113
10
53
2
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Jun 09, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions. #CVE_2026_45447
12
0
17
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 11, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @lordkhan@social.cologne
@lordkhan@social.cologne In terms of energy and resource consumption, very likely so.
0
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 11, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @gnirre@mastodon.social
@gnirre@mastodon.social None.
3
1
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 11, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Vulnerabilities found from #curl:

#Mythos: 1
Me: 30

- https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
- https://sintonen.fi/advisories/

137
8
94
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 04, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Several vulnerabilities in #Apache HTTP Server 2.4 have been fixed in release 2.4.67. The most severe of these are:

- CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset

- CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

- CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack

https://httpd.apache.org/security/vulnerabilities_24.html

#CVE_2026_23918 #CVE_2026_24072 #CVE_2026_33006 #infosec #cybersecurity

6
0
8
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 03, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @rebane2001@infosec.exchange
@rebane2001 This reminds me of a certain provider who used to have a pre-created user on the default Linux image with a password the same as the username. The user was in sudoers. This user account wasn't documented anywhere. So even if you changed the root password, all systems set up with that image remained trivially exploitable over ssh.
5
0
1
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 03, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
Certainly, it was a different time back then, but the huge spying incidents related to the US nuclear program had already happened. It boggles my mind that Los Alamos National Laboratory would just hand out any hardware to third parties, rather than just destroying it.
1
2
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · May 03, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Los Alamos nuclear secrets "leaked" in LGP-21 magnetic disk memory:

https://www.youtube.com/watch?v=IBjh0SaA5dc

I guess securely wiping storage media wasn't a thing eh?

#retrocomputing #usagielectric

5
2
3
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 30, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Reminder to anyone using #ApacheCamel SCP/SFTP connections: Apache Camel does not perform host identity validation unless you explicitly configure "StrictHostKeyChecking" as "yes". The default value for "StrictHostKeyChecking" is "no". If you do not explicitly configure this option as "yes", the connections are susceptible to meddler in the middle attacks.

What is the impact of such insecure configuration?

If you are using SSH password authentication, the attacker in a privileged network position can perform full MiTM, grab the username and password, and thus gain authenticated access to the target server.

If you use a key-based authentication, the attacker cannot perform full MitM. However, they can still present a fake server and, in case of upload, steal the uploaded files. In case of download, the malicious server can present fake or malicious files for download.

So, any configuration that could get intercepted MUST always specify the host identity and use "StrictHostKeyChecking" "yes". Even configurations in secured networks should use "yes" for additional security.

Unfortunately, the Apache Camel documentation isn't clear on this topic, and the OpenSSH's similar option and its default value working in a different manner can easily lead to confusion and insecure configurations.

#insecuredefaults

1
0
6
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 30, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
You can use the following the check if the mitigation has been applied correctly: python3 -c 'import socket; s=socket.socket(38,5,0); try: s.bind(("aead","authencesn(hmac(sha256),cbc(aes))")) print("AEAD interface present") except OSError: print("AEAD interface disabled")'
5
0
6
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 30, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Mitigation to #CVE_2026_31431 / #copyfail :

  • If kernel config has CONFIG_CRYPTO_USER_API_AEAD=m:

echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf; sudo rmmod algif_aead

  • If kernel config has CONFIG_CRYPTO_USER_API_AEAD=y:

Add "initcall_blacklist=algif_aead_init" to the kernel command line and reboot.

https://www.openwall.com/lists/oss-security/2026/04/30/2

24
5
31
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 24, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
In other news: UK Biobank health data listed for sale in China, government confirms https://www.bbc.com/news/articles/cpvxgl3n138o
1
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 24, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Finnish medical data is available for researchers, unless if you specifically opt-out. I have, you should, too.

https://findata.fi/en/about-findata/your-data-rights/#how-can-I-exercise-my-rights

#privacy #medicaldata #secondaryuseofdata

9
1
9
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 23, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @Netux@mastodon.sdf.org
@Netux@mastodon.sdf.org @signalapp@mastodon.world I of course included a PoC. This is not my first ride.
1
1
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

I've tried to report a security vulnerability to @signalapp@mastodon.world for months now (first attempt was 2025-11-23 to the official security-at email address). I haven't gotten any response from them, even after repeated attempts. This is highly frustrating.

Is there a way to reach them? I don't need any kind of special treatment, just someone acknowledging that the message has been received would be okay.

#signalapp

mastodon.world

Signal (@signalapp@mastodon.world) - Mastodon

12
12
18
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @zackwhittaker@mastodon.social
@zackwhittaker No amount of AI can protect one from human stupidity.
4
0
1
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @harrysintonen@infosec.exchange
If this sounds bloody obvious to you, that is because it is. Yet, it seems to be forgotten by many these days.
3
0
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 22, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

Not every security adjacent bug is an exploitable vulnerability.

4
1
2
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 16, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange

#OpenSSL 4.0.0 ported and we have #curl #ECH

41
0
12
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 13, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @leeloo@c.im
@leeloo If "spending money you don't have" is a concern there's a rather easy mitigation: pay with cash only when the network is down.
3
2
0
0
Open post
harrysintonen
Harry Sintonen @harrysintonen@infosec.exchange · Apr 13, 2026
Harry Sintonen
@harrysintonen@infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

infosec.exchange
Replying to @christopherkunz@chaos.social
@christopherkunz A solution that mitigates this risk would be preferable, indeed. As reported in https://www.ecb.europa.eu/press/pr/date/2025/html/ecb.pr250228_1~7f0697af45.en.html in 2022 only 37% of payments used national systems. Even those likely have many dependencies to systems outside of EU.
1
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:29:05 UTC