Remote
#Blueteam in #infosec / #cybersecurity at a place.
Outside of tech, interested in #camping, #gardening and family.
0
Followers
0
Following
22
Posts
Joined November 06, 2022
Posts
Replying to
@ramin_hal9001@fe.disroot.org
@ramin_hal9001@fe.disroot.org I too am being forced to use it, with the same observations. Even getting it to create or modify scripts to do the actual work is troublesome.
It will get something in its head and once it decides on it, it will just attempt the same thing three or more times in a row despite you telling it no repeatedly.
I don't feel guilty at all swearing at it, so because of that, I prefer to think of it as a glassy eyed intern rather than a babysitting job, but the effects are the same.
Open post
Australian Government 2026 Census website is failing, and it isn't even the real Census night yet. Imagine what is going to happen on Tuesday!
This is reminicent of the 2016 census, which was the first attempt to allow online submissions, which failed because everyone logged in after tea to do it at the same time and flooded the system (causing the government to claim they were hacked, rather than just not provisioning their systems correctly to handle the correct load).
I thought that surely there wouldn't be a flood on Saturday night, so do it now, but it appears that wasn't a good assumption.
#auspol #censusfail #census2026
0
0
0
0
Open post
Replying to
@sourceware@fosstodon.org
@sourceware@fosstodon.org
Ratelimiting requests without cookies, and separately ratelimiting requests which had previously accepted cookies using the cookie as the rate limit key, when put together may help.
0
0
0
0
Open post
Replying to
@ludicity@mastodon.sprawl.club
@ludicity@mastodon.sprawl.club
The turning point in my belief was watching someone with a spectacular amount of money on the line fire their highest performers because they were achieving that performance without LLMs.
I can personally testify to this. Actual performance measurements have been ignored if LLM usage is not indicated.
1
2
1
0
Open post
Replying to
@mgd81@infosec.exchange
@mgd81@infosec.exchange Getting past commercial fingerprinters is just the first step.
As long as it either accepts cookies, or doesn't accept cookies, each IP address, can be detected and blocked after N queries, where N depends on the risk you want to accept for also blocking legitimate users.
0
0
0
0
Open post
Replying to
@bob_zim@infosec.exchange
@bob_zim@infosec.exchange @FuturisticRobert@infosec.exchange @jerry@infosec.exchange 2FA isn't designed to stop credential leaks. If that happens everyone should be doing password resets and onboarding 2FA again. It is solely designed to prevent someone else's data breach from affecting other websites.
Even if a site uses passkeys, you can have an account takeover through someone adding another passkey to your account. And if the site is hacked, they wouldn't try to impersonate a user through the front door. They own the whole house.
1
5
0
0
Open post
Replying to
@colinmford@typo.social
@colinmford@typo.social
This explains their recent oddness.
To escape the electricity costs they are going to make consumers generate the results locally with their 3GB inbuilt Chrome model...
And to quantify fraud with this new distributed scheme they want recaptcha to know about every mobile device on earth...
1
1
0
0
Open post
Open post
Replying to
@eff@mastodon.social
@eff@mastodon.social Both companies control the client applications, the operating systems, and are required by multiple jurisdictions to run client side scanning.
Never be fooled by transport encryption, even if it is end-to-end.
1
2
1
0
Open post
Replying to
@silvermoon82@wandering.shop
@silvermoon82@wandering.shop @DaveMWilburn@infosec.exchange @Sempf@infosec.exchange Needing a report to be deterministic doesn't stop the true AI believers. Personal experience hand writing a real report after lawyers complain about team members slop taught me that.
1
0
0
0
Open post
Replying to
@dangoodin@infosec.exchange
@dangoodin@infosec.exchange It needs to be good faith on both sides.
Having a human hide behind a robot facade and then release the recent ImageMagick vulnerability after their LLM failed in 7 days of feedback with maintainers pushed the good faith argument on both sides.
1
0
0
0
Open post
Replying to
@wdormann@infosec.exchange
@wdormann@infosec.exchange At least they say they went to linux-distros and received advice first. Small mercies that we aren't the first to alert distros to it.
2
0
0
0
Open post
Replying to
@SwiftOnSecurity@infosec.exchange
@SwiftOnSecurity It is great to get to the stage in defensive security where you can piss the bad ones off but you don't even need to know they exist.
Almost makes all the other times worth the effort.
2
0
0
0
Open post
Replying to
@nyanbinary@infosec.exchange
@nyanbinary@infosec.exchange @gayint@infosec.exchange Awesome. I don't even remember what the imposter organization letters stand for now.
0
0
0
0
Open post
Replying to
@gayint@infosec.exchange
@gayint@infosec.exchange GCHQ infiltrates another organisation! /s
2
2
0
0
Open post
Replying to
@reverseics@infosec.exchange
@reverseics Vance should know, just look what happened to the previous pope after their visit.
0
0
0
0
Open post
Replying to
@Viss@mastodon.social
@Viss@mastodon.social @cR0w@infosec.exchange Wow! Just wow! I thought OpenSnitch was a long term thing for me now that I switched.
2
0
0
0
Open post
Replying to
@nixCraft@mastodon.social
@nixCraft@mastodon.social Mine let you know which "agent" every document has to be run through to "correct errors" before it gets to that level. If you don't, they reject it based on believing the non-human more than the human.
0
0
0
0
Open post
Replying to
@petealexharris@mastodon.scot
@petealexharris @ErikvanStraten @grammasaurus @SteveRudolfi They have been working for years to destroy URLs as a basis of trust.
Even when you think a domain is real on a Google search result it can be someone else's site that they told Googlebot went through to your real site after a redirect.
In that context HTTPS could be used but just send you to their new AMP site (or whatever they are calling this feature once it actually comes out).
2
0
0
0
Open post
Replying to
@troberts@theblower.au
@troberts@theblower.au Canberra forecast is positively cool compared to that (except for a 43 in the middle)
0
0
0
0
Open post
Replying to
@crazyeddie__dup_521@mastodon.social
@crazyeddie@mastodon.social @nixCraft@mastodon.social I haven't been in a job yet where the contents of my yearly performance review wasn't heavily tweaked (ie, censored) by my manager to focus on things that aren't day-to-day or technical debt reducing. This isn't unique to my current job at all.
Managers love the term "technical debt" as it flies by on their agile boards, but god forbid you would actually focus on it.
0
1
0
0
Remote instance
infosec.exchange
Open on original server