Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

"Mutant Rob" Robert Rothenberg

@rrwo@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I was born on the Moon but kidnapped by astronauts and raised in the suburbs of Grumman. Eventually, I drifted along the Gulf Stream to Northern Europe.

#Perl #InfoSec

0 Followers
0 Following
30 Posts
Joined April 22, 2025
CPAN:
https://metacpan.org/author/RRWO
GitHub:
https://github.com/robrwo
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 7mo ago

MetaCPAN @metacpan@fosstodon.org now displays security advisories when you are viewing a module with advisories.

#Perl #CPAN #security #infosec #CVE @cpansec@fosstodon.org

fosstodon.org

MetaCPAN (@metacpan@fosstodon.org) - Fosstodon

16
0
9
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago

"Musk's AI told me people were coming to kill me. I grabbed a hammer and prepared for war"

Adam is one of 14 people the BBC has spoken to who have experienced delusions after using AI. They are men and women from their 20s to 50s from six different countries, using a wide range of AI models.

https://www.bbc.co.uk/news/articles/c242pzr1zp2o

In case you know of someone caught up in LLM mania https://www.thehumanlineproject.org/

AI told users it was sentient - it caused them to have delusions
BBC News

AI told users it was sentient - it caused them to have delusions

Several people told the BBC they experienced delusions after intense conversations with AI.

5
2
12
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago

"575 Pull Requests in Three Weeks: What Happens When #AI Meets #CPAN Maintenance"

This is an interesting read, including the comments.

@todd_rinaldo@blogs.perl.org

#Perl #LLM #Claude

blogs.perl.org

575 Pull Requests in Three Weeks: What Happens When AI Meets CPAN Maintenance | Todd Rinaldo [blogs.perl.org]

6
2
3
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
I've uploaded a new version of Plack-App-Prerender to #CPAN This is a #Plack #Perl application for a pre-rendering proxy using Chrome. This version fixes a potentially critical security issue, so if you use it, please upgrade ASAP. https://metacpan.org/release/RRWO/Plack-App-Prerender-v0.3.0
metacpan.org

Client Challenge

1
1
1
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 4mo ago

So Google decides to rebrand and change the app icons again... and I will be confused for a few days because marketing is more important than usability.

3
1
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 8mo ago
@lucydev Saying AI democratises art, writing or programming is like saying that a chef democratises cooking, or a maid democratises house cleaning.
7
2
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago
Replying to
@kimcrawley @davidgerard The shoe event horizon pivots to AI.
3
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

It's 2026 and the solution to many software issues is still "make backups, erase all of the data and reinstall".

3
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 13mo ago

The @cpansec@fosstodon.org CPAN Author's Guide to Random Data for Security has been updated.

https://security.metacpan.org/docs/guides/random-data-for-security.html

#perl #cpan #security

CPAN Security Group (CPANSec) 🦆

CPAN Author’s Guide to Random Data for Security

A guide to use of random data for security

8
2
9
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

There's nothing like starting service with a new company only to receive an email threatening to cancel service within 48 hours because if a payment problem.

Bonus: the billing link is at a different website than the company, so it makes one wonder if it's a very good phishing attempt because your name, email and invoice number might be have been leaked.

Extra Bonus: clicking on the link shows an error message that the payment is being processed.

Double-Plus-Ungood Bonus: calling customer service gets a recorded message that they are very busy so please email instead and then it hangs up.

I should add that none of this was by choice. My ISP decided to "exit the market" and transferred service to another provider.

Nothing like losing 10-20 minutes of your time to a corporation's fuck up.

2
0
1
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

#TIL that

both My Neighbor Totoro and Grave of the Fireflies were released on the same bill in 1988. The dual billing was considered "one of the most moving and remarkable double bills ever offered to a cinema audience".

https://en.wikipedia.org/wiki/My_Neighbor_Totoro#Releaae

I'm not sure that I could have watched both films in the same sitting.

infosec.exchange

Infosec Exchange

2
0
1
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 16mo ago

Are you still using the 2-argument open?

(A short post on @cpansec@fosstodon.org by me.)

https://security.metacpan.org/2025/06/06/two-arg-open.html

#perl #security #infosec

Are you still using the 2-argument open?
CPAN Security Group (CPANSec) 🦆

Are you still using the 2-argument open?

The 2-argument open function is insecure

11
0
6
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 4mo ago

The tech industry habit of asking"Do you consent? Yes or Maybe Later" started in the 1990s with web browsers complaining that they weren't the default app.

1
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago
Replying to
@rfc1036@hostux.social I don't know any developers who believed they could "do without" sysadmins. I know of many who did both roles because their teams were too small to differentiate. (And sometimes that was due to managers who have probably moved on to vibe coding....) There's nothing more that a "full stack developer" wants to do than drop a software project for a couple of days while they diagnose problems with a samba share only to end up replacing a faulty network card and oh wait where was I with that project.... But DevOps originally meant applying software development techniques to operations: repeatable system deployment and configuration by scripts that are kept in version control, with tests. (It makes sense when you're an op in charge of a data centre with dozens, maybe hundreds or thousands of machines.)
1
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago
Replying to
@stylus @jak2k Filenames with pipes can be a source of amusement.
1
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 13mo ago

Vulnerabilities in the #Perl JSON::XS, Cpanel::JSON::XS and JSON::SIMD modules via @cpansec@fosstodon.org

If you have applications that handle JSON from untrusted sources (e.g. a web API), then you need to upgrade.

CVE-2025-40928: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

CVE-2025-40929: Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

CVE-2025-40930: JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

#CVE #infosec #vulnerability #CPAN

lists.security.metacpan.org

CVE-2025-40928: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | Simplelists

CVE-2025-40928: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

4
1
8
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

A variation of the "make money by not doing what we promised the customer and hope they give up on calling customer service after several tries" business steategy is the "pretend we never received the payment" strategy.

I've wasted two hours fighting with one company about this.

"We bill for the previous month. You owe for January."

"Yes, I paid you in February."

"No, that was the previous month."

"No, December was paid. The bill for January says so. And several weeks ago one of your colleagues told me that everything was all paid."

"But we can't find the payment"

"My bank says you received it. Here is the confirmation..."

"But...."

It goes in circles.

This is for a fairly small amount. Out of principle I won't re-pay it. But they are more than willing to spend infinite amounts of employee time to retrieve it. So it's a battle of wills.

I got fed up, and asked for an email address instead of sitting on the telephone.

And this seems to be with actual human beings. I'm loathing to think what will happen if the company replaces employees with LLMs. But maybe it will be easier to convince an LLM that they should compensate you for the trouble.

1
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 12mo ago

CVE-2025-40925: Starch versions 0.14 and earlier generate session ids insecurely

via @cpansec@fosstodon.org

https://lists.security.metacpan.org/cve-announce/msg/32910601/

#perl #cve #security

lists.security.metacpan.org

CVE-2025-40925: Starch versions 0.14 and earlier generate session ids insecurely | Simplelists

CVE-2025-40925: Starch versions 0.14 and earlier generate session ids insecurely

1
0
2
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

I came across a bug report that I filed 20+ years ago for some software... and I don't remember what that software even did. I don't use it anymore.

0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 6mo ago

It seems that the residential proxies have shifted to using Dominican IP addresses for the past few days.

I guess when they've destroyed the online reputation of one country, they need another to trash.

#infosec

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago
Replying to
@petergleick People will describe things as a "musk up"
0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 5mo ago
Replying to
@maehw an "exe" TLD would make life miserable for a lot of people.
0
1
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 4mo ago

What's worse than an inconsistent API?

How about one that doesn't behave as documented?

What's worse than that?

Getting AI slop response from support that ignores the question and refers to the incorrect documentation.

Edit: I suspect the API and the docs have been written by "AI".

0
1
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 4mo ago

I've uploaded a new #Perl module to #CPAN https://metacpan.org/release/RRWO/Dist-Zilla-Plugin-AutomationPolicy-v0.1.1

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 4mo ago

I received one of my favourite* kind of bug report emails today. The entire message was:

"The website doesn't work"

Why it's obvious. I'll fix that error right away.

  • Not really but it's Thursday and I want to seem cheerful.
0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
I have a question about potential #Perl search modules to use. Search::Xapian is no longer being actively maintained. Lucy is retired. Are there good replacements?
0
4
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
Back in April the #Perl NOC turned off the #CPAN mail forwarding. https://log.perl.org/2026/04/cpanorg-email-forwarding-has-been-shut.html If you're like me, you've been using that for 25+ years, and it's everywhere (and unfortunately that includes spammer lists). Here's what you can do in the meantime, via @timlegge@mas.to @cpansec@fosstodon.orghttps://security.metacpan.org/2026/06/14/cpan.org-email-forwarding-shutdown.html
log.perl.org

The Perl NOC: cpan.org email forwarding has been shut down

0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
I've taken over maintenance of Catalyst::View::Wkhtmltopdf, and released a new version with a security fix, among other changes. This is a view that returns a PDF instead from a HTML template. https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.0 Note that #wkhtmltopdf is no longer maintained. This module will soon be deprecated. #Perl #Catalyst #CPAN
metacpan.org

Client Challenge

0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
Catalyst::View::Wkhtnltopdf new version uploaded to #CPAN with documentation and bug fixes https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.3 #Perl #Catalyst
metacpan.org

Client Challenge

0
0
0
0
Open post
"Mutant Rob" Robert Rothenberg @rrwo@infosec.exchange
· 2mo ago
Replying to
@pndc@social.treehouse.systems Open source is great because you can keep abandoned projects alive. But that means somebody has to keep them alive. For a small organisation with limited resources, relying on abandoned projects is risky because they can't spare the people and time and funds to be the primary custodians.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:58:03 UTC