Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

tehfishman

@tehfishman@ioc.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on ioc.exchange

"professional" peanut gallery for security stuff

12 Followers
75 Following
50 Posts
Joined November 08, 2022
Open post
tehfishman @tehfishman@ioc.exchange
· 3w ago
Replying to
@cR0w@infosec.exchange @z0b4t@infosec.exchange "I'm not sure what the dick smasher 9000 is but this check for $500 says it's pretty awesome"
4
1
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 3w ago
Replying to
@kajer@infosec.exchange @cR0w@infosec.exchange I spent the weekend patching this but it only just occurred to me... is there even another kind of interface? Like maybe they mean to exclude the backup and HA links? But I think those are also considered dataplane because they connect to the fucking dataplane. They probably really could have simplified and just said "all interfaces" and saved a lot of confusion and waffling about whether the device is exploitable
4
2
2
0
Open post
tehfishman @tehfishman@ioc.exchange
· 3w ago
Replying to
@Sempf@infosec.exchange @cR0w@infosec.exchange those pickles are slippery, real tricky to hold them down long enough to scan
3
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 1w ago
Replying to
@kajer@infosec.exchange Muse being a clown show? DNS All time high diesel prices? DNS KiteWorks "imminent zero day attack"? Believe it or not, DNS
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 1w ago
Replying to
@snkhan@infosec.exchange @chronovore@infosec.exchange @GossiTheDog@cyberplace.social _very_ hypothetically: it could be a supply chain attack. The systems could already be compromised, and there's a script waiting in a cron job to execute. That would explain the time window, and why they're saying there's no "vulnerability"
1
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to

@cR0w@infosec.exchange @theorangetheme@en.osm.town I recently (this month) had solar installed. In the contract was a specific line item under client responsibilities, copied here verbatim:

Solar is a 6-12 month total process from Site Survey to the customer receiving REC incentives, throughout the 12 months the customer will be installed, inspected, Net Metered, and then there will be a lull period while we wait on the State Agencies and Utilities to process the remaining paperwork. This process cannot be sped up by customer assistance/interference no matter what CHATGPT/GROK say so please refrain.

18
4
6
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@evacide@hachyderm.io Also rephrased as "Should I engage in an action that could easily be perceived as destruction of evidence?" to the shrieks of lawyers everywhere
14
15
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 3w ago
Replying to
@cR0w@infosec.exchange @z0b4t@infosec.exchange actually? That's a shocking amount of self awareness
1
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social at work I keep saying that we're putting way too much trust in our EDR vendor because if they get hacked we're totally fucked. And everyone thinks that's impossible and I'm crazy for suggesting it. And here's Microsoft, demonstrating the very clear possibility of an EDR vendor mishandling data security
7
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@smn@l3ib.org @evacide@hachyderm.io I'm hardly a legal expert, but I think it's fair to say that many things can be true at once, and they all contribute to various layers of a fucked up situation 1) if someone is planning to destroy potential evidence when faced with a search, that's planning to commit a crime regardless of circumstances and the legal system really doesn't care about your situation 2) warrantless searches are appalling 3) warrantless searches happen anyway, the legal system permits them, and pretending they don't is failure to plan ahead 4) regular people are not prepared for them because who the fuck has time to deal with that 5) goto 1 I really really doubt that deleting evidence would fly in court. It doesn't matter how fucked the circumstances are, that is still considered a crime Also, who the fuck you think operates in a court of law? Might it be lawyers?
8
11
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@Dio9sys@haunted.computer I feel this in my bones. Recently realized that I have a habit of saying "no problem" to things that are DEFINITELY problems because I'd rather not deal with having to confront someone who has caused a problem.
5
1
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@paul_ipv6@infosec.exchange @cR0w@infosec.exchange if ever there were a group of engineers that would benefit from a co-op or heavily unionized org structure, Mozilla engineers are that group.
5
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange I just finished reading their blog post and they really don't seem to be taking this seriously. Their key take-away appears to be that the "model alignment" was insufficient, when it's been proven fairly rigorously that trained-in model alignment isn't a strong deterministic control.
5
0
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange it's real thorny. Additional concerns: long-term usage causes you to slowly de-skill, which means you progressively become less capable as a defender. And the LLM tools will almost certainly become more expensive over time because the industry is in the sweetheart deal phase, leading to you having to charge more for defense. Both of which are negative for the overall goals of providing defense.
3
3
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@DaveMWilburn@infosec.exchange @jerry@infosec.exchange Hot take: it's also just kind of a mediocre con at this point. I've had more fun and gotten way more out of local events.
4
3
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@ahltorp@mastodon.nu @jackemled@furry.engineer @smn@l3ib.org despair is certainly one interpretation. And what with all the fascism swirling around, I feel that way, too, sometimes. But another interpretation is that it's only like this because enough people decided it should be that way. Which means it can be changed if enough people want to change it. And yet a third interpretation is what the EFF has been recommending, which is to prepare by not having any data on your phone during border crossings. Take a backup, store it on a cloud service, wipe your device, and restore the backup when you've crossed. It's horribly inconvenient, but it avoids any legal issues. None of these ideas are mutually exclusive.
3
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mdc@mstdn.ca @mttaggart@infosec.exchange They didn't even recess the screw heads. So you'll just hurt your hands on it if you use it long enough. It's poetic.
2
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange Degenerate poll idea, which threat actor did marketing draw the most fuckable fursona for
1
1
1
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@pedro_mateus@mas.to @wdormann@infosec.exchange This from Pedro Meatus
1
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@c0coChannel@infosec.exchange These demons... do they at least have a flared base?
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to

@cR0w@infosec.exchange hmm if we're talking dumb ideas, my last idea is to split the file and delete the files containing what you don't want. I don't know if split uses intermediary files though, and re-combining them seems like it would be a problem if you don't have space to store multiple copies of your pruned data.

1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange then just open it in vim smh my head
1
4
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to

@cR0w@infosec.exchange Yeah was just a joke. I do wonder if there's a way to make truncate operate on the head end of a file instead of the ass end. That would definitely modify the file in-place. I'm pretty sure sed -i also uses a temp file. Curious to know what your actual solution was.

1
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@abuse_ch@ioc.exchange Just spitballing here, but I think you may be in a position to publish a list of abusers of your service.
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to

@fuzzyfuzzyfungus@cyberplace.social @hrbrmstr@mastodon.social The Cow Was Not Valued

  • Lorem Ipsum
1
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@ahltorp@mastodon.nu @jackemled@furry.engineer @smn@l3ib.org oh they absolutely can still mess with you. Which is a huge problem. But in terms of ways to protect oneself during a border crossing, it's a way that doesn't invite them to mess with you further in the form of a legal proceeding. It's harm reduction. If the conclusion for you personally is to not travel to the US ever under any circumstances, then that's a decision that you can certainly make for yourself. But it's not possible for a lot of people to opt out.
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org usually I wish my posts would get more reach. But then I see braindead responses that posts like yours and another post by evacide got last night when they do get hundreds of boosts and it just makes me go "nah."
1
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@Iwillyeah@mastodon.ie @smn@l3ib.org @evacide@hachyderm.io it doesn't matter if a crime has been committed. The act itself is a crime. https://en.wikipedia.org/wiki/Tampering_with_evidence
en.wikipedia.org
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange totally reasonable skepticism
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange I think there's a good chance it's real, because their containment environment seems like it had basically no monitoring or strong controls in place. They did obviously write their "report" from a marketing perspective to hype it up because these people are also ghouls and think this thing should be spun into a flex, but that doesn't mean that an incident caused by their own predictable incompetence didn't happen.
1
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange @ifin@infosec.exchange will do if I have anything interesting to share. Haven't fully confirmed exploitation yet but it sure doesn't look good
1
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange been doing incident response for two hours now and I'm pretty sure it was being exploited when you were writing this. I'll try to post some details when I have them.
1
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange @theorangetheme@en.osm.town 💯. I think the semi informal writing style shows that a contract lawyer probably didn't even review it. Everything else in the contract is standard formal legalese so I think someone was just really pissed off at some egregious nonsense and slapped this in at the end
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
re: UKpol
@mdhughes@appdot.net @lambdacalculus@masto.hackers.town Blowing right past the fact that curfews are dumb, she's actually right. What the fuck even is the point of a curfew that you can opt out of? "Oh I'm sorry officer, I decided that the curfew didn't matter tonight"
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange Duped comment from what I tooted at OP: My first question is whether any of this is even real. The EO was signed a month ago. I have a hard time believing there's anything more than a vibe-coded pile of shit outputting garbage to a dashboard in that time.
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange this seems like it could be a link-rot event on par with the imgur purge from a few years back
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@h2onolan@infosec.exchange "subjected to a security threat" like anything on the Internet is not subjected to security threats literally all of the time
1
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org I can imagine. Getting into an Internet fight with several dozen people is a rough way to spend a Friday night, even if the fight is a good cause. Also we are all legends on this blessed day
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange @theorangetheme@en.osm.town this line is in red and italicized in a legal document. Even the payment requirements weren't given that treatment
0
2
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@nixCraft@mastodon.social Doesn't matter, it all goes in ~/.bashrc. Custom environment variables? Goes in ~/.bashrc. Login scripts? They go in ~/.bashrc. Command aliases? That's right, they go in ~/.bashrc.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org Just saying, @abuse_ch@ioc.exchange has the opportunity to publish a list of the abusers here. Anyone abusing a community-based service like this should be named and shamed.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
The nut-buster 9001 is a gun that has been designed for maximum penetration depth. During automated testing, the nut-buster fired a round that penetrated all of the back stops and obliterated a children's hospital on the other side. We believe that this incident may be prevented by installing childrens-hospital-avoidance safeties. While we are deeply sorry for the loss of life, we encourage all interested parties to apply for our early access program.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 1w ago
Replying to
@index they should really just rebrand again, it would be less embarrassing than continuing to front as a security company
watchTowr Labs
watchTowr Labs

watchTowr Labs

watchTowr Labs is the epicentre of offensive security expertise at watchTowr - where research, innovation, and real attacker insight power our Preemptive Exposure Management technology.

0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange cory doctorow recently wrote about the hazards of using LLMs as a teaching aid that I think has some overlap here. The short version being that LLMs when used for learning are hazardous because an expert knows when an LLM is producing bullshit, but a novice doesn't and is more susceptible to accepting bullshit as fact. You have probably done enough malware analysis to know when an LLM based tool is way off the mark. But a novice security analyst might throw a malware sample at an LLM, get a terribly misleading result, and be completely lacking in the skills to refute it. To some degree, that's true of many tools in the security space. That same novice analyst let loose on the full contents of an enterprise Splunk environment will easily get lost in the endless sea of scary looking log events. But many tools don't lie so... convincingly. I guess those limits, and where they translate into added danger, are up to every individual defender to gauge for themselves though. So many thorns.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Anyone wrangle with #passkey implementation in a virtual desktop environment where you can't pass through a hardware device and software installs are limited?
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 1w ago
Replying to
@GossiTheDog@cyberplace.social @snkhan@infosec.exchange @chronovore@infosec.exchange Yeah I agree that's how they're making it sound. But that could be because they're incompetent.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange If the data is very compressible and you do have disk space to store the original + the compressed version, gzip it first, delete the original, then pipe it back through gzip and pull out only the lines you want with tail or grep or something
0
1
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@hrbrmstr@mastodon.social My first question is whether any of this is even real. The EO was signed a month ago. I have a hard time believing there's anything more than a vibe-coded pile of shit outputting garbage to a dashboard in that time.
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
Replying to
@pmbrandvold@techtoots.com because it's an appliance, it probably needs 120 volts to run, so this is actually "dangerous if you're a careless idiot" territory. But to assess what you'll need, a simple kill-a-watt power meter is a good place to start. Wire up a plug to the pump, make sure it's plumbed up so it has water to circulate (could just stay in the dishwasher with water for testing), and let it rip. Check for how many amps and watts it pulls. You'll need a battery and a 120 volt inverter that can support that much power draw for as long as you'll need to run it, and a solar panel and charge controller to charge that battery
0
0
0
0
Open post
tehfishman @tehfishman@ioc.exchange
· 2mo ago
A cat meowing at a bucket of corn #CatsOfMastodon #CaturdayEveryday #CatLovers #CatsOfTheFediverse #CatContent #FediCats #FelineFriday
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:34:01 UTC