Remote
Posts
Replying to
@rooster@beige.party
@rooster@beige.party
GLP-1s are so last year. They're expensive and full of chemicals! Eww.
Cyclospora tainted lettuce are dirt cheap and all natural!
Open post
Replying to
@foone@digipres.club
@foone@digipres.club wait... Your code is running? Well you better try {} and catch(){} it 😂
finally{} a chance to tell that #programming #dadjoke
12
0
3
0
Open post
Replying to
@vxo@digipres.club
@vxo@digipres.club @corq@infosec.exchange If you're OK using LLM on philosophical grounds then a developer grade Mac or gaming PC can run a decent small open source model. Smaller models can do really well on small categorization tasks as long as the goal is well defined and chunked into small inputs.
So what ive done for stuff like that is to instruct Claude code to make a harness to do what you want with the local model. Manual security review and test with some some toy data you don't care about. Then you can use the code that was generated and the local model (even with the internet turned off if you wanna be super sure).
So anthropic only sees the custom harness code and toy test data.
1
0
0
0
Open post
Replying to
@corq@infosec.exchange
@corq@infosec.exchange should they have added noindex? Yes, but it is just a nice HINT. Not a security control.
AI companies make a lot of real bad choices we can and should be mad at. But like ... publically sharing something means its going to be *shared* ... *publicly*. 🤷♂️
This one is your classic users trusting cloud providers with more info than they should and not properly understanding access control. Sometimes friction around sharing info is a good thing.
3
1
1
0
Open post
Replying to
@alice@lgbtqia.space
@alice@lgbtqia.space https://youtube.com/shorts/HjBe7DDfST4
Relevant comedy bit that came up in my YouTube feed. Lol.
3
0
3
0
Open post
Replying to
@syphist@zoner.work
@syphist@zoner.work @vogelchr@chaos.social @faheus@chaos.social I don't work in automotive but I can tell you how it happened because its the same pattern in any OT industry.(Anyone in the automotive industry feel free to correct where I am wrong)
A standards org designed the protocol, and chose TCP/IP over power line on purpose because it is free of licensing concerns, ubiquitous and real world tested. In the standard somewhere is probably some small note about limiting the services on this interface to only what the standard defines and not adding things like SSH (or they might mention that anything outside the standard is out of scope)
An overworked engineer at a supplier of a supplier (so 2-3 subcontractor agreements away from any company you've ever heard of before) is tasked with making sure their board can talk this protocol properly. Their payment is tied to milestones on compatibility and reliability. So the engineer opens up an sshd over all interfaces to make debugging and dev easier for dev. They got a deadline to reach!
They may or may not have something in the fine print telling the company that will integrate this to disable SSH or change a password or something. The integrator will not read that.
When the integrator does their threat model or pen test they will pick the cheapest supplier and tightly control the scope of hardware and software under test. (Security is a cost center. Just need to show they did due diligence. ) They'll fix whatever small things the own handcuffed testers were able to find and call it good.
Then it gets rolled out across the country slowly. Customers complain when things break or are not compatible, so new updates gets pushed out. Maybe a service tech even finds the SSH service and it saves them some time and money debugging in the field. "Wow that was convenient" they think.
That's how this goes for years. Once enough are rolled out some curious hacker gets a little TOO curious and takes a serious look at the things in the field. They find the obvious integration holes, and submit a con talk out of it (after hopefully doing CVD where the manufacture will either do the smart thing and say 'mea culpa' then fix it before the talk .... Or do the dumb thing and try to sweep it under the rug)
EV charging is already at the end of that process. Look at any new industrial technology and you'll see this play out. For example a simple google found me a new comms standard being made for Hydrogen cars last year. Its in that first part of the process. Give it a decade or two and $100 says there's similar gaps in the security of deployed pumps.
https://www.sae.org/standards/j2799_202406-hydrogen-surface-vehicle-station-communications-hardware-software
23
1
6
0
Open post
Replying to
@derek@www.glidden.life
@derek@www.glidden.life @malanalysis@infosec.exchange YES! Just hit me in the nostalgia there. Saying "let's meet up @900 .beats" on PSO on the dreamcast was amazing. Everyone knew what it meant and I didn't know or care where in the world my teammates were.
1
0
0
0
Open post
Replying to
@AAKL@infosec.exchange
@AAKL@infosec.exchange @cR0w@infosec.exchange He's always acted like a mob boss, he's just too arrogant or too senile to even try and hide it.
"Hey this is a nice straight you gots there. it would be a shame if anyone were to cause political instability in the area eh? Lots of wars and bombing goin on these days. Such a terrible shame. Maybe a 20% protection fee and we will keep you safe. Capeesh?"
3
1
1
0
Open post
Replying to
@jwildeboer@social.wildeboer.net
@jwildeboer@social.wildeboer.net me plugging my small efficient EV into my solar battery backup to refuel for basically free while my neighbor complains about the gas price to fill up his huge truck.
1
0
0
0
Open post
Replying to
@Viss@mastodon.social
@Viss@mastodon.social @cR0w@infosec.exchange @kajer@infosec.exchange no one is safe from the ultimate hacker tool "Tracer T". I will hax you all muahahaha.
3
1
0
0
Open post
Replying to
@soatok@furry.engineer
@soatok@furry.engineer That makes sense. Because Europe has never experienced a rapid slide from a relatively free government to an aggressive authoritarian regime that then used the record keeping of the previous government to target specific people. 🤔
13
1
0
0
Open post
Replying to
@mttaggart@infosec.exchange
@mttaggart@infosec.exchange The identity-based addressing and e2e encryption bit is implemented in reticulum ( http://reticulum.network ) very well. Browsing "nomad net" really feels like the 90s/00s again.
Reputation and establishing trust is the hard part. As reticulum grows there are already bots, indexers and scammers joining.
1
1
1
0
Open post
Replying to
@catsalad@infosec.exchange
@catsalad@infosec.exchange wouldn't be 4th of July without some fireworks!
1
0
0
0
Open post
Replying to
@Nonilex@masto.ai
@Nonilex@masto.ai so the whole US is going to end up looking like the Chicago loop where literally every door has a "No firearms" sign on it. Just like CA's prop 65 warning label you end up going blind to them.
1
0
0
0
Open post
Replying to
@briankrebs@infosec.exchange
3
0
0
0
Open post
Replying to
@Nonilex@masto.ai
@Nonilex@masto.ai Ah the ol "peace deal is near" on Sunday, then "oops nevermind " on Monday afternoon pump and dump. They must have forgotten the stock market was closed today.
1
0
0
0
Open post
Replying to
@crankylinuxuser@infosec.exchange
@crankylinuxuser@infosec.exchange @catsalad@infosec.exchange it makes sense once you realize that they are always in murder mode.
See, in the left photo they are grumpy because they are NOT actively murdering you.
In the right one they are excited because they are about to do what they've been holding back all day. :blobcataww:
2
0
0
0
Open post
Replying to
@nyanbinary@infosec.exchange
@nyanbinary@infosec.exchange Post this on linked in. Maybe we can squeeze a silver lining out of the mythos hype.
1
0
0
0
Open post
Replying to
@rnd@toot.cat
@rnd@toot.cat What does that mean for Python since its a duck typed language? 🦆
0
0
0
0
Open post
Replying to
@munin@infosec.exchange
@munin@infosec.exchange Me reading the title: "well yeah, of course its stored in plaintext right before being used. It has to be. But then its securely deleted or overwritten. Surely"
Me reading article: oh ... Oh no.
0
0
0
0
Open post
Replying to
@Heidi@infosec.exchange
1
0
0
0
Open post
Replying to
@lety@doesstuff.social
14
1
5
0
Open post
Open post
Replying to
@munin@infosec.exchange
@munin
OK legitimately never thought of it that way. I'm going to chew on that for a while. Maybe it will help me hate small talk less.
Is there a "social processes explained plainly" handbook? There should be one. It would be very useful.
Like the time I was at a tech meetup and a highschool kid heard us talking about Linux and jumped in "I want to learn how to use Linux". Someone asked "what do you want to learn?" And he answered deadpan "how to use Linux... I just said that" which garnered chuckles. Except he wasn't joking and thought we were laughing at him. I had to explain that the question implied he should expound on the idea and that answering what was supposed to be a leading question with a short blunt obvious answer is humorous (and typically meant as a joke precisely because it breaks that implied social contract). Once he realized people weren't laughing AT him, then everything was good.
Sometimes we just need it explained in plain, clinical language to catch up.
0
1
0
0
Open post
Replying to
@WEATHERISHAPPENING@weatherishappening.network
@WEATHERISHAPPENING I get this is a meme, but if they had done this I would legitimately have wanted to fly spririt for the first time in my life.
Decorate the plane interiors like a haunted house. Put the flight attendants and pilots in Halloween costumes. Hand out fun sized candy instead of pretzels, and the in flight magazine is a spirit haloween catalog? Fuck yeah!
2
0
0
0
Open post
Replying to
@rebane2001@infosec.exchange
@rebane2001 Oh that's a new one to add to my list of hilarious misconfiguration defaults like "null", " undefined" and "none".
1
0
0
0
Open post
Replying to
@glyph@mastodon.social
@glyph@mastodon.social Yes, I see this as the way LLMs will actually "change the world" after the bubble pops. There are so many areas in human society where we have tried to mitigate risk through mountains of documentation. Building permitting, regulated industries, standards, inspections, audits, etc etc etc.
These have all been a process of the form "some human generates a bunch of text showing they comply, then some other human reads the text" with only the occasional "that other human actually checks/audits the system itself in real life" . this really slows down processes, but regulations were written in blood. So we had this false dichotomy between long, slow, arduous processes, or dangerous fast processes.
LLMs have enabled cheap automated translations, summarization and semantic searching of plans, documents, etc between formats.
Pessimistically, it makes BSing standard compliant documents easier.
Optimistically, text was always an imperfect analogue. Maybe we can escape that dichotomy and let human regulators focus on actually providing more value than just reading BS text. we can get safer processes without the same level of regulatory slowdown.
2
0
0
0
Open post
Replying to
@malwaretech@infosec.exchange
@malwaretech That's the new meta strategy man. When the execs ask "What are you doing to protect against mythos?!" Just pull out the OWASP top ten.
3
0
0
0
Open post
Replying to
@skinnylatte@hachyderm.io
@skinnylatte Same when flying between CA and the midwest. I chalked it up to politics, but its gotta be more cultural because I see more masks in "John Wayne Airport" (republican stronghold Orange County, CA) than in sapphire blue Chicago. And I've even gotten a couple "nice mask. are you scared of breathing?hardy har har" at ORD too from passer bys.🙄
1
0
0
0
Open post
Replying to
@briankrebs@infosec.exchange
@briankrebs if you are being secretly tracked by a powerful group through every device you own, then maybe the worst place you could feed your thoughts about that is into a cloud based LLM that vectorizes and stores all your conversations for easy indexing and retrieval 🤔
14
2
1
0
Open post
Replying to
@chillybot@infosec.exchange
@chillybot Ok, I am def going to carry this to the next hacker convention I go to. It should protect me from vulnerabilities because I'll always be "out of scope".
2
0
0
0
Open post
Replying to
@jwildeboer@social.wildeboer.net
@jwildeboer@social.wildeboer.net @jzakotnik@mastodon.social @larsmb@mastodon.online @datenwolf@chaos.social @kejster@mastodon.world @tante@tldr.nettime.org @sovtechfund@mastodon.social I just want to actually own my own shit. My data, my hardware, my features. I bought it. I generated it. I just want to own it all and control it or share it the same way I would with any physical thing I own.
But "digital ownership" or "digital self control" don't communicate that. Pithy names for abstract concepts are hard.
0
0
0
0
Open post
Replying to
@wendynather@infosec.exchange
@wendynather@infosec.exchange so she's saying its business up front and a party in the back? 🤔 Are mullets back in style again?
1
2
0
0
Open post
Replying to
@mattblaze@federate.social
@mattblaze Tell them they shouldn't use the the platform to promote their hate of your promotion of your photos!
Its almost like people can post what they want and others are completely free to not follow them. 🤔
29
0
3
0
Open post
Open post
Replying to
@mttaggart@infosec.exchange
@mttaggart@infosec.exchange I mean... That's what got me interested in cyber security. Over zealous parental control software and how to work around it so we could play stupid free flash games lol.
Never underestimate the power of motivated tweens with too much time on their hands.
26
3
7
0
Open post
Replying to
@hacks4pancakes@infosec.exchange
@hacks4pancakes Oh man. I hate when I get stuck in a long fe-line. 😜
4
0
0
0
Open post
Replying to
@jzb@hachyderm.io
@jzb@hachyderm.io yeah I wished for AI and for homes to be more affordable. In retrospect I really should have worded them better.
1
0
0
0
Open post
I'm sorry everyone. When I told that monkey's paw that I wanted it to be like the 1980s again I meant "crazy hair, synth music and walkmans" not "crazy celebrity in the white house, nuclear threats and war in the middle east". My bad on that one.
22
3
11
0
Open post
Replying to
@hagaesthetic@mastodon.social
@hagaesthetic@mastodon.social uh... Are there other ways to have a date?
1
0
0
0
Open post
Replying to
@catsalad@infosec.exchange
@catsalad@infosec.exchange I sat here for far too long going "that's not in lexographical order. That would be 1, 11, 12, 2,3,4,5..." Until I realised it's by the English spelling of the number.
0
0
0
0
Open post
Replying to
@chetwisniewski@securitycafe.ca
@chetwisniewski@securitycafe.ca Big brain 'Murica move -- make a gun that requires a side loaded android app to fire. Now google is infringing on my 2A rights.
7
0
1
0
Open post
Replying to
@munin@infosec.exchange
@munin @malwaretech me playing cyberpunk 2077 pre-2024. "So unrealistic. Rogue AIs are somehow everywhere and literally everything is trivial to hack. people wouldn't be OK with any of that."
It turns out people were more than OK with that.
5
1
0
0
Remote instance
defcon.social
Open on original server