Ramdom thought / further evidence that this universe is against me:
In the cycling world, clipless pedals are pedals that you clip into.
I don't like this.
Remote
Will Dormann
@wdormann@infosec.exchange
I play with vulnerabilities and exploits.
I used to be https://twitter.com/wdormann but Twitter has become unbearable, so here I am.
4594 Followers
592 Following
50 Posts
Joined October 28, 2022
Open post
Seen as an ad on my Fire TV stick.
For Blade Runner.
Two AI-generated guys in a car, sharing a single AI cheeseburger and a single AI french fry order.
Who comes up with this, and more importantly who gives it the green light?
3
1
2
0
Open post
Well, I made the jump from macOS 15.8 directly to 27.0 (Golden Gate). Version 26 (Tahoe) was painful enough to my eyes that I didn't even consider it.
Things I've noticed:
It looks a touch different.There's seemingly more AI shoehorned into the OS.Some of my auto-start apps no longer auto-started when I logged in. This was resolved by twiddling with settings and/or re-installing said apps.Somehow a Time Machine backup was running, yet the menu that pops up from the icon at the top didn't indicate that anything was currently being backed up.Microsoft Remote Desktop no longer connects to a host with a double-click. It requires a right-click and a click of Connect.
Things that I have not noticed:
A single thing that makes me think "This was worth upgrading for."
I've noticed macOS Sequoia (15) doesn't seem to get the update love that 26 and later get. For example, on August 17 Apple released Tahoe 26.6.2, which fixes 34 CVEs. Six of the CVE's were listed in the September 14 release of 15.8. That's close to a month of known fixes having been released for 26, but 15 had no updates. What are we to think of the other 28 CVEs, though?
Anyway, macOS 27 isn't bad. Given the unclear pseudo-support of Sequoia 15.x these days, running 27 makes me feel a touch more comfortable that the OS will get the attention that it needs from Apple. But at the same time, I haven't (yet?) encountered a thing that I enjoy about the new OS, compared to the two-major-releases ago version. 🤷♂️
6
1
0
0
Open post
Open post
Replying to @wdormann@infosec.exchange
Since upgrading to iOS 27 I can report that sending a text message via Siri in CarPlay is almost completely broken. (One of the two things I use Siri for... Setting a timer is the other)
What would you like to say to ? is often truncated. After I say the message, the It says response usually gets stuck in a loop of It says... It...
Sometimes it sends the message automatically without confirmation. If I send the message it usually just says It says in the message body as opposed to what I said. On rare occasions it sends what I said, but without my audible confirmation, since I'm driving and all.
I'm not sure if it's related to my various disablings of Apple Intelligence, the fact that I have Lockdown Mode enabled, or if it's specific to my rental car (which worked fine two days ago when I was on iOS 26), or if it's just broken for everyone.
But this is all quite disappointing.
6
1
0
0
Open post
Replying to @wdormann@infosec.exchange
It seems that in the iOS settings, there's an Apple Intelligence Report item, where you can Export Activity.
At least on my phone, it seems that Apple Intelligence has not been used anywhere.
{
"modelRequests": [],
"privateCloudComputeRequests": []
}
8
1
1
0
Open post
Replying to @wdormann@infosec.exchange
Update:
As my trip went on, sending text messages with Siri on wireless CarPlay seemed to work better.
After switching back to wired CarPlay on my own car, it works flawlessly.
So I don't know. Is wireless CarPlay just flakier WITH iOS 27 than it was with 26? Is it flaky for some period of time after an update while the dust is settling? Something else?
Either way, I don't have the mental stamina to even think about it. But the whole experience was indeed nonphenominal. 😂
2
0
0
0
Open post
RE: https://flipboard.com/@cbsnews/latest-headlines-3kai39s2z/-/a-fY6emZFXTAC7OV2eCgjWVA%3Aa%3A2476075171-%2F0
Honest question:
Why do politicians basically work until they die?
Open quoted post
Quoting
Sen. Mitch McConnell returns to Congress after 3-month absence
https://www.cbsnews.com/video/mitch-mcconnell-returns-congress-3-month-absence/?utm_source=flipboard&utm_medium=activitypub
Posted into Latest Headlines @latest-headlines-CBSNews
Open quoted post 5
0
2
0
Open post
Replying to @wdormann@infosec.exchange
What's even more confusing, is if you leave it on the default Siri AI (Beta), you see a Try Siri AI link in the Siri settings. Which sort of implies that Siri AI is not enabled by default? 🤷♂️ (At least on my phone that had Apple Intelligence disabled globally while on iOS 26)
There are a bit too many unknowns in all this.
4
2
0
0
Open post
Wiz found a master key that could access every database in Azure's Cosmos DB. #cosmosescape
Whoops.
https://nitter.net/yuvalavra/status/2082864672294736324
171
16
184
4
Open post
Replying to @wdormann@infosec.exchange
@mysk@mastodon.social
Related: While Siri AI (Beta) is indeed the default in iOS 27, if I go into the Siri settings in iOS 27, I see that there's a link for Try Siri AI (Beta), which implies that my phone isn't opted in to Siri AI.
(I had Apple Intelligence disabled globally in iOS 26)
2
1
1
0
Open post
Open post
Replying to @ajn142@infosec.exchange
@ajn142@infosec.exchange @mysk@mastodon.social
Right, so the individual features themselves are there, but the thing is implied is that Siri Classic will give you a more rudimentary implementation of the feature that does not use AI?
1
1
0
0
Open post
Replying to @mysk@mastodon.social
@mysk@mastodon.social
Does setting the Siri version to Siri Classic perhaps function more as a global "I don't want to use AI" setting?
1
2
0
0
Open post
Replying to @wdormann@infosec.exchange
Meta jumps on the "We do crime too!" bandwagon:
https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/
26
2
15
0
Open post
Replying to @wdormann@infosec.exchange
Not to be outdone by Anthropic's felony bragging, OpenAI assures us that they also did more felonies.
https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/
24
3
5
0
Open post
Replying to @wdormann@infosec.exchange
Just to be clear, the Anthropic LLM was instructed to behave as if it were sandbox, and it did. But Anthropic was just kidding. It had direct internet access. Whoopsie daisy.
The amount of YOLO in all of this is completely terrifying.
21
3
4
0
Open post
Replying to @wdormann@infosec.exchange
Anthropic: Hey, our models have hacked other organizations too!
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
Consequences when?
15
7
12
0
Open post
Replying to @wdormann@infosec.exchange
Ah, lovely.
In case you were a uBlock Origin user who had rules that they've built up over the years, you can now no longer access these rules, because you can't access the uBlock Origin GUI anymore. For your safety.
And no, even from a terminal, those rules aren't stored anywhere in a human-readable form. You'll need an extraction script. If you run this on your uBlock Origin directory (e.g. ~/Library/Application\ Support/Google/Chrome/Default/Extensions/cjpalhdlnbpafiamejdnhcphjbkeiagm), you'll get a user-filters.txt file that has your rules. Which you can import into uBlock Origin on a browser that doesn't have contempt for you.
I pretty much hate computers.
6
1
1
0
Open post
Replying to @wdormann@infosec.exchange
Meh. Looks like this workaround is finally dead. That is, one can make the radio button clickable by making this edit. But clicking it now does nothing.
Time to find a new primary web browser, I suppose. 😕
4
1
1
0
Open post
Replying to @tychotithonus@infosec.exchange
@tychotithonus@infosec.exchange
My hope is that a human being didn't write this.
Wait a minute... We're hosed either way, aren't we?
5
0
0
0
Open post
Open post
Replying to @dangoodin@infosec.exchange
@dangoodin@infosec.exchange
So no humans were involved at all in enabling this hack? 🤔
5
0
0
0
Open post
Saw The Odyssey over the weekend. Was a pretty good example of the type of epic fantasy film.
Several people I invited to come along backed out saying that they were waiting to see it on IMAX.
Of course I had to be the person to bring up that the closest IMAX screen is 4.5 hours away. (Look up "LieMAX" if you want to read about the nonsense you've been led to believe)
If you have an actual IMAX nearby, sure, go ahead and pop for it. If not, then just go see it on a normal screen. I can count the number of times that I wished for a more-square aspect ratio while viewing this film on zero fingers.
4
1
0
0
Open post
Replying to @wdormann@infosec.exchange
If we look at the driver permissions, it turns out it actually is a vulnerable driver, as anybody can tickle any of the ioctls.
So if anybody already had this driver on their system (which might be named DCRCVDrv.sys), then it is indeed a driver that introduces a vulnerability. The term "BYOVD" is complete nonsense, as if an attacker is bringing their own driver, it doesn't need to be vulnerable. It's a BYOD attack.
Vaguely interesting is that with this driver, Ghidra actually did a better job of decompiling the vulnerable code than IDA did.
IDA:
Take the ioctl, subtract 0x220540, then subtract 4, then subtract 4, then subtract 4, then subtract 4, then subtract 0x34, and then if you're left with 0x3C, run the function.
Ghidra:
If the ioctl is 0x2205c0, run the function.
3
0
1
0
Open post
Replying to @wdormann@infosec.exchange
OK, this stuff doesn't work at all. Time to exercise my "100% money-back guarantee". 🤦♂️
2
3
0
0
Open post
Replying to @MLE_online@social.afront.org
@MLE_online@social.afront.org
It's unfortunate that the only way to find out how long a film is, is to watch it.
1
0
0
0
Open post
Last's night entertainment:
Puddles Pity Party and Weird Al.
They were both spectacular.
1
0
0
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange @hrbrmstr@mastodon.social
Ditto.
But I've seen that page be obnoxiously slow in the past. And on the regular.
1
0
0
0
Open post
I'm old enough to remember when Google helped you find websites to go to. It was indeed better than HotBot, which was pretty decent.
https://www.theringer.com/2026/08/04/tech/google-search-ai-internet
0
1
0
0
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange @FritzAdalis@infosec.exchange
This was an original confusion of mine when trying out Mastodon for the first time.
In the most popular web browser in the world, how does one add a bookmark for a site? You click the star icon. It's hard to dissociate "star" and "bookmark" if you're a person who has used a web browser.
0
1
0
0
Open post
Replying to @ajn142@infosec.exchange
@ajn142@infosec.exchange @mysk@mastodon.social
Hm, that's very different than what I see.
I click the "add image" button and I get a pop up where I can pick where from.
0
1
0
0
Open post
Replying to @wdormann@infosec.exchange
And for anyone considering growing their own tomatillos, be aware that you need at least two of them if you want fruit. Unlike tomatoes (and everything else I grow), they cannot self pollinate.
I got mine via our local seed swap, and luckily I looked up the details before I donated my seedlings. I've got one purple and one traditional green, so apparently they're compatible. 🎉
0
1
0
0
Open post
Replying to @joshbressers@infosec.exchange
@joshbressers@infosec.exchange
If possible, I plan to eat some venison jerky, while making direct eye contact.
0
1
0
0
Open post
Replying to @ajn142@infosec.exchange
@ajn142@infosec.exchange @mysk@mastodon.social
Yeah, I suspect I'm using Vanilla. At least, that's what's selected by default when I go to flavors. (Though it still asks me if I want to use vanilla there for some reason 😂)
0
0
0
0
Open post
Replying to @scrutinizer@social.vivaldi.net
0
0
0
0
Open post
Replying to @wdormann@infosec.exchange
And yes, it made a delicious green salsa verde with some flecks of purple skin in it.
0
1
0
0
Open post
Replying to @NebulaTide@mastodon.bsd.cafe
@NebulaTide@mastodon.bsd.cafe
I'm pretty sure that happened last year.
0
1
0
0
Open post
Replying to @da_667@infosec.exchange
@da_667@infosec.exchange
I suppose if you can predict getting sacked by an ICE goon, go ahead and hold volume-up and power for a few seconds on an iPhone. Or press power 5 times. Biometrics will be disabled at this point.
0
2
0
0
Open post
Replying to @wdormann@infosec.exchange
As opposed to the recent purple tomato, which is very purple, all the way through. Due to genetic shenanigans in a lab with a snapdragon flower.
0
0
0
0
Open post
Replying to @drewdaniels@mastodon.online
@drewdaniels@mastodon.online
I feel like just about any of the concerns about CVE would also apply to as well. 🤷♂️
0
0
0
0
Open post
Washington Post editor:
Maybe we should find a picture of Susan Collins where the fotographer's finger isn't partly covering the camera lens?
Their boss:
Just ship it.
0
1
0
0
Open post
Replying to @sambowne@infosec.exchange
@sambowne@infosec.exchange
Maybe this will teach Americans that not using a bidet is both disgusting but also cost-ineffective? 😂
0
0
0
0
Open post
Replying to @johnmark@freeradical.zone
@johnmark@freeradical.zone
Coffee also doubles as fertilizer! 🎉
0
0
0
0
Open post
Replying to @xabean@infosec.exchange
@xabean@infosec.exchange
My neighbor says that a deer can jump an 8-foot fence from a standing start. So I guess it all depends on how determined it is.
0
0
0
0