13reak :fedora:

Incident Responder and hobby reverse-engineer interested in #DFIR #malware #reverseengineering and #purpleteam . #fedora fan

#GCFA #GCFR

Proud of #EU

13reak :fedora: boosted:
2025-05-25

Eruption on Mount Etna (Sicily) giving the illusion of a Phoenix in the sky.

#Photography

Eruption on Mount Etna (Sicily) giving the illusion of a Phoenix in the sky
2025-05-25

#DFIR #threatintel #Knowledgedrop

Attackers are still actively exploiting firewall "../" vulnerabilities. Be aware and patch your firewalls!

2025-05-23

@kkarhan @richi

Time to switch to self-hosted Matrix/Xmpp I guess? :bloblaugh:

(I found Xmpp is dead and Matrix sadly not getting off the ground and feels very beta/unstable)

2025-05-23

@kkarhan @richi @signalapp @torproject

Have a look at Moxie's CCC talk a few years ago. He explained why they do these points.

From what I remember (not my arguments but theirs):

1) they need a means to identify you and combat bots. So it probably boils down to email vs phone number. Phone number works well for identifying your peers and makes it easy for non-tech folks

2) if you don't like their servers, you can host signal yourself, it's open source.

3) it's centralized because development would be much too slow with decentralized apps and quick patching is difficult (everyone would need to update). One can see this with matrix. It's beta since ages and doesn't really gain momentum.

Not saying I agree with all the points but I can understand them. Signal wouldn't be as usable and widespread if they didn't do it like that.

2025-05-19

Wenn ein Prof rappen muss, um auf Cyber Security aufmerksam zu machen:

youtube.com/watch?v=6Hcs78NTqpE

13reak :fedora: boosted:
Jackie 🍉 :gay_communism: :trantifa:burnoutqueen@todon.nl
2025-05-19

#reasonshellfrozeover #HashtagGames

The Billionaires have not been overthrown yet

13reak :fedora: boosted:
2025-05-18

NASA celebrated this employee's story of resilience, then tried to scrub it from the internet. Then fired her.
livescience.com/space/nasa-cel

13reak :fedora: boosted:
Katharina Nocunkattascha@chaos.social
2025-05-18

Die Open Source Business Alliance (OSBA) hält das Vorgehen von Microsoft "in diesem Kontext und dieser Auswirkung" für "beispiellos". Der OSBA-Vorstandsvorsitzende Peter Ganten betont: Die von den USA angeordneten und von dem Software-Giganten mit umgesetzten Sanktionen gegen den Strafgerichtshof "müssen ein Weckruf für alle sein, die für die sichere Verfügbarkeit staatlicher und privater IT- und Kommunikationsinfrastrukturen verantwortlich sind". heise.de/news/Strafgerichtshof

13reak :fedora: boosted:
2025-05-18

Over on Bluesky, westeners are reporting Palestinian accounts and Bluesky are suspending. On Mastodon, westeners are also reporting Palestinian accounts for seeking mutual aid.

Everyone has the right to seek mutual aid. Not just westeners. Even if it makes westeners uncomfortable to be reminded that apartheid Israel is starving and massacring Palestinian people.

Don't like being reminded of genocide? Well, don't report people seeking mutual aid for their dying families. Just use your fucking privilege and scroll on.

2025-05-18
13reak :fedora: boosted:

A rant on why I think we need realistic Solarpunk, plus some other things 1/2 ☀️

Felt compelled to make this. It will finally stop floating around in my head 🎉

Podcast over here if you're interested: podcast.tomasino.org/@Solarpun

#solarPunk #hopePunk #art #myArt #comics #sustainability

Page 1 of comic. The uppermost caption states: "I like realistic Solarpunk. I think it's the best kind, actually!" Under it is a horizontal space filled with doodles: someone exiting a tool library, a girl holding a mended sock, a chama group is pooling donations, a woman browses Wikipedia, a volunteer is filling a bowl with free soup.
"By realistic I mean grounded. Something that we could imagine happening in our real world. No magic (a drawing of a girl with fire powers), no supernatural elements unless you know what you're doing (a talking cat), no cure-all tech (a man is claiming a tiny piece of tech is going to solve everything).
The artist appears. "I feel that way because of my answer to this question: what is Solarpunk for?"Page 2. "Well, let's see...Solarpunk isn't just an aesthetic, it's an emerging genre and artistic movement." The statement is accompanied by mandala-like drawing of several hands drawing the Solarpunk symbol.
Then there's a dualistic drawing: Cyberpunk and Solarpunk next to each other. In the Cyberpunk drawing, a man is holding a gun, and in the other he is unloading soil from a big bag into a garden bed. Three tiny people are floating next to the Solarpunk man, imagining what tasty stuff can grow from that soil.
The caption reads: "Solarpunk is also sort of CyberPunk's counterpart. While Cyberpunk concerns itself with wrecking bad old systems, Solarpunk is about building new, better ones. SolarPunk's creation was very intentional - it's for letting us imagine a tomorrow that's not a fucking shitshow."
In the corner, the artist points at a box labeled "future" and asks "If it's alive, what do you reckon it looks like?"Page 3. "And that tomorrow part is important! When it comes to technology, we can stop climate change and achieve a sustainable world right now." A whole section next to this text is filled with various sustainable technologies: perma- and polyculture, wind turbines, vernacular architecture, reforestation, libraries of everything, trains, trams, bikes, solar panels, habitat restoration, degrowth etc.
"We don't need to wait until a fancy piece of tech comes along and fixes everything." There's a rendition of that meme where people are huddling together to discuss something. A contraption called "carbon sucker 9000 appears". The group gives it a thumbs up and continues discussing their own stuff like minimizing plane travel.

"What we need is large cultural and societal change. But most people struggle to imagine anything but dystopia."
In a frame nearby, a rich guy gleefully puts his foot on a pair of scales, favoring a bag of money over the planet. However, just out of frame is a group of people with tools, ready to take the planet back.

"Solarpunk is for filling that blank space! And a grounded, though not unambitious, approach makes it feel more achievable to the average person."Page 4. "If we can imagine absolute Cyberpunk dystopia with ease but not the opposite, it's because we don't have enough popular stories yet which would showcase that believable alternative." A lady is reading a Solarpunk book. She exclaims: "So you're telling me people can just do stuff without a monetary incentive or the risk of hunger and homelessness? Movie number 3752 about robots enslaving humanity was much more realistic!"
"The hard part for Solarpunks is imagining what the culture and structure of this new society would look like. How would it operate?" Drawing: the author sits gloomily at a desk, mumbling "I wish I could try out this hobby but the tools are so expensive, and I don't even know if it'll be a long-term interest or not...". But then they have an epiphany. "Wait, I could literally just go to the library!"
"How does this new world think? And what do we change about ourselves to get closer to it?" The final doodle is of a man stating we must ensure economic growth until the end of time, though the woman next to him retorts: "You and what endless planetary resources?" She then suggests that we instead produce what's necessary and give it to those who need it.
2025-05-16
13reak :fedora: boosted:

@nextcloud posting about why their Android app was forced by #google to remove the ability to auto-upload all files. I'll be switching to the F-droid version to gain this functionality back. #HomeLab #FOSS #degoogle

"As your experience with the Nextcloud Files app for Android has worsened, we wanted to share the background. Google has revoked a critical permission to sync all files. Despite multiple appeals since mid-2024, Google has refused to reinstate it, forcing us to limit file uploads for millions of users."

"Despite multiple appeals since mid-2024, Google has refused to reinstate the permission, blocking automated Nextcloud file uploads for millions of users."

"To make it crystal clear: All of you as users have a worse Nextcloud Files client because Google wanted that. We understand and share your frustration, but there is nothing we can do."

nextcloud.com/blog/nextcloud-a

2025-05-13

@401matthall @wdormann

Disagree on Slack. If you have to use it in a browser, calls do not work.

I frankly lack alternatives to Teams.

Slack has bad calls. Zoom has no good chat functionality. Matrix/rocketchat/etc lack functionality or are very unstable.

Don't get me wrong, I don't like Teams. Especially the groups and Team's "Teams" are terrible. But I don't know a better tool.

2025-05-13

@0xF21D @cR0w

I (as a user) gave up opening tickets with the help desk. In Q3/4 2023 my boss made me document all my tickets and their resolutions.
The result: 11 tickets opened, 1 solved, 10x help desk didn't do anything.

Same experience in 3 big corporations.

By now I raise my IT issues with my wall, it's less waste of time.

2025-05-13

@wdormann

At least you didn't get sued for informing them about a vulnerability :bloblaugh:

13reak :fedora: boosted:
2025-05-13

Haha...

My wish is that people who clearly don't "get" security, please don't get into CVE arguments. 😂

limited to the employees and contractors of that enterprise, which would be liable for an obvious attempt to circumvent security

Ah, interesting. Yes, in that case you'd be affected, but OTOH, your set of users is (most likely) limited to the employees and contractors of that enterprise, which would be liable for an obvious attempt to circumvent security (e.g. by crafting a openssl.cnf and putting it into onto the path that's baked into old openssl builds).

Please let us know what (if anything) comes out of the CVE thing. In the meantime, I'm closing this as fixed.
2025-05-13

@catsalad

Choice is an illusion. You already know what you have to do. :troll:

2025-05-12

Skindred - Gimme that Boom

#metalmonday

2025-05-12
Drake meme:
Guy rejecting heavily "having a DFIR expert handle the major incident case".
Then smiling and pointing at "assign a SOC level 1 junior analyst".

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst