Brian

A recovering academic interested in #infosec, #cybersecurity, #linux/#unix, #pinball, #hamradio, and in general learning new things. Current projects are fixing up a pinball machine, building air sensors, and getting into LoRa radios.

#pinball #hamradio #cybersecurity
Interested in Earthquakes? Check out my bot at @quakes

You can tell someone is in middle school by the fact that they are far more likely to criticize someone for doing a thing poorly that they feel really self conscious about doing poorly.

@jerry make sure it injects itself into the kernel so it can catch everything. What could go wrong?

More devices should default to not working if connected directly to the internet. Seems like a default that would solve a lot of problems.

Brian boosted:
2025-06-13

Highly credible and accurate source to follow on the Iran attacks. t.co/5loXyFVXln

Brian boosted:
2025-06-13
Brian boosted:
Zack Whittakerzackwhittaker
2025-06-10

NEW, by me: Whole Foods has told its employees in an internal communication, seen by TechCrunch, that the cyberattack at its primary distributor United Natural Foods (UNFI) will affect its product availability and may take “several days to resolve."

techcrunch.com/2025/06/10/whol

Brian boosted:
Earthquake Reportsquakes@bots.krohsnest.com
2025-06-08

Mww 6.30 earthquake (reviewed) occured at 2025-06-08T13:08:05 UTC, 16 km NNE of Paratebueno, Colombia #quake #earthquake #colombia
earthquake.usgs.gov/earthquake

@atomicangel sounds like it is the laptop/drive combo then.

Brian boosted:
2025-06-08

Remember the threads¹² about #LetsEncrypt removing a crucial key usage from certificates issued by them in predictive obedience to their premium sponsor Google?

We were at first concerned about #SMTP. While I had lived through this problem with #StartSSL by #StartCom back in 2011, I only had a vague recollection of Jabber but recalled in detail that it broke server-to-server SMTP verification (whether the receiving server acted on it or just documented it).

Well, turns out someone now reported that it indeed breaks #XMPP entirely: https://community.letsencrypt.org/t/do-not-remove-tls-client-auth-eku/237427/66

This means that it will soon no longer be possible at all to operate Jabber (XMPP) servers because the servers use the operating system’s CA certificate bundle for verification, which generally follows the major browsers’ root stores, which has requirements from the CA/Browser forum who apparently don’t care about anything else than the webbrowser, and so no CA whose root certificate is in that store will be allowed to issue certificates suitable for Jabber/XMPP server-to-server communication while these CAs are the only ones trusted by those servers.

So, yes, Google’s requirement change is after all breaking Jabber entirely. Ein Schelm, wer Böses dabei denkt.

Update: it also breaks the connections between domain registrars and registries, with most being unaware that there even is a problem at this time, let alone the crazily short timeframe. See the thread linked to in a self-reply, which also confirms that the CA/Browser forum is supporting Google in this (possibly by means of Google paying, my interpretation).

While https://nerdcert.eu/ by @jwildeboer would in theory help, it’s not existent yet, and there’s not just the question of when it will be included in operating systems’ root CA stores but whether it will be included in them at all.

Google’s policy has no listed contact point, and the CA/B forum isn’t something mere mortals can complain to, so I’d appreciate if someone who can, and who has significant skills to argument this in English and is willing to, to bring it to them.

① mine: https://toot.mirbsd.org/@mirabilos/statuses/01JV8MDA4P895KK6F91SV7WET8
② jwildeboer’s: https://social.wildeboer.net/@jwildeboer/114516238307785904

@atomicangel what level of spinrite?

Brian boosted:
Natasha Jay 🇪🇺Natasha_Jay@tech.lgbt
2025-06-07

Another charming piece by chalk artist David Zinn to start your weekend on a good note 🍎

#Art #DavidZinn #StreetArt

A chalk drawing of a cartoon squirrel on a grey rock. The squirrel has a bag and is bending over to pick up a (real) red apple in the golden autumn leaves
Brian boosted:
2025-06-06

This should be on TV every day, possibly multiple times per day…. #AI

I am tilting at windmills.

What are the most productive responses to old people who seem to think describing their intolerance or intentional ignorance is funny?

Brian boosted:
Wonder of Sciencewonderofscience
2022-11-25

A mesmerizing timelapse of the Sun in ultraviolet light, captured by the SDO spacecraft over the course of a month.

Credit: NASA/SDO

For the good of the family I have only eaten 1/4 of the pie.

@dinosm do you mean you can’t see it or your profile isn’t visible to those on jouna.host? Either way they are currently in purgatory here. They did sone unhappiness and @jerry made the call to not full sync with that instance. Alternatively I often have to go to the instance site to see a full profile.

@thebestsophist as Mr. Rogers said look for the helpers.

youtu.be/-LGHtc_D328

I wonder if someone is alone in the Twitter offices trying to put out the dumpster fire and singing “everything is awesome” to themselves, I would be.

Brian boosted:
Scalziscalzi
2022-11-18

You know things are bad on Twitter when Mastodon suddenly takes forever to load.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst