Sönke

Previously Privacy stuff in Göttingen and Security Researcher at @seemoo / TU Darmstadt. #Green. #d64hurra. He/him. Personal Account. Developer of @D64_Covidbot

Sönke boosted:
2025-04-16

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

usaspending.gov/award/CONT_AWD

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

MITRE | SOLVING PROBLEMS
FOR A SAFER WORLD"
April 15, 2025
Dear CVE Board Member,
We want to make you aware of an important potential issue with MITRE’s enduring
support to CVE.
On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop,
operate, and modernize CVE and several other related programs, such as CWE, wil
expire. The government continues to make considerable efforts to continue MITRE’
role in support of the program
If a break in service were to occur, we anticipate multiple impacts to CVE, including
deterioration of national vulnerability databases and advisories, tool vendors, incident
response operations, and all manner of critical infrastructure.
MITRE continues to be committed to CVE as a global resource. We thank you as a
member of the CVE Board for your continued partnership.
Sincerely,
Yosry Barsoum
VP and Director
Center for Securing the Homeland (CSH)
7515 Colshire Drive ® McLean, VA 22102-7539 ® (703) 983-6000
Sönke boosted:
2025-01-11

Techies, we need to get better at recognising tendencies that pave the way for fascist ideology. One example is transhumanism (part of the #TESCREAL bundle) - the belief in feasibility and desirability of radical human enhancement. Joscha Bach is a transhumanist (and "AI researcher") who conceptualises humans as software, as AI. He was given a stage at the #38c3.

I'd like to unpack some of his statements that he presents as personal takes, but they come with horrid political implications.
A 🧵

Sönke boosted:
Steve Hermanw7voa@journa.host
2025-01-04

“I’ve worked for the Washington Post since 2008 as an editorial cartoonist. … I’ve never had a cartoon killed because of who or what I chose to aim my pen at. Until now.” anntelnaes.substack.com/p/why-

Sönke boosted:
jiska 🦄:fairydust:jiska@chaos.social
2024-12-30

What has been seen cannot be unseen 🥬 #38c3

38c3 logo looks like cabbage
2024-12-22

@Prucker Schicke Tasse!

Sönke boosted:
Lukasz OlejnikLukaszOlejnik
2024-12-19

Google is explicitly allowing the use of device fingerprinting from February 2025. UK data protection authority is not happy. The EU ones did not voice any concerns so far. ico.org.uk/about-the-ico/media

Sönke boosted:
2024-12-13

NoName trying to get their supporters to find German media contacts, I’m guessing next week is Germany week.

#noname #threatintel

Sönke boosted:
Sascha Pallenberg 🇹🇼 ♻️ ⚡pallenberg
2024-12-08

Hab gerade die Domain herzstattmerz.com registriert.

Gibt es hier ne(n) Webdeveloper(in), die/der mit mir naechste Woche eine Seite, inkl. Spendenkampagne aufsetzt, die bis zur BTW zeigt, dass Deutschland so viel mehr ist als das, was der Mr Burns der Union hier zeigt?

Meldet euch!
Lasst uns was machen!
Wir sind mehr!

Sönke boosted:
2024-12-03

Überwachungstechnologien dürfen nicht in die Hände von Verfassungsfeinden fallen, autoritäre Kräfte dürfen nicht über die digitale Zukunft unserer Gesellschaft entscheiden. Daher setzen wir uns gemeinsam mit einem breiten Bündnis aus 50 zivilgesellschaftlichen Organisationen dafür ein, das Verbotsverfahren gegen die AfD einzuleiten.

Gemeinsam fordern wir alle demokratischen Fraktionen im Bundestag auf, jetzt zu handeln und unsere Demokratie zu verteidigen!

Mehr Infos: @AfDVerbotJetzt

Digitalpolitik faschismussicher: AfD-Verbotsverfahren jetzt! D64 fordert gemeinsam mit 50 zivilgesellschaftlichen Organisationen die Einleitung des AfD-Verbotsverfahrens. D64 – Zentrum für Digitalen Fortschritt
Sönke boosted:
Trammell Hudsonth@v.st
2024-11-20

@wawik older Dutch laptops had a stroopwafel warming tray.

laptop with a cd tray ejected and a stropwafel fitting perfectly in the recessed space
Sönke boosted:
David Chisnall (*Now with 50% more sarcasm!*)david_chisnall@infosec.exchange
2024-11-18

When I was a PhD student, I attended a talk by the late Robin Milner where he said two things that have stuck with me.

The first, I repeat quite often. He argued that credit for an invention did not belong to the first person to invent something but to the first person to explain it well enough that no one needed to invent it again. His first historical example was Leibniz publishing calculus and then Newton claiming he invented it first: it didn’t matter if he did or not, he failed to explain it to anyone and so the fact that Leibniz needed to independently invent it was Newton’s failure.

The second thing, which is a lot more relevant now than at the time, was that AI should stand for Augmented Intelligence not Artificial Intelligence if you want to build things that are actually useful. Striving to replace human intelligence is not a useful pursuit because there is an abundant supply of humans and you can improve the supply of intelligent humans by removing food poverty, improving access to education, and eliminating other barriers that prevent vast numbers of intelligent humans from being able to devote time to using their intelligence. The valuable tools are ones that do things humans are bad at. Pocket calculators changed the world because being able to add ten-digit numbers together orders of magnitude faster allowed humans to use their intelligence for things that were not the tedious, repetitive, tasks (and get higher accuracy for those tasks). If you want to change the world, build tools that allow humans to do more by offloading things humans are bad at and allowing them to spend more time on things humans are good at.

2024-11-17

@hackertours Hi! Close to venue at S Bahnhof Schanzenviertel is this new Rewe Pick&Go, where you can shop without checking out at a desk. I was wondering if you could provide a tour with some engineer from rewe through the market, might be interesting from a hackers perspective!

Sönke boosted:
2024-10-06
"- If I were to say to you, 'I am a stranger traveling from the East, seeking that which is lost'...
- Then I would reply that, 'I am a stranger traveling from the West, it is I whom you seek.'"

https://mummy.fandom.com/wiki/Medjai

Is there a technical term for similar "identifier phrases"?

I'm looking for ways for mutual authentication for humans, e.g. over the phone.
Sönke boosted:
2024-09-02

das ifo-institut hat rausgefunden: wenn öpnv bezahlbar ist, nutzen die leute den öpnv — auch für freizeit — und das überlastet den öpnv, was vielleicht daran liegen könnte, dass der öpnv über jahrzehnte kaputt gemacht wurde.

Sönke boosted:
2024-08-15

🤖 KI Scraping Bots sind ein immer größeres Ärgernis und entwickeln sich zu einem echten Problem. Wie wir aktiv werden und wie die Zukunft aussieht, haben wir hier für euch aufgeschrieben: blog.uberspace.de/2024/08/bad-

Sönke boosted:
Meredith WhittakerMer__edith@mastodon.world
2024-06-18

📣Official statement: the new EU chat controls proposal for mass scanning is the same old surveillance with new branding.

Whether you call it a backdoor, a front door, or “upload moderation” it undermines encryption & creates significant vulnerabilities

signal.org/blog/pdfs/upload-mo

New Branding, Same Scanning: “Upload Moderation”
Undermines End-to-End Encryption
A statement from Meredith Whittaker, Signal President, in the context of the EU debate
End-to-end encryption is the technology we have to enable privacy in an age of unprecedented state and
corporate surveillance. And the dangerous desire to undermine it never seems to die. For decades, experts have
been clear: there is no way to both preserve the integrity of end-to-end encryption and expose encrypted
contents to surveillance. But proposals to do just this emerge repeatedly — old wine endlessly repackaged in
new bottles, aided by expensive consultancies that care more about marketing than the very serious stakes of
these issues. These embarrassing branding exercises do not, of course, sway the expert community. But too
often they work to convince non-experts that the risks of the previous plan to undermine end-to-end encryption
are not present in the shiny new proposal. This is certainly how the EU chat control debate has proceeded.
In November, the EU Parliament lit a beacon for global tech policy when it voted to exclude end-to-end
encryption from mass surveillance orders in the chat control legislation.
2024-05-19

Starting my travel to San Francisco for IEEE S&P. I'll present our Linux Kernel Fuzzing paper on wednesday, for which we just published the source code 👇
github.com/seemoo-lab/VirtFuzz

Sönke boosted:
Jason Koeblerjasonkoebler
2024-05-12

Scoop: Solar storm is causing farmers' tractor GPS systems to go haywire. Many have shut down planting altogether during a critical period. A Deere dealer said accuracy is "extremely compromised"

404media.co/solar-storm-knocks

Sönke boosted:
Gabriele Svelto [moved]gabrielesvelto@fosstodon.org
2024-05-09

Memory errors in consumer devices such as PCs and phones are not something you hear much about, yet they are probably one of the most common ways these machines fail.

I'll use this thread to explain how this happens, how it affects you and what you can do about it. But I'll also talk about how the industry failed to address it and how we must force them to, for the sake of sustainability. 🧵 1/17

Sönke boosted:
2024-05-06

Unser langjähriges Mitglied @mattecke wurde am Wochenende brutal überfallen. Lieber Matthias, wir wünschen dir alles Gute. Du hast unsere volle Solidarität!

Gemeinsam machen wir deutlich: Genug ist genug! Werdet aktiv oder unterstützt Menschen, die sich täglich für die Demokratie einsetzen.

Wir stehen in Solidarität mit unserem Mitglied Matthias, das am Wochenende brutal angegriffen wurde. Als  Demokrat:innen müssen wir jetzt zusammen halten!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst