Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
paco@infosec.exchangeP

paco@infosec.exchange

@paco@infosec.exchange
About
Indlæg
10
Emner
1
Fremhævelser
0
Grupper
0
Følgere
0
Følger
0

Vis Original

Indlæg

Seneste Bedste Controversial

  • Coxon: oh shit don't give away how deep in I am with the rationalistsCoxon: I'm totally not a rationalist, I just hung out with them for a decade because I admire their huge swole brains and how right they are about everythingCoxon: nailed it
    paco@infosec.exchangeP paco@infosec.exchange

    @davidgerard I’m doing what I can to hasten the Quornpocalypse!

    @aslakr @tante

    Ikke-kategoriseret

  • Project Glasswing:
    paco@infosec.exchangeP paco@infosec.exchange

    @0xabad1dea Internally at work we had a shit-ton of Glasswing findings. I got 5 sev-2 tickets for Glasswing issues. All on a project we had shut down 18 months prior. Of the 5, 4 were junk. They were in code that was only a partial implementation of a new feature, and we had stopped the entire project before the feature was finished.

    The fifth was really subtle and interesting. It was legit, and something I had wondered whether it was possible. I checked it out and it was definitely true and exploitable the way it described. Shame the project had been shut down for 18 months.

    I ended up accepting its PRs and then marking all the code repos as deprecated just to shut the bot up. They probably call that success.

    Ikke-kategoriseret

  • the rm -rf's will continue until morale improves
    paco@infosec.exchangeP paco@infosec.exchange

    @webhat As they say: if that first cup of coffee doesn’t wake you up in the morning, try dropping a table in production. 😜
    @neurovagrant

    Ikke-kategoriseret

  • the rm -rf's will continue until morale improves
    paco@infosec.exchangeP paco@infosec.exchange

    @astraleureka At approximately the same time (same year, probably) we had a WAF vendor some in and give a presentation on their product. We had demo access to a live version of it. We were playing with the console of the WAF itself, not some app behind the WAF.

    While the vendor is speaking my colleague starts testing stuff on the product console and within a couple minutes he’s pretty sure it’s vulnerable to SQL injection. He tries the classic “or 1=1” and he gets a well-formatted security error. Huh. It detected that and stopped it. He tried “or 2=2”. Bingo. It WAS vulnerable, but they were detecting and matching on the value “or 1=1” as some kind of literal. 🤦🏻

    I dont mean to derail the thread about careless people losing data to the automated , climate-destroying intern. It just triggers memories of hand made, non-automated failures in the past.

    @jztusk @neurovagrant

    Ikke-kategoriseret

  • New article: this time, we use Heidegger to explain why the "it's just a tool" line that often comes up in tech is so very silly:
    paco@infosec.exchangeP paco@infosec.exchange

    @mrsbeanbag I think the blog and the reasoning in it is really good. I’m going to use it in the future. But I also agree with you that LLMs really strain the definition of “tool”.

    The same person giving the same LLM the same exact input more than once to solve the same problem more than once will get 2 different outputs (probably similar, but not at all identical). That makes it a strange “tool,” indeed.

    And there’s so much cargo culting around just the right phrases to prevent this problem or that problem. People can develop expertise with a tool. But LLMs’ non-determinism limit the value of past experience with respect to future performance.

    @iris_meredith

    Ikke-kategoriseret

  • The bird-on-a-stick has no idea that a wily predator is hiding nearby—nearly invisible in his perfect camouflage.#catsofmastodon #caturday #mrmittens
    paco@infosec.exchangeP paco@infosec.exchange

    The bird-on-a-stick has no idea that a wily predator is hiding nearby—nearly invisible in his perfect camouflage.
    #catsofmastodon #caturday #mrmittens

    Ikke-kategoriseret catsofmastodon caturday mrmittens

  • the rm -rf's will continue until morale improves
    paco@infosec.exchangeP paco@infosec.exchange

    @jrdepriest It’s a true story, but I tell it a certain way to get a reaction. It was in a UAT environment, not prod. To be fair, it was a precious UAT environment that hundreds of people count on. It was not quick to rebuild. The client was pissed. But it wasn’t deleting real users from the real web site.

    @jztusk @womble @neurovagrant

    Ikke-kategoriseret

  • the rm -rf's will continue until morale improves
    paco@infosec.exchangeP paco@infosec.exchange

    @jztusk There are tons. Calculations or delays that indicate it was processed without doing anything to data.
    @neurovagrant

    Ikke-kategoriseret

  • the rm -rf's will continue until morale improves
    paco@infosec.exchangeP paco@infosec.exchange

    @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

    Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

    Ikke-kategoriseret

  • The US has declared Autistici/Inventati, an Italian anarchist hacker (in the classic sense of the term) collective, a terrorist organization.
    paco@infosec.exchangeP paco@infosec.exchange

    @cwebber I agree. Someone recently circulated a list of TLDs that didn't have an ICANN connection, and it's like 15-20 country-based domains. I went and looked at dotMeow, which I supported, and they're based in Belgium. But, no, they're going to be an ICANN registered domain. Still a worthy cause, but that's a shame. So much of the Internet has been built on trusting the US. Few people built contingencies for this breach of trust.

    Ikke-kategoriseret
  • Log ind

  • Har du ikke en konto? Tilmeld

  • Login or register to search.
Powered by NodeBB Contributors
Graciously hosted by data.coop
  • First post
    Last post
0
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper