home.social

Search

68 results for “nyanbinary”

  1. RE: infosec.exchange/@nyanbinary/1

    Say, where do the cool kids get their LinkinPark_Numb.mp3.exe these days?

  2. CW: shitpost

    SSVC stands for "Subjectively Scored Vibe Classification"

  3. hm, no, this one isn't on me.

    The bot uses the cvelistV5 repo for determining CISA KEV. For this it checks for a metrics object with type kev in the cisa ADP container. For these it appears this object wasn't created until ~1h ago: github.com/CVEProject/cvelistV

    Interestingly the SSVC metrics object & the CISA KEV reference was already included - while building the bot I was considering including checking for SSVCs exploitation:active but decided against it as, at the time & iirc, every single CVE record with exploitation:active also had the kev metrics object.

  4. grmph, was @kev_bot broken again? :dragon_confused:

  5. re: reddit.com/r/BetterOffline/com

    So, we have security systems set up. Basically, when you create a user, you can give it extremely fine-grained control on what it can access in the program. See examples above: Bill on the floor can’t run a report and get all the credit cards, unless Bill’s user was explicitly granted that security permission.

    Another important note: the LLM is just a lower-level Claude running inside the application. It has full access to the database for that particular company. Anything available in their company’s database, the agent could technically grab on their behalf. It writes and executes its own SQL queries to try and answer user questions.

    This is just malpractice. I know permissions are hard & chatbots are still kinda new but this is a well known & solved problem, even before chatbots.

    *...remembers running @hardcoded_bot *

    nvm, what did I expect

  6. "3 billion devices run java" factoid actually just statistical error. average device runs 0 java. atlassian cloud, which lives in a cave and runs 3 billion different java versions, is an outlier adn should not have been counted.

  7. Therapy is a PvP game, right?

  8. The good thimg about my thoughts jumping all over the place all the time is I am probably not lieing when answering the question what I am thinking about...

  9. We all have strategic stockpile of topics & memories to deflect, right? We all try to map out past conversation flows so we can control where the conversation doesnt go, right?

  10. It's a good sign if you are actively thinking about ways to avoid therapy sessions & dread going there, right?

  11. Oh, great, looks like the Nextcloud Client update fucked with the local settings so it prompted me to log in again & set up a new local sync folder (with it just not accepting the old one). Stopping the client & restarting it had it recover with the old settings so yay, I dont need to pull another 100GB over a residental upstream.

  12. Part 1 of my brain: I should get tattoos :neobot_pleading: .
    Part 2 of my brain: Yeees, agreed. I got a great idea for a face tattoo
    Part 1: Oh neat, usually we struggle with ideas... waaait... hold on...!

  13. CW: US pol, aber Deutsch

    Na, welche werdens?

  14. CW: US pol, aber Deutsch

    Super, jetzt muss ich drüber nachdenken welche Stadt Merz bereit wäre dem Iran zu opfern...

  15. RE: infosec.exchange/@hardcoded_bo

    This is fine, right? Whats the worst that can happen, right?

  16. Sag mal, darf man die Coldmirror HP dubs eigentlich noch genießen? :thinking_cirno:

  17. I guess I could just yt-dlp ...

  18. Scheiß drauf, ich guck ob ich irgendwo ne gepiratete Version finde & schick denen 20 Euronen in der Post

  19. Nein, ich will dein Album nicht streamen. Gib mir einfach nen Link wo ich dir Geld geben kann und du mir Dateien gibst.

    Das schöne an Auto-Deletion ist, dass ihr nicht nachweise könnt, dass ich das hier alle paar Monate poste...

  20. No, I didnt think this through

  21. CW: Silly idea

    So, I think its a bit of a missed opportunity with passkeys but opportunistic e2e cross-session storage of availability-uncritical confidentiality-critical data would be quite neat?

    Fundamentally passkeys/webauthn is just pubkey authentication taken to the web (in the application layer). The assumption that underpins the broad passkey rollout is that we have built ecosystems that manage to abstract the key management enough so users dont have to worry about keymanagement, with keys being created and enrolled without user interaction & follow users through ecosystems.

    So why limit this to authentication if we can also do encryption?

    Encryption has one issue that authentication doesn't: If you lose your authentication key you can have account recovery procedures that restore full access. If you lose an encryption key (unless you are also encrypting it with the sites key) its gone. As such we are kinda limited to data with low availability requirements.

    Example: Credit card or other payment options. You run a webshop & you want to allow people to store their payment options without the risk of storing that data in a way your employees can access it. So... you just have your customer send you an e2e encrypted blob. If they make another purchase they get sent the blob and if they still have the key they can decrypt it & reuse it. And if someone doesnt use passkey+? Well, do it opportunistically, either dont store it or store it for only those customers.

  22. RE: infosec.exchange/@BleepingComp

    Not to shit on the reporting, on the contrary, but the absence of reporting on the flood of BEC is fascinating to me. When I still did IR at $lastjob one of our vendors/suppliers getting popped (or at least a couple of their M365 accounts, incl. mail & sharepoint) & sending us phishing was a near-daily occurrence. And thats just the stuff that made it through the filters & was reported to us...

  23. Gonna make the pope 1v1 me in CoD MW2 for the title

  24. Most cursed IT company mergers?

  25. Hey you. You want any of the .... good stuff? opens coat, showing collection of parmesan wedges

  26. vandalizing every single surveillance camera is the moderate position, istg

  27. But honestly much worse: The ubiquitous surveillance cameras in public transport. I have been on one too many late night trains where the ceiling camera globes outnumbered the passengers. I have been in one too many train stations with more cameras than people boarding the train.

  28. One day I will take a grafiti spray can to every surveillance camera on this fucking street. Fuck you and your rich people bunker.

  29. Sometimes I realized how dead privacy is in the physical world and it makes me fucking angry.

Share on Mastodon

Enter the server where you have an account.