home.social

#darknet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #darknet, aggregated by home.social.

fetched live
  1. Catching up this evening on issues and PRs that have been queuing up for Darknet/YOLO.

    Two different users submitted nearly identical 50-line patches for a particular issue. Variable names are the same, comments are very similar, and the logic is identical.

    If it was a 5-line change, this wouldn't be difficult to imagine. But the patches are ~50 lines each.

    I assume this was created using a LLM. So much LLM-generated submissions. #Darknet #YOLO #LLM

  2. Catching up this evening on issues and PRs that have been queuing up for Darknet/YOLO.

    Two different users submitted nearly identical 50-line patches for a particular issue. Variable names are the same, comments are very similar, and the logic is identical.

    If it was a 5-line change, this wouldn't be difficult to imagine. But the patches are ~50 lines each.

    I assume this was created using a LLM. So much LLM-generated submissions. #Darknet #YOLO #LLM

  3. I've been working with source code for ~40 years. I'm very comfortable with zero-based versus one-based.

    But when talking about line numbers in source files we never use zero-based counting!

    I assume at this point that this e-mail I received where all the line numbers they reference are off by 1 was created with a LLM. #Darknet #YOLO #LLM

  4. I've been working with source code for ~40 years. I'm very comfortable with zero-based versus one-based.

    But when talking about line numbers in source files we never use zero-based counting!

    I assume at this point that this e-mail I received where all the line numbers they reference are off by 1 was created with a LLM. #Darknet #YOLO #LLM

  5. Another LLM-generated security report e-mailed to me today concerning some code I didn't write but I maintain. Requires users to load invalid configuration files to exploit a buffer overrun.

    I've been given 90 days to fix the problem. Note I don't get paid to work on open-source software. And users shouldn't be loading random invalid configuration files.

    This is just like e-mail. When there is zero cost associated with sending out junk mail, then you guarantee that junk mail will continuously be sent out. #Darknet #YOLO #CVE

  6. Another LLM-generated security report e-mailed to me today concerning some code I didn't write but I maintain. Requires users to load invalid configuration files to exploit a buffer overrun.

    I've been given 90 days to fix the problem. Note I don't get paid to work on open-source software. And users shouldn't be loading random invalid configuration files.

    This is just like e-mail. When there is zero cost associated with sending out junk mail, then you guarantee that junk mail will continuously be sent out. #Darknet #YOLO #CVE

  7. Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten

    Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen.

    heise.de/news/Neobank-Revolut-

    #Cybercrime #Darknet #Datenleck #IT #Security #news

  8. Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten

    Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen.

    heise.de/news/Neobank-Revolut-

    #Cybercrime #Darknet #Datenleck #IT #Security #news

  9. Interesting topic came up today on the Darknet/YOLO discord. What can we -- or should we? -- do about how people use our open-source project?

    We know the U.S. military for example uses Darknet/YOLO. This was confirmed again just a few weeks ago, and was responsible for Joseph Redmon's departure many years ago.

    Darknet/YOLO is fully open-source. I cannot possibly monitor how people use the project, since anyone can clone it. If anything, we'd be restricted to changing the license to exclude military use, but again there is no way for me to monitor or enforce this condition.

    All they would have to do is clone the last revision prior to the license change. #Darknet #YOLO #OpenSource #USMilitary

  10. Interesting topic came up today on the Darknet/YOLO discord. What can we -- or should we? -- do about how people use our open-source project?

    We know the U.S. military for example uses Darknet/YOLO. This was confirmed again just a few weeks ago, and was responsible for Joseph Redmon's departure many years ago.

    Darknet/YOLO is fully open-source. I cannot possibly monitor how people use the project, since anyone can clone it. If anything, we'd be restricted to changing the license to exclude military use, but again there is no way for me to monitor or enforce this condition.

    All they would have to do is clone the last revision prior to the license change. #Darknet #YOLO #OpenSource #USMilitary

  11. Darknet Diaries Deutsch: Nackt im Netz - Teil 2

    Die Zwillingsschwestern Madison und Christine wurden über Jahre hinweg von einer unbekannten Person massiv im Internet belästigt. Jetzt wehren sie sich.

    heise.de/news/Darknet-Diaries-

    #Cybercrime #Darknet #DarknetDiaries #Journal #news

  12. Darknet Diaries Deutsch: Nackt im Netz - Teil 2

    Die Zwillingsschwestern Madison und Christine wurden über Jahre hinweg von einer unbekannten Person massiv im Internet belästigt. Jetzt wehren sie sich.

    heise.de/news/Darknet-Diaries-

    #Cybercrime #Darknet #DarknetDiaries #Journal #news

  13. *Darknet-Drogenhandel endet in langjähriger Haftstrafe*
    Der kalifornische Drogenhändler Darren Hughes wurde zu über 26 Jahren Haft verurteilt, nachdem er durch eine Reihe von Fehlern im Darknet auffiel.
    { #Szene #Uber #DarkCommerce #Darknet }
    >> nydus.org/news/135861-darknet-

  14. *Großangriff auf den Darknet-Drogenmarkt in Niedersachsen*
    Die Strafverfolgungsbehörden in Niedersachsen haben einen multinationalen Drogenschmuggel aufgedeckt. Dieses Netzwerk soll innerhalb mehrerer Jahre über 1.000 Verkäufe vorgenommen haben. Die Zahl der Transaktionen beläuft sich auf enorme Summen – mindestens 500.
    { #Szene #Uber #Cybercrime #DarkCommerce #Darknet }
    >> nydus.org/news/135850-groszang

  15. social.bund.de/@bsi/1166807574

    Ginge es darum, Menschen zu sensibilisieren, Nutzerzugänge besser abzusichern, damit ihre Daten nicht im Darknet verkauft werden - das wäre unterstützenswert und im Sinn des Auftrags des #BSI.

    Das sog. #Darknet so darzustellen, als wäre es die Wurzel des Übels, jeder Besucher/Nutzer des Teufels und Anonymität das eigentliche Problem... ist schlicht falsch. Aus so vielen Gründen.

  16. Darknet Diaries Deutsch: Nackt im Netz - Teil 1

    81
    Madisons Nacktfotos wurden online veröffentlicht. Ihre Zwillingsschwester Christine kam ihr zu Hilfe. Es beginnt eine Jagd durch die Abgründe des Internets.

    heise.de/news/Darknet-Diaries-

    #Cybercrime #Darknet #DarknetDiaries #Journal #news

  17. Darknet Diaries Deutsch: Nackt im Netz - Teil 1

    81
    Madisons Nacktfotos wurden online veröffentlicht. Ihre Zwillingsschwester Christine kam ihr zu Hilfe. Es beginnt eine Jagd durch die Abgründe des Internets.

    heise.de/news/Darknet-Diaries-

    #Cybercrime #Darknet #DarknetDiaries #Journal #news

  18. Bug Bounty situation = Netflix & Piracy situation?

    *Boosts welcome

    I want to hear your opinion on an idea I had recently:

    So, movies/TV piracy is rising recently. And much of it is due to the overwhelming amount of providers, and the fact that each one has a small portion of the pie.
    Unlike Music, where providers have mostly the same, allowing for a good customer experience, lowering the need to pirate music, in the movies/TV industry the situation is just getting worse each day, making the rise of piracy (discussed in DarknetDiaries' episode about the magic box) bigger each day.

    I was wondering if the same thing would/is happening in the bug bounty world.
    As more and more companies close their bug bounty programs, or lower the rewards, could researchers turn to selling their findings on the dark net/other forums alike?

    After all, many researchers do this to make a living, and not be a knight on a white horse.
    And if someone invested months researching and testing to find a critical vulnerability, they won't be able to go shopping with a Thank You letter.

    what do you think?

    I'm not a bug bounter so I don't really live this world, but some of you are. what do you think?
    is it already happening?

    #BugBounty #SecurityResearch #Piracy #Darknet

  19. Bug Bounty situation = Netflix & Piracy situation?

    *Boosts welcome

    I want to hear your opinion on an idea I had recently:

    So, movies/TV piracy is rising recently. And much of it is due to the overwhelming amount of providers, and the fact that each one has a small portion of the pie.
    Unlike Music, where providers have mostly the same, allowing for a good customer experience, lowering the need to pirate music, in the movies/TV industry the situation is just getting worse each day, making the rise of piracy (discussed in DarknetDiaries' episode about the magic box) bigger each day.

    I was wondering if the same thing would/is happening in the bug bounty world.
    As more and more companies close their bug bounty programs, or lower the rewards, could researchers turn to selling their findings on the dark net/other forums alike?

    After all, many researchers do this to make a living, and not be a knight on a white horse.
    And if someone invested months researching and testing to find a critical vulnerability, they won't be able to go shopping with a Thank You letter.

    what do you think?

    I'm not a bug bounter so I don't really live this world, but some of you are. what do you think?
    is it already happening?

    #BugBounty #SecurityResearch #Piracy #Darknet

  20. Einigung statt Aufklärung: Im Fall #Unimed läuft vieles falsch - besonders brisant ist nun die Aussage von #UKSH-Chef Jens Scholz, wonach Unimed sich offenbar mit den Hackern geeinigt hat, was im Klartext bedeuten könnte, dass #Lösegeld geflossen ist.

    Scholz begründet damit seine persönliche Erwartung, dass die Daten nicht im #Darknet landen werden, weil die Nichtveröffentlichung gestohlener Daten das eigentliche "Geschäftsmodell" solcher Angriffe sei:

    kn-online.de/lokales/kiel/nach #cybersecurity

  21. Einigung statt Aufklärung: Im Fall #Unimed läuft vieles falsch - besonders brisant ist nun die Aussage von #UKSH-Chef Jens Scholz, wonach Unimed sich offenbar mit den Hackern geeinigt hat, was im Klartext bedeuten könnte, dass #Lösegeld geflossen ist.

    Scholz begründet damit seine persönliche Erwartung, dass die Daten nicht im #Darknet landen werden, weil die Nichtveröffentlichung gestohlener Daten das eigentliche "Geschäftsmodell" solcher Angriffe sei:

    kn-online.de/lokales/kiel/nach #cybersecurity

  22. Nagelstudios: Ein Phänomen. Aus dem nichts entstanden und nun massenhaft vorhanden. Bei zu viel Konkurrenz muss man sich über Alternativen Gedanken machen. Verständlich. Wann wird es mit den Barber Shops weiter gehen? :mastocheeky:

    Nagelstudios für Drogenhandel im #Darknet und Geldwäsche | Security heise.de/news/Nagelstudios-fue #Nemesis #KingdomMarket #AlphaBay #Archetyp #Incognito #Bohemia #ASAP #Tor2Door #WhiteHouseMarket #EmpireMarket #CyberCrime #cryptocurrencies #cryptocurrency

  23. Nagelstudios: Ein Phänomen. Aus dem nichts entstanden und nun massenhaft vorhanden. Bei zu viel Konkurrenz muss man sich über Alternativen Gedanken machen. Verständlich. Wann wird es mit den Barber Shops weiter gehen? :mastocheeky:

    Nagelstudios für Drogenhandel im #Darknet und Geldwäsche | Security heise.de/news/Nagelstudios-fue #Nemesis #KingdomMarket #AlphaBay #Archetyp #Incognito #Bohemia #ASAP #Tor2Door #WhiteHouseMarket #EmpireMarket #CyberCrime #cryptocurrencies #cryptocurrency

  24. Someone sent me 2 e-mails to report a parsing bug in the Darknet/YOLO code I maintain. They didn't send me a PR, just the e-mails. And they want their name associated with the fix, either in the readme, or some sort of text file.

    Am I wrong to think that if they send me a PR, then their name would automatically be part of the commit, but if they cannot be bothered to send me the 1-line PR then they can get lost with their requirement that they receive credit?

    I suspect this an LLM-discovered issue, since the code they reported hasn't been used in many years unless you pick a configuration that is no longer supported. #Darknet #YOLO #InfoSec

  25. Someone sent me 2 e-mails to report a parsing bug in the Darknet/YOLO code I maintain. They didn't send me a PR, just the e-mails. And they want their name associated with the fix, either in the readme, or some sort of text file.

    Am I wrong to think that if they send me a PR, then their name would automatically be part of the commit, but if they cannot be bothered to send me the 1-line PR then they can get lost with their requirement that they receive credit?

    I suspect this an LLM-discovered issue, since the code they reported hasn't been used in many years unless you pick a configuration that is no longer supported. #Darknet #YOLO #InfoSec