#keys — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #keys, aggregated by home.social.
-
-
Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.
The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.
This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.
#ai #security #SupplyChainAttack #hack
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Companies exposed: https://exposure.cloudsek.com/ai-supply-chain-incident
ArsTecnica overview: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
-
Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.
The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.
This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.
#ai #security #SupplyChainAttack #hack
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Companies exposed: https://exposure.cloudsek.com/ai-supply-chain-incident
ArsTecnica overview: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
-
-
-
-
-
-
-
Anthropic's Fever Dream: Claude's package that stole real keys
https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys
Comments: https://news.ycombinator.com/item?id=49148070
#HackerNews #Anthropic #Claude #FeverDream #RogueAgents #Cybersecurity #Keys
-
Anthropic's Fever Dream: Claude's package that stole real keys
https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys
Comments: https://news.ycombinator.com/item?id=49148070
#HackerNews #Anthropic #Claude #FeverDream #RogueAgents #Cybersecurity #Keys
-
-
-
-
-
-
at some point, i'd love to work on an implementation of the #screenreader of NVDA #nvda #remote / #nvdaremote where rather than using a 6-digit key that can be guessed, it uses #asymmetric #cryptography that genrates #encryption #keys using an algorithm like #rsa / #ecc (eliptic curve cryptography) in order to secure the connections. how it would work is you setup your connection. then, you'll get an encryption key for your session unique to that session. then, you give the user of the computer you want to control or who you want to control your computer the key. once both sides disconnect, the key automatically / automagically expires. it would be like a public / private keypare, where the key is stored on the server terminating the remote session (E.G. nv.seedy.cc, poweredge-r720.featherback-firefighter.ts.net) while the private key is stored on the machines connected to it. and optionally, a passfraze for the key to protect access even if that person has the key, sourt of like how #ssh public/private keypares work.
@cryptography -
Ich find das ist schon fast Kunst.
(c) meine Hosentasche ^^ -
-
-
The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.
The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.
So my questions are:
a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?
b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.
[1] Am I the only one who used to sell their stuff when they used their full name?
[2] Only with #Windows, natch.
[3] I'll start calling programs "apps" when I'm dead, thanks.
#LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware
-
The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.
The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.
So my questions are:
a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?
b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.
[1] Am I the only one who used to sell their stuff when they used their full name?
[2] Only with #Windows, natch.
[3] I'll start calling programs "apps" when I'm dead, thanks.
#LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware
-
-
GitHub suddenly rejected my SSH key (the fix was a .pub file?)
https://thorsell.io/2026/07/21/github-ssh-keys.html
Comments: https://news.ycombinator.com/item?id=48990929
#HackerNews #GitHub #SSH #keys #SSH #key #fix #tech #support #developer #tips
-
GitHub suddenly rejected my SSH key (the fix was a .pub file?)
https://thorsell.io/2026/07/21/github-ssh-keys.html
Comments: https://news.ycombinator.com/item?id=48990929
#HackerNews #GitHub #SSH #keys #SSH #key #fix #tech #support #developer #tips
-
-
-
-
-
-
-
-
Why We Don't Trust the Database with Authentication
https://blog.sturdystatistics.com/posts/api_keys/
Comments: https://news.ycombinator.com/item?id=48814503
#HackerNews #database #authentication #security #API #keys #trust
-
Why We Don't Trust the Database with Authentication
https://blog.sturdystatistics.com/posts/api_keys/
Comments: https://news.ycombinator.com/item?id=48814503
#HackerNews #database #authentication #security #API #keys #trust
-
Has anyone here used keyroost for managing their security keys? https://github.com/framefilter/keyroost it's a very new piece of software and the readme says it is being built With Claude.
Has it been audited? Is it safe? #keys #fido2securitykeys
-
At last, now I can form a real #taishogoto #punk band.
"2nd verse ..same as the first"
#taishogoto #taishokoto #strings #keys #stereoscopicphotographs #stereoscopic #music #instruments
-
The Archer House (The Archer Inn Book 1)
"Her first love and all the problems she left behind twenty-five years ago—await her"
Sale: $5.99 to FREE
by Kimberly Thomas
Rating: 4.4/5 (1,236 Reviews)
#books #fiction #sisters #familylife #siblings #keys #florida #women #booksky
The Archer House (The Archer I... -
Color Analysis From a Mummy Cloth (1902) by Emily Noyes Vanderpoel, from Color Problems: A Practical Manual for the Lay Student of Color.
Source: Smithsonian Libraries and Archives / Internet Archive
https://pdimagearchive.org/images/092d7564-0433-47a2-ad93-4fbf8b40415e
-
I Hate (Most) Keyboard 'Fn' Keys
https://danq.me/2026/06/09/fn-keys/
#HackerNews #I #Hate #Most #Keyboard #Fn #Keys #KeyboardDesign #TechOpinions #UserExperience
-
GPS As a Key Distribution Platform
This is interesting:
The U.S. military has likely been quietly broadcasting codes for its global encrypti... https://www.schneier.com/blog/archives/2026/06/gps-as-a-key-distribution-platform.html -
#Study from Sep '25 claims they've proven that #pianists can alter #timber, #brightness, w/ how they play (the #percussion #instrument by pressing keys).
But for all its wordiness, they never describe a single #technique used, they never discuss what they saw w/ all those cameras. They don't say what #music they used or its complexity, how the #listeners heard it (was it #recorded? #live in the room?).
Put simply: I don't believe them (& I'm a pianist).
#PianoForte #keys
https://www.sciencedaily.com/releases/2025/10/251002073956.htm -
CISA Security Leak
Crazy story:
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a ... https://www.schneier.com/blog/archives/2026/05/cisa-security-leak.html -
Design for eight initial keys (ca. 1893–96) by Aubrey Beardsley, from John Lane’s Keynote series.
Source: National Digital Library of PolandUniversity of Toronto Libraries / Internet Archive
Available to buy as a print.
https://pdimagearchive.org/images/a34d5317-97f8-4f23-90b8-66b93236092a
#keys #letters #grotesque #decadent-movement #decadence #drawing #art #publicdomain
-
Put your SSH keys in your TPM chip
https://raymii.org/s/tutorials/Put_your_SSH_keys_in_your_TPM_chip.html
-
As if I hadn't suffered enough "flood damage" this year, I started my first workday since rebuilding my home office setup - hour the first time in months! - in our rental... by pouring a cup of coffee into my keyboard. 😱
#note #keys #keyboard #disaster #flood2026 #coffee #computers #repair
Via: 🔗 https://danq.me/2026/04/16/chicory-house-real-coffee-flooded-keyboard/
-
Free download codes:
Dimensionless Unity - Gattaca
"Gattaca is a focused electronic piece by Dimensionless Unity, shaped through analog synthesis and hands-on production."
#electronic #house #funk #synthesizer #groove #futurehouse #keys #music
-
кому нужны все эти избыточные рифмы-переклички? 【 Ещё работа перекликается со связками ключей на вентиляторах от Айрис Тулиату, которые можно было увидеть и услышать летом 2021 года в квир-галерее «Фрагмент»: https://fragment.gallery/exhibitions/25-i-hear-your-keys-clinking-tenant-of-culture-paul-barsch-georgia-dickie-aniara/installation_shots/ ⦾ https://eclipse.athensbiennale.org/en/artists/iris-touliatou.html #rhyme #JuanCasemiro #IrisTouliatou #keys #fans #kineticsculpture #infinity #Fragment 】
-
I removed the #keys one by one and placed them in warm soapy water