Toots for cynicalsecurity@bsd.network account

Written by cynicalsecurity :cm_2: on 2025-01-26 at 20:20

Is anyone working on a minimalistic C compiler which outputs minimal RISC opcodes, i.e. no fancy instructions, “let the silicon optimiser do the work”?

Does that even make sense in 2025 or do you lose tons of performance if you don’t use the latest & greatest newfangled opcodes?

Note that I am explicitly excluding CRISC from this, i.e. x86 in any form.

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-24 at 12:11

I am pondering an attack based on the "new" performance/efficiency processor dichotomy.

Some stuff is starting to happen.

:flan_hacker:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-22 at 14:58

Q: "What is the IPv6 range you are sending email from?"

A: "IPv6 does not exist, we gave you the IP range"

:flan_molotov:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-21 at 16:06

Thinking back over the decades of my career in this wretched industry, and the only product I have always, unfailingly, recommended is @ThinkstCanary …

Seriously, if you are honest about security and you don't run a canary (there's an opencanary too¹!) on an internal network then you are not doing your job.

:flan_molotov:​

__

¹ https://github.com/thinkst/opencanary

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-20 at 21:04

Oh the horrors…

I have just merged two CVSROOT trees which I had inadvertently been running in parallel depending on I am not even sure what actually…

A bizarre feeling of abject folly has overcome me as I ran cp from one CVSROOT to another and then merged the history files.

:flan_molotov:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-20 at 16:12

LOL™

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-20 at 11:42

Unfortunately my 2017 vintage Xeon-D servers are starting to feel long in the tooth and are suffering under load, not to mention I am starting to get random machine check errors.

Yes, they have been kept (very) clean, with UPS-cleaned power and within decent temperature range (never above 28C).

I have to share the office with them so, for obvious noise reasons, I cannot have rackmounts so I need something similar to my current SuperMicro Superserver 5028D-TN4T.

The key requirements are:

Will be running #FreeBSD.

The crux is that it is some sort of a tower machine.

I could consider rackmounts but only if they are (very) quiet as I have to work next to them…

:flan_beg:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-20 at 08:01

You know that we have allowed something really really wrong to happen when there's a job title called "Deliverability Team Leader".

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-15 at 08:38

"Windows update is committed to helping reduce carbon emissions. Learn more"

:flan_XD:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-14 at 16:55

The 1990s are back! 🤣

D. Noever et al., "Infecting Generative AI With Viruses"¹

This study demonstrates a novel approach to testing the security boundaries of Vision-Large Language Model (VLM/ LLM) using the EICAR test file embedded within JPEG images. We successfully executed four distinct protocols across multiple LLM platforms, including OpenAI GPT-4o, Microsoft Copilot, Google Gemini 1.5 Pro, and Anthropic Claude 3.5 Sonnet. The experiments validated that a modified JPEG containing the EICAR signature could be uploaded, manipulated, and potentially executed within LLM virtual workspaces. Key findings include: 1) consistent ability to mask the EICAR string in image metadata without detection, 2) successful extraction of the test file using Python-based manipulation within LLM environments, and 3) demonstration of multiple obfuscation techniques including base64 encoding and string reversal. This research extends Microsoft Research's "Penetration Testing Rules of Engagement" framework to evaluate cloud-based generative AI and LLM security boundaries, particularly focusing on file handling and execution capabilities within containerized environments.

:flan_molotov:​

__

¹ https://arxiv.org/abs/2501.05542

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-14 at 08:17

I am reading David N. Schwartz, "The last man who knew everything" (on Enrico Fermi) and I am starting to suspect that what I thought was an exception is now the rule in non-fiction books.

Why on Earth is no sentence ever longer than ten words? All the recent non-fiction books I have read in the past year have this annoying hyper-simple English structure which drives me absolutely mad. Ironically, the quotes of other physicists in the Schwartz book are far more elaborate even though they are from mostly immigrant scientists: Hans Bethe writes better English than Schwartz, how sad.

I should qualify that: books by US authors have this.

I read both P. Caddick-Adams, "Monte Cassino: Ten armies in Hell" and S. Plohky, "Nuclear Folly: A New History of the Cuban Missile Crisis", neither of them suffer from the short, simple sentences disease.

:flan_sad:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-13 at 18:29

Is there a way to upgrade the first @PINE64 PineNote to the latest firmware which seems to deliver a good eBook experience?

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-12 at 17:08

Sunset over Meyrin, photos taken towards Bellgarde-sur-Valserine.

[#]Photograhy #Meyrin

=> View attached media | View attached media

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-12 at 17:05

The Mt. Blanc at sunset.

Taken from Meyrin, Switzerland (high zoom, probably pixelated on a large screen).

[#]Photography #SilentSunday #MtBlanc

=> View attached media

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-12 at 11:26

The Crête de la Neige, the sky blue and cloud-free thanks to an impetuous Bise blowing.

Nobody is out for a walk as it is bitterly cold due to windchill.

[#]Photography #SilentSunday #Switzerland

=> View attached media

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-10 at 10:37

A child is drowning, and four men who stand upon the bank see it struggling in the water. One of them does not stir, he is a partisan of "Each one for himself," the maxim of the commercial middle-class; this one is a brute and we need not speak of him further. The next one reasons thus: "If I save the child, a good report of my action will be made to the ruler of heaven, and the Creator will reward me by increasing my flocks and my serfs," and thereupon he plunges into the water. Is he therefore a moral man? Clearly not! He is a shrewd calculator, that is all. The third, who is an utilitarian, reflects thus (or at least utilitarian philosophers represent him as so reasoning): "Pleasures can be classed in two categories, inferior pleasures and higher ones. To save the life of anyone is a superior pleasure infinitely more intense and more durable than others; therefore I will save the child." Admitting that any man ever reasoned thus, would he not be a terrible egotist? and, moreover, could we ever be sure that his sophistical brain would not at some given moment cause his will to incline toward and inferior pleasure, that is to say, towards refraining from troubling himself? There remains the fourth individual. This man has been brought up from his childhood to feel himself one with the rest of humanity: from his childhood he has always regarded men as possessing interests in common: he has accustomed himself to suffer when his neighbours suffer, and to feel happy when everyone around him is happy. Directly he hears the heart-rending cry of the mother, he leaps into the water, not through reflection but by instinct, and when she thanks him for saving her child, he says, "What have I done to deserve thanks, my good woman? I am happy to see you happy; I have acted from natural impulse and could not do otherwise!”

You recognise in this case the truly moral man, and feel that the others are only egotists in comparison with him. The whole anarchist morality is represented in this example. It is the morality of a people which does not look for the sun at midnight—a morality without compulsion or authority, a morality of habit.”

-- Kropotkin

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2025-01-09 at 17:13

Remember my Christmas Day #OpenBSD crashes (and Boxing Day, for good measure) with WIreguard tunnels pumping loads of traffic…

… https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/006_wg.patch.sig

:flan_XD:​

Not sure I win any prizes for seeing it happen…

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2024-12-28 at 07:37

This morning I woke up to find my iPhone in “Holiday” focus. On its own, just like that.

A message from the Cupertino Overlords?

Naah, this is an implant which sets holiday mode so I can’t see notifications and sounds as it messes with my phone!

Hope you liked the paranoid version :flan_XD:

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2024-12-26 at 11:37

Hrm… I am wondering… while I put the new Wireguard tunnels in place I also decided to move from IPv4 to IPv6 on the VPLS link.

Could it be that the interaction between the IPv6 UDP code and the off-loading to ix is the issue? I should have the courage to test again with IPv4…

:flan_think:​

=> More informations about this toot | View the thread

Written by cynicalsecurity :cm_2: on 2024-12-26 at 11:07

Depressing: /var/crash is empty :flan_disappointed:​

=> More informations about this toot | View the thread

=> This profile with reblog | Go to cynicalsecurity@bsd.network account

Proxy Information
Original URL
gemini://mastogem.picasoft.net/profile/71106
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
371.109871 milliseconds
Gemini-to-HTML Time
5.083229 milliseconds

This content has been proxied by September (3851b).