Deebster

joined 2 years ago
[–] Deebster@infosec.pub 0 points 2 hours ago (1 children)

Here we were having a civil, good faith discussion, then you start flinging around downvotes to try to suppress any post you don't 100% approve of. That's not conducive to quality discourse, and you should stop it. You comments votes are downvotes 42% of the time.

Thanks for the link and I'll look into this, but I won't be talking with you any further.

[–] Deebster@infosec.pub -1 points 2 hours ago (3 children)

AISI is the AI Security Institute, so it's within their remit to discover what the AI companies' products can do - but then to not be monitoring them while they were running is where I call incompetence and negligence.

This is at least independent verification that these "breaches" aren't just AI bro marketing.

[–] Deebster@infosec.pub 2 points 3 hours ago (5 children)

AISI admitted it was not actively monitoring the agents’ behaviour during the evaluation and said it was putting tighter controls on internet access in tests as a result of the incident, introducing constant monitoring and reassessing its design of tests.

Sounds like the AISI are irresponsible and negligent - they took off the guardrails and gave it internet access, then didn't monitor it.

[–] Deebster@infosec.pub 7 points 2 days ago

He's been given an official birthday of 4 December 1832, so he's not quite there yet.

He predates Queen Victoria's coronation, the telegraph, Hans Christian Andersen's fairy tale collections, Charles Darwin's theory of natural selection, etc.

[–] Deebster@infosec.pub 10 points 2 days ago

Perhaps it's that wall protecting them from their neighbours to the north.

[–] Deebster@infosec.pub 3 points 2 days ago

Wow, this is comprehensive. What I've read so far is great. I love the coral reef metaphor/imagery.

[–] Deebster@infosec.pub 1 points 3 days ago* (last edited 3 days ago)

I'm still using shutdown -h now, even though the -h flag has been pointless for, what, 20 years?

edit: looks like sysvinit's shutdown still defaults to single-user mode, so I guess that muscle memory will still be useful if I ever use a Devuan or antiX box.

[–] Deebster@infosec.pub 8 points 3 days ago (1 children)

I loved my Palm Pilot, and I still remember how to write using Graffiti (although I had to look up what it was called).

[–] Deebster@infosec.pub 19 points 3 days ago

The Brdy dam was intended to restore the area to its natural state, decades after the Czech military built a bypass gully that drained its surroundings.

The beaver version is sure to be more natural than anything a human would manage, with less disruption. Another bonus is that the officials are now incentivised to protect the beavers as they're maintaining infrastructure.

[–] Deebster@infosec.pub 3 points 4 days ago

I don't much like gin, but I think this sounds great, and the shopping list is feasible. Thanks for sharing the recipe.

[–] Deebster@infosec.pub 4 points 4 days ago (1 children)

You do! It's the DDA (Disability Discrimination Act). A famous case is Maguire v SOCOG 2000 over the Olympic website. Also Coles got sued in 2014.

[–] Deebster@infosec.pub 6 points 4 days ago* (last edited 3 days ago)

And if you do get a true believer to visit the real Google Earth and see the lack of the faked addition, they'll claim that Google replaced the "real" version with what they're seeing.

35
submitted 2 weeks ago* (last edited 2 weeks ago) by Deebster@infosec.pub to c/canvas@toast.ooo
 

This is good fun, as always, but I've gone afk and am not enjoying the mobile experience as much as desktop because I keep having to click through the welcome modal and/or deal with a screen covered in duplicate (and superseded) errors. Sometimes it's more errors than fit on the screen so I get it multiple times.

Please only one of each error.

43
submitted 2 weeks ago* (last edited 2 weeks ago) by Deebster@infosec.pub to c/canvas@toast.ooo
 

I'm a little late with this news, but it's a good write-up.

The unread file was src/_probe/never_read_canary.txt, planted with a unique marker. Cloning the captured bundle recovered it verbatim along with the repo's full commit history, and the same test replicated on a second, unrelated repo.

 

The Linux kernel has recently been facing a series of discovered privilege escalation vulnerabilities, starting with the Copy Fail vulnerability and followed by subsequent vulnerabilities in the same spirit (Dirty Frag, Fragnesia). This development is part of a general trend where vulnerabilities are being found - and disclosed - faster than before. We expect it to continue, at least for the short-term.

The Gentoo Linux Kernel and Distribution Kernel teams are doing their best to keep Gentoo kernels secure. This includes both packaging the latest upstream releases as soon as possible, and backporting additional vulnerability fixes or mitigations whenever they become available. As example, while upstream kernel releases are still vulnerable to Fragnesia, the respective Gentoo kernels feature fixes from day one. At the time of writing, all supported Gentoo kernels feature the latest Fragnesia v5 patch. Please expect more updates. We recommend exploring ways to automate upgrading your kernel.

Please note that only sys-kernel/gentoo-kernel, sys-kernel/gentoo-kernel-bin and sys-kernel/gentoo-sources packages are security-supported. The vanilla kernel packages are vulnerable at the moment. Other kernel packages may carry fixes, but they usually are slower to be updated. Additionally, we recommend running the latest kernel version (~arch or latest stable LTS), as upstream does not reliably backport security fixes to older versions.

 

CPUID has since confirmed the breach, pinning it on a compromised backend component rather than tampering with its software builds.

"Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display malicious links (our signed original files were not compromised)," one of the site's owners said in a post on X. "The breach was found and has since been fixed."

 

Original IFF Deluxe Paint images from back in the day, courtesy of the Amiga Graphics Archive.

This is the one that always makes me think of DPaint:

source

11
submitted 4 months ago* (last edited 4 months ago) by Deebster@infosec.pub to c/chrisspargo@feddit.uk
 

My favourite bit is this from the comments:

I wrote "please do not deliver this letter" on a correctly addressed and stamped letter once, it never arrived. A thrilling day indeed.

 

I love Doom Bar and I'm not alone since it's among the bestselling cask ales in the UK, but it seems that the US owners are going for a quick payout by closing and asset stripping what's left.

I wonder how long until they start building houses or an industrial park on the old site?

 

This video covers Great Ormond Street Hospital, Quality Street and copyright special cases.

 

A severed mosquito proboscis can be turned into an extremely fine nozzle for 3D printing, and this could help create replacement tissues and organs for transplants.

I've linked to a decent write-up on Tom's Hardware, but New Scientist covered it last week too.

Source paper: 3D necroprinting: Leveraging biotic material as the nozzle for 3D printing (science.org)

 

An Australian YouTuber got invited to a NATO wargame and made this very interesting video about it.

The section that starts at 3m30s (10 minutes long) discusses the military history of wargaming which I found fascinating.

The rest of it is also well worth a watch.

It's not new (it sat in my watch later list for a month since it's 65 minutes long) so apologies if you've already seen it.

view more: next ›