Show newer

A quote from the article explaining what happened at Basecamp:

“Do you protect this extremely senior employee that you’ve protected for many years? And [the answer] was yes.”

You cannot both tolerate toxic people and have an inclusive work environment at the same time.

I looked into the Ninja Cookie extension and found it really sloppy with security. I don’t know why after three months they only managed to address the biggest issue, they never wrote back after acknowledging my initial report.

The add-on blocklist is now a Bloom filter, meaning that seeing its contents isn’t trivial. Also, stopped updating last year. If you need a human-readable list of blocks, it seems that is the only place now.

Great thread on how to manage a team in order to make it more inclusive and welcoming to women. Yes, it’s sad but all of this is really necessary. Patricia knows what she is talking about. No, we cis men don’t.

Wow. As we don’t have enough vulnerabilities in open source projects as it is, “researchers” from University of Minnesota introduce more on purpose. To “prove” that it can be done. 🤦‍♂️


It seems that he has shut down most of his websites hosting copycat content, that’s good news. Yes, even the one with copyright message replaced by “See you in court.” However, he has set up a new fake company website and a Twitter account for it. 🙄

Show thread

Another upcoming disclosure deadline in less than four weeks. Universal XSS in a browser extension, really bad. The vendor managed to produce two releases in the time but no fix for the critical issue. Sent out a reminder… 🙄

The Print Friendly & PDF browser extension allowed any website to completely take over the extension. Considerable attack surface remains, and Firefox version is still vulnerable (exploitation slightly more complicated there).

Guess what: the extension vendor who took almost three months to address a critical vulnerability, cutting it very close to the deadline, only did some minor surface polishing. The underlying issues are still present and I better don’t look too closely. Disclosure tomorrow. 😬

Don’t get me wrong, deepfakes are a concern. But apparently not big enough a concern yet that we need to worry about a mom manipulating videos in order to harass her daughter’s competition. Harassment with a real video is enough to get her indicted.

So whoever compromised the PHP source code repository did so by pushing via HTTPS with password-based auth. They had to guess usernames. Sounds like a password reuse issue: the password leaked elsewhere, so they didn’t know the matching username.

So apparently the leaked data of 533 million Facebook users came from a 2019 breach that wasn’t previously disclosed after all. Not just that, Facebook chose not to notify the users affected either. Yes, totally reasonable and responsible behavior, as you would expect.

Noticed that a former follower blocked me. Weird, what did I do? Oh, I retweeted something about the harm RMS has done and is still doing…

People, choosing heroes means also reconsidering the choice sometimes. Some turn out to be awful human beings when you take a closer look.

Great blog post, explaining how linked list questions in job interviews had their time and place in the 80s. Also showing how the cargo culting likely happened which made them still popular today despite being largely pointless.

What we need is software that users can rely on, that will act in their best interest rather than monetize them behind their backs. Clearly, Free Software failed to define ethical aspects of software, and we now know why. So maybe is the right answer.

Show thread

While at it, could we consider moving beyond Free Software? I’m increasingly convinced that it is a dead end we wasted decades on. GNU/Linux is used everywhere, yet it gives users exactly zero leverage. Having access to those mountains of code is no gain, it’s almost useless.

After loosing RSS feeds again in Thunderbird I got fed up and reported the bug. Looks like it has good chances to get fixed!

Free Software Foundation Europe is severing its ties to FSF. Yes, at this stage it’s the only right decision.

Stumbled upon a (legitimate) website that managed to drive up Firefox memory usage by 2 GB and almost hang the entire UI before I closed the tab. And Firefox spent around five minutes working on freeing all that memory. I feel an urge to dissect it and figure out what they did…

For anybody concerned that my previous article on Amazon Assistant only discussed potential threats: here is the actual data being collected for “analytics” purposes. Lots of it and linked to the user’s Amazon account.

Show older
Infosec Exchange

A Mastodon instance for info/cyber security-minded people.