GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Marcus Hutchins :verified: (malwaretech@infosec.exchange)'s status on Monday, 12-May-2025 19:32:00 JST Marcus Hutchins :verified: Marcus Hutchins :verified:

    As much as I love the job security, someone is going to have to stop these AI bros before they have us watering the crops with Brawndo.

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/494/287/618/576/384/original/99fe46b2fe5c3613.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/494/287/734/645/542/original/ade27f87a960ba4a.png
    • Embed this notice
      iced depresso (icedquinn@blob.cat)'s status on Monday, 12-May-2025 19:32:00 JST iced depresso iced depresso
      in reply to
      @malwaretech :comfystoner: ya'll gonna get the society ya'll deserve.
      In conversation about a year ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Monday, 12-May-2025 19:40:42 JST Blurry Moon Blurry Moon
      in reply to
      @malwaretech He's right about the three years thing even if he's an idiot
      In conversation about a year ago permalink
      feld likes this.
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 13-May-2025 00:38:04 JST feld feld
      in reply to
      • Charl van der Walt 🌻🇵🇸
      @charlvdwalt @malwaretech because we used to live in a world where ISPs, open wifi networks (cafes, etc) could intercept your HTTP responses and inject javascript/HTML into your browser to force you to see ads and/or attack you
      In conversation about a year ago permalink
      Doughnut Lollipop 【記録係】:blobfoxgooglymlem: likes this.
    • Embed this notice
      Charl van der Walt 🌻🇵🇸 (charlvdwalt@infosec.exchange)'s status on Tuesday, 13-May-2025 00:38:05 JST Charl van der Walt 🌻🇵🇸 Charl van der Walt 🌻🇵🇸
      in reply to

      @malwaretech side note (and maybe I gave flu and it’s making me more stupid) but what are the arguments for having SSL on brochureware websites that don’t collect private information?

      In conversation about a year ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 13-May-2025 00:41:32 JST feld feld
      in reply to
      • Charl van der Walt 🌻🇵🇸
      @charlvdwalt

      > Do you all feel that there is enough integrity in browser trusted root certificate stores to still provide robust defence against the content / malware injection threat?

      It's the best we can do with what we've got to work with. All we can hope is that the bad actors get caught from the Certificate Transparency Logs and are swiftly removed from all root certificate stores as their punishment.
      In conversation about a year ago permalink
      Doughnut Lollipop 【記録係】:blobfoxgooglymlem: likes this.
    • Embed this notice
      Charl van der Walt 🌻🇵🇸 (charlvdwalt@infosec.exchange)'s status on Tuesday, 13-May-2025 00:41:33 JST Charl van der Walt 🌻🇵🇸 Charl van der Walt 🌻🇵🇸
      in reply to

      Thanks everyone for your comments on this. I like this excerpt from doesmysiteneedhttps.com:

      "this discussion isn't about PKI. It's the best system we've got for right now. Deal with it and secure your site. Use CAA records to restrict which CAs can issue certificates for your site, then cross your fingers and hope transparency and oversight works (it does, so far)".

      Do you all feel that there is enough integrity in browser trusted root certificate stores to still provide robust defence against the content / malware injection threat?

      Also - have these kinds of injection attacks ceased now, and is SSL the reason for this?

      Thanks!

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Does my site need HTTPS?
        from @mholt6
        Find out if your site needs HTTPS.
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Tuesday, 13-May-2025 15:54:17 JST 翠星石 翠星石
      in reply to
      • Ron Bowes
      • Charl van der Walt 🌻🇵🇸
      @iagox86 @malwaretech @charlvdwalt SSL is very broken and insecure and is equivalent to null encryption really.

      You need TLS.

      In the age of the NSA, every last request over the internet needs to be encrypted, as it leaks a lot of information if "needs to be secure" connections are encrypted.

      You would think that correct TLS implementations would mostly mitigate the problem, but then came along massive MiTM's like cloudflare.
      In conversation about a year ago permalink
    • Embed this notice
      Marcus Hutchins :verified: (malwaretech@infosec.exchange)'s status on Tuesday, 13-May-2025 15:54:18 JST Marcus Hutchins :verified: Marcus Hutchins :verified:
      in reply to
      • Charl van der Walt 🌻🇵🇸

      @charlvdwalt the content of the website doesn’t matter because the content is whatever an attacker wants it to be if you aren’t using SSL. Your brochureware is now malware.

      In conversation about a year ago permalink
    • Embed this notice
      Ron Bowes (iagox86@infosec.exchange)'s status on Tuesday, 13-May-2025 15:54:18 JST Ron Bowes Ron Bowes
      in reply to
      • Charl van der Walt 🌻🇵🇸

      @malwaretech @charlvdwalt SSL is super important and all, but that statement is awfully FUD-y. The odds of somebody actually doing that are vanishingly small, but you make it sound like their site can be replaced by anyone any time

      In conversation about a year ago permalink
    • Embed this notice
      djsumdog (djsumdog@djsumdog.com)'s status on Tuesday, 13-May-2025 16:01:36 JST djsumdog djsumdog
      in reply to
      • Charl van der Walt 🌻🇵🇸
      I was in Europe and saw a Vodaphone banner injected on websites without TLS/SSL. At a basic level, it ensures your ISP isn't injecting bullshit into your page.
      In conversation about a year ago permalink
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Tuesday, 13-May-2025 16:08:38 JST 翠星石 翠星石
      in reply to
      • Ron Bowes
      • Charl van der Walt 🌻🇵🇸
      • 𝅙𝅙𝅙𝅙𝅙𝅙𝅙𝅙
      @sally @charlvdwalt @iagox86 @malwaretech The issues with TOFU is that it's too easy to MiTM it and keep it MiTM'd forever.

      TLS needs root certificates to work, but an alternative non-proprietary CA root could mitigate many of the issues with the current CA system.
      In conversation about a year ago permalink
    • Embed this notice
      𝅙𝅙𝅙𝅙𝅙𝅙𝅙𝅙 (sally@freesoftwareextremist.com)'s status on Tuesday, 13-May-2025 16:08:39 JST 𝅙𝅙𝅙𝅙𝅙𝅙𝅙𝅙 𝅙𝅙𝅙𝅙𝅙𝅙𝅙𝅙
      in reply to
      • 翠星石
      • Ron Bowes
      • Charl van der Walt 🌻🇵🇸
      @Suiseiseki @iagox86 @charlvdwalt @malwaretech

      TLS has been far more abused to sabotage the little guy with CA certification bullshit than to secure anything, I'd rather see it burn in GNU/hell and replaced entirely with SSH-like asynchronous encryption, or just keep TLS around and get rid of CAs altogether.
      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.