GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Jan Schaumann (jschauma@mstdn.social)

  1. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Sunday, 13-Sep-2026 06:32:18 JST Jan Schaumann Jan Schaumann

    Dear journalists: it's not "AI escaped", it's "AI companies failed to restrict the programs". Programs that did exactly what they were instructed to do. By those companies.

    Place the blame where it belongs.

    In conversation about 4 hours ago from mstdn.social permalink
  2. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Wednesday, 09-Sep-2026 07:52:43 JST Jan Schaumann Jan Schaumann
    in reply to
    • Rich Felker

    @dalias @mirabilos Most of those (except for the RDS ones) require CONFIG_USER_NS, I think.

    In conversation about 4 days ago from gnusocial.jp permalink
  3. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Tuesday, 08-Sep-2026 22:18:29 JST Jan Schaumann Jan Schaumann

    Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".

    https://www.openwall.com/lists/oss-security/2026/09/08/1

    Various exploits/PoCs here:
    https://github.com/NebuSec/CyberMeowfia/tree/main/security-research

    While I don't know how widespread the use of RDS is, it's the "and 20 more" that kills me. Pretty much assuming shell access == root access at this point.

    In conversation about 5 days ago from mstdn.social permalink

    Attachments


  4. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Saturday, 05-Sep-2026 05:47:55 JST Jan Schaumann Jan Schaumann

    Hey kids! It's the start of the Fall semester, and I'm again teaching "Advanced Programming in the UNIX Environment".

    The syllabus and all course materials including all code examples are available here:
    https://stevens.netmeister.org/631/

    As usual, we'll be using #NetBSD as our main platform. All video lectures are public and available for free on YouTube:
    https://www.youtube.com/playlist?list=PL0qfF8MrJ-jxMfirAdxDs9zIiBg2Wug0z

    I'll be posting individual lecture videos and related links in this thread throughout the semester.

    #programming #unix #apue

    In conversation about 8 days ago from mstdn.social permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      undefined
      undefined
  5. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 03-Sep-2026 23:37:19 JST Jan Schaumann Jan Schaumann

    So that log4j thing that came in last week... that's just a nothing burger, right?

    Claiming it's an RCE in log4j because if you find an endpoint to which you can upload an object and that _then_ de-serializes the attacker controlled data feels like claiming Apache httpd has an RCE because you found a web server configured to accept POSTs to its cgi-bin directory. (If you remember what that is.)

    I mean, sure, don't de-serialize attacker controlled data, but that's not news.

    In conversation about 9 days ago from mstdn.social permalink
  6. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 20-Aug-2026 17:58:55 JST Jan Schaumann Jan Schaumann

    Incident: actively exploited CVE

    Service team: Not to worry. The EoL'd version we run is *much* older than that, so we're not affected. 🤡

    Infosec: 🤦♂️

    (This happens far too often.)

    In conversation about 24 days ago from mstdn.social permalink
  7. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Monday, 10-Aug-2026 06:21:07 JST Jan Schaumann Jan Schaumann

    ‘“The world looks different now than when we co-founded the climate pledge,” said Margaret Callahan, an Amazon spokeswoman.’

    Yeah, no kidding. IT’S ON FUCKING FIRE because of soulless sacks of shit and the corporate bullshitters like you.

    Climate pledge my ass.

    https://www.nytimes.com/2026/08/08/climate/amazon-data-center-texas-pollution.html

    In conversation about a month ago from mstdn.social permalink
  8. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Tuesday, 14-Jul-2026 09:49:26 JST Jan Schaumann Jan Schaumann

    Really looking forward to the first large-scale OpenAI / Anthropic API outage, where 85% of the industry will be flopping around trying to remember how to hello-world on their own while execs google "how to write an email".

    In conversation about 2 months ago from mstdn.social permalink
  9. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 09-Jul-2026 06:39:02 JST Jan Schaumann Jan Schaumann

    Here's your weekly batch of Linux local privilege escalation vulnerabilities:

    CVE-2026-43499 "GhostLock"
    https://nebusec.ai/research/ionstack-part-2/

    CVE-2026-46242 "Bad Epoll"
    https://github.com/J-jaeyoung/bad-epoll

    Enjoy! ✌️

    In conversation about 2 months ago from mstdn.social permalink

    Attachments



  10. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Tuesday, 07-Jul-2026 01:45:55 JST Jan Schaumann Jan Schaumann

    Oh, goodie. KVM Guest-to-Host escape

    "Januscape (CVE-2026-53359)" -- https://github.com/V4bel/Januscape

    https://www.openwall.com/lists/oss-security/2026/07/06/7

    In conversation about 2 months ago from mstdn.social permalink

    Attachments


  11. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Tuesday, 16-Jun-2026 19:52:05 JST Jan Schaumann Jan Schaumann

    I miss Web 1.0. You click a link, you get to the website, you read the content. What a concept.

    In conversation about 3 months ago from mstdn.social permalink
  12. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Wednesday, 10-Jun-2026 23:48:08 JST Jan Schaumann Jan Schaumann

    So people are totally now using AI models for regular stuff that you can do via shell scripts and cron, because why do something for free when you can burn tokens and at the same time actively forget how to use the normal tools at your disposal?

    🤦 🙏 🤦

    In conversation about 3 months ago from mstdn.social permalink
  13. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 21-May-2026 23:11:17 JST Jan Schaumann Jan Schaumann
    in reply to

    Now this is some bullshit.

    Today: Don't have an "approved" phone? Too bad for you.
    Tomorrow: Don't have a Google account? Good bye.

    Another nail in the coffin of the Open Web. Those fuckers.

    https://thecodersblog.com/google-breaks-recaptcha-for-de-googled-android-users-2026/

    https://cybernews.com/privacy/google-qr-code-recaptcha-requires-approved-phone/

    In conversation about 4 months ago from mstdn.social permalink
  14. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 21-May-2026 14:42:50 JST Jan Schaumann Jan Schaumann

    Now what the fresh fuck is this, then?

    Not today, Satan.

    In conversation about 4 months ago from mstdn.social permalink

    Attachments


    1. https://media.mstdn.social/media_attachments/files/116/610/266/172/810/693/original/d079b19672b93cdf.png
  15. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Saturday, 09-May-2026 04:31:22 JST Jan Schaumann Jan Schaumann

    #DirtyFrag status/advisories:

    AlmaLinux:
    https://almalinux.org/blog/2026-05-07-dirty-frag/

    Debian:
    https://security-tracker.debian.org/tracker/CVE-2026-43500
    https://security-tracker.debian.org/tracker/CVE-2026-43284

    Gentoo:
    https://bugs.gentoo.org/974307

    RedHat:
    https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2026-43284
    https://access.redhat.com/security/cve/cve-2026-43284
    nothing yet on CVE-2026-43500

    Rocky:
    https://kb.ciq.com/article/rocky-linux/rl-dirty-frag-mitigation

    SUSE / OpenSUSE:
    https://www.suse.com/security/cve/CVE-2026-43500.html
    https://www.suse.com/security/cve/CVE-2026-43284.html
    https://www.suse.com/c/addressing-copy-fail2-aka-dirtyfrag-in-suse-virtualization/

    Ubuntu:
    https://ubuntu.com/security/CVE-2026-43284
    https://ubuntu.com/security/CVE-2026-43500
    https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available

    AWS:
    https://aws.amazon.com/security/security-bulletins/rss/2026-027-aws/
    https://explore.alas.aws.amazon.com/CVE-2026-43284.html

    In conversation about 4 months ago from mstdn.social permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      CVE-2026-43500


    2. No result found on File_thumbnail lookup.
      2467771 – (CVE-2026-43284) CVE-2026-43284 kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel
    3. No result found on File_thumbnail lookup.
      cve-details

    4. Domain not in remote thumbnail source whitelist: www.suse.com
      CVE-2026-43500 Common Vulnerabilities and Exposures | SUSE
      Secure your Linux systems from CVE-2026-43500 with SUSE.
  16. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Friday, 08-May-2026 09:22:35 JST Jan Schaumann Jan Schaumann

    The rxrpc module is likely easier for you to block, but if you can't blocklist the ESP kernel modules, note that that exploit path requires the ability to call `unshare(CLONE_NEWUSER | CLONE_NEWNET)`.

    That is

    ```
    sysctl -w kernel.unprivileged_userns_clone=1
    ```

    prevents the ESP exploit.

    (That also prevents that other silly variant.)

    #DirtyFrag

    In conversation about 4 months ago from mstdn.social permalink
  17. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Friday, 08-May-2026 08:31:21 JST Jan Schaumann Jan Schaumann

    Oh FFS.

    #DirtyFrag
    https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md

    "Because the embargo has now been broken, no patches or CVEs exist for these vulnerabilities."

    https://www.openwall.com/lists/oss-security/2026/05/07/8

    Well, just put that CopyFail incident work on rinse and repeat, I suppose...

    In conversation about 4 months ago from mstdn.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      dirtyfrag/assets/write-up.md at master · V4bel/dirtyfrag
      Contribute to V4bel/dirtyfrag development by creating an account on GitHub.

  18. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Tuesday, 14-Apr-2026 16:05:56 JST Jan Schaumann Jan Schaumann

    *slow clap* to everybody out there doing Anthropic's Marketing Team's job for them. 🍿

    In conversation about 5 months ago from mstdn.social permalink
  19. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Sunday, 12-Apr-2026 02:39:29 JST Jan Schaumann Jan Schaumann

    "#Mythos discovers 27-year-old bug" is intentionally conflating length of existence of a bug with difficulty of finding it. There is no such correlation.

    If software projects and companies performed regular, ongoing, in-depth code audits over and over and missed it, sure, then age would be meaningful, but that is simply not what organizations do.

    But sure, it makes for great headlines.

    In conversation about 5 months ago from mstdn.social permalink
  20. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Monday, 23-Mar-2026 22:55:57 JST Jan Schaumann Jan Schaumann

    The monetary waste aside, and assuming companies using leaderboards and bonus incentives for token use haven't ever heard (!) of Goodhart's Law, the obliviousness to the environmental impact resulting from "tokenmaxxing" is just obscene.

    Encouraging and rewarding employees to do maximum environmental damage is positively evil and journalists should call this out in their coverage every single time.

    https://www.nytimes.com/2026/03/20/technology/tokenmaxxing-ai-agents.html

    In conversation about 6 months ago from mstdn.social permalink
  • Before

User actions

    Jan Schaumann

    Jan Schaumann

    Vell, I'm just zis guy, you know?

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          110518
          Member since
          31 Mar 2023
          Notices
          201
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.