GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Tinker ☀️ (tinker@infosec.exchange)

  1. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 24-Jul-2026 03:26:44 JST Tinker ☀️ Tinker ☀️
    in reply to

    THEY DID IT AGAIN!!!

    My local library built out another seed library at a second branch!!!

    The first one has been such a success that they've begun to install seed libraries at other branches. This one is smaller but is well used (see the "check out" list) and can be grown easily by placing more holders on the wall.

    I like this approach. The main branch is using an old card catalogue. This branch is using wall holders. There's no right way to do it, just what works best for your area.

    Word from the librarians are that they're mostly self sustaining. Many folks check out seeds for free, plant/grow/harvest their plants, and let some of those plants go to seed as well - returning those seeds back to the library (or checking in their seeds).

    One seed turns into hundreds of seeds. The more this is used, the more it grows.

    #solarPunk #seedLibrary #foodSecurity #Libraries

    In conversation about 19 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/970/084/778/232/371/original/8d43d3768c81e42f.jpeg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/970/084/902/537/824/original/d4f6e983f4611de6.jpeg

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/970/085/153/706/419/original/5ed4135608231bfc.jpeg
  2. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 16-Jul-2026 23:42:32 JST Tinker ☀️ Tinker ☀️

    Regarding AI slop permeating everything...

    It's incredibly important to know that right now there is a MASSIVE amount of money and effort by corporations, financial institutions, and governments to get people to use it.

    (There are motivations behind pushing that use that go well beyond just making a buck. AI is a layer of abstraction over information control, it's a method of locking in compute control, etc etc)

    But that use is still heavily subsidized - from cheap tokens and use subscriptions to local governments subsidizing power and water and taxes for their data centers.

    That can't last.

    And nor can its current heavy use.

    I have no idea how it will look moving forward. So much of AI is propped up artificially on one hand that it will fall if left to its own devices. But on the other hand there is so much money and power behind it that it can last artificially for a long time.

    Anyhow. Don't give up hope. Every act of resistance increases its cost and therefore its ability to withstand.

    In conversation about a month ago from infosec.exchange permalink
  3. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 16-Jul-2026 18:49:56 JST Tinker ☀️ Tinker ☀️

    Damn. This quote from Linus Torvalds is... well... damning.

    In response to a discussion around use of generative AI as it relates to contributions to the Linux code base, Linus (creator and lead contributor to Linux) firmly states that AI contributions are welcome.

    But then he goes on and concludes with this:

    "The kernel project has been and will continue to be about the technology.

    Sure, the social angle of working on open source is important and often a very motivating part of the project, but in the end that's a side benefit, not the _point_ of the project.

    This is *NOT* some kind of "social warrior" project, never has been, and never will be.

    In the kernel community we do open source because it results in better technology, not because of religious reasons.

    And so we make decisions primarily based on technical merit. Not fear of new tools.

    Linus"

    A lot of us are on Linux specifically because of the social and political positives. Closed source is control. Open source is democracy.

    Linus doing the typical tech-bro "i don't think of politics, I only think of tech" harkens back to any number of "science without ethics" atrocities.

    Linus is and has always been a tech-bro (or proto tech bro). He has his throne of power and is happy where he is. Other tech-bros want money and influence. They're all the same.

    But Linus is wrong.

    Tech is politics.

    And his stance and guiding influence with Linux is wrong.

    Linus just made a political statement and has shifted the politics and societal approach of Linux.

    Source: https://lore.kernel.org/linux-media/CAHk-=wi4zC+Ze8e+p3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/

    #linux #solarPunk #Linus #AI #openSource

    In conversation about a month ago from infosec.exchange permalink

    Attachments



    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/928/372/545/608/291/original/5fd4e997813e4bb2.jpeg
    2. No result found on File_thumbnail lookup.
      Re: Linking Patchwork with Sashiko? - Linus Torvalds
  4. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 16-Jul-2026 15:07:17 JST Tinker ☀️ Tinker ☀️

    RE: https://floss.social/@doctormo/116927739358578223

    So serious question...

    What is #OpenBSD's take on AI? (in general and as a whole, i imagine individual contributors have their own stances of course).

    I'm running out of places to run to (and I'm already standing and fighting as much as I am able).

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Martin Owens :inkscape: (@doctormo@floss.social)
      from Martin Owens :inkscape:
      "Hello my name is Tovalds and I'd like to stick this fork into the Bitkeeper electrical socket again" https://www.theregister.com/ai-and-ml/2026/07/15/linus-torvalds-tells-ai-haters-to-fork-off/5271894 What is it with privileged white men who feel their position in society as a coddled person makes the concerns of every other living being a nuance to be fought until we all just accept the bright end-of-history where there is nothing wrong because there is no politics. There are problems. Your hand waving isn't actually magic and doesn't make them disappear.
  5. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 13-Jul-2026 09:17:09 JST Tinker ☀️ Tinker ☀️

    Fun side effect of terrible search engines that try to "correct" what you search for...

    I found the movie "Master of the Universe" available for streaming.

    Not... "Masters of the Universe"

    One has an 'S' in it, the other does not. Both made in 2026. One is the movie released in theaters, the other is Asylum slop made to typo squat.

    Searching for Master of the Universe (even with quotes) produces "Masters of the Universe". I wanted to search for the slop one to see the trailer and see how bad it was or read reviews on it.

    But nope. Took me writing out the Asylum director's name to finally force it.

    So yay! Search engines deciding for you what they thought you meant, despite you being specific, obfuscates and protects typo squats. So much for "research and validate it before clicking".

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 11-Jul-2026 17:24:51 JST Tinker ☀️ Tinker ☀️

    #notAnAd #iJustThoughtItWasANiceSticker

    https://pencilsandpurpose.square.site/product/only-data-center-we-should-fund/QY7WBTP2TW4EXFJHQKRXIMFF

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/900/204/512/840/240/original/9fd2e57e2ec2ea3b.jpeg
  7. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 01-Jul-2026 00:03:48 JST Tinker ☀️ Tinker ☀️
    • Pixel Occult

    New Cyberpunk Tarot just dropped!!!

    I have @PixelOccult's Neon Moon Tarot. This one - the Teknebrae Tarot - looks awesome!

    https://www.kickstarter.com/projects/pixeloccult/teknebrae-tarot-v20

    #art #tarot

    In conversation about a month ago from infosec.exchange permalink
  8. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 23:51:45 JST Tinker ☀️ Tinker ☀️
    in reply to
    • John

    @silent_john - And the answer is neither. Out of the frying pan and into the fire. It becomes a false dichotomy.

    Another way I've asked myself that similar questions is "do I trust a general business model of the ISP whose main money maker is providing general internet access and ALSO spies on me or do I trust a small niche corporation that purports to have a business model that is there to protect vulnerable individuals but allows for business and operational goals to attack that vulnerable individual."?

    Simply put, I don't trust the ISP. I really don't trust the VPN. So I find other solutions outside of the ISP to address specific security and privacy needs.

    In conversation about a month ago from infosec.exchange permalink
  9. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 23:46:49 JST Tinker ☀️ Tinker ☀️

    RE: https://infosec.exchange/@tinker/116838874756853338

    That was a very good conversation.

    If you're interested in the topic of privacy and security oriented VPNs, what their strengths are, what their weaknesses are, and what their alternatives are, you might give this thread and the many responses a read.

    I disagree with several elements of some of the responses, but even those responses are often given with backed up claims, nuance, and in a respectful manner.

    I really love the fediverse, lol!

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Tinker ☀️ (@tinker@infosec.exchange)
      from Tinker ☀️
      All "privacy oriented" commercial VPNs are honeypots. You can't change my mind on that. Mullvad VPN has heavy marketing in Washington DC (their ads are plastered all across the metro stops frequented by government workers and foreign diplomats) for example. The whole "you need to hide something? here we'll hide it for you! Everyone that wants to hide something should put is all in this one consolidated place!" But they totally won't look at it. They swear. No logs, bro. I promise. I can look, but I won't. I could log, but I won't. So while Mullvad the company is showing their ass, asking what other VPN to hop to begs the question: Why are you using a commercial VPN? If it's to change your IP address to bypass porn restrictions in fundamentalist theocratic states, then cool. That's a solid use case. If it's for a nebulous reason like "for privacy" or "for security". Then you might want to see if that tool actually meets your specific threat modeling. #VPN #mullvad #mullvadVPN
  10. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 21:35:08 JST Tinker ☀️ Tinker ☀️
    in reply to

    Regarding the follow up question of "what should I use if no commercial VPN solves my issue"...

    ...that entirely depends on what you need a VPN for.

    For many folks, modern HTTPS (TLS) covers what many VPNs sought to address - namely, limiting who can see your secure traffic.

    For folks using public or non-personal wifi, the local router implementing wireless isolation prevents folks on your subnet from sniffing your traffic (https/tls helps here too).

    For folks wanting to hide their browsing habits - shifting the inspection of traffic from their ISP to some for-purpose honeypot may not be the best solution.

    Also, you'll always get the "spin up your own VPN" answer in these sort of threads, but as has already been pointed out this isnt something most folks can do (it is straightforward to do!!!! Iffff... you have the knowledge and experience.... which most folks don't have. They are focusing on other things in life, etc).

    Two big things to consider here:

    1) What are you actually trying to accomplish with a VPN? Specifics. Not just "increased privacy" or "increased security". What. Exactly. Are you trying to accomplish. And then sort out if a VPN actually does that thing for you. (Many are just snake oil promising to meet your valid desire for general health but dont actually do the thing they promise).

    2) There might not be a viable solution to your need. Sometimes the answer is "this proposed solution is a scam, and there is no alternative - no actual solution. You have a real need and there is no real thing to meet that need. Sorry."

    #vpn #mullvad #mullvadVPN

    In conversation about a month ago from infosec.exchange permalink
  11. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 21:35:08 JST Tinker ☀️ Tinker ☀️

    All "privacy oriented" commercial VPNs are honeypots.

    You can't change my mind on that.

    Mullvad VPN has heavy marketing in Washington DC (their ads are plastered all across the metro stops frequented by government workers and foreign diplomats) for example.

    The whole "you need to hide something? here we'll hide it for you! Everyone that wants to hide something should put is all in this one consolidated place!"

    But they totally won't look at it.

    They swear.

    No logs, bro. I promise. I can look, but I won't. I could log, but I won't.

    So while Mullvad the company is showing their ass, asking what other VPN to hop to begs the question: Why are you using a commercial VPN?

    If it's to change your IP address to bypass porn restrictions in fundamentalist theocratic states, then cool. That's a solid use case.

    If it's for a nebulous reason like "for privacy" or "for security". Then you might want to see if that tool actually meets your specific threat modeling.

    #VPN #mullvad #mullvadVPN

    In conversation about a month ago from infosec.exchange permalink
  12. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 14-Jun-2026 21:52:13 JST Tinker ☀️ Tinker ☀️

    RE: https://masto.hackers.town/@phaedr0s/116745679345455076

    I don't talk fashion here often, but it's one of those interests of mine that is both latent and very rarely explored.

    (You know those interests of your's that you have both neither the time nor the money to pour into them? So you enjoy the topic when it's brought up but don't have deep involvement. Anyhoo!)

    The quoted post is about popculture depictions of the aesthetics of hacking in the 90's as seen through a very 90's hacking movie.

    "Hackers" is not an accurate depiction of hacking.

    "Hackers" is an accurate depiction of how hacking felt.

    It is an "artistic depiction" of hacking.

    I spent my highschool years hacking along the border of Texas and Mexico. My clothes were very typical of a highschooler then. T-shirt with edgy saying, under an unbuttoned short sleeve button-up "overshirt" on top of relaxed-fit to loose-fit jeans and tennis shoes.

    I thought of the clothes in the movie "Hackers" as avant-garde and the type of thing you would only see in NYC proper (I had only experienced New York through movies) or the type of thing you would (separately in my mind) see in movies.

    It was very punk and very hacker to me.

    This was also the time that The Matrix came out. Another - albeit from the complete opposite end - depiction of Hacker culture and aesthetics.

    Neither looked good in real life 😂 but they lookef amazing in our minds.

    1/3

    #fashion #hacking #solarpunk

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      phaedr0s (@phaedr0s@masto.hackers.town)
      from phaedr0s
      Every single outfit in the movie Hackers https://taramariagonzalez.substack.com/p/every-single-outfit-in-hackers
  13. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 12-Jun-2026 03:15:19 JST Tinker ☀️ Tinker ☀️

    I just had a simple chalupa combo (number 1) at taco bell (Two chalupas. One soft taco. One medium pepsi zero).

    Cost me $14.68 USD.

    This was drive through. Not doordash.

    I am officially done with fast food.

    Taco Bell.

    In conversation about 2 months ago from infosec.exchange permalink
  14. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 10-Jun-2026 00:06:46 JST Tinker ☀️ Tinker ☀️

    Article on Repair Cafes and Repair Clinics.

    If you haven't gone to a local one, I recommend it.

    If you don't have a local one, I recommend spinning one up.

    #solarPunk #repairCafe #repairClinic #rightToRepair

    https://apnews.com/article/repair-cafes-economy-anticonsumerism-affordability-buy-nothing-d3acac3ec2aae5e85294b34f0f4764b8

    In conversation about 2 months ago from infosec.exchange permalink
  15. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 04-Jun-2026 21:16:45 JST Tinker ☀️ Tinker ☀️

    Folks use AI (LLMs) to send emails and even full on reports.

    And, the same folks use AI (LLMs) to summarize emails and even full on reports.

    They write a concise prompt with attached data to expand into an email or report only to have it compressed into a concise summary with attached data.

    Just send the concise prompt with attached data. Send it as a bullet point list. Its easier to write and easier to send and easier to read and cheaper and so on.

    They use LLMs to write reports because they dont want to spend the time and effort to write, and they use LLMs to read reports because they dont want to spend the time and effort to read.

    So dont do either.

    Just send the short message (prompt) directly and remove the fluff expander / fluff condenser middle man entirely.

    In conversation about 2 months ago from infosec.exchange permalink
  16. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 25-May-2026 17:18:59 JST Tinker ☀️ Tinker ☀️

    I'm going to whisper this. So I'll choose my words carefully. I'll use general terms but am referring to specific multiple things. Please read between the lines.

    Those of you that are doing things are having a good effect.

    - The media is not covering you (this is a good sign. it means they dont want to bring attention to your actions).
    - They are discussing you in board rooms and in decision making meetings.
    - They are saying things like "we have to pause that project at that location because its currently drawing too much attention" and "we have to reframe this announcement to downplay that thing" and "we need to try these concessions to lower the heat a bit".

    They are hoping you "get tired and bored and move to a new thing" so they can get back to work without interference.

    Keep doing what you're doing. Join folks that are doing things if you aren't doing anything yet. Do what you can, as you can, when you can.

    It is working.

    #solarpunk

    In conversation about 3 months ago from infosec.exchange permalink
  17. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 01-May-2026 00:36:01 JST Tinker ☀️ Tinker ☀️

    We went from precise web search with boolean operators to "natural language models" of AI search.

    You can tell nuerodivergent, Autistic, ADHD, AuDHD, etc folks created the early internet...

    ...and you can tell that neurotypical folks are now leading the current overlays of the internet.

    We used to have very precise search mechanisms. Specific words found in web pages with boolean operators (AND, OR, NOT, etc) to filter out the web pages that contained specific words and did not contain other words.

    Now, we search for web sites (or don't even search for web sites, yay abstraction layers that separate us from actual raw information) using "natural language" to try and coax out info.

    Have you ever been frustrated when you use very precise and direct language to communicate a specific idea with someone who then takes those specific words and adds obscure meaning and connotations and personal fears and bias to what you said... thus completely misunderstanding you... only to then try and clarify what you said with more precise language only to have that further degrade the conversation?!

    Yeah. That's the internet with AI "search" now.

    They took something that worked precisely and directly and muddied it.

    We've introduced the "double-empathy problem" to web search.

    I'm noticing that everyone in my circles, family, and especially work that are nuerotypical LOVE LOVE LOVE the new AI search mechanisms. They'll tell me exactly what the answer they received was - regardless of whether it's right or has multiple possible and conflicting answers. They just repeat what the AI said like it was the Gospel Truth.

    And they love talking to it like it was a "real person."

    It certainly takes my search parameters and adds its own interpretation to which I have to clarify and correct which is then misinterpreted further...

    I haven't tried vibe coding, but I can only imagine the horror.

    Can you imagine vibe pentesting with Claude / Mythos?!?!?!

    You know how neurodivergent folks gravitated towards IT because it was precise?

    Yeah, that's gone now.

    #AI #LLM #Claude #Mythos #infosec #Autism #ADHD

    In conversation about 3 months ago from infosec.exchange permalink
  18. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 24-Apr-2026 05:49:35 JST Tinker ☀️ Tinker ☀️

    Ummm... Is SANS training ICE?

    https://sam.gov/workspace/contract/opp/99f8bdc298c34f06bcac9bd7e39b1bca/view

    Edit to add: SANS is training ICE how to pull information off of harddrives, etc.

    FOR498: Digital Acquisition and Rapid Triage

    "Course Overview:
    A digital forensic acquisition training course, FOR498 provides the skills to identify the many and varied data storage mediums in use today, and how to collect and preserve this data in a forensically sound manner despite how and where it may be stored. This forensics data collection course covers digital acquisition from computers, portable devices, networks, and the cloud, and teaches rapid triage—the art and science of identifying and starting to extract actionable intelligence from a hard drive in 90 minutes or less."

    This training will directly hurt people.

    #sans #ice #infosec

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/455/387/549/431/966/original/d50d6e8cf529b072.jpeg
  19. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 24-Apr-2026 04:07:01 JST Tinker ☀️ Tinker ☀️

    RE: https://infosec.exchange/@tinker/116455392351826512

    Lol when "ethical hacking" is equated to corporate infosec.

    SANS is teaching Unethical Hacking.

    ICE will hurt more people as a *direct* result of this training.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      Tinker ☀️ (@tinker@infosec.exchange)
      from Tinker ☀️
      Attached: 1 image Ummm... Is SANS training ICE? https://sam.gov/workspace/contract/opp/99f8bdc298c34f06bcac9bd7e39b1bca/view Edit to add: SANS is training ICE how to pull information off of harddrives, etc. FOR498: Digital Acquisition and Rapid Triage "Course Overview: A digital forensic acquisition training course, FOR498 provides the skills to identify the many and varied data storage mediums in use today, and how to collect and preserve this data in a forensically sound manner despite how and where it may be stored. This forensics data collection course covers digital acquisition from computers, portable devices, networks, and the cloud, and teaches rapid triage—the art and science of identifying and starting to extract actionable intelligence from a hard drive in 90 minutes or less." This training will directly hurt people. #sans #ice #infosec
  20. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 12-Apr-2026 08:11:07 JST Tinker ☀️ Tinker ☀️
    in reply to
    • Dr. bicycle whisperateror

    @adamsteer - This one? https://toolsfortherevolution.com/the-fallacy-of-technological-inevitability/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: toolsfortherevolution.com
      The fallacy of technological inevitability
      from adam
      When discussing technology scientists and dreamers of science are often quoted to make a point. I want to make a MarićSteinian one here ( an idea attributed to Albert Einstein, although it could ha…
  • Before

User actions

    Tinker ☀️

    Tinker ☀️

    Tinkerer | Solarpunk | Hacker
☸️ Buddhist ☸️
Profile Pic: @PixelOccult

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          15377
          Member since
          31 Oct 2022
          Notices
          229
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.