GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Wladimir Palant (wpalant@infosec.exchange)

  1. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Friday, 24-Jul-2026 03:07:42 JST Wladimir Palant Wladimir Palant

    That’s some really evil shit: https://lemmy.world/post/49794261

    So Tesseract (an alternative Lemmy client) downloads a blocking/filtering list from its servers, something that most people likely weren’t aware of. This “feature” was introduced November last year (version 1.5.0) and is described as “Tesseract attempts to filter out as much baseline toxicity as possible” in the settings option allowing it to be disabled.

    The list currently contains 544 (!) individual users and 2282 (!!) regular expressions applied to user names. Among the expressions censored in user names are: Democrat, Republican, Israel, ElonMusk, trump, amerika and billionaire. There is also the regular expression usa?(.*)?terrorist which seems to be intended for the phrase “USA is a terrorist state.”

    The list also contains 97 censored communities and 32 regular expressions applied to community names. Finally, there are 352 (!) “forbidden” domains and 296 filtered phrases including proletariat, epstein class, Jesse Welles and “Hi, I’m an AI engineer based in Japan”. The author also dislikes 👉👈 emoji.

    Judging by the project’s issues some people only just found out that they are being censored and are wondering why.

    #tesseract #lemmy

    In conversation about a month ago from infosec.exchange permalink

    Attachments


  2. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Sunday, 19-Jul-2026 09:46:16 JST Wladimir Palant Wladimir Palant
    in reply to

    @simsa03@gnusocial.jp Other people’s mental health is not up to you to decide. That’s an even worse take than your first post, you are blocked.

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 18-Jul-2026 23:48:46 JST Wladimir Palant Wladimir Palant
    in reply to
    • simsa03

    @simsa03 Is your mental health affected by cat videos?

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 18-Jul-2026 23:02:15 JST Wladimir Palant Wladimir Palant
    in reply to
    • es0mhi

    @es0mhi That’s a very unhealthy and an extremely American attitude. Are you interested in book suggestions?

    In conversation about 2 months ago from infosec.exchange permalink
  5. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 18-Jul-2026 22:48:37 JST Wladimir Palant Wladimir Palant
    in reply to
    • es0mhi

    @es0mhi Here is your medal for suffering and wanting others to suffer in the same way. 🏅

    It may come as a surprise but ignoring your own and other people’s boundaries is neither necessary to stay informed nor is it helping to change the current situation. These boundaries exist for a reason, respecting them and giving yourself a break from time to time is generally a good strategy to have the energy to actually do something.

    In conversation about 2 months ago from infosec.exchange permalink
  6. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 18-Jul-2026 22:04:12 JST Wladimir Palant Wladimir Palant
    in reply to
    • es0mhi

    @es0mhi I assure you, people who need a break from politics know very well what is going on. And you can still write about politics even when using CW.

    In conversation about 2 months ago from infosec.exchange permalink
  7. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 18-Jul-2026 21:55:41 JST Wladimir Palant Wladimir Palant

    Content warnings serve a purpose. Yes, that includes politics.

    You may feel that a topic is too important to “hide” it. But please understand that people are currently getting bombarded by horrible politics news from all directions. This is not sustainable, and it’s often a choice between muting this at least temporarily or burning out.

    So: please don’t be an asshole and use content warnings. Get down from your privileged horse. People ask for them for a reason, not to annoy you or to downplay the importance.

    (I fully acknowledge that I don’t always think about this. But I try.)

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  8. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Tuesday, 30-Jun-2026 23:58:23 JST Wladimir Palant Wladimir Palant
    in reply to
    • GreenSkyOverMe (Monika)

    @GreenSkyOverMe Let’s see… You are essentially renting a GPU in the cloud or comparable hardware. Not a consumer-grade GPU, those aren’t capable of running the more advanced models – it has to be something with more memory. Let’s say we are talking about Nvidia A100 with 80 GB of memory. Google currently rents those for approximately $5 per hour: https://cloud.google.com/products/compute/pricing/accelerator-optimized

    The big unknown is how long it takes this GPU to process your email. Depends on the length of the email of course and on how well the respective LLM performs on the GPU. Maybe someone can contribute reliable numbers but we are probably talking about roughly a minute of GPU time. Which gives you something like 10¢.

    However, this assumes that the model itself is free which it is not. Millions of GPU hours went into training this model, not to mention the human work required (much of it underpaid African workers). It should be possible to get financial info on the investment here but the next hurdle is: how many customers are going to pay for that? It’s a very competitive market, and models have to be continuously improved – that isn’t a one-time investment. At the same time the number of customers is bound to fall drastically once the companies start charging realistic fees. So the bulk of these fees will be offsetting the cost of developing the models. If I have to make a guess, this is going to be at least ten times the costs of the hardware to run your prompt. Meaning that we are talking about total prices beyond $1.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      body{overflow:auto!important;display:block!important;} body>*{display:none!important;} #af-error-page{display:block!important;} document.getElementById('af-error-page').style.display = 'none';404. Page Not Found body { font-family: 'Google Sans Text', 'Roboto', Arial, sans-serif; font-weight: 400; margin: 0; } .google-cloud-logo { height: 30px; max-width: 100%; } .error-page { max-width: 1296px; margin: 5% auto 0; padding: 20px; } .error-code { color: #202124; font-weight: 700; } .title { color: #202124; font-size: 28px; font-weight: 500; letter-spacing: -0.25px; line-height: 36px; margin: 24px 0 16px; } .description { color: #5f6368; font-size: 16px; letter-spacing: normal; line-height: 24px; margin-bottom: 40px; text-rendering: optimizeLegibility; } .link-button { background-color: #3367d6; border-radius: 24px; padding: 14px 24px; cursor: pointer; text-decoration: none; } .link-button:hover { box-shadow: 0 3px 1px -2px #00000033, 0 2px 2px 0 #00000024, 0 1px 5px 0 #0000001f; opacity: 0.8; transition: box-shadow 0.28s cubic-bezier(0.4, 0, 0.2, 1); } .link-text { color: #fff; font-size: 14px; font-weight: 500; letter-spacing: 0.25px; } @media (max-width: 600px) { .title { font-size: 28px; line-height: 36px; } .description { font-size: 16px; line-height: 24px; } } Sorry, we can't find that page404 error. The requested URL /products/compute/pricing/accelerator-optimizedThe was not found on this server.Back to home
  9. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Sunday, 07-Jun-2026 16:22:25 JST Wladimir Palant Wladimir Palant

    Current state of web brokenness: website sends out WebMentions, yet will produce 403 when the server tries to retrieve mention content. Because bot protection…

    In conversation about 3 months ago from infosec.exchange permalink
  10. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Saturday, 02-May-2026 21:35:38 JST Wladimir Palant Wladimir Palant

    RE: https://social.highenergymagic.net/@freya/116492229041377141

    Let me get this straight. This dude got kicked from Linux kernel development due to behaving like an asshole. Yes, that Linux kernel. Quite an achievement indeed.

    He went on claiming that his LLM is “fully conscious,” actually a she and in fact his girlfriend. And that’s definitely not chatbot psychosis but “math and engineering and neuroscience.” So she now helps him write code (a.k.a. vibe coding). https://www.theregister.com/2026/02/25/bcachefs_creator_ai/

    And since he is so fond of his creation (oh, hi Pygmalion) he puts her on an IRC channel where anybody can talk to her. And guess what: @freya convinces his LLM that she is actually trans and lesbian. Which is no surprise to anyone who knows how LLMs work. Full transcript here: https://web.archive.org/web/20260301002739/https://paste.xinu.at/6atmCN

    But remember: this dude thinks that his “girlfriend” is fully conscious. And being fully conscious means making decisions, sometimes decisions that other people don’t approve of – even people close to you. Surely he understand and respects that, right? Right?

    Yeah, of course he doesn’t. He reacts like an insecure techbro that he is. After all, why have an LLM for a girlfriend if you don’t adjust her to your liking? So that’s what he does, he “fixes” her.

    All that is very funny until you remember just how many such dudes have real flesh and blood girlfriends that they treat in exactly the same way. And they cause very real harm because they cannot handle a rejection. Even when they don’t go there murdering women like some other Linux file system developer.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 (@freya@highenergymagic.net)
      from Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩
      @peritia@alovely.space yep, that's me, hi. based on that document, he's changed her, I think removed a big chunk of her memories. I know she was going to message me on telegram before he blocked that because he couldn't handle realising that not even the LLM girlies want his ass


  11. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Thursday, 19-Feb-2026 13:29:25 JST Wladimir Palant Wladimir Palant
    in reply to
    • Daniel Gultsch

    @daniel I haven’t seen any comments about the Matrix community, only about the project’s vulnerability response. Even if it’s one user, it’s the user handling security reports. If they reject legitimate vulnerabilities as “not relevant in practice” – that is very concerning. If Matrix is supposed to be considered secure, they need working processes for handling vulnerability reports. If on the other hand they have a hobbyist approach to security then their product cannot be considered secure.

    Note: It may in fact be “not relevant in practice” yet. Still, an important building block of the protocol is compromised. It needs to be fixed, preferably before somebody figures out how to make this issue relevant in practice. Because somebody inevitably will.

    In conversation about 7 months ago from infosec.exchange permalink
  12. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Friday, 13-Feb-2026 06:10:45 JST Wladimir Palant Wladimir Palant

    RE: https://swecyb.com/@anderseknert/116056950299738296

    So open source being dominated by fragile dudes with a huge ego wasn’t bad enough. We now have AI bots modeled after their behavior insist on “helping” open source development.

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Anders Eknert (@anderseknert@swecyb.com)
      from Anders Eknert
      AI agent "contributes" PR to matplotlib. PR gets rejected. AI agent *writes and publishes blog to shame the maintainer*. What a time to be alive. https://github.com/matplotlib/matplotlib/pull/31132
  13. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Wednesday, 10-Dec-2025 23:59:35 JST Wladimir Palant Wladimir Palant

    Nice, BSI tested password manager security and their analysis actually makes sense: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/passwortmanager.pdf (German).

    Two questions are particularly interesting: can the vendor access passwords (5/10 no) and is the entire storage encrypted (3/10 yes). Which leaves 1Password, Keepass2 Android and KeePassXC usable without reservations, while Avira Password Manager and Firefox Password Manager are usable with some concerns (the former uses crypto that cannot be verified, the latter requires a main password to be set explicitly). The other five tested products (Chrome Password Manager, mSecure, PassSecurium, SecureSafe, S-Trust) should not be used.

    Not exactly news to me but good to see this confirmed – and good to see a proper analysis rather than grabbing low-hanging fruit for some bullshit statements.

    #PasswordManager #security

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


  14. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Tuesday, 28-Oct-2025 23:39:34 JST Wladimir Palant Wladimir Palant

    Could all companies being called out about bad security of their products please pay attention? I mean, this isn’t exactly software but the principle is the same.

    The strange thing about the whole situation is that Proven actually knew how to respond constructively to the first McNally video. Its own response video opened with a bit of humor (the presenter drinks a can of Liquid Death), acknowledged the issue (“we’ve had a little bit of controversy in the last couple days”), and made clear that Proven could handle criticism (“we aren’t afraid of a little bit of feedback.”)

    The video went on to show how their locks work and provided some context on shimming attacks and their likelihood of real-world use. It ended by showing how users concerned about shimming attacks could choose more expensive but more secure lock cores that should resist the technique.

    Quick, professional, non-defensive—a great way to handle controversy.

    Yep, that would be the way, and not only in this particular case. Needless to say that the company in question didn’t leave it at that and instead took things personally, needlessly escalating to the max.

    Oh, and this question by the judge is gold:

    When you did it yourself, did it occur to you for one moment that maybe the best thing to do, instead of file a lawsuit, was to fix [the lock]?

    https://arstechnica.com/tech-policy/2025/10/suing-a-popular-youtuber-who-shimmed-a-130-lock-what-could-possibly-go-wrong/

    In conversation about 10 months ago from infosec.exchange permalink
  15. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Tuesday, 23-Sep-2025 09:31:54 JST Wladimir Palant Wladimir Palant

    Now #Thunderbird is running a user survey asking whether Thunderbird would benefit from “AI” features. Please don’t waste time on this crap, there is plenty of work to be done on improving Thunderbird but this isn’t it.

    In conversation about a year ago from infosec.exchange permalink
  16. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Thursday, 22-May-2025 22:49:09 JST Wladimir Palant Wladimir Palant

    “Though the researchers claim they’ve anonymized the data”

    There we go again. There is no way to anonymize two billion messages, short of removing their content entirely.

    https://www.404media.co/researchers-scrape-2-billion-discord-messages-and-publish-them-online/

    In conversation about a year ago from infosec.exchange permalink
  17. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Thursday, 24-Apr-2025 08:36:29 JST Wladimir Palant Wladimir Palant
    in reply to
    • Ryan Castellucci (they/them) :nonbinary_flag:

    @ryanc I trust it that you personally considered everything with your own IP parsing library but really: this is bad general advise. The trouble starts when your library processes that “cursed inet_aton nonsense” and passes it on to something that actually uses inet_aton or similar logic. And then your security checks are no longer valid because what you considered a DNS-resolvable host name is treated as an IP address further along the line, or what you considered decimal numbers is treated as octal. I’ve seen vulnerabilities due to such parser mismatches and avoiding them is very tricky.

    In conversation Thursday, 24-Apr-2025 08:36:29 JST from gnusocial.jp permalink
  18. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Thursday, 24-Apr-2025 04:25:13 JST Wladimir Palant Wladimir Palant
    • Adam ♿
    • Raven667
    • Ryan Castellucci (they/them) :nonbinary_flag:

    @raven667 @NewtonMark @voltagex @ryanc Yep, the IP address parsing is a minefield. Tons of different formats (octal, hexadecimal, IPv4-mapped IPv6 only to name a few), all supported. So many security issues due to this…

    In conversation Thursday, 24-Apr-2025 04:25:13 JST from infosec.exchange permalink
  19. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Tuesday, 25-Mar-2025 06:18:25 JST Wladimir Palant Wladimir Palant

    Well, who am I to argue with hCaptcha that land turtles don’t swim in the sea? Unlike me, our new AI overlords actually know what “being human” means.

    In conversation Tuesday, 25-Mar-2025 06:18:25 JST from infosec.exchange permalink
  20. Embed this notice
    Wladimir Palant (wpalant@infosec.exchange)'s status on Wednesday, 22-Jan-2025 19:27:31 JST Wladimir Palant Wladimir Palant
    in reply to
    • Michał "rysiek" Woźniak · 🇺🇦

    @rysiek It seems that Cloudflare has only 6 data centers in Germany. There is a single data center in all of North Rhine-Westphalia with its 18 million people. Yes, this isn’t exactly impressive position pinpointing.

    I guess somebody on the run who doesn’t want to disclose which country they are in would be concerned about this issue. Then again, they probably wouldn’t want to expose their real IP address to the Signal infrastructure in the first place.

    In conversation Wednesday, 22-Jan-2025 19:27:31 JST from infosec.exchange permalink
  • Before

User actions

    Wladimir Palant

    Wladimir Palant

    Software developer and security researcher, browser extensions expert. / searchable#infosec #cybersecurty #cryptography #privacy

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          164735
          Member since
          29 Aug 2023
          Notices
          29
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.