So the Tor Browser/Firefox identification vuln that just dropped, if I'm reading it right they exploited the hashdos mitigations, which is hilarious.
Notices by Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 24-Apr-2026 01:36:53 JST
Ryan Castellucci (they/them) :nonbinary_flag:
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 24-Apr-2026 01:30:50 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@jelte It probably depends on whether you're using GnuTLS or OpenSSL?
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 24-Apr-2026 01:28:23 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@hypha 404?
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 24-Apr-2026 01:24:48 JST
Ryan Castellucci (they/them) :nonbinary_flag:
Me: lightly teasing
Partner: Mean! Mean!
Me: Mode! Mode!
Partner: You're a very median enby! -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 24-Apr-2026 01:23:54 JST
Ryan Castellucci (they/them) :nonbinary_flag:
Don't be the reason I have to buy a new piece of testing equipment.
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 23-Apr-2026 20:06:07 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@ujay68 USB-C charging source ports limit their output unless the device either negotiates USB-PD protocol or has some resistors (of negligible cost and size) to request the power passively. USB-A charging source ports don't have any such checks.
See https://hackaday.com/2023/01/04/all-about-usb-c-resistors-and-emarkers/ for more details.
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 23-Apr-2026 04:40:59 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@jernej__s what the fuck
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 23-Apr-2026 04:40:39 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@foone that is impressively passive aggressive
In conversation from infosec.exchange permalink -
Embed this notice
Taggart :ifin: (mttaggart@infosec.exchange)'s status on Wednesday, 22-Apr-2026 06:29:43 JST
Taggart :ifin:
Yo did we forget about the Framework-funding-fash thing or
In conversation from infosec.exchange permalink Repeated by ryanc -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 23-Apr-2026 04:38:17 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@dakkar I don't use it (more effort to type), but I recognize it.
In conversation from gnusocial.jp permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 23-Apr-2026 04:36:38 JST
Ryan Castellucci (they/them) :nonbinary_flag:
I replaced my laser level because the battery was dead and I couldn't get it to charge. It has a USB-C port for charging, which I was using with a C-to-C cable. Tonight, when I was about to throw it out, I saw an A-to-C cable and tried it.
Charging is occuring. They cheaped out on an SMD resistor that would have cost a fraction of a cent.
This should be a crime.
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 22-Apr-2026 17:16:29 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@hermitcl I have multiple /24s.
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 22-Apr-2026 04:33:17 JST
Ryan Castellucci (they/them) :nonbinary_flag:
Achievement Unlocked: Run out of space in the IP scheme for your home network.
In conversation from infosec.exchange permalink -
Embed this notice
Tube❄️Time (tubetime@mastodon.social)'s status on Sunday, 19-Apr-2026 04:54:06 JST
Tube❄️Time
just wiring up a fuse plug, as you do.
In conversation from mastodon.social permalink Repeated by ryanc Attachments
-
Embed this notice
Kemotep :de_gouges:🔰 (kemotep@mastodo.neoliber.al)'s status on Saturday, 18-Apr-2026 19:01:12 JST
Kemotep :de_gouges:🔰
@AwoogaGeneral I feel like my upcoming performance review has been like the Sword of Damocles.
In conversation from mastodo.neoliber.al permalink Repeated by ryanc -
Embed this notice
d.rift (d_rift@beige.party)'s status on Saturday, 11-Apr-2026 23:24:24 JST
d.rift
Well my missing yubikey isn't under the couch. 🤷♂️
In conversation from beige.party permalink Repeated by ryanc -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 09-Apr-2026 17:19:37 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@RoganDawes @AMS @chaos Yup, should work. Though for something wireless, you may want to run SSH over PPP so that it doesn't die the first time a packet gets dropped.
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 09-Apr-2026 17:16:47 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@penryu @jpmens I released a tool called ugetty that supports Login/PPP/SSH over a single serial port with protocol auto-detect.
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 09-Apr-2026 15:16:24 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@mirabilos @AMS @chaos I don't believe so, as a serial port is not a socket.
In conversation from infosec.exchange permalink -
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 09-Apr-2026 15:14:28 JST
Ryan Castellucci (they/them) :nonbinary_flag:
rsync-over-ssh-over-serial.
~/code/ugetty$ rsync -anv root@ttyACM0:/media/mmcblk0p1/boot .
receiving incremental file list
boot/
boot/System.map-6.12.67-0-rpi
boot/config-6.12.67-0-rpi
boot/initramfs-rpi
boot/modloop-rpi
boot/vmlinuz-rpi
sent 43 bytes received 200 bytes 486.00 bytes/sec
total size is 52,403,630 speedup is 215,652.80 (DRY RUN)In conversation from infosec.exchange permalink