GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Harry Sintonen (harrysintonen@infosec.exchange)

  1. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Friday, 19-Jun-2026 10:14:02 JST Harry Sintonen Harry Sintonen
    in reply to
    • Rich Felker

    @dalias If you don't update you will be vulnerable to various exploits. https://en.wikipedia.org/wiki/AGESA and look for "Security fixes"

    In conversation about 2 months ago from gnusocial.jp permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: auth.wikimedia.org
      AGESA
      AMD Generic Encapsulated Software Architecture (AGESA) is a procedure library developed by Advanced Micro Devices (AMD), used to perform the Platform Initialization (PI) on mainboards using their AMD64 architecture. As part of the BIOS of such mainboards, AGESA is responsible for the initialization of the CPU cores, chipset, main memory, and the HyperTransport controller. History AGESA was open sourced in early 2011, aiming to aid in the development of coreboot, a project attempting to replace PC's proprietary BIOS. However, such releases never became the basis for the development of coreboot beyond AMD's Bulldozer microarchitecture, and were subsequently halted. AGESA became particularly relevant with the AM4 platform, which AMD designed for futureproofing and served as the socket for four different generations of CPUs based on its Zen architecture. For each of these generations, a new branch of AGESA code has been released. AGESA versioning often runs separately for each of these three releases, so numbering regressions are bound to happen when going from one generation to the next. The...
  2. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Friday, 19-Jun-2026 08:57:34 JST Harry Sintonen Harry Sintonen

    Heads up to anyone using #AMD CPUs in a setting where Transparent Secure Memory Encryption (TSME) is critical: AMD has disabled this feature for consumer AMD products as of the latest AGESA updates. The feature is now only available for "PRO" CPU variants.

    https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/

    #enshittification

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Wednesday, 03-Jun-2026 23:42:32 JST Harry Sintonen Harry Sintonen

    Apparently, AI capacity outages are hitting users big time. You can't get resources even with money. Daily tokens run out in hours, and weekly by Tuesday.

    The only remedy for this will be to hike prices by a lot.

    Or... just not use AI.

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Wednesday, 03-Jun-2026 23:42:31 JST Harry Sintonen Harry Sintonen
    in reply to

    "Github Copilot customers report up to 100-fold price hikes — AI sticker shock bites as Microsoft switches to usage-based pricing"

    https://www.tomshardware.com/tech-industry/artificial-intelligence/github-copilot-customers-suffer-from-sticker-shock-as-microsoft-switches-to-usage-based-pricing-customers-report-up-to-100-fold-price-hikes

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.mos.cms.futurecdn.net
      Github Copilot customers report up to 100-fold price hikes — AI sticker shock bites as Microsoft switches to usage-based pricing
      from https://www.tomshardware.com/author/bruno-ferreira
      The AI investment chickens have come home to roost.
  5. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Saturday, 23-May-2026 08:25:10 JST Harry Sintonen Harry Sintonen

    #Signalapp doesn't actually delete messages when they're deleted (either manually or by automation). The message deletion is written to Write-ahead Log, and the data is only truly deleted once Signal is restarted or threshold of 1000 pages is reached. For macOS Signal application, extra complication arises from the fact that the signal message database can be backed up before the database consolidation occurs. Large amount of the supposedly already deleted messages could be recovered from the device or backups.

    This concerns use cases where deleting messages actually getting removed in timely manner is of high importance and recovery of the deleted messages could lead to grave consequences.

    TL;DR: If you don't care about deleted messages being actually deleted you don't need to worry.

    Full advisory at: https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt

    #fulldisclosure #infosec #cybersecurity

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments



    1. Invalid filename.
  6. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Friday, 22-May-2026 18:53:53 JST Harry Sintonen Harry Sintonen

    All my attempts to communicate a vulnerability in #Signalapp have failed - I have not received any response to my multiple messages to them. Good people have tried to forward my concern to them (and I am thankful for your efforts and help), yet this has been to no avail.

    I am disappointed in the lack of communication from Signal. I will be disclosing the full details of the issue later today (with end-user mitigations), after the six-month anniversary of the initial report.

    In conversation about 3 months ago from infosec.exchange permalink
  7. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Monday, 11-May-2026 16:59:09 JST Harry Sintonen Harry Sintonen

    Vulnerabilities found from #curl:

    #Mythos: 1
    Me: 30

    - https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
    - https://sintonen.fi/advisories/

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: daniel.haxx.se
      Mythos finds a curl vulnerability
      from Daniel Stenberg
      yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →
    2. No result found on File_thumbnail lookup.
      Security Advisories and Vulnerabilities
      from Harry Sintonen
      Security Advisories and Vulnerabilities by Harry Sintonen
  8. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Thursday, 23-Apr-2026 15:56:19 JST Harry Sintonen Harry Sintonen
    • Signal

    I've tried to report a security vulnerability to @signalapp for months now (first attempt was 2025-11-23 to the official security-at email address). I haven't gotten any response from them, even after repeated attempts. This is highly frustrating.

    Is there a way to reach them? I don't need any kind of special treatment, just someone acknowledging that the message has been received would be okay.

    #signalapp

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


  9. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Monday, 13-Apr-2026 21:34:26 JST Harry Sintonen Harry Sintonen

    Finland, Denmark, Norway, Sweden, and Estonia are soon enabling offline debit card payments for at least seven days without network connectivity. The change covers payments for essential goods in physical trade, such as food, medicine, and fuel. Each country has made - or is in the process of making - the required changes to their related regulations to enable it.

    The motivation for this change is to enable payments even in exceptional situations such as network disruptions due to sabotage or conflict. TL;DR: You can pay for essentials even if Russia cuts the cables.

    Plans for this change were announced in May 2025: https://www.reuters.com/business/finance/nordics-estonia-plan-offline-card-payment-back-up-if-internet-cut-2025-05-07/

    #resilience #preparedness #infrastructure #payments #banking

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


  10. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Thursday, 26-Mar-2026 23:45:42 JST Harry Sintonen Harry Sintonen

    #Microsoft sent an email to everyone saying they're listening to people now and they will definitely not pushing AI to everything anymore.

    Also Microsoft enabled #github to collect all your "inputs, outputs and associated context to train and improve AI models". This new tickbox is enabled by default, even if you explicitly disabled Copilot before.

    Actions speak louder than words.

    You can disable the option at https://github.com/settings/copilot/features

    #enshittification

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: github.githubassets.com
      Build software better, together
      GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/292/469/927/816/620/original/b94d62d045955444.png
  11. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Saturday, 28-Feb-2026 02:41:14 JST Harry Sintonen Harry Sintonen

    This should be obvious for everyone by now, but if you're not from US you must assume that all your use of US AI services (#ChatGPT, #Claude, #Gemini etc) is fed directly to US intelligence services.

    "We may share your Personal Data, including information about your interaction with our Services, with government authorities ... in compliance with the law (i)" (OpenAI)

    "We may disclose personal data to governmental regulatory authorities as required by law" (Claude)

    "We will share personal information outside of Google ... to: Respond to any applicable law, regulation, legal process, or enforceable governmental request" (Gemini)

    The amount of valuable information fed to the systems voluntarily is staggering. It's not a matter of "if" it is happening, but "of course it is". It would be outright negligent if they weren’t capturing and disseminating it all.

    https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act#Without_a_court_order
    https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act#Amendments

    #privacy

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: upload.wikimedia.org
      Foreign Intelligence Surveillance Act
      The Foreign Intelligence Surveillance Act of 1978 (FISA, Pub. L. 95–511, 92 Stat. 1783, 50 U.S.C. ch. 36) is a United States federal law that establishes procedures for the surveillance and collection of foreign intelligence on domestic soil. FISA was enacted in response to revelations of widespread privacy violations by the federal government under President Richard Nixon. It requires federal law enforcement and intelligence agencies to obtain authorization for gathering "foreign intelligence information" between "foreign powers" and "agents of foreign powers" suspected of espionage or terrorism. The law established the Foreign Intelligence Surveillance Court (FISC) to oversee requests for surveillance warrants. Although FISA was initially limited to government use of electronic surveillance, subsequent amendments have broadened the law to regulate other intelligence-gathering methods, including physical searches, pen register and trap and trace (PR/TT) devices, and compelling the production of certain types of business records. FISA has been repeatedly amended since the September...
  12. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Thursday, 26-Feb-2026 22:24:00 JST Harry Sintonen Harry Sintonen

    Retroactively changing the role of a token or key is a very bad idea.

    https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

    #google #googleapikeys #infosec #cybersecurity

    In conversation about 6 months ago from infosec.exchange permalink
  13. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Saturday, 07-Feb-2026 08:09:43 JST Harry Sintonen Harry Sintonen
    in reply to

    You can do the following to remove the scheduled task that executes the vulnerable AMDAutoUpdate:

    1. Run cmd.exe as administrator

    2. schtasks /delete /TN AMDAutoUpdate /F

    This prevents the AMDAutoUpdate from executing.

    #infosec #cybersecurity #amd #ryzenmaster

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/026/191/996/522/605/original/1e8412a7c69b7083.png
  14. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Saturday, 07-Feb-2026 00:26:18 JST Harry Sintonen Harry Sintonen

    Apparently AMD's AutoUpdate downloads the updates over HTTP and executes them without any validation (presumably as SYSTEM user). AMD was notified of the vulnerability but according to them "attack requiring physical access to victim's computer/device, man in the middle or compromised user accounts" are out of scope.

    Madness.

    source: https://mrbruh.com/amd/

    #vulnerability #infosec #cybersecurity

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      The RCE that AMD won't fix!
      After reporting a RCE in AMD's auto-update software, they decided to not patch it due to it requiring a man-in-the-middle attack to perform.
  15. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Wednesday, 12-Nov-2025 18:56:36 JST Harry Sintonen Harry Sintonen

    This is a reminder to everyone that security is more than just memory safety. https://www.phoronix.com/news/sudo-rs-security-ubuntu-25.10

    #rust #vulnerability #sudo_rs

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.phoronix.net
      sudo-rs Affected By Multiple Security Vulnerabilities - Impacting Ubuntu 25.10
      from @michaellarabel
      The Ubuntu 25.10 transition to using some Rust system utilities continues proving quite rocky
  16. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Sunday, 02-Nov-2025 00:35:20 JST Harry Sintonen Harry Sintonen

    Several months ago, I found a #vulnerability from #MantisBT - Authentication bypass for some passwords due to PHP type juggling (CVE-2025-47776).

    Any account that has a password that results in a hash that matches ^0+[Ee][0-9]+$ can be logged in with a password that matches that regex as well. For example, password comito5 can be used to log in to the affected accounts and thus gain unauthorised access.

    The root cause of this bug is the incorrect use of == to match the password hash:

    if( auth_process_plain_password( $p_test_password, $t_password, $t_login_method ) == $t_password )

    The fix is to use === for the comparison.

    This vulnerability has existed in MantisBT ever since hashed password support was added (read: decades). MantisBT 2.27.2 and later include a fix to this vulnerability. https://mantisbt.org/download.php

    #CVE_2025_47776 #infosec #cybersecurity

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/474/477/612/174/308/original/ee8cbaf2c8da7b9e.png
    2. Domain not in remote thumbnail source whitelist: mantisbt.org
      Mantis Bug Tracker
      MantisBT is a popular free web-based bug tracking system. It is written in PHP works with MySQL, MS SQL, and PostgreSQL databases. MantisBT has been installed on Windows, Linux, Mac OS, OS/2, and others. It is released under the terms of the GNU General Public License (GPL).
  17. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Sunday, 02-Nov-2025 00:03:15 JST Harry Sintonen Harry Sintonen

    #Microsoft is clearly becoming desperate due to low adoption rates of #Copilot.

    Apparently, Microsoft is now pushing Copilot to all #Microsoft365 personal subscribers and calling it a "subscription price increase". Only when you decide to cancel your subscription are you presented with the option to switch to "Microsoft 365 Personal Classic" without Copilot (and nearly the old price). The classic plan is not presented as an option unless you try to cancel your subscription.

    This is a classic scammy trick: Modify the existing plan and add the feature no one wants and hide the old plan from view. Presto, now you have an insane adoption rate you can present to investors as a great success.

    I personally don't use Microsoft subscription services, so I don't know if they tried this bullshit in the EU, but if they did, they're asking for trouble. They got sued in Australia over this already: https://www.accc.gov.au/media-release/microsoft-in-court-for-allegedly-misleading-millions-of-australians-over-microsoft-365-subscriptions "Microsoft in court for allegedly misleading millions of Australians over Microsoft 365 subscriptions"

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.accc.gov.au
      Microsoft in court for allegedly misleading millions of Australians over Microsoft 365 subscriptions
      The ACCC has commenced proceedings in the Federal Court against Microsoft Australia and its US-based parent company Microsoft Corporation for allegedly misleading approximately 2.7 million Australian customers when communicating subscription options and price increases, after it integrated its AI assistant, Copilot, into Microsoft 365 plans.
  18. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Tuesday, 28-Oct-2025 03:27:42 JST Harry Sintonen Harry Sintonen
    • Python Software Foundation

    I would be glad to donate to the #Python project, but doing so requires me to divulge my name and contact information as per their 501(c)(3) charitable organisation status:

    "Contact information is required for tax reporting purposes and will be shared only with the US government."

    Considering the current status of the US government, I don't feel comfortable doing this. Are there some other ways to donate to Python project without getting the US government involved?

    - https://pyfound.blogspot.com/2025/10/NSF-funding-statement.html
    - https://psfmember.org/civicrm/contribute/transact/?reset=1&id=2

    @ThePSF

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: s3.dualstack.us-east-2.amazonaws.com
      The PSF has withdrawn a $1.5 million proposal to US government grant program
      In January 2025, the PSF submitted a proposal to the US government National Science Foundation under the Safety, Security, and Privacy of Op...

  19. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Monday, 20-Oct-2025 21:06:25 JST Harry Sintonen Harry Sintonen

    A lot of services that are supposedly running in EU are currently having significant issues due to AWS US-EAST-1 being impacted. But surely this is just some dependencies that are down and all our data is really stored in EU. Right?

    https://health.aws.amazon.com/health/status

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/405/472/792/024/109/original/23ab4443d7ed3fcf.gif
  20. Embed this notice
    Harry Sintonen (harrysintonen@infosec.exchange)'s status on Monday, 20-Oct-2025 18:33:47 JST Harry Sintonen Harry Sintonen

    IRC is working just fine. As always.

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/405/612/128/424/706/original/76fe103f662fd72c.png
  • Before

User actions

    Harry Sintonen

    Harry Sintonen

    Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          185551
          Member since
          11 Oct 2023
          Notices
          49
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.