GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by hanno (hanno@mastodon.social)

  1. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 04-Jul-2026 07:13:15 JST hanno hanno
    in reply to
    • David Chisnall (*Now with 50% more sarcasm!*)

    @david_chisnall I mean... they made a staggeringly bad call on EternalBlue, which led to WannaCry, so the third option seems plausible. However, I think reviewing code and missing a bug in an obscure feature and missing that it's enabled by default is also not implausible.

    In conversation about 3 months ago from mastodon.social permalink
  2. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 19-May-2026 16:58:10 JST hanno hanno

    Hot take: DKIM signatures with ed25519 are largely useless🔥🔑

    I know what you're thinking. RSA is bad. You read that blogpost with the "f" word. (It's not good.) This isn't about ed25519 vs. RSA, but about how DKIM works

    Here's the problem: if you introduce a new crypto algorithm into a protocol, you need to know if the other side" supports it. But in DKIM, you don't. You're sending e-mails to arbitrary receivers. DKIM has no mechanism to tell you if that receiver supports any algorithm.
    🧵

    In conversation about 5 months ago from mastodon.social permalink
  3. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 14-May-2026 21:07:07 JST hanno hanno
    in reply to
    • Rich Felker

    @dalias I think in both vulnerability cases it was in ESP (esp{4,6} modules for IPv4/v6). But AH is also "something from IPSEC", so I disabled that as well. I'm not super familiar with IPSEC beyond "it's something I do not use and do not need"...

    In conversation about 5 months ago from mastodon.social permalink
  4. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 14-May-2026 04:58:52 JST hanno hanno

    Hey, we have another linux kernel local root exploit in IPSEC. If you build your own kernels: you probably don't need ipsec, disable INET{6,}_{ESP,AH}.

    In conversation about 5 months ago from mastodon.social permalink
  5. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:49:00 JST hanno hanno

    AI, a few thoughts, observations about AI & security vulns.
    My standard line about AI is "there's a lot I'm uncertain about". But let's be clear, there's a lot I don't like & I'm probably biased towards the "here's how spectacularly AI failed once again" news (of which there are plenty) or at least the "it's not as impressive as it may look".
    Yet, I don't want to close my eyes if I see things that clearly don't fit my biases. And I know a thing or two about security vulnerabilities.🧵

    In conversation about 7 months ago from mastodon.social permalink
  6. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:59 JST hanno hanno
    in reply to

    Something else happened, and that was *very* recently. Those reports grew in numbers.
    if I see 1-2 valid reports in a major open source lib from an AI tool, I'm not impressed. If I had enough funding, I could find valid vulns in a variety of ways.
    When the Mozilla/Antropic thing came out, that was what I was thinking. "Yeah, these are real bugs, but you know, if I had infinite funding like Antropic, and a team of top security people, you know how many bugs I could find in Firefox?"

    In conversation about 7 months ago from mastodon.social permalink
  7. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:59 JST hanno hanno
    in reply to
    • daniel:// stenberg://

    The most visible thing how AI impacted security vulnerabilities early on were slop reports. Famously, @bagder shared plenty of experiences with AI written garbage reports.
    But there's another more recent development. Real, and valuable security reports show up. I heard those starting early this year. Those were single instances, but they were clearly showing that there are companies out there developing tools that spit out real vulnerabilities, with proof of concepts, and sometimes even patches.

    In conversation about 7 months ago from mastodon.social permalink
  8. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:58 JST hanno hanno
    in reply to

    FWIW: I don't have a big conclusion here, I'm just sharing random thoughts and observations. /end thread

    In conversation about 7 months ago from mastodon.social permalink
  9. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:58 JST hanno hanno
    in reply to

    But that wasn't an isolated development either. It's clearly showing up everywhere. I'm running out of reasons not to think that AI tools got really good at finding security vulnerabilities.

    Obvious caveat: None of that changes that there are plenty of good reasons to be very worried about the whole AI thing.

    In conversation about 7 months ago from mastodon.social permalink
  10. Embed this notice
    hanno (hanno@mastodon.social)'s status on Wednesday, 21-Jan-2026 22:22:57 JST hanno hanno

    Ihr sorgt Euch über den hohen Krankenstand? Wir haben da vor ein paar Jahren ein paar Dinge gelernt, wie man Infektionskrankheiten vermeidet. Impfungen, Luftfilter, Homeoffice, Masken, ...
    Es ist schon bizarr, wie das komplett nicht Teil der Diskussion dazu ist.

    In conversation about 9 months ago from mastodon.social permalink
  11. Embed this notice
    hanno (hanno@mastodon.social)'s status on Wednesday, 14-Jan-2026 00:02:19 JST hanno hanno
    in reply to
    • Rich Felker

    @dalias for what it's worth, I couldn't get this to work. But it seems there's some subtlety, trap command having different usage depending on shell, etc.
    For now, it appears putting apache in the back and having "sleep inf" as the main command seems the most pragmatic solution (in case I'm not missing some downside I haven't yet learned about).

    In conversation about 9 months ago from mastodon.social permalink
  12. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 21:11:10 JST hanno hanno
    in reply to
    • Rich Felker

    @dalias how would I do that practically? can you block a signal in a shell script or does that have to be a c wrapper or something alike?

    In conversation about 9 months ago from mastodon.social permalink
  13. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:17 JST hanno hanno
    in reply to

    Today, the issue showed up again, this time with my debugging code showing me the logfiles before shuttiing down the container:
    "AH00170: caught SIGWINCH, shutting down gracefully"

    What is SIGWINCH? It is a signal for "window change", aka, I resized the terminal window. Ok... that makes some sense that I would observe this occasionally, but not reproducibly, and resizing a terminal is certainly not something I had expected as the cause. But... why?

    In conversation about 9 months ago from mastodon.social permalink
  14. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:17 JST hanno hanno

    Mysterious bug from hell: I noticed that a Docker container running an Apache web server was sometimes shutting down for no apparent reason, but rarely enough that it was difficult to reproduce. After adding some debugging (given this shuts down the container there was no way to access the logs afterwards easily) and waiting for the issue to show up again.

    🧵

    In conversation about 9 months ago from mastodon.social permalink
  15. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:16 JST hanno hanno
    in reply to

    I guess there's some way to workaround this... just have to figure out how.

    But... certainly unexpected, and given that "run thing in the foreground in your container" is pretty common stuff these days, maybe Apache should reconsider that decision...

    In conversation about 9 months ago from mastodon.social permalink
  16. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:16 JST hanno hanno
    in reply to

    I mean, why does apache, A WEB SERVER THAT SHOULD NOT DISPLAY MUCH ON THE TERMINAL AND CERTAINLY HAS NO GUI TO REDRAW, care when I resize my terminal?
    Turns out, as you can read here https://stackoverflow.com/a/787509/3780436 or in their bug tracker (however, they locked down their bugtracker and you cannot even read it without registration) that, apparently, apache decided to reuse the SIGWINCH signal as you usually don't run apache in the foreground...

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


  17. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:15 JST hanno hanno
    in reply to

    For what it's worth: this also happens with the official Dockerhub httpd image...
    So I guess they haven't found a workaround yet either...

    In conversation about 9 months ago from mastodon.social permalink
  18. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Jan-2026 20:47:14 JST hanno hanno
    in reply to

    Reported: https://github.com/docker-library/httpd/issues/280

    In conversation about 9 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      httpd container unexpectedly stops when resizing terminal window · Issue #280 · docker-library/httpd
      When one starts the container and resizes the terminal window, it suddenly stops. To reproduce: docker run httpd:latest [...] [resizing window] [Tue Jan 13 11:25:11.623227 2026] [core:notice] [pid ...
  19. Embed this notice
    hanno (hanno@mastodon.social)'s status on Sunday, 04-Jan-2026 22:00:47 JST hanno hanno

    Anyone got a recommendation for a good web search engine? The one I used to use has decided to pivit towards providing a chatbot with a crappy search engine attached that isn't really working properly.

    In conversation about 9 months ago from mastodon.social permalink
  20. Embed this notice
    hanno (hanno@mastodon.social)'s status on Sunday, 04-Jan-2026 22:00:46 JST hanno hanno
    in reply to

    I really don't have any idea what they're doing at google. I had a recent instance where I was searching for a filename that was on an open source mirror in plenty of places, and Google said it knows nothing about it... there's, like, zero possiblity they don't have any of the mirror dirlistings indexed.

    In conversation about 9 months ago from mastodon.social permalink
  • Before

User actions

    hanno

    hanno

    Freelance Journalist. Industry Decarbonization, Climate, Energy, IT-Security. #searchable

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          47857
          Member since
          3 Dec 2022
          Notices
          72
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.