GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by hanno (hanno@mastodon.social)

  1. Embed this notice
    hanno (hanno@mastodon.social)'s status on Wednesday, 07-May-2025 19:02:44 JST hanno hanno

    This is a gruelling summary of all the things wrong with OpenSSL https://www.haproxy.com/blog/state-of-ssl-stacks I've mostly watched this whole thing from the sidelines, but was also affected noting that private key parsing suddenly became 70 times slower. I think they've now improved it to "only" be 10-20 times slower, and there does not seem any effort to work on it any more.

    In conversation about a month ago from mastodon.social permalink

    Attachments


  2. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 15-Apr-2025 20:26:29 JST hanno hanno
    • Rich Felker

    Coding question / mmap:
    I'm mmap'ing a file (Python, but I guess mmap should behave the same no matter which language), read-only. Code is constantly reading from the mmap'ed buffer. Another process is writing to the same file. Process reading from the file stops with a Bus error. Is this... to be expected? I find it surprising, to say the least. @dalias maybe you know?

    In conversation about 2 months ago from mastodon.social permalink
  3. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 01-Apr-2025 18:09:28 JST hanno hanno
    • Let's Encrypt

    Hey @letsencrypt is your plan for OCSP deprecation really "we will do it in one month, and we provide no way to let you test it whatsoever"? I mean... would it be asking for too much to at least have an HTTPS host configured with such a cert that people can, e.g, use to test monitoring tools? And ideally an optional way to get such certs issued before they become the default?

    In conversation about 3 months ago from mastodon.social permalink
  4. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 08-Mar-2025 02:26:51 JST hanno hanno

    Dear Internet hivemind, I have a tech problem. I use nextcloud as my calendar. I get a lot of ics files these days, via email, or from web pages where I signup for events. I want to get the ics files into my nextcloud calendar without it being annoying. I think it should be simple to solve, but somehow, it isn't. I don't find any good answers how I might do that. Maybe I'm googling for the wrong terms. 🧵

    In conversation about 3 months ago from mastodon.social permalink
  5. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 18-Jan-2025 01:19:12 JST hanno hanno

    About that Fortinet thing: there are also some private keys affected. https://blog.hboeck.de/archives/908-Private-Keys-in-the-Fortigate-Leak.html

    In conversation about 5 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Private Keys in the Fortigate Leak - Hanno's blog
  6. Embed this notice
    hanno (hanno@mastodon.social)'s status on Friday, 17-Jan-2025 18:36:42 JST hanno hanno

    I hear Fortinet customers are having a lot of fun. Shall I repeat my rant about "cybersecurity" products from last time? If you run a Forti appliance: Will you stop doing so? Will you buy one from one of those other vendors that fucked up in recent years? Is there any situation in which you will admit that these things do more harm than good?

    In conversation about 5 months ago from mastodon.social permalink
  7. Embed this notice
    hanno (hanno@mastodon.social)'s status on Wednesday, 08-Jan-2025 16:14:52 JST hanno hanno

    Es sagt ja so viel über den kaputten Stand unserer gesellschaftlichen Diskurse, dass wir gerade eine Diskussion über den Krankenstand haben, aber kein einziger Vorschlag dazu zielt darauf ab, dass Leute weniger krank werden. Ich mein, ist ja nicht so dass man da nix tun könnte. (Luftfilter, Masken, Homeoffice, leichterer Zugang zu Impfungen, ...)

    In conversation about 5 months ago from mastodon.social permalink
  8. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 02-Jan-2025 06:57:37 JST hanno hanno

    Due to lack of time, there was no Q&A after my #38C3 talk, but in the chat, someone asked an interesting question. I said in the talk that Methanol is the simplest carbon-containing liquid, the person remarked that this would instead be formic acic (de: "Ameisenseure") + asked whether using formic acid instead of methanol would be interesting. The molecular difference between formic acid and methanol is that it contains one oxygen atom instead of 2 hydrogen atoms.🧵

    In conversation about 6 months ago from mastodon.social permalink
  9. Embed this notice
    hanno (hanno@mastodon.social)'s status on Monday, 30-Dec-2024 01:09:27 JST hanno hanno

    Ach echt, es war gar keine tolle Idee, die Heidekrautbahn mit Wasserstoff (wohlgemerkt aus Erdgas) fahren zu lassen? Hätte uns nur jemand gewarnt! https://www.rbb24.de/wirtschaft/beitrag/2024/12/wasserstoff-engpass-einschraenkungen-regionalbahn-berlin-brandenburg-vbb.html

    In conversation about 6 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.rbb24.de
      Wasserstoff-Engpass führt zu Einschränkungen bei Regionalbahn
      Auf der Strecke der Heidekrautbahn zwischen Berlin und Groß Schönebeck fahren seit Mitte Dezember Züge mit Wasserstoffantrieb. Damit ist nun vorerst Schluss - weil nicht genug Wasserstoff geliefert wird. Das hat Auswirkungen auf andere Linien.
  10. Embed this notice
    hanno (hanno@mastodon.social)'s status on Friday, 13-Dec-2024 21:45:32 JST hanno hanno

    This is quite something: The BBC reports about health misinformation. One example is... a show on BBC!
    I mean, I guess it's good that they critically evaluate their own reporting.

    But it gets better: "A spokesperson for the BBC declined to comment."

    That's quite arrogant of the BBC to decline to comment when a journalist working for the BBC asks you for a comment

    https://www.bbc.com/news/articles/c4gpz163vg2o

    In conversation about 6 months ago from mastodon.social permalink
  11. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 26-Nov-2024 14:35:29 JST hanno hanno
    in reply to

    I'm seeing lots of spam lately either from domains that have [easytoremembername].com and end up being domains for sale, or, today, a flood of [name of bank].de, which belongs to the bank, but is probably not used by them for email. All without DMARC.
    I don't recommend p=reject for actually used domains, but for domains that are *unused for email*, you have no deliverability problem, you want non-deliverability for all mails with that sender.

    In conversation about 7 months ago from mastodon.social permalink
  12. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 26-Nov-2024 14:35:18 JST hanno hanno
    in reply to
    • uberspace.de
    • Tim Philipp Schäfers

    @TimPhSchaefers then @ubernauten should fix that. Allow customers to set a "no email" option that sets dmarc to reject, SPF to -all, and mx to . (nullmx)

    In conversation about 7 months ago from mastodon.social permalink
  13. Embed this notice
    hanno (hanno@mastodon.social)'s status on Monday, 25-Nov-2024 17:56:28 JST hanno hanno

    Dear everyone who owns domains that are *not used for e-mail*, particularly ones that are potential targets for phishing (banks, high-profile names): Could you please configure SPF+DMARC, ideally with p=reject? You may wonder: Why should I configure anything email for a host that isn't used for email? Well... it helps others to identify spam sent with your domain as the sender.

    In conversation about 7 months ago from mastodon.social permalink
  14. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 21-Nov-2024 23:06:21 JST hanno hanno
    in reply to
    • Kees Cook :tux:
    • yossarian (1.3.6.1.4.1.55738)

    @kees @yossarian I'm confused, this tells me [[ is the bash'ism, and [ the posix thing: https://mywiki.wooledge.org/BashFAQ/031

    In conversation about 7 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      BashFAQ/031 - Greg's Wiki
  15. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 21-Nov-2024 23:06:21 JST hanno hanno
    in reply to
    • Kees Cook :tux:
    • yossarian (1.3.6.1.4.1.55738)

    @kees @yossarian uh, good to know. I'm pretty sure at some point I've been told (maybe by some linting tool?) that [[ is preferrable to [.

    In conversation about 7 months ago from mastodon.social permalink
  16. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 12-Nov-2024 22:24:03 JST hanno hanno

    I had feared that the topic would be too obscure, but #38c3 accepted my talk. So you'll be able to hear me talk about Green Methanol, and why it may be an important technology for a climate-neutral future.

    In conversation about 7 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/470/140/291/955/747/original/074f07363a9a698a.jpg
  17. Embed this notice
    hanno (hanno@mastodon.social)'s status on Thursday, 10-Oct-2024 18:49:07 JST hanno hanno

    Falls Ihr in Potsdam lebt und Fahrrad fahrt: Die Stadt Potsdam wüsste gern was Ihr zur Radverkehrssituation denkt. https://besserradeln.potsdam.de/potsdam/de/home/beteiligen

    In conversation about 8 months ago from mastodon.social permalink

    Attachments


  18. Embed this notice
    hanno (hanno@mastodon.social)'s status on Tuesday, 13-Aug-2024 02:31:58 JST hanno hanno

    If you think that Texas is an example for successful clean energy buildout, please read this https://ketanjoshi.co/2024/08/12/texas-builds-clean-power-but-it-isnt-a-climate-champion/

    In conversation about 10 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: i0.wp.com
      Texas builds clean power – but it isn’t a climate champion
      from ketanjoshi85
      Texas is meant to be a deregulated, free-market clean power hero that proves killing government scores climate progress. So I checked the numbers.
  19. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:48 JST hanno hanno
    in reply to

    Their products are flawed not just because they're badly implemented - which they are - but because they are based on a stupid idea. The idea that you improve your IT security by adding more complexity. Doing the opposite is the right approach. But you can't sell that as a product. (You can still sell it, but it's not something you just plug into your network and get security magically.)

    In conversation about a year ago from mastodon.social permalink
  20. Embed this notice
    hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:47 JST hanno hanno
    in reply to

    Actually, the value of Citrix rose after that: https://www.marketscreener.com/quote/stock/CITRIX-SYSTEMS-INC-4863/ These things have no consequences for these companies, it's a completely broken market. I'm reading news that crowdstrike's value dropped, I have doubts that this will be permanent.

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.marketscreener.com
      Citrix Systems, Inc. Stock (CTXS) - Quote Nasdaq- MarketScreener
      Citrix Systems, Inc. (CTXS.NASDAQ): Stock quote, stock chart, quotes, analysis, advice, financials and news for Stock Citrix Systems, Inc. | Nasdaq: CTXS | Nasdaq
  • Before

User actions

    hanno

    hanno

    Freelance Journalist with a focus on Climate, Energy, IT-Security. #searchable

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          47857
          Member since
          3 Dec 2022
          Notices
          48
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.