GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Tobias Fiebig (tfiebig@wybt.net)

  1. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Tuesday, 15-Apr-2025 01:16:41 JST Tobias Fiebig Tobias Fiebig

    "European universities urged to review dependence on top technology companies as Trump policies expose vulnerabilities" in Times Higher Education:

    https://www.timeshighereducation.com/news/reconsider-reliance-us-tech-companies-universities-warned

    Such discussions are increasingly taking place, Fiebig said, telling THE, “With the second Trump presidency, the risks [of depending on US providers] certainly did not change."

    “What did, however, change is people's willingness to see that these risks are indeed real, and increasingly likely to materialise.”

    In conversation about 2 months ago from wybt.net permalink
  2. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Friday, 21-Mar-2025 04:24:45 JST Tobias Fiebig Tobias Fiebig

    https://boycott-ietf127.org/

    In conversation about 3 months ago from wybt.net permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: boycott-ietf127-django.content.as207960.net
      Boycott IETF 127
      The IETF LLC has decided to continue to hold meetings in the US. Voice your disagreement with this decision here.
  3. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:59 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek Ok, the bug is somewhat old. Something else must have changed. Change of default value?

    In conversation about 3 months ago from wybt.net permalink
  4. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:57 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek What I do know: How to turn it off:

    Admin -> Sharing -> 'Federated Cloud Sharing' -> 'Allow people to publish their data to a global and public address book'

    Which "mildly" understates the "sends for all users" part. -.-'

    Brb, playing with my cats, feeding them, and then figuring out who all gets a data leak notification from me. -.-'

    In conversation about 3 months ago from wybt.net permalink
  5. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:51 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @bert_hubert @jospoortvliet @niels @Karlitschek to add on this: The data leaked may include:

    name, email, address, website, twitter, phone, twitter_signature, website_signature, twitter_verification_status, and website_verification status.

    I do not really see how one can get this data purged. This is... a disaster.

    In conversation about 3 months ago from wybt.net permalink
  6. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:41 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek See my post above; This seems to be something regular, constraint to specific time windows. Not relaly the maintenance window, though (at least not aligning with mine.)

    In conversation about 3 months ago from wybt.net permalink
  7. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:40 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek Current suspect: Notifications app ; it just got a push feature. And er... this sadly makes sense for that.

    In conversation about 3 months ago from wybt.net permalink
  8. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:39 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @bert_hubert @jospoortvliet @niels @Karlitschek https://github.com/nextcloud/server/issues/51335 << bug is there

    In conversation about 3 months ago from wybt.net permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      [Bug]: Severe data leak due to updated interaction/unexpected behavior in federation sharing feature · Issue #51335 · nextcloud/server
      ⚠️ This issue respects the following points: ⚠️ This is a bug, not a question or a configuration/webserver/proxy issue. This issue is not already reported on Github OR Nextcloud Community Forum (I'...
  9. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:30 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek https://github.com/nextcloud/server/issues/25290 << digging here.

    from: server/apps/lookup_server_connector/lib/UpdateLookupServer.php

    /**
    * check if we should update the lookup server, we only do it if
    *
    * + we have an internet connection
    * + the lookup server update was not disabled by the admin
    * + we have a valid lookup server URL
    *
    * @return bool
    */

    In conversation about 3 months ago from wybt.net permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Server is not publishing user properties to lookup-server · Issue #25290 · nextcloud/server
      There is a bug in the getUserAccountData method in the RetryJob.php of the lookup-server-connector module. The properties are written into an one dimensional array $publicData: server/apps/lookup_s...
  10. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:09 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @bert_hubert @jospoortvliet @niels @Karlitschek No worries; Real work starts now. -.-' Need to notify users, for that document this, file a nextcloud bug, report to the DPA etc. -.-' I just wanted a quiet weekend. -.-'

    In conversation about 3 months ago from wybt.net permalink
  11. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:02 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek We will know more shortly. Forcing all background-jobs to run actually triggers this. Now only about finding the right one.

    In conversation about 3 months ago from wybt.net permalink
  12. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:31:00 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek Job class: OCA\LookupServerConnector\BackgroundJobs\RetryJob is the culprit.

    Ephemeral jobs, only present for the userIds for which the suspicious callback was seen during a run.

    In conversation about 3 months ago from wybt.net permalink
  13. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:30:59 JST Tobias Fiebig Tobias Fiebig
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek Then again, why is there a commit from 2021 at the top of the history from a user that has zero other commits to server?

    In conversation about 3 months ago from wybt.net permalink
  14. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Saturday, 08-Mar-2025 12:30:57 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • Frank Karlitschek
    • bert hubert 🇺🇦🇪🇺🇺🇦
    • Jos Poortvliet

    @jospoortvliet @bert_hubert @niels @Karlitschek FOR FUCKS FUCKING SAKE.

    Ok, this is a new default setting for the new sharing integration, defaulting (seemingly? now? need to dig further... -.-') to 'yes'.

    code:
    https://github.com/nextcloud/server/blob/06119eda7a05f2b2861737532b84cef93af53f21/apps/federatedfilesharing/lib/Settings/Admin.php#L42

    and

    https://github.com/nextcloud/server/blob/06119eda7a05f2b2861737532b84cef93af53f21/apps/federatedfilesharing/lib/FederatedShareProvider.php#L1009

    Latter touched in a recent clean-up effort:
    https://github.com/nextcloud/server/commit/669e6cadd6bcb73df3f2cf8774e8ee2e3bfb7c77

    I do not _fully_ get why the behavior change occured yet, though.

    In conversation about 3 months ago from wybt.net permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: repository-images.githubusercontent.com
      server/apps/federatedfilesharing/lib/Settings/Admin.php at 06119eda7a05f2b2861737532b84cef93af53f21 · nextcloud/server
      ☁️ Nextcloud server, a safe home for all your data - nextcloud/server

  15. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Thursday, 20-Feb-2025 23:03:22 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • The gallant knight
    • Bodo Tasche

    @burningTyger @bitboxer Well, the underlying truth is that the holocaust was fundamentally enabled by what we call "IT people" today.

    And for some reason, nobody in IT got that memo and happily collects (meta) data without thinking about the possible dire consequences.

    You can't lose data you don't have.

    In conversation about 4 months ago from wybt.net permalink
  16. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Wednesday, 19-Feb-2025 00:16:46 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • Bodo Tasche

    @bitboxer Actually; Even more so in the Netherlands. The Dutch had migrated to a fully IBM/Hollerith Machine backed public administration ('digital' first, bedenken second oder so) before the invasion. After the invasion, the German's were just like "uuuuh, we know these machines! Got a query to run, let's call our IBM consultant!";

    This is why (by %/population) so many more were murdered in NL; And why the Dutch resistance burned archives:

    https://www.annefrank.org/en/timeline/128/the-resistance-attacks-the-population-register-of-amsterdam/
    https://en.wikipedia.org/wiki/1943_Amsterdam_civil_registry_office_bombing

    In conversation about 4 months ago from wybt.net permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: upload.wikimedia.org
      1943 Amsterdam civil registry office bombing
      The 1943 bombing of the Amsterdam civil registry office was an attempt by members of the Dutch resistance to destroy the Amsterdam civil registry (bevolkingsregister), in order to prevent the German occupiers from identifying Jews and others marked for persecution, arrest or forced labour. The March 1943 assault was only partially successful, and led to the execution of 12 participants. Nevertheless, the action likely saved many Jews from arrest and deportation to Nazi extermination camps. Background Following the 1940 German invasion and occupation of the Netherlands, everyone aged 15 and older was required to carry an identification card, the persoonsbewijs, with them at all times. Jews had to carry a persoonsbewijs marked with a large J. Resistance members soon started to forge identification cards on a large scale – the largest such operation, led by Gerrit van der Veen, produced some 80,000 forged documents. However, forged documents could be easily detected because they could be compared against the records in the civil registries. Some civil servants were willing to falsify records in the civil...
  17. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Friday, 17-Jan-2025 02:07:50 JST Tobias Fiebig Tobias Fiebig
    • Kevin Beaumont

    @GossiTheDog It appear, after careful evaluation, that I am an idiot; Sorted by count and there was a large cluster of small things and no 3320 in there. *hide*

    cat ips_bttf|grep -E '"ASN":[0-9]*' -o --color|sed s/'"ASN":'//|sort | uniq -c|sort -n|less

    In conversation about 5 months ago from gnusocial.jp permalink
  18. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Friday, 17-Jan-2025 02:03:09 JST Tobias Fiebig Tobias Fiebig
    • Kevin Beaumont

    @GossiTheDog I have to say, I only had the second post show up in my feed. With both messages, of course you are not. 🙂

    In conversation about 5 months ago from gnusocial.jp permalink
  19. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Friday, 17-Jan-2025 01:49:54 JST Tobias Fiebig Tobias Fiebig
    • Kevin Beaumont

    @GossiTheDog As i said, so is AS3320, so it may also be the Germans by that reasoning.

    Also, i don't suspect Iran to be that... well... simple to just scrap themselves. Scrapping a usual suspect from a dataset to poke suspicion, though... might also be on the plate for some. ;-P

    In any case, I'd be a bit more conservative with attribution. ;-P

    In conversation about 5 months ago from wybt.net permalink
  20. Embed this notice
    Tobias Fiebig (tfiebig@wybt.net)'s status on Thursday, 16-Jan-2025 21:47:44 JST Tobias Fiebig Tobias Fiebig
    in reply to
    • Neil Craig
    • Kevin Beaumont

    @tdp_org @GossiTheDog I find the absence of, e.g., 3320 in that list a bit odd.

    In conversation about 5 months ago from wybt.net permalink
  • Before

User actions

    Tobias Fiebig

    Tobias Fiebig

    Networking & Security; Misconfigurations, human factors, and Internet measurement; AS59645; Senioren Unix User🐡;I am a system administrator turned network & security researcher, looking at digital infrastructures & society, and operators. Inspecting #cloudification at scale.I am also operating a small hoster-ish AS for the good of the Internet (and to make it more distributed), making it ping. Happy to help non-profits with infrastructure.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          74467
          Member since
          16 Dec 2022
          Notices
          26
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.