GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by fugueish (fugueish@infosec.exchange)

  1. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Saturday, 06-Jan-2024 13:12:10 JST fugueish fugueish

    Chrome vs Firefox when it comes to Reader Mode: not even close.

    It's been like this for years. Chrome should just remove the feature completely if they aren't going to support it/make it work at all.

    There's no shame in just saying "we're not doing that feature, we're doing other stuff"! It's ok. But don't raise a pop-up for a feature that has never worked.

    In conversation Saturday, 06-Jan-2024 13:12:10 JST from infosec.exchange permalink

    Attachments



    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/706/690/282/137/711/original/61754130c15fa545.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/706/690/748/424/043/original/33fa3a91558a4f07.png
  2. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Wednesday, 27-Dec-2023 04:49:58 JST fugueish fugueish

    This bug has everything:

    • Airport advertiser
    • ...of anti-virus
    • ...which runs unsandboxed
    • ...evaling the inputs it's supposed to be scrutinizing
    • ...the inputs come from intelligence agencies

    https://www.barracuda.com/company/legal/esg-vulnerability

    In conversation Wednesday, 27-Dec-2023 04:49:58 JST from infosec.exchange permalink
  3. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:57 JST fugueish fugueish
    in reply to

    Intelligence agencies begging vendors to fix the bugs they use for intelligence gathering might seem surprising. But they have complex equities to balance, among them the fact that it is their nations who most depend on reliable information infrastructure.

    In conversation Thursday, 07-Dec-2023 05:57:57 JST from infosec.exchange permalink
  4. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:57 JST fugueish fugueish

    Eliminating this vulnerability class should be seen as a business imperative likely requiring participation from many departments. The authoring agencies urge executives to lead from the top by publicly identifying senior staff who will drive publication of their roadmap and assist with realigning resources as needed.

    https://www.cisa.gov/resources-tools/resources/case-memory-safe-roadmaps

    In conversation Thursday, 07-Dec-2023 05:57:57 JST from infosec.exchange permalink
  5. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:55 JST fugueish fugueish
    in reply to

    In part, this is because they are planning for the post-memory-unsafety future. (See e.g. https://www.youtube.com/watch?v=mi6ZLmrXNP0)

    But vendors are still addicted to their ability to dump these externalities onto customers. It's 'expensive' to move away from C/C++ in exposed attack surface — but only because the existing costs are externalized.

    In conversation Thursday, 07-Dec-2023 05:57:55 JST from infosec.exchange permalink

    Attachments

    1. #HITB2021SIN KEYNOTE 1: Security Technology Arms Race 2021 - Medal Event - Mark Dowd
      The investment into both offensive and defensive technologies has grown dramatically in line with the Internet’s rise as the pivotal system for communication...
  6. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Wednesday, 25-Oct-2023 13:33:59 JST fugueish fugueish

    Capitalism: You need me so you can have health care.

    Me: OK. Can I have health care?

    Capitalism: No.

    Me: OK. Why do I need you?

    Capitalism: So you can have health care.

    Me: ...

    Capitalism: ...

    Capitalism: what

    In conversation Wednesday, 25-Oct-2023 13:33:59 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      no.me is a premium name - but it could be yours!

  7. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Tuesday, 17-Oct-2023 21:14:39 JST fugueish fugueish

    The Solarpunk Manifesto: exists

    The Green New Deal: Reportin' for duty! 🫡

    Libraries: The Information Age is our entire jam, literally

    Marc Andreessen: I, a modern day John Galt, a modest billionaire, have given the world fraudcoins. Yet I am oppressed

    In conversation Tuesday, 17-Oct-2023 21:14:39 JST from infosec.exchange permalink
  8. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Sunday, 15-Oct-2023 05:28:47 JST fugueish fugueish
    in reply to

    I feel like some hypothetical person who actually read the entire HTML specification could stride across the face of web development as a giant of productivity, performance, and accessibility

    boooommm...

    booooommm...

    Ho ho hoooooo! <textarea> already exists, my hearties! Hooo hoooooo! And it already knows how to scroll itself

    boooomm....

    booooooommmm...

    In conversation Sunday, 15-Oct-2023 05:28:47 JST from infosec.exchange permalink
  9. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Sunday, 15-Oct-2023 05:28:44 JST fugueish fugueish

    Do you ever think about how <input type="date"> and <input type="time"> exist, but so many sites roll their own janky stuff

    In conversation Sunday, 15-Oct-2023 05:28:44 JST from infosec.exchange permalink
  10. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Friday, 22-Sep-2023 03:42:16 JST fugueish fugueish

    These 3 things are related:

    https://www.whitehouse.gov/oncd/briefing-room/2023/08/10/fact-sheet-office-of-the-national-cyber-director-requests-public-comment-on-open-source-software-security-and-memory-safe-programming-languages/

    https://support.apple.com/en-us/HT213926

    https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2023/p2759r0.pdf

    The disregard for safety of all kinds that is endemic in C/C++ is having human rights and foreign policy implications way above the level of engineers who have built little fiefdoms on quicksand.

    In conversation Friday, 22-Sep-2023 03:42:16 JST from infosec.exchange permalink
  11. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Friday, 08-Sep-2023 18:16:41 JST fugueish fugueish

    Right-click and Open Image In New Tab is the greatest lightbox image viewer of all tiiiiiiimmmmmeeeeeee #UseThePlatform

    In conversation Friday, 08-Sep-2023 18:16:41 JST from infosec.exchange permalink
  12. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Friday, 08-Sep-2023 18:16:40 JST fugueish fugueish
    in reply to

    This toot brought to you by how Mastodon's lightbox somehow disables pinch and zoom

    They had to do extra work to break it

    In conversation Friday, 08-Sep-2023 18:16:40 JST from infosec.exchange permalink
  13. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Friday, 08-Sep-2023 18:16:39 JST fugueish fugueish
    in reply to

    The year is 2038. Craigslist still uses its 1998-era HTML and Perl CGI script. It is the fastest, most usable, and most accessible web site on the planet. The New York Times front page is 6 TiB. Gmail UI elements have 17 distinct border radii.

    In conversation Friday, 08-Sep-2023 18:16:39 JST from infosec.exchange permalink
  14. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Monday, 28-Aug-2023 17:19:28 JST fugueish fugueish
    • Thomas Broyer

    Climate-Friendly Software, by @tbroyer

    • Pick servers in carbon-neutral or low-carbon datacenters first, then optimize your architecture and code.
    • Don't be the one that will make your users change their device.
    • Optimize for the perceived performance and battery life.

    https://blog.ltgt.net/climate-friendly-software/

    In conversation Monday, 28-Aug-2023 17:19:28 JST from infosec.exchange permalink
  15. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Saturday, 01-Jul-2023 03:40:43 JST fugueish fugueish

    The Supreme Court is obviously illegitimate. But it is the way it is due to the Senate, the electoral college, and lifetime appointments: explicitly anti-democratic, slavery-upholding institutions designed to produce a government that does not support the needs or desires of the people it governs. It was designed to be illegitimate, and it is working as intended. It always has.

    In conversation Saturday, 01-Jul-2023 03:40:43 JST from infosec.exchange permalink
  16. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Saturday, 01-Jul-2023 03:40:42 JST fugueish fugueish
    in reply to

    "But Biden has gotten so much done!", say the system justifiers. There was no sane reason to think that his grossly insufficient achievements would ever fare any better than the Clean Water Act or the Voting Rights Act. The Inflation Reduction Act will go the way of student loan forgiveness, even if he 'wins' in 2024.

    In conversation Saturday, 01-Jul-2023 03:40:42 JST from infosec.exchange permalink
  17. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Friday, 14-Apr-2023 13:14:01 JST fugueish fugueish

    Prioritize the use of memory safe languages wherever possible. The authoring agencies acknowledge that other memory specific mitigations, such as address space layout randomization (ASLR), control-flow integrity (CFI), and fuzzing are helpful for legacy codebases, but insufficient to be viewed as secure-by-design as they do not adequately prevent exploitation.

    https://media.defense.gov/2023/Apr/13/2003198917/-1/-1/0/CSI_SECURE_BY_DESIGN_DEFAULT.PDF

    In conversation Friday, 14-Apr-2023 13:14:01 JST from infosec.exchange permalink
  18. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Tuesday, 17-Jan-2023 06:06:25 JST fugueish fugueish

    It is legal to eat breakfast at any time of day.

    In conversation Tuesday, 17-Jan-2023 06:06:25 JST from infosec.exchange permalink

User actions

    fugueish

    fugueish

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          88807
          Member since
          16 Jan 2023
          Notices
          18
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.