Posts

This profile is from a federated server and may be incomplete. Browse more on the original instance.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

I have this poll running on LinkedIn and it’s way worse outcome than I’d imagined. Many of the yes votes are Microsoft staff and resellers 😅

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Microsoft’s publicity team do a thing with media articles they don’t like, which is a not engage and amplify message to staff.

The problem they have - every time Recall is mentioned, the botched rollout will come back up and the privacy and security concerns will reappear.

So they basically have a situation where the AI product group, or whoever owns Recall, are going to negatively impact the security product and services group.

jadugar63,
@jadugar63@mastodon.social avatar

@GossiTheDog
Microsoft
This was by design to gauge consumer/customer sentiment and then make changes based on outcry. Zero privacy and security focus.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.

From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."

Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.

video/mp4

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I got ahold of the Copilot+ software.

Recall uses a bunch of services themed CAP - Core AI Platform. Enabled by default.

It spits constant screenshots (the product brands then “snapshots”, but they’re hooked screenshots) into the current user’s AppData as part of image storage.

The NPU processes them and extracts text, into a database file.

The database is SQLite, and you can access it as the user including programmatically. It 100% does not need physical access and can be stolen.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

If you want to know where tech companies are with AI safety, know Microsoft Recall won’t record screenshots of DRM’d movies..

..but will record screenshots of your financial records and WhatsApp messages, as corporate interests were prioritised over user safety.

And it’s enabled by default.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A company paid a ransomware group.. then had their info leaked by the same ransomware group anyway. Not isolated at all, eg UnitedHealthcare paid $20m and then got extorted again by the same person.

Stop paying ransomware groups. You are directly funding serious organised crime. https://www.bleepingcomputer.com/news/security/pandabuy-pays-ransom-to-hacker-only-to-get-extorted-again/

peterbutler,
@peterbutler@mas.to avatar

@GossiTheDog This has always seemed like an underreported story to me

Same thing happened to Change Healthcare

https://www.wired.com/story/change-healthcare-admits-it-paid-ransomware-hackers/

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

If you buy two Xbox Series X consoles and stick them together, you have enough disk space to install Call Of Duty.

uzayran,
@uzayran@cyberplace.social avatar

@GossiTheDog maybe they download the 8k textures and stream in the 4k ones

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Reform candidate said UK should have been neutral against Hitler https://www.bbc.com/news/articles/cjmmrwexv4ko

kcarruthers,
@kcarruthers@mastodon.social avatar

@GossiTheDog that's what Hitler thought too!

steve,
@steve@mastodon.nexusuk.org avatar

@GossiTheDog I guess at least he pins his colours to the mast... He also said that Putin is great and that women are all spongers and should be denied healthcare...

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Very big cyber incident playing out at Snowflake, who describe themselves as “AI Data Cloud”. They have a free trial where anybody can sign up and upload data… and they have.

Threat actors have been scraping customer data using a tool called rapeflake, for about a month.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The tl;dr of the Snowflake thing is mass scraping has been happening, but nobody noticed.. and they're pointing at customers for having poor credentials. It appears a lot of data has gone walkies from a bunch of orgs.

Snowflake is a big AI data company with a conference in the US next week, chances of that going ahead are interesting.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Snowflake: there is absolutely no cybersecurity incident.

Also Snowflake: Please run these commands and look for "threat activity" logins with the user agent "rapeflake" using this knowledge base article we haven't listed on our website.

https://community.snowflake.com/s/article/Communication-ID-0108977-Additional-Information

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

A few days ago, IT systems and services at Leicester City Council stopped working. Councillors were not told the cause. (Link: https://www.leicestermercury.co.uk/news/leicester-news/systems-outage-leicester-city-council-9151322)

At 7pm this Friday, they tweeted it is a "cyber incident". Services are still offline.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The UK government really needs a radical rethink on ransomware IMHO. If you can’t even say the word you can’t manage the problem.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Leicester City Council remains offline, from my automated monitoring, from their ransomware incident. A person in the council tells me they’ve been told not to admit it is ransomware by central government.

The BBC reports they expect to return mid week. My take - very unlikely they will get back online mid week.

https://www.bbc.com/news/uk-england-leicestershire-68533743

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

New Dragon Age game. Looks good, I think? https://www.youtube.com/watch?v=4F3N4Lxw4_Y

quitty,
@quitty@cyberplace.social avatar

@GossiTheDog
I thought it looked like the Overwatch team were tasked with furthering the franchise.
I think I'll pass

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

I just almost accidentally tooted a photo of my cat’s latest diarrhoea episode.

Chill3r,
quitty,
@quitty@cyberplace.social avatar

@GossiTheDog
Imitation is the sincerest form of flattery

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Microsoft Copilot+ Recall launch recap.

video/mp4

Paxxi,
@Paxxi@hachyderm.io avatar

@GossiTheDog with the well thought out security of Recall, I'm kinda expecting someone breaking the DB with sql injection while writing sql for something unrelated 😀

rolle,
@rolle@mementomori.social avatar

@GossiTheDog Hahaha, brilliant! :joy_animated:

GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

Two big updates:

Starfield House Varun DLC trailer, launches this year but undated: https://www.youtube.com/watch?v=iNM1HFzQC8c

(I tooted about that 6 weeks ago, they accidentally leaked it).

And the big one: surprise Starfield update dropping today: loads of new content in it, official mod support, mod marketplace, Creation Kit etc.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Here's the mod support, it's called Creations and drops today.

Anybody can upload free mods, Bethesda can drop their own mods, and vetted community creators can charge for mods.

I know, I know - paid mods, lame etc as the groupthink, but it should enable modders to make a living and.. well.. incentivises creating big and good mods as it rewards content creators financially.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

PSA: If you use ComfyUI_LLMVISION in ComfyUI, it was hacked by "Nullbulge Group" and had malware injected. It had Async remote access trojan for Windows embedded in it.

Github repo was https://github.com/AppleBotzz/ComfyUI_LLMVISION, has been pulled now.

"This repository provides integration of GPT-4 and Claude 3 models into ComfyUI, allowing for both image and text-based interactions within the ComfyUI workflow."

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Btw ComfyUI should be blocked in business environments as the setup of it is ripe for abuse - it's an AI 'stable diffusion' thing where every plugin allows native code execution by design, and there's absolutely no QA or guardrails at all.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

thoughts:

They badly needed a good showcase as the Xbox brand is in self inflicted turmoil... and they got it I think. It was great.

Lots of big games and new IP to look forward to.

Not announcing a Pro console when PS5 are about to announce one for this year will probably lead to further console sales erosion but I think they've just given up on hardware now.

gsuberland,
@gsuberland@chaos.social avatar

@GossiTheDog imo refocusing on getting better gameplay and features out of the same hardware when graphics hardware performance per watt has largely stagnated is a good move.

gsuberland,
@gsuberland@chaos.social avatar

@GossiTheDog (especially at a time when consumers are looking to cut big entertainment expenditures)

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

The next Doom will launch this year and be on PlayStation 5 too, along with Starfield.

Source: me.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Starfield is coming to PS5 (paywalled) along with next Doom, you’ll be surprised to know. https://www.theverge.com/2024/6/6/24172684/microsoft-xbox-showcase-2024

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Doom: The Dark Ages trailer, coming to PS5 day one. https://www.youtube.com/watch?v=CpgAOAOMUnA

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Very amusing seeing Frank taking a victory lap for Twitter when the Mastodon thread consistently has more boosts and favourites.

evacide,
@evacide@hachyderm.io avatar

@GossiTheDog Yeah, this is not a win for X.

jrconlin,
@jrconlin@soc.jrconlin.com avatar

@GossiTheDog

For some, just making a lap is a victory.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • khanakhh
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • InstantRegret
  • slotface
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • JUstTest
  • Durango
  • everett
  • tacticalgear
  • modclub
  • normalnudes
  • ngwrru68w68
  • cisconetworking
  • tester
  • GTA5RPClips
  • Leos
  • anitta
  • provamag3
  • lostlight
  • All magazines