avuko

@avuko@infosec.exchange

Everybody wants to be a warrior,
nobody wants to be a nurse.
Move slow and make things.
STIX or it didn't happen.
he/him :donor:

#ThreatIntel #BlueTeam #InfoSec #CTI #DFIR #OSCP #OSCE #GCFA #ISO8601 #ActuallyAutistic#SecularBuddhist #ENTJ-A #SolarPunk #Historian #Dutch #PublicServant

Header image: statues of tyrannicides Harmodius and Aristogeiton, photo by Miguel Hermoso Cuesta
Avatar image: screenshot of the braille Unicode for “As” (⠠⠵) which looks like a glider from the Game of Life.

auto-delete >7 days

This profile is from a federated server and may be incomplete. Browse more on the original instance.

ElleGray, (edited ) to random
@ElleGray@mstdn.social avatar

whenever my boss says "think of the big picture, elle" I'm immediately an astronaut floating silently in space tethered to my ship looking down on earth, and nothing he wants seems important or even relevant really so this strategy has backfired on him more than once is what I'm saying

avuko,

@ElleGray if he ever shifts to “making an impact”, just imagine yourself back up there, but now with a tungsten rod in your hands… 😉

unrelatedwaffle, to random
@unrelatedwaffle@kolektiva.social avatar

a male engineer just referred to the only woman on the team as "the team mom." dear men: don't ever. EVER. do this

avuko,

@theWeaver @unrelatedwaffle referring, probably not.

Acting out their unresolved daddy issues? If they are okay with the “mom” remark, I’m 💯 certain of it.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Enjoying this fully patched Ivanti Pulse Connect box (yes, the kernel has dirty in it)

Linux version 2.6.32-00366-gsd3b182-dirty - December 2009

curl 7.19.7 2009-11-04 (14 years)
openssl 1.0.2n-fips 2017-12-07 (6 years)
perl 5.6.1 2001-04-09 (23 years)
psql 9.6.14 2019-06-20 (5 years)
cabextract 0.5 2001-08-20 (22 years)
ssh 5.3p1 2009-10-01 (14 years)
unzip 6.00 2009-04-29 (15 years)

avuko,

@GossiTheDog @postmodern noticed python modules in the licences. Any idea where those are used?

https://infosec.exchange/@postmodern/111902953325063485

avuko,

@fencepost @GossiTheDog the only thing they updated consistently on that thing is the corporate logos.

avuko,

@postmodern @GossiTheDog

If I read this right, they see python used for internal API functions:

https://labs.watchtowr.com/are-we-now-part-of-ivanti/

avuko, to random

This is (again) absolutely worth reading, even if just for this quote from the article:

By @pluralistic

“If, on the other hand, the problem is that AI systems just suck and shouldn’t be trusted to fly drones, or drive cars, or decide who gets bail, or identify online hate-speech, or determine your creditworthiness or insurability, then all those AI companies are out of business.”

https://doctorow.medium.com/ayyyyyy-eyeeeee-4ac92fa2eed

🔥🙏🏻

avuko, (edited ) to random

Those who would give up essential Well-being for all, to purchase a little temporary Wealth for some, deserve neither Well-being nor Wealth.

avuko, to random

Made a meme for everyone who’s getting tired of explaining current affairs to people just waking up.

Really more like a proactive “”, come to think of it.

stux, to random
@stux@mstdn.social avatar

Hm, I love Mastodon... ❤️

It scared the shit out of me when there where toots not from me but I right away knew where to look for the issue!

Since Masto has a perfect account access log plus 2FA it was quickly clear the posts came from a 3rd party app so revoking and done!

Still, a goooood reminder to clean access tokens, perhaps even for apps not used for a bit 🤷

avuko,

@stux for those looking for it, in the web app:

Settings > Account > Authorized Apps.

https://<your_instance>/oauth/authorized_applications

avuko, (edited ) to random
avuko, to random

TIL: when you set up PayPal to link with your bank account, then –according to my bank’s privacy statement– you will give PayPal:

  • Access to 90 days of payment information, not only of things you do with PayPal, but EVERY SINGLE TRANSACTION OF THAT BANKACCOUNT
  • access to YOUR BANKING ACCOUNT DETAILS for ANOTHER 90 DAYS, for a total of 180 days
  • one-time access to ALL of YOUR TRANSACTIONS IN YOUR BANKING ACCOUNT FOR AS FAR BACK AS THAT GOES, in my case for a…

wait…
.
.
.
wait for it…
.
.

… MAXIMUM OF 8 YEARS!

Am I just the last to know?
Is everybody else okay with this?

krypt3ia, to random

So yeah, last night I was in a funk due to the whole applying for jobs fuckery, asking me my sexual preferences (once again, how is this fucking legal to even ask?) Then, the whole call from a recruiter but an email from the automated system saying nyet, no interview.

My friends, it is definitely fucked up out there and it's only gonna get worse.

I tell you though, I took a nice pot gummy (half of one, mango flavored) and within a half hour, I was mellowed out and helped.

If you are stressed, half a gummy can do wonders.

Today, I am getting back on the horse and gonna tilt this fucking windmill of unemployment again. This time, I have been working with the LLM to game the fucking automated application systems.

Fuck this, gonna hack this shit and get a job.

avuko,

@krypt3ia sorry to hear this, and besides asking for things which are non of their business (in NL it is normal to ask for or supply without asking the relationship status. Why!?) I’m appalled at the “let’s test out the LLM on job applications.” I thought that was a myth!

Besides the clear and publicly displayed lack of basic technical understanding of every single person involved in that monstrous “let’s do selection based on AI” idea, if I had to pick ONE field where biases are deeply rooted, clear as day and have immediate and real-world implications, it would literally be hiring processes.

Who in the living hell looked at that and thought: “you know what would work well? LLMs!”

Only greed and privilege can fuel evil like this.

avuko,
avuko,

@krypt3ia so it is either an automated bias, or a social bias. Utter fuckery

PacificNic, to ADHD
@PacificNic@zeroes.ca avatar

Huh... Damn.

"Be aware that a subset of people with autism are highly adept at noticing micro expressions, the very quick expressions that flit across someone’s face before they “rearrange” into a socially acceptable reaction. The people able to perceive this, however, are often unaware that they are supposed to ignore those expressions and respond to the “public face” instead. This can lead to social awkwardness."

https://theconversation.com/how-to-conduct-job-interviews-with-candidates-who-have-autism-123152

🤯

Sometimes I wonder...

On another note, that's such fucking patronizing language. Maybe it's not that people with autism are unaware they're not supposed to respond to the microexpressions, but that the microexpressions are impossible to ignore and it doesn't feel right to perform a conversation instead of have a conversation.

avuko,

@PacificNic I have the same with “sensory processing issues”.

These folks be like: “People with autism can be highly adept at noticing micro-expressions, which we’ll label as “processing issues” because people seeing us for how we really feel makes us feel uncomfortable.”

avuko, to CASIO

Okay, dear , please bring the F-91WC-8AEF back.

avuko, to random
avuko, to random

The $500 billion ‘Office real estate apocalypse’: Researchers find remote work’s effect even worse than expected | Fortune https://fortune.com/2023/05/25/office-space-crash-harder-than-expected-remote-work-economy-cre-crash/

“And in their model, that equates to a $500 billion “value destruction,” nationwide.”

In case you wondered: That’s value for someone other than you and me, the office workers.

Did even a single one of all of those C-level people, their HR, sycophant managers, the newspapers, the real estate companies, brokers etc.

Did even a single one of those who insisted you and I should go back to the office, ever have the courage to tell you it was for their profits, and for their profits only?

All those times you and I ventured out, without a vaccin, with flimsy screens between desks, pretend masks, hand sterilisation dispensers, arrows taped to the ground, warning signs… all to keep us away from our colleagues but IN THE OFFICE; sick, scared and dying.

All of that just so their wealth, stuffed into office buildings, the very buildings enclosing you from all sides, literal death traps, would keep its value. Value for them. Never for us. Because they don’t care about us.

avuko, to RedHat

I have no detailed opinions about what is doing, because I don’t know about the ins- and outs of their ecosystem or what may or may not be GPL etc.

But reading the whole blog post at https://www.redhat.com/en/blog/red-hats-commitment-open-source-response-gitcentosorg-changes, it struck me that what started as:

“[…] there isn’t value in having a downstream rebuilder.”

ended with:

“Simply rebuilding code, […] represents a real threat to open source companies.”

I’m seeing a company, in this case , considering , and etc. as a “real threat” to their profits, and deciding to kill them off.

This is completely expected behaviour, because for-profits exist for one thing only: Profit.

Can we please stop believing companies when they say they are pro-FOSS (or for-people)? Those companies simply don’t exist.

avuko, to iOS
avuko, to infosec

“300,000+ Fortinet firewalls [still, Ed.] vulnerable to critical FortiOS RCE bug”
https://www.bleepingcomputer.com/news/security/300-000-plus-fortinet-firewalls-vulnerable-to-critical-fortios-rce-bug/

(with compliments from the Dutchies)

Sapristiki, to Cybersecurity Dutch

Maar even serieus, had Omtzigt nu echt een bericht via WhatsApp gestuurd om door te geven dat hij zich terugtrok uit het informatieproces?

Ik lees dat om sommige plekken. Op andere plekken staat slechts "appje".

Ik mag toch hopen dat communicatie over staatszaken niet via WhatsApp gaat, maar via een veiliger berichtenservice?

avuko,

@Sapristiki

https://open.overheid.nl/documenten/5e5e1d84-97bc-4fec-a38f-2ac4f0d11410/file
Ze gebruiken het allemaal.

Op zich niet heel erg vind ik (onderliggende protocol is veilig genoeg, hoewel ik liever niet heb dat mijn overheid afhankelijk is van Meta), als het maar gearchiveerd wordt. 🤷🏻‍♂️

Wat ik wèl problematisch vind, is dat er door de selectie “sms, iMessage en WhatsAppberichten”, zaken zoals Threema, Signal–en God verhoede Telegram–buiten beeld blijven. Ik zou wet- en regelgeving over archivering non-protocol specifiek willen houden.

@avhuffelen

avuko,

@Sapristiki @avhuffelen je zou het denken hè? 😂

Maar overheid noch bedrijfsleven hebben hier een goed antwoord (met voldoende draagvlak) op, althans niet voor zover ik weet (en ik heb al heel wat organisaties van binnen gezien).

avuko, (edited ) to random

I’m sitting in a “high class” (read: white, rich, boomer) establishment, and the complaining is insufferable.

Alcohol and feeling safe amongst their peers (I’m a white man of a certain age, so I blend in) probably makes them say all the quiet things out loud.

Subject of ridicule include:
• Dutch historical figures being removed as namesakes of streets etc.
• transgender people
• inclusion programmes
• young people who don’t want or can’t handle their “feedback” and advise
• addendum: bad snow in ski resorts
• 2nd addendum: climate activists

And I am left wondering how ANY of that in any way would or could EVER impact even a second of their lives.

But clearly that is not how they perceive it. Maybe it is true that if all you’ve known is privilege, even a tiny step towards equality really feels like a threat to your very livelihood or even existence.

avuko, (edited ) to psychology




Please interpret both “emotionally” and “physically” however you like, and feel free to respond in the comments.

If you identify as (mostly) male, did you feel your father is/was:

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • thenastyranch
  • ngwrru68w68
  • magazineikmin
  • khanakhh
  • rosin
  • mdbf
  • Youngstown
  • slotface
  • everett
  • cubers
  • kavyap
  • DreamBathrooms
  • Leos
  • InstantRegret
  • Durango
  • osvaldo12
  • ethstaker
  • cisconetworking
  • tacticalgear
  • normalnudes
  • anitta
  • modclub
  • tester
  • provamag3
  • megavids
  • lostlight
  • All magazines