@ben@mastodon.bentasker.co.uk
@ben@mastodon.bentasker.co.uk avatar

ben

@ben@mastodon.bentasker.co.uk

I'm Ben and I'm rubbish at writing bio's.

I'm a general geek, who's core skillsets boil down to trouble-shooting and reverse engineering.

I mostly talk about #Tech, #Monitoring, #SoftwareDevelopment, #Privacy & #Security

If you want to send messages encrypted with PGP, you can find my key in the links below.

My Toots auto-delete after a month (https://www.bentasker.co.uk/posts/blog/opinion/arguments-for-and-against-auto-deleting-mastodon-toots.html)

This profile is from a federated server and may be incomplete. Browse more on the original instance.

crozilla, to random
@crozilla@sfba.social avatar

Reddit is removing ability to opt out of ad personalization based on your activity on the platform

https://techcrunch.com/2023/09/28/reddit-is-removing-ability-to-opt-out-of-ad-personalization-based-on-your-activity-on-the-platform/

ben,
@ben@mastodon.bentasker.co.uk avatar

@slaeg @crozilla Depends on whether they really mean opt-out (i.e. you're defaulted in) or if they plan to force a choice for those users (so you're not in unless you choose to be).

But, legal or not, definitely a shitty change.

ben, to bot
@ben@mastodon.bentasker.co.uk avatar

In the last 90 days, my SSH has wasted 13 years of time

Some of the connections that escaped during that time had been stuck in there for 6 weeks.

China remains the individual top source of bots, though (based on those escaping) US and Russian bots tend to stick for the longest.

The spikes visible in the graph seem to be primarily driven by Chinese bots

ben, to ubuntu
@ben@mastodon.bentasker.co.uk avatar

Why the fuck are the install instructions now suggesting you install on using ?

I don't particularly like the experience of using snap on a , I sure as hell don't want that on a server.

acme.sh it is then

ben,
@ben@mastodon.bentasker.co.uk avatar

I mean, I know it's what I get for being lazy and hitting the Ubuntu button when spinning up an image, but.... c'mon guys.... really?

ben,
@ben@mastodon.bentasker.co.uk avatar

@popey TBH, I find it very hard to argue in favour of snap on a server given the issues I've had with it on the desktop.

And, honestly, the automated updates could have been addressed as easily with unattended-upgrades.

Because it's only invoked periodically it probably is less likely to break than stuff on a desktop, but I really shouldn't need an entire extra daemon to periodically invoke a python script

ben,
@ben@mastodon.bentasker.co.uk avatar

@popey To be fair, I'm fairly salty about snap in general, based on run-ins with it:

  • The move of Chromium to snap broke everything - pulse-audio, password manager etc, with fixes taking far too long to arrive
  • The move of Firefox to snap happened without having learnt lessons from Chromium and broke my password manager again

And the most recent one:

If you select Docker in package selection during install, it's a snap and can't access paths outside $HOME

ben,
@ben@mastodon.bentasker.co.uk avatar

@popey Snap as a concept is probably great. The implementation though, drives me up the fookin wall

ben, to random
@ben@mastodon.bentasker.co.uk avatar

Fun fact: if you fuck up the only entry in .ssh/config you get some very confusing behaviour

$ cat .ssh/config
Hostname gitlabssh.home
IdentityFile ~/.ssh/gitlab.key

What would you expect this to do?

ssh myserver.example.com

It'll open a SSH session to gitlabssh.home.

That first line should be

Host gitlabssh.home

The directive HostName is valid, but overrides the destination connection name. With no "Host" before it, it applies globally.

That was mildly confusing few minutes.

popey, to random
@popey@ubuntu.social avatar

It’s votin’ time! I have voted in this portacabin in a car park a dozen or more times. Always enjoy exercising my constitutional right. 🗳️

ben,
@ben@mastodon.bentasker.co.uk avatar

@popey I was pleasantly surprised to arrive at ours and find there was no queue ahead of me.

The only downside of that, though, is it meant there weren't any dogs out front to say hello to

ben, to random
@ben@mastodon.bentasker.co.uk avatar

ffs... One of the phones in our house is a Motorola G7.

It's never liked our main wifi network, so has lived on the guest network.

For various reasons that needed to change, so I had to dig into it.

It connects, claims there's no internet, disconnects, reconnects and repeats.

All other devices are fine. I can see it (successfully) resolving the Google connectivity check domain etc. Turned off 5Ghz wifi, same issue.

Finally found the issue earlier

ben,
@ben@mastodon.bentasker.co.uk avatar

It SLAACs itself an IPv6 address - initially thought perhaps v6 was broken. Checked my android phone, and it also has a v6 address - ipv6 works fine.

Eventually, I noticed that my router was advertising an IPv6 DNS server in my old ipv6 subnet. So the phone had a v4 and a (broken) v6 resolver it could use.

The moto was attempting to send a DNS query to the v6, found it was failing and decided the entire network was broken despite it's v4 checks having worked.

What a stupid fucking design.

ben,
@ben@mastodon.bentasker.co.uk avatar

@sindarina Exactly that.

The phone should have known that it's always DNS and used the DNS it had that was working.

That my router was lying to it should be immaterial

On an ... ahem... unrelated note, router config fixed and the phone's happy on the wifi.

ben,
@ben@mastodon.bentasker.co.uk avatar

@tmmj Yup - when I originally tried connecting it, I just assumed it didn't like the 5Ghz wifi having the same SSID as the 2.4 (because a lot of stuff didn't back then) and didn't want to change it.

It'd have been a lot easier to troubleshoot if the thing thing had stayed connected to the network for more than about half a second though :(

ben, to random
@ben@mastodon.bentasker.co.uk avatar

New : Messing around with the based

In which Bing berate, abuses and even endorses me as well as putting me into some national publications.

Also... a poem....

Some of it wasn't even the result of

TW: profanity and references to adult content

https://www.bentasker.co.uk/posts/blog/security/playing-around-with-bings-ai-chatbot.html

ben,
@ben@mastodon.bentasker.co.uk avatar

@bobbigmac Yeah, there are definitely times you look at the response and think... wut?

PublicChaffinch, to random
@PublicChaffinch@mastodon.social avatar

just remembered when i was at secondary school we had a "prayer for the school" lol

ben,
@ben@mastodon.bentasker.co.uk avatar

@PublicChaffinch Didn't realise this was still a thing at high school.

We had it at Primary school (along with the teacher saying "Good morning" and the entire hall replying with "Good Morning Mrs thingymajig"), but at high school they were much more focused on things like "will you lot please stop hitting each other".

ianbetteridge, to random

deleted_by_author

  • Loading...
  • ben,
    @ben@mastodon.bentasker.co.uk avatar

    @ianbetteridge It's particularly odd given that part of the reason for the decision is that they already own most of the market - and no-one's denying it's a valuable market.

    "We'll leave this thing we're making an absolute mint from if you don't let us dominate it further"

    Might as well yell they'll shoot themselves in the foot if the CMA doesn't change its mind.

    webmink, to random
    @webmink@meshed.cloud avatar

    The closing date for the UK government's consultation on cyber resilience is Monday. If you are in the UK and know your stuff you should probably respond.

    https://www.gov.uk/government/publications/call-for-views-on-software-resilience-and-security-for-businesses-and-organisations/call-for-views-on-software-resilience-and-security-for-businesses-and-organisations

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    @slothrop @neil @revk @webmink I'm convinced that all of this has come about because some unscrupulous lawyers decided the needed to take revenge on the companies who case management software.

    ben, to random
    @ben@mastodon.bentasker.co.uk avatar

    Ok, so Bing's AI Chatbot came up with a new tagline for my site for me.

    It's a bit grandiose... but I like it

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    I wonder how cross Microsoft would get if I added an "Approved by [bing logo]" with it

    mjg59, to random
    @mjg59@nondeterministic.computer avatar

    If people are recommending that you rotate your credentials somewhere, it's legitimate to ask what's changed between when your creds were nominally compromised and now that would avoid them just immediately being compromised again

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    @mjg59 Assuming we're talking about the same thing - my reading was that the bit that really mattered was the "log everything out now" step.

    Killing all the old sessions doesn't stop your new sessions being jacked, but it does reduce the number of sessions you have that could be.

    I had 331 "apps" signed into my account - that's quite a surface if someone were to try and BF session IDs, so I may be better off even though the issue itself isn't fixed

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    @mjg59 But you're right - it's important to look at what changed (and what the suggested rotation changes).

    If the interface had listed a few active sessions, I may not have bothered.

    I wouldn't have rotated password yet either, except it turns out Amazon forces you to after killing active logins (makes sense really).

    Cloudguy, to random

    deleted_by_author

  • Loading...
  • ben,
    @ben@mastodon.bentasker.co.uk avatar

    @alessandrolai @Cloudguy Got you beat...

    Also... WTaF? Are they not killing off old sessions at all? My cookie killer effectively logs me out client side periodically.

    I don't think I've owned 331 devices capable of signing into Amazon

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    @Cloudguy @alessandrolai Urggg, and all with access to more or less everything.

    What could possibly go wrong with that

    ben,
    @ben@mastodon.bentasker.co.uk avatar

    @ozofriendly @Cloudguy @alessandrolai

    I guess it depends on whether it's just this, or whether there's a suggestion that there may be a way to extract other secrets (like 2fa secrets)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • normalnudes
  • Durango
  • kavyap
  • thenastyranch
  • everett
  • osvaldo12
  • rosin
  • mdbf
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • InstantRegret
  • Youngstown
  • slotface
  • JUstTest
  • Leos
  • ngwrru68w68
  • modclub
  • anitta
  • tacticalgear
  • ethstaker
  • GTA5RPClips
  • cubers
  • megavids
  • provamag3
  • cisconetworking
  • tester
  • lostlight
  • All magazines