@h3artbl33d@exquisite.social
@h3artbl33d@exquisite.social avatar

h3artbl33d

@h3artbl33d@exquisite.social

Hacker | OpenBSD | InfoSec | Coffee addict | Todays paranoia is tomorrows truth

This profile is from a federated server and may be incomplete. Browse more on the original instance.

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Oh my :flan_ooh: A big Youtuber with 20M subscribers (Mrwhosetheboss) talks about Enshittification, features @pluralistic right in the intro.

Now that there is some momentum, it might be a good time to help your loved ones move away from big tech and reclaim their privacy. Please help, you all, increase the awareness!

The video in question:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Eleventy is a simpler static site generator

Have you even met ssg?

$ doas pkg_add lowdown<br></br>$ mkdir -p bin<br></br>$ ftp -Vo bin/ssg https://romanzolotarev.com/bin/ssg<br></br>$ chmod +x bin/ssh<br></br>

Way simpler and doesn't require the bizarre nodejs kitchensink.

Thank you @romanzolotarev

stux, to random
@stux@mstdn.social avatar

What's in my daily toolbelt?

Well, Visual Code Studio, Terminus, Photoshop, FileZilla, Atom and some other utilities ⚒️

Oh, and a saw

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@stux

You have the saw to sever the ties to other Adobe bloat?

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@stux

"Here, another creative cloud tool for you!"

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

A map of Europe drawn from memory

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

From what I gather, from the very limited information available: the signedness folks are being vocal about an NFS exploit and dubbing it as an OpenBSD RCE.

I have no reason to assume that this is misinformation, given the track record of these folks. However: NFS is disabled by default.

If you are running nfsd, especially exposed publicly, you might want to disable it until this vulnerability is patched.

#OpenBSD :openbsd:

h3artbl33d,
@h3artbl33d@exquisite.social avatar

Furthermore, both me and PurpleRaiN (from @secbsd fame) went through the source tree. Seems that this is still unpatched.

From that, there is one logical conclusion: the vulnerability is not shared with #OpenBSD. Because if it were, it'll be patched faster than one can pronounce "remote code execution".

Hence, this is irresponsible behaviour. "We have a RCE exploit for NFS on OpenBSD, but we aren't disclosing any details, nah-nah".

h3artbl33d, to Signal
@h3artbl33d@exquisite.social avatar

Signal on OpenBSD

Rust-powered Signal client for the terminal. Sans Java.

Here is how you do it, pending my port:

$ doas pkg_add git protobuf rust<br></br>$ cargo install --git https://github.com/boxdot/gurk-rs gurk<br></br>$ export PATH=~/.cargo/bin:$PATH<br></br>$ gurk<br></br>

Might want to grab a coffee (or beer, wine, whatever your poison is) while cargo runs.

Enjoy - and as always HACK THE PLANET :flan_hacker:

#OpenBSD #Signal

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Apple's move to create a single ecosystem, based on the same architecture is fantastic.

One exploit to pwn them all :flan_hacker:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Over a decade ago, I took a leap of faith and became an entrepreneur. It has somewhat escalated - as in: my company incorporated and that I have employees nowadays (still getting used to that, but that is a story for another day).

There are some key lessons that I learned, that I want to share:

  • The single most worthy 'asset' is humans. Treat them with respect. If you don't, you'll be digging your own grave. Listen, reward and pay effin attention. Nobody is perfect - nor are you and I.
  • Having an attitude can be good. The client isn't always right - and if you can explain why you don't want to work on it, it might just open their eyes.
  • Being an entrepreneur often requires taking risk. But do it at your own expense - never, ever at the expense of others.
  • Let go. You can't manage everything - even though your company feels like it is your 'child'. Micro-managing will end up hurting everyone.
  • Always be open to learn and adapt. We are human, bound to make mistakes and fuck up. Be honest and humble. Apologize if you effed up.
  • Never, ever, give tight deadlines. If your estimation is three weeks, communicate double (six weeks). It'll cut you some slack when things don't go according to plans.

1/2 🧵

h3artbl33d,
@h3artbl33d@exquisite.social avatar
  • Again: humans. Employees and workers above everything else. Don't ever throw them under the bus. If you do - I might pay you a visit and give you a deserved slap in the face.

And... Silicon Valley (...and others) should be an example of how not to conduct business. Seriously. Steer clear of VC - as it'll only end up hurting everybody.

As a business owner, you should never, ever be the first beneficiary. Because if you are, you are doing it wrong.

2/2 🧵

thomholwerda, to random
@thomholwerda@exquisite.social avatar

There's two ways to handle linking to someone else's work on a blog or news website.

  1. Find an interesting paragraph, quote it, and link back to the post. Add a few lines of your own, if needed. You can also not quote and only link, but that's immaterial.

  2. Take someone else's work, reword it, maybe add a link to an earlier related story you also lazily reworded, to give it a veneer of original reporting, and post it as a full 'new' news story.

@osnews has, since its inception, pretty much exclusively done 1. This is very old-fashioned and not SEO-friendly, but I am convinced it's the only correct way to link to someone else's work, and ensure as much traffic as possible is sent the source's way. I'm always very cognisant of the fact people tend to not follow links to sources, so I try to quote only a taste, a bite, a sample, ensuring people are encouraged to browse to the source and read it in full.

A lot of popular, funded, profit-driven tech news websites do 2. It makes it seem as if every story they post is original reporting, but in reality, it's just a form of theft. It's taking someone else's hard work, posted on a less well-known blog, rewording it just enough to seem original, and claim the clicks. (1/2)

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@thomholwerda

Thank you for that. As Cory Doctorow (@pluralistic) phrases it:

five giant websites, each filled with screenshots of the other four

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@pluralistic

Thank you for the reply and correction. Really appreciate it :flan_heart:

@thomholwerda @tveastman

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Did you know that Mastodon has a nifty NSA-esque feature?

It stores all user IP addresses by default for a year :flan_nooo:

Exquisite retains the IP addresses for 4 (four) hours before being pruned completely.

Should we become the target for abuse, we can increase the retention. But one full year? That is just plain and utter madness - and a complete disregard for privacy and protecting the community :flan_molotov:

#MastoAdmin

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@legume

Good question - @mastohost please elaborate on this :)

ParadeGrotesque, to random
@ParadeGrotesque@mastodon.sdf.org avatar

Ooops... ☹️

grep -ic 2024 /etc/hosts.deny

2363

That is 2363 unique hosts added to the deny list because they tried to brute-force SSH since the beginning of the year. Today is March 4th, 64 days into the year. That's about 36 new hosts per day.

It is quite obvious to me that there is a concerted effort to attack SSH ports opened on the Internet.

Anyone else see this?

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@ParadeGrotesque

Yep! I do use #iBlock, the number of (perma)blocked IPs is madness. I do have to add that it isn't only the SSH port, but also 445/tcp (SMB), 3389/tcp (RDP) and others.

All that while I already use pf-badhost with a fair number of blocklists. The internet really is a clusterf*ck nowadays.

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Our platform uses military grade end-to-end encryption to protect your data from hackers. We recently have upped the ante, by switching to ROT-17576.

h3artbl33d,
@h3artbl33d@exquisite.social avatar

Remember when ROT-13 was all the rage? The initial version of our platform already took that to the next level by implementing ROT-26.

Now we have truly outdone ourselves. Our internal R&D spent years and years developing ROT-17576 - and now finally having it implemented makes us immensely proud.

mariyadelano, to mentalhealth
@mariyadelano@hachyderm.io avatar

is a real bitch, y’all.

Because of it I’m not good with conceptualizing a coherent sense of reality beyond the present moment.

So right now I’m deeply upset because someone I really care about and like working with is on vacation until Monday.

Even though we have messaged every single day for a month now - my brain is telling me that because we aren’t speaking RIGHT NOW it doesn’t count, they aren’t real, they don’t care about me. Ugh

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@mariyadelano

Thank you so much for sharing this and being this open. Reading your thread is really insightful, but also painful.

In the past I have been in a relationship (engaged even) with someone with . While I am open to elaborate - this is your thread and I am not going to hijack it.

I think you being aware of the irrational impulse and actively fighting it, is so powerful. Complete and utter respect - it has to be anything but easy.

Please always try to remember that you matter. Every single day.

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Whoop. Mastodon is throwing in a change that might just help battle the increase in spam.

This PR will flip open registrations to approval required if the staff (admins/mods) have been inactive over a week.

#mastoadmin

thomholwerda, to random
@thomholwerda@exquisite.social avatar

So my wife and I have been using Signal for a few months now and... Damnit I wish I could get everyone to use it. It's such a nice, no-nonsense application.

Just wish their desktop applications weren't shit.

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@thomholwerda

They indeed are shit - Electron crap. There are some unofficial clients. For GTK, check Flare and for a TUI check scli :flan_hacker:

h3artbl33d, to Signal
@h3artbl33d@exquisite.social avatar

Molly is an hardened fork of Signal for Android.

It is designed to keep userdata safe, even in the case of a full phone compromise. But that is not where it stops. Not at all:

  • Molly has an official FOSS version with FCM, GMaps etc stripped out,
  • Additionally, there is a UnifiedPush version. Push messages from either a trusted party or selfhosted.
  • It features encryption at rest, secure RAM wiper, automated lock, multi device support and much more.

Now grab a Pixel (preferably 8+ due to MTE), install GrapheneOS and Molly.

While we are on the #Signal subject, the upcoming v7 beta will feature usernames and phone number privacy (source). Finally :flan_hurrah:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

A new episode in Torvalds' "all bugs are equal" bullshit. Citing Ian Coldwater on the birdsite:

The Linux kernel became a CNA and are planning on issuing a CVE for every bug whether security-related or not “because security fixes aren’t special”. It’s blatant sabotage of a system people rely on and it’s going to fuck all kinds of systems that rely on it.

h3artbl33d,
@h3artbl33d@exquisite.social avatar

A good friend just mentioned:

So every bug is a vulnerability in their own eyes?

:flan_molotov: :flan_set_fire:

h3artbl33d,
@h3artbl33d@exquisite.social avatar

It is a very just observation of the state of Linux. There were some really good initiatives aiming to systematically improve the security of Linux - which were met with hostility, discontempt etc.

One example: grsecurity - which offers systematic and foundational improvements and hardening. Originally, it was submitted as patches to merge upstream.

Grsecurity has a paid-for model nowadays, due to the 'toxicity' of the project they were contributing to.

Just one of the massive numbers of examples.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines