krelnik

@krelnik@infosec.exchange

Application security consultant interested in misinformation, film, Wikipedia. Curated Whats the Harm website and other skeptic/science stuff over the years. #StarTrek #Jazz

This profile is from a federated server and may be incomplete. Browse more on the original instance.

krelnik, to random

Heard an awesome story about a marine rescue on #NPR #PlanetMoney - the crew of an oil tanker risked their lives to rescue a tugboat in trouble during Hurricane Gordon. They discover after the fact that the tug was towing a $51 million Space Shuttle external tank, and under marine salvage law they were entitled to a reward. The rest of the story is a bit of a ride (spoiler: they DID get paid). I was disappointed to see this great story and historic court case not mentioned anywhere on Wikipedia so I've added it to a few relevant articles. https://www.npr.org/transcripts/1197956698

krelnik, to random

Every so often the #NYTimes games section sends me an email with the subject line, “Solve a Friday crossword on Easy Mode”. HOW DARE YOU insinuate such a thing, New York Times! The nerve! #nytxw #nytxword

krelnik, to infosec

The #OWASP YouTube channel just posted a set of videos from their global event in Washington and they are all just raw video of the speaker with no slides shown. (Well except for a tiny sliver on the edge proving that there were in fact slides at the live presention). Not even a link to slide deck below the video! Surely this was done in error? (Some of) the videos are even formatted with a big hunk of blank wall to the left of the speaker that is clearly intended for insertion of slides, while the actual slides are off camera to the right. Frustrating because some of these talks I'd really like to watch but it is difficult or impossible to follow a technical talk that had slides originally with just the speaker on screen. #InfoSec #AppSec #YouTube

krelnik,

@cirku17 Hmmm, unfortunately not in the ones I wanted to watch!

carnage4life, to random
@carnage4life@mas.to avatar

This is the wildest thing I’ve ever seen posted on LinkedIn. Instead of embarrassing everyone who has his former company on their resume he has simply embarrassed himself.

My company failed because I didn’t raise enough money to hire good people is code for I’m a terrible CEO.

krelnik,

@carnage4life I’m guessing he deleted it? Can’t find it. But his whole feed is filled with dumb stuff.

TheWinegasm, to random

When you run away to join the circus …

krelnik,

@TheWinegasm Apparently the trolling of the Mole Catcher continued, I found this on Reddit:

bastardsheep, to random
@bastardsheep@aus.social avatar

It's that time of the year where the Oscars nominations have been announced. Here's the Best Picture nominations and my thoughts.

American Fiction - Never heard of it?
Anatomy of a Fall - Not out in AU yet.
Barbie - Loved it, but best picture?
The Holdovers - Never heard of it?
Killers of the Flower Moon - Currently it for me.
Maestro - Skipped because not a fan of biographicals.
Oppenheimer - Good directing, cinematography, scripting & acting, but never felt a single thing for any character at all. The entire first 2/3 of the movie you could go for a pee break and not miss anything vital. Just a bunch of stuff happening.
Past Lives - Only heard of it when awards season came around.
Poor Things - Loved it, but best picture?
The Zone of Interest - Never heard of it? 📽️

krelnik,

@bastardsheep Its a good movie.

krelnik,

@treleanor @bastardsheep Glad you liked it. Just saw an interesting article today about all the incredible technical hoops they jumped through to make the movie "look" like it was shot on film in 1970 even though they shot it on digital. https://filmmakermagazine.com/124994-film-look-35mm-holdovers-emulation/

krelnik, to node

Study finds a ton of unmaintained packages in #npm but an #OpenSource tool to find them in your project has been released. #security #SupplyChain #vulnerabilities https://blog.aquasec.com/deceptive-deprecation-the-truth-about-npm-deprecated-packages

ELLIOTTCABLE, to random

Welp, that's a first.

Xfinity won't let me pay them for Internet service, because my … last name is “not valid.”

krelnik,

@ELLIOTTCABLE A million years ago in the dial-up BBS days there were certain systems that refused my last name “Farley” Eventually figured out the cause was trolls who would log in as “Chuck U. Farley” Due to sysops sharing block lists this problem followed me around on certain brands of BBS for a while.

krelnik, to random

Sheesh, talk about evergreen headlines... “Critical flaw found in WordPress plugin used on over 300,000 websites”

krelnik, to random

My #MLKDayOfService was helping to clean up the North Fork of Peachtree Creek along the #PeachtreeCreekGreenway We had a great crew as you can see. Among the unusual items I personally removed from the creek (along with various trash) were a stroller, TV remote, three shoes, a PC keyboard and an Ethernet cable. #MLKday #ATL #Brookhaven #Greenway

MarcAbrahams, to random
@MarcAbrahams@mstdn.science avatar

Google keeps on finding new ways to make its searches less informative. Now they've stopped giving a count of how many times the searched-for thing occurs. On a gross level (is the searched-for thing rare or common?) that count was useful.

krelnik,

@MarcAbrahams Still showing up in my results, I wonder if this is something they are A/B testing, or rolling out gradually?

mttaggart, to random

Do you think gas stoves are "better" for cooking?

Are you sure you know why you think that? www.npr.org/2023/10/17/1183551603/gas-stove-utility-tobacco

krelnik,

@PJ_Evans @kielkontrovers @sangster @mttaggart @mekkaokereke Yes they had to exist first, then the propaganda campaign to sell more of them comes later.

krelnik, to random

I’m guessing a crap ton of #NPR stations are getting angry calls from #Whamageddon players this morning. (Beware the interview with Dr. Daniel Levitin about nostalgia).

krelnik,

@notsoloud Good point.

jerry, to random

I continue to be squeezed by both sides of the threads situation. I am operating on the premise that people who think I’m a terrible person and this is a terrible instance for allowing any interaction with threads have left and/or blocked, those remaining seem to want to either have nothing to do with threads at all and are mainly concerned with their data, and those who want to seamlessly interact with threads. I have threads limited/silenced on Infosec.exchange, but that isn’t seamless, and it’s also not fully blocking. So, here’s my proposal:
I remove the limit from threads, and run a job to domain block threads for each account. Any account who chooses can undo the block (or ask me to do it) and then they can seamlessly interact with threads, and those who want nothing to do with them get their way.

Thoughts?

krelnik,

@jerry That seems like a good compromise to me.

carnage4life, to random
@carnage4life@mas.to avatar

The AI snake is already eating its own tail. xAI’s Grok responds with ChatGPT error messages because there’s now so much ChatGPT content on the web that new LLMs are being trained on LLM output.

One can imagine LLMs getting worse over time in much the same way Google Search has gotten worse over time due to SEO spam.

krelnik,

@carnage4life I seem to recall something similar happening to Google Translate. Early versions were trained on websites and documents that had multiple language versions. But then Google offered an API that let webmasters dynamically translate their content for readers. The training engine started hitting that content and getting polluted and quality of translation went down. Google had to withdraw access to the webmaster API. We aren’t learning from our own mistakes.

krelnik, to apple

There’s a new feature due to drop in iOS 17.2 but I experienced it this morning even though I’m on 17.1.2. When my wife texted me the attached photo, I had “Announce Notifications” active and Siri read out “Jessica texted a photo [of] two dogs running on a grassy field.” I’m pretty quick to criticize but this is pretty neat.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar
krelnik,

@mattblaze @gossithedog It is a different company.

gerrymcgovern, to random
@gerrymcgovern@mastodon.green avatar

Lots of carbon need to "decarbonize"

"Every step in the production of solar PV power systems requires an input of fossil fuels - as the carbon reductants needed for smelting silicon from ore, to provide manufacturing process heat and power, for the intercontinental transport of materials, and for on-site deployment."

https://www.researchgate.net/publication/335083312_Why_do_we_burn_coal_and_trees_to_make_solar_panels

krelnik,

@gerrymcgovern I’m by no means knowledgeable about renewables but that paper strikes me as deliberate anti-solar propaganda. Nowhere does the author attempt to answer the question: “how does the lifetime renewable energy output from the panels being manufactured compare to the non-renewables used in manufacturing?” Sure let’s do better in manufacturing techniques, I agree of course.

krelnik, to Software

Just downloading some updates and checking #SHA hashes, like you do. Insofar as people actually bother, I wonder how many people just look at the first few digits and the last few digits and call it a day. Which raises a question: has anyone ever explored the idea of hash "partial" collisions in a crypto context? I.e. if the first and last 8 hex digits are the same, but the middle could differ. Might be a useful thing for some attackers trying to deposit nasty things in public repositories. #Malware #HashCollisions #Cryptography #Software #InfoSec #SupplyChain

adhdeanasl, to random
@adhdeanasl@beige.party avatar

Interpreting Zoom court this morning, and my team interpreter’s Mac laptop is making balloons and confetti fly because of his signing, LOL

krelnik,

@adhdeanasl @victor Can confirm, same thing in Zoom. Green icon in menu bar when camera is live. Oh and it DOES remember the setting so you only have to do this once.

dev_ric, to random
@dev_ric@fosstodon.org avatar

One of my clients appears to be using some kind of email client that has reactions. I keep receiving an email that just tells me they "liked" my previous email...

This doesn't feel like a feature the email protocol needed 🤔

krelnik,

@dev_ric @shibashecurity oh I bet you patterns to match those are being written for every major spam filter product as we speak

krelnik,

@dev_ric @shibashecurity well that will sure teach people not to use this thing. I suppose a filter that just silently drops these messages might be less disruptive and more humane.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines