prof

joined 2 years ago
[–] prof@infosec.pub 15 points 1 month ago (1 children)
[–] prof@infosec.pub 44 points 2 months ago

Charge people who accidentally used their Java SDK.

[–] prof@infosec.pub 4 points 3 months ago

Just give the AI command line access and it can do everything for you, haha.

I'm not sure what to think of AI agents and I'm writing a master's thesis specifically about MCP security atm.

[–] prof@infosec.pub 15 points 3 months ago

Pivoting from wanting the Nobel Peace Price to threatening a war is wild.

[–] prof@infosec.pub 63 points 3 months ago (3 children)

News about the USA makes me so incredibly sad and anxious currently.

I hope the world won't go to shit and people will eventually see reason again.

[–] prof@infosec.pub 35 points 4 months ago (8 children)

Linux users when you use Windows: 😡

Linux users when you use Linux: 😡

[–] prof@infosec.pub 2 points 6 months ago

You tell me, haha 😄

DNS usually is a bit of an issue when TTL is too high and the stuff the records point to isn't available.

[–] prof@infosec.pub 5 points 6 months ago (2 children)

Well... Afaik the AWS outage only affected a certain region. So the company could have just deployed their online service in two different regions for redundancy.

Or even better. Enable Offline Support 😐

[–] prof@infosec.pub 11 points 6 months ago

See an example here:

Microsoft said both issues could allow attackers to execute code with elevated privileges, although there are currently no indications on how they are being exploited and how widespread these efforts may be. In the case of CVE-2025-24990, the company said it's planning to remove the driver entirely, rather than issue a patch for a legacy third-party component.

The security defect has been described as "dangerous" by Alex Vovk, CEO and co-founder of Action1, as it's rooted within legacy code installed by default on all Windows systems, irrespective of whether the associated hardware is present or in use.

New attack vectors are found constantly. Having no support can very likely result in a system that can be automatically breached in a few weeks to months.

As long as you don't have a public IP on your device and are in a trusted network you should be fine. But if you use a public wifi or somehow expose a port to the internet you're increasingly vulnerable for each day after the last security update.

[–] prof@infosec.pub 5 points 7 months ago

Anyone having a screen reader read the alt text is going to have a quacking stroke.

[–] prof@infosec.pub 3 points 7 months ago

Makes me wonder what problems they faced with a Client/Server architecture.

Scope creep maybe? Supporting lots of platforms can be very time consuming.

[–] prof@infosec.pub 9 points 8 months ago (2 children)

Recently I tried to get some advice from some locals and posted in a larger subreddit.

Post got immediately removed because it's a duplicate of a year old post which is only remotely related.

That place can be so stupid.

175
submitted 9 months ago* (last edited 9 months ago) by prof@infosec.pub to c/pics@lemmy.world
 

If anyone has additional context please share.

 

I hope this doesn't come across as bragging, but I'm really looking forward to my expanded roster of warframes 😄

Admittedly I didn't farm them myself, I just bought the blueprints from the market. Saryn I randomly got this week from the circuit as only warframe I didn't have yet. But my Helminth will finally get something to munch on at least.

 

Insert <it's not much but it's honest work> meme. It only supports ints and bools, some logic and simple arithmetics and it compiles to Java but damn was it hard to get that far.

Can you guess what everything does?

view more: next ›