CyberSeeker

joined 1 year ago
[–] CyberSeeker@discuss.tchncs.de 82 points 1 month ago (1 children)

Shouldn’t be this hard to find out the attack vector.

Buried deep, deep in their writeup:

RocketMQ servers

  • CVE-2021-4043 (Polkit)
  • CVE-2023-33246

I’m sure if you’re running other insecure, public facing web servers with bad configs, the actor could exploit that too, but they didn’t provide any evidence of this happening in the wild (no threat group TTPs for initial access), so pure FUD to try to sell their security product.

Unfortunately, Ars mostly just restated verbatim what was provided by the security vendor Aqua Nautilus.

[–] CyberSeeker@discuss.tchncs.de 3 points 4 months ago (1 children)

Only the cyber truck. Model S and 3 refreshes are still on the legacy platform, with a lithium ion 12V.

 

Hi all,

The following post appears to crash my feed while scrolling:

https://mander.xyz/post/13720820

It is a very long text post with some technicals, so possibly a parsing error in the text preview?

Thanks! Worked around it by blocking the user temporarily.

[–] CyberSeeker@discuss.tchncs.de 16 points 5 months ago

This server, maintained by Internet carrier Cogent Communications

Found the problem!

[–] CyberSeeker@discuss.tchncs.de 67 points 5 months ago (7 children)

So the article repeats, several times, “waymo relies on remote operators”. I don’t think the author knows what “self-driving” means.

[–] CyberSeeker@discuss.tchncs.de 4 points 6 months ago* (last edited 6 months ago)

Possible? Yes. Likely? Not at all.

To perform a zero knowledge proof, you’d have to have structured data to support the claim, which most whistleblowers would not have. If a whistleblower already had the hard evidence in hand, e.g., serial numbers and timestamps, they could have just provided those anonymously, and someone could follow up. The problem is, you can’t always get a copy of the hard evidence without revealing your intent to the employer, or at least, other employees.

Presumably most whistleblowers are making unsubstantiated claims that something happened, or maybe with light evidence. Based on who they are, a journalist or investigator may then elect to follow up and dig up the hard evidence to support the claim. This requires revealing your name and position/relationship to at least one person. Rarely, they would be willing to put themselves out there to provide an affidavit under oath, which itself is not enough to pursue criminal charges (though it could help build a case around intent or willful neglect, or help support a warrant or discovery).

It’s illegal, but not unheard of, to try to force journalists to reveal their sources, but the same protections are not universally in place if you reported a finding to a company’s internal affairs, for example. But unlike attorney-client privilege, or shield law protections, the risk in signing an affidavit is, as we’ve seen in recent US trials, that records will not stay sealed, and your name will be revealed to the defense and/or public.

[–] CyberSeeker@discuss.tchncs.de 13 points 6 months ago (1 children)

As far as people I’d trust to not just make shit up, I’d say Librarian, aka, professional fucking researcher is high on the list.

[–] CyberSeeker@discuss.tchncs.de 6 points 6 months ago* (last edited 6 months ago) (5 children)

So if ISPs are once again Title II common carriers, how can they enforce the TikTok ban? 🤔

[–] CyberSeeker@discuss.tchncs.de 10 points 6 months ago* (last edited 6 months ago)

When are you adding the bok choy to your stir fry? I’d wager you’re over cooking it; try adding it much later to the cooking process. It should only take a minute or two at most to cook.

The greens are also quite bitter, so possibly don’t use all of the leaf.

[–] CyberSeeker@discuss.tchncs.de 3 points 6 months ago

I believe this is already the case; domain reputation is weighted pretty heavily by Gmail and others, so it will take some months before you’ve established enough rep. Following SPF/DMARC/DKIM is crucial, followed with time your domain has been registered and typical outbound volume from your domain.

view more: next ›