Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

GeneralX ⏳

@generalx@freeradical.zone
mastodon 4.7.3
  • Open on freeradical.zone

but most of all, @generalx@freeradical.zone is my hero

#privacy #security #foss #abolishICE #hacktheplanet

Toots reflect the views of my other employer

Header: lawyers Denise Heberle and Bill Goodman, in a PSA for the National Lawyers Guild ("NLG Know Your Rights Reminder")

Avatar: jack of hearts

Posts spontaneously combust except polls

72 Followers
66 Following
34 Posts
Joined March 30, 2025
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

In case you missed it, all of these malicious VS Code extensions use techniques that were responsibly disclosed to Microsoft, to which the response was:

"After careful investigation, this case has been assessed as low severity and does not meet MSRC’s bar for immediate servicing"

"Therefore, it is the user’s responsibility to ensure that they are not installing malicious extensions."

Five months later, Microsoft's own GitHub was compromised.

https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/
#security #vscode #openvsx

Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming
Mazin Ahmed

Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming

Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming.

49
5
40
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 2mo ago
When a colleague uses AI, it's like being exposed to secondhand smoke. And you can't avoid it because you have to work with them. #ai #workerhealth
4
1
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

Very happy to see the results of a security audit by @cure53@infosec.exchange of TorVPN (next gen Orbot).

While no High issues found, the Medium issues that could cause Denial of Service conditions are very important to focus on.

Why?

Because if you can't attack the security, you attack the ability to do things securely. Downgrades. Fallbacks. Prevent Signal from working so you're forced to use SMS.

Glad to see the focus on Availability!

https://blog.torproject.org/code-audit-tor-vpn/torvpn_cure53_audit.pdf
#tor #privacy #security #android #orbot

blog.torproject.org
14
0
5
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 3mo ago
Replying to

@gsuberland@chaos.social Joke's on you.

--oh-god-when-will-the-horrors-end is an invalid option, but it is a valid package name...that I just published.

5
2
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Boosted by @silverpill@mitra.social
Palantir is hiring neurodivergent individuals! Click here to have your neurodiversity taken advantage of and exploited! hxxps://jobs.lever.co/palantir/61eaa54c-e1b7-4064-afad-f7df3d48d652 #Palantir #neurodivergent #hiring #whistleblowers_needed
8
8
7
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

How do you mostly pay for stuff, in-person?

#poll #askfedi #money #personalfinance

5
4
10
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 6mo ago

Self hosters, do you use Cloudflare in front of your hosted services?

#cloudflare #selfhosting #privacy #security

7
7
8
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Did the jabber.ru "lawful" intercept on Hetzner and an RCE vuln in acme.sh go hand in hand in 2023?

This blog raises the question, but the reality is probably more mundane, especially since the op was discovered from expired certs.

The recommendation list linked to protect against this MITM misses a key feature - (TLS) channel binding. Conversations supports it.

https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
#xmpp #jabber #security

Parallel Reconstruction of Lawful TLS Wiretapping
REMY HAX

Parallel Reconstruction of Lawful TLS Wiretapping

Transport Layer Security (TLS) is the protocol involved in getting the lock icon to appear in your browser next to the URL. Under the hood it uses a bunch of really cool numbers for encryption. Some numbers are considered private and need securing; some are considered public and are fine for sharing. You can mix your numbers with other people’s numbers in such a way that you can verify a chain of trust. Ultimately, at the top of this chain there has to be an entity or entities that are implied t

2
0
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

The meshtastic firmware pipeline on GitHub was vulnerable to pwnRequest 5 days ago, the same vuln that popped Trivy.

This could have let someone take over signing keys for Debian packages and publish malware that infects the machine installing the packages.

Since there are a few vendors that preinstall firmware and sell meshtastic-ready devices, the malware could have been an entry into some e-commerce organization.

https://github.com/meshtastic/firmware/security/advisories/GHSA-mjx5-98jq-q736
#meshtastic #security #devops

GitHub

Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

### Summary The main_matrix.yml workflow is triggered by pull_request_target (line 19) and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and ele...

3
0
2
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

The attribution for Mastodon's CVE-2026-46349 (CVSS 5.3, retracted boost reissuance) is interestingly reported as:

"This security issue has been reported by Doyensec in collaboration with Claude and Anthropic Research"

Is this how they say "Mythos" without revealing that Doyensec is one of the undisclosed Project Glasswing members?

https://github.com/mastodon/mastodon/security/advisories/GHSA-chgx-jx3p-rf73

https://w.on-t.work/activitypub/may-2026-vulnerability says:

"Doyensec has contacted us on *behalf* of Anthropic".
#security #mastoadmin #mythos #ai #glasswing

GitHub

LD-Signature Bypass via JSON-LD Named-Graph Restructuring

### Summary Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing attackers t...

2
0
8
1
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

"Don't Look Up" talk:

That Feeling When the NSA says "damn you, academics!"

(T-Mobile using a null cipher in an IPSec tunnel and broadcasting unencrypted voice to whole continents and other free for all data from the US military, Mexican military, inflight WiFi).

https://events.ccc.de/congress/2025/hub/de/event/detail/don-t-look-up-there-are-sensitive-internal-links-in-the-clear-on-geo-satellites

#39c3 #security #sigint #privacy

[39c3] Don’t look up: There are sensitive internal links in the clear on GEO satellites
39c3

[39c3] Don’t look up: There are sensitive internal links in the clear on GEO satellites

In this talk, we will cover our hardware setup, alignment techniques, our parsing code, and survey some of the surprising finds in the data. This talk will include some previously unannounced results. This data can be passively observed by anyon...

6
0
4
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 9mo ago

When Big Tech clouds fail, are censored, or collude with the (US) government, which would you choose for private messaging?

#privacy #security #decentralization #securemessaging #matrix #xmpp #simplex #deltachat #signal #poll #polls #askfedi

6
6
12
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@evan Clearly replies, as the other options are only allowed once per account. I'll wait for a spammer to prove me right.
2
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

It's hard to fall for 'support' scams that target free and open-source software.

Because "support" is browsing GitHub issues, a mailing list, or a discourse forum.

And then submitting your own patch.

#foss #scams #half_joking #signal

1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Yet another wave of "cybersecurity hiring shortage" articles, this time featuring AI as the cause.

After unsuccessfully finding a job in "cybersecurity" for years, this shortage story is getting old.

The good news: watching how my company does security from afar, I'm glad I'm not a part of it.

#cybersecurity #hiring #oldnews

1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

New Nightmare Eclipse account is at https://gitlab.com/nightmare-eclipse

"You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.

Now you take the courtesy to flag my github account and wipe it out of the public, just like that ?

Mark this date July 14th, I will make sure your bones are shattered that day."
#threatintel

Blocked user · GitLab
GitLab

Blocked user · GitLab

GitLab.com

1
1
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Have you ever watched a public access TV show?

(Via internet is okay, but PBS doesn't count)
#poll #askfedi #tv #colbert #usa #nonprofit

1
2
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Pro tip: PGP/GPG public keys store creation date.

Pro Pro tip: creation date can be anything you want.

Think about this the next time you create another rando email account at an encrypted email provider.

#privacy #opsec

1
1
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

The page cache was a mistake.

#linux #security #dirtycbc #dirtydecrypt #dirtyfrag #fragnesia #copyfail

1
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

How much money do you make?

#poll #askfedi #money #finance #polls

1
2
4
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 10mo ago

Are you a procrastinator?
#poll #askfedi #procrastodon

1
1
2
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 10mo ago

Thought experiment:

Should Mastodon hide the number of followers you have, as shown to other people?
#poll #askfedi #mastodon

1
0
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Which would you rather deal with?
#security #infosec #cybersecurity #blueteam #poll

0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@ai6yr @SwiftOnSecurity Don't forget the IR, radar, or ultrasound sensors.
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

I like the narrative of Nightmare-Eclipse being a disgruntled security researcher, because I think the reality is more exciting.

- active/former Microsoft employee?
- NSA employee?
- Shadow Brokers adjacent?
- APT?

🍿
#threatintel

0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to
@lizzard@social.tchncs.de @cityhallin@infosec.exchange Luckily it's the US. Where employers can't ask if you're a citizen, but many of them flat out ask anyway. Possible job versus lawsuit...pick your battles.
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

"The scene that grew my love for CTFs is emptying out. The CTFTime leaderboard has almost no semblance of history or human skill anymore. The 2026 scoreboard is unrecognisable compared to every year before it. TheHackersCrew, alongside many other large and reputable teams, either do not play, play with far fewer people, or struggle to cut into the top 10. Unregulated cheating is through the roof."

https://kabir.au/blog/the-ctf-scene-is-dead
#security #pwn2own #reverseengineering

kabir.au

The CTF scene is dead

Why frontier AI has broken the open CTF format, hollowed out the scoreboard, and made competitive CTF performance a weaker signal than it used to be.

0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Do you trust the HR department to have your back when you've got a harassment or hostile work environment issue?

#hr #workers #harassment #workplace #poll

0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 3mo ago
Replying to
@protocol7@cyberpunk.lol @alice@lgbtqia.space Thoughts on collateral damage?
0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Everyone's talking about GenAI code, but have you seen GenAI software requirements?

Now it makes sense why our product is riddled with bugs. The code is poor quality, execs blame coders and QA, but not one person realizes slop, poorly specified requirements are the root of our problems.

Software architects have been replaced with software slopitects.

In this AI-infested ecosystem, 50% of my CSM job is apologizing on behalf of AI.

End rant.

#ai #genai #sdlc #projectmanagement #software

0
0
1
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago
Replying to

@cityhallin@infosec.exchange Some of my other favorites:

  1. Asking "what is your full home address?"

  2. Asking for your LinkedIn profile, and actually validating the URL starts contains linkedin.com, not considering that you may not use LinkedIn. One time "idontuse-linkedin.com" worked.

  3. "Voluntary" self-disclosure section that has required questions without an "I do not wish to answer" option, e.g. "Are you Latino? Yes/No"

0
2
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

For the last time,

_NSAKEY is not a backdoor!

Sending Bitlocker recovery keys to Microsoft is not a backdoor!

The Bitlocker YellowKey login bypass feature is not a backdoor!

Where do people get these ideas???!!

#security #privacy #conspiracies

0
0
0
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 5mo ago

Infosec (and adjacent) people:

Are you forced by your employer to use AI to help you do your job?
#infosec #cybersecurity #security #AI #poll

0
3
3
0
Open post
GeneralX ⏳ @generalx@freeradical.zone
· 4mo ago

Thought experiment:

- Vulnerability researchers uses centralized AI model to find a vulnerability

- Vulnerability gets automatically reported upstream by the AI vendor, without the AI user's consent

- Alternative: declare a group of embargoed entities who receive the reports instead of the affected projects (cough, cough, Project Glasswing), perhaps for triage or validation.

Is this good or bad?
#ai #security #mythos #projectglasswing

0
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Pricing
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:26:44 UTC