Josh Rickmar is a user on bsd.network. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
Josh Rickmar boosted

From Jasper and Theo:

"""> Thanks to Ben Gras of VUSec for sharing an early version the research paper
> with us. More details will be made public soon as 'tlbleed'.

Thanks for saying that Jasper. And thanks to Ben for getting the paper to us.

As demonstrated in the commit message, we hesitate to pass on more information. That remains Ben's thunder in Vegas.
"""

Blackhat, Aug 4-9.
blackhat.com/us-18/briefings/s

Josh Rickmar boosted

My life is swirling sewage-laden toilet bowl right now, but the world needs an article on OpenBSD "breaking embargos."

If other people find the sources, I'll take an hour and hammer them into a post.

Post original mailing list and article links in answer to this toot. Or don't. Whatevs.

I'll credit folks, of course.

My bias on this: there were fubars, like the 8 out of 10 OpenSSL bug. They'll argue against embargos over beer, but if they agree to it they'll keep it.

Josh Rickmar boosted

Ever wondered how expensive it is to own a (pure) proof-of-work cryptocurrency? crypto51.app/

Josh Rickmar boosted

Clerk at a shop was convincing me that installing the $brand loyalty Android/iOS app was a good deal. I declined stating privacy reasons and was surprised as she asked why.

So I asked her if it would be OK in me having information on:
- where & when she shops
- what she buys
- with whom she meets
- how often she uses the toilet
- and potentially leaking that information online by accident
in exchange for a 20% price cut on a deodorant.

She uninstalled the app on the spot. No joke.

Josh Rickmar boosted

If you see ?utm_source and a bunch of other gibberish at the end of a shared URL, go ahead and just take off everything starting with the ?

This is Google Analytics tracking information.

Josh Rickmar boosted

Gmail enters the "extend" phase of Embrace, Extend, Extinguish by creating new proprietary features for email then forcing non-gmail users the view the mail through a link with Google Login (and sometimes SMS confirmation!)

arstechnica.com/gadgets/2018/0

Josh Rickmar boosted

I can't even begin to say how much I love the sheer cross-conceptual nerdery of this.

if some meta toot about this being my first toot is never made, i'll probably never toot at all.