Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by Tinker ☀️ (tinker@infosec.exchange)

  1. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 06-Jan-2024 09:47:05 UTC Tinker ☀️ Tinker ☀️
    • William Gibson

    So this actually happened:

    I rode an electric kickscooter down to a side alleyway across from a rail transit station to pick up some second hand body modification electronics (a CPAP) from a man who has cybernetic implants in his chest! I had to get the 2nd hand body mods off the street because I can't afford proper healthcare.

    I'm living in a @GreatDismal novel.

    (And, yes, the weather was cold, dreary, and overcast - the sky above was the color of a TV tuned to a dead channel...)

    #cyberpunk

    In conversation Saturday, 06-Jan-2024 09:47:05 UTC from infosec.exchange permalink
  2. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 28-Dec-2022 10:47:33 UTC Tinker ☀️ Tinker ☀️
    in reply to
    • Toni :mastodon:

    @coloco - No, me refiero a mi teléfono. Mi teléfono creará un collage de mis fotos. Pero mi teléfono usa fotos que no me gustan.

    In conversation Wednesday, 28-Dec-2022 10:47:33 UTC from infosec.exchange permalink
  3. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 28-Dec-2022 03:50:57 UTC Tinker ☀️ Tinker ☀️

    Ohhhhhkay... We're gonna turn off those "this time last year" picture collages.

    Don't need to see any of that.

    In conversation Wednesday, 28-Dec-2022 03:50:57 UTC from infosec.exchange permalink
  4. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 21-Dec-2022 22:21:16 UTC Tinker ☀️ Tinker ☀️
    in reply to
    • Toni :mastodon:

    @coloco - Los gobiernos y las corporaciones deciden las leyes.

    In conversation Wednesday, 21-Dec-2022 22:21:16 UTC from infosec.exchange permalink
  5. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 21-Dec-2022 22:02:40 UTC Tinker ☀️ Tinker ☀️
    in reply to
    • cuan_knaggs
    • Robert Hollingshead
    • v :heart_lesbian: :verified:

    @valkyrie @mensrea @0xF21D - Sadly, if you LIVE in the US, it doesn't matter where the server physically resides.

    Plenty of examples of Americans hosting servers in non-extradition countries but still living in the states. Alot of the tor-hidden-service drug markets fall into this category. Heck, look at Kim Dotcom who both did not live in the US nor had physical servers in the US, lol.

    In conversation Wednesday, 21-Dec-2022 22:02:40 UTC from infosec.exchange permalink
  6. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 21-Dec-2022 21:57:11 UTC Tinker ☀️ Tinker ☀️
    in reply to
    • cuan_knaggs
    • Robert Hollingshead
    • v :heart_lesbian: :verified:

    @mensrea @0xF21D @valkyrie - Yeah, capitalists and their bribed lobbied politicians will use laws to try and destroy non-capitalist endeavors.

    In conversation Wednesday, 21-Dec-2022 21:57:11 UTC from infosec.exchange permalink
  7. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 21-Dec-2022 21:54:17 UTC Tinker ☀️ Tinker ☀️

    Mastodon, PixelFed, PeerTube, and other Fediverse admins of public servers might have to sort out legal issues and liability issues.

    Article on some of that here: https://www.wired.com/story/mastodon-legal-issues-tipping-point/

    Some possible solutions is to create a join legal insurance and legal advice co-op. Admins could pay a monthly fee to gain access to an liability insurance fund and to establish best practices in maintaining their instances.

    ._______
    #mastodon #fediverse #admin

    In conversation Wednesday, 21-Dec-2022 21:54:17 UTC from infosec.exchange permalink

    Attachments


  8. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 17-Dec-2022 19:34:47 UTC Tinker ☀️ Tinker ☀️

    For those wondering about the John Mastodon meme, here is the publication that claimed:

    • John Mastodon was banned from twitter (it was JOIN... Join Mastodon... not John.)
    • Mastodon was named after this fictitious man.
    • Confusing Mastodon the software with a centralized social media company.

    They're just making up things now, lol.

    ._______
    #JohnMastodon

    In conversation Saturday, 17-Dec-2022 19:34:47 UTC from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/530/583/777/570/280/original/2a07f6e16c2218c5.jpeg
  9. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 25-Nov-2022 14:31:16 UTC Tinker ☀️ Tinker ☀️

    Here before too long, I'm just going to close down my account permanently.

    I think enough time has passed that anyone that was going to find me here, has.

    I've got a method that will remove all of my followers and a second method that will seal off my name so no one can use it to spread disinfo (Once I've done that, and it takes a bit, I'll do a quick post here on how to do it.)

    I thought of just letting the name go, but I've been quoted in too many news articles and blogs throughout the years that doing so would be irresponsible.

    In conversation Friday, 25-Nov-2022 14:31:16 UTC from infosec.exchange permalink
  10. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 15-Nov-2022 21:39:45 UTC Tinker ☀️ Tinker ☀️
    • Gareth Heyes :verified:
    • James Kettle

    Lol, when a bunch of hackers migrate to new services, they tend to kick the tires a bit 😂.

    Here, some hackers found a way to steal Mastodon passwords by manipulating the way Mastodon allows (and sidestepping the way Mastodon protects) HTML imbedded into posts.

    It also highlights the ways that third party plugins (here Glitch, found on the Mastodon server infosec(dot)exchange and others) introduce interesting attack vectors that core maintainers don't initially control (thoughts go out to Wordpress).

    The hackers then reported the issues to the Mastodon team and the Glitch team so they could issue security patches.

    Big shoutout for finding/reporting the vuln:

    • @gaz
    • @albinowax

    Kudos to the Mastodon & Glitch teams for coordinating and issuing a timely security patch.

    I expect we'll see a lot of more of these initially (this is good, means the website is getting more secure).

    Takeaways:

    • Users: Consider changing your Mastodon password. Implement Multi-Factor Authentication.
    • Admins: Update to the latest Mastodon version. Update any plugins as well.

    Full writeup here: https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp

    #infosec #WebAppPentesting #hacking #BugHunting

    In conversation Tuesday, 15-Nov-2022 21:39:45 UTC from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Stealing passwords from infosec Mastodon - without bypassing CSP
      The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose
  11. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 14-Nov-2022 12:37:01 UTC Tinker ☀️ Tinker ☀️

    Here's the mobile UI showing the tabs on the right and the button to follow hashtags.

    In conversation Monday, 14-Nov-2022 12:37:01 UTC from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/341/902/844/422/817/original/da7fc77dc014fca1.jpeg
  12. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 12-Nov-2022 12:53:23 UTC Tinker ☀️ Tinker ☀️

    Reminder: You can follow hashtags (not just individual accounts).

    So, to reiterate, your Home feed can contain not just accounts you follow or their boosts, but posts of specific hashtags as well.

    All blended together.

    #feditips

    In conversation Saturday, 12-Nov-2022 12:53:23 UTC from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/330/866/986/710/811/original/befafb37bfc3f2d3.jpeg
  13. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 10-Nov-2022 13:07:02 UTC Tinker ☀️ Tinker ☀️
    in reply to
    • Toni :mastodon:
    • Jerry Bell

    @coloco - verdad

    @jerry

    In conversation Thursday, 10-Nov-2022 13:07:02 UTC from infosec.exchange permalink
  14. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 10-Nov-2022 12:41:32 UTC Tinker ☀️ Tinker ☀️
    • Jerry Bell

    We have announcements now?!

    @jerry, this is shnazzy.

    In conversation Thursday, 10-Nov-2022 12:41:32 UTC from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/319/494/803/345/710/original/7414988c71b0f340.jpeg
  15. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 10-Nov-2022 00:24:10 UTC Tinker ☀️ Tinker ☀️

    Neither the software development behind Mastodon, nor your local instance (assumption) runs on Ads.

    You aren't subject to the surveillance economy.

    You aren't subject to an algorithm that is designed to cause addiction and engagement through rage porn.

    It is generally free and open source, but it still costs money to run.

    *If* you have the means, consider donating monthly or once, even a little bit, to both the software development of Mastodon and to your local instance.

    (Don't worry if you're not able to or don't want to.)

    Mastodon Software Development:
    https://www.patreon.com/mastodon

    Example Local Instance (for infosec(dot)exchange): https://liberapay.com/Infosec.exchange/

    _____
    #feditips

    In conversation Thursday, 10-Nov-2022 00:24:10 UTC from infosec.exchange permalink

    Attachments



    1. Invalid filename.
  16. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 10-Nov-2022 00:18:47 UTC Tinker ☀️ Tinker ☀️

    Demonstration of how #Peertube and #Mastodon interact and federate with each other:

    Note: The video below is hosted on Peertube.

    https://peertube.cpy.re/w/da2b08d4-a242-4170-b32a-4ec8cbdca701

    In conversation Thursday, 10-Nov-2022 00:18:47 UTC from infosec.exchange permalink
  17. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 06-Nov-2022 21:21:46 UTC Tinker ☀️ Tinker ☀️

    Folks talking about various Mastodon instances being slow or laggy while they scramble to upgrade...

    ...should remember when Twitter was like this:

    In conversation Sunday, 06-Nov-2022 21:21:46 UTC from infosec.exchange permalink

    Attachments


    1. https://infosec.exchange/system/media_attachments/files/109/297/235/039/462/962/original/bfa47a227d5e9dfe.jpeg
  18. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 15-Feb-2019 01:20:02 UTC Tinker ☀️ Tinker ☀️

    ~=8 Character Passwords Are Dead=~

    New benchmark from the Hashcat Team shows a 2080Ti GPU passing 100 Billion password guesses per second (NTLM hash).

    This means that the entire keyspace, or every possible combination of:
    - Upper
    - Lower
    - Number
    - Symbol

    ...of an 8 character password can be guessed in:

    ~2.5 hours

    (8x 2080Ti GPUs against NTLM Windows hash)

    #Hacking #Infosec

    In conversation Friday, 15-Feb-2019 01:20:02 UTC from infosec.exchange permalink
  19. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 01-Jan-2019 22:17:43 UTC Tinker ☀️ Tinker ☀️

    Writeup on Installing KDE Plasma Mobile onto a Raspberry Pi, part of my TinkPhone project.

    Cheers to all that helped and offered encouragement and support!

    #TinkPhone #Phone #FOSS #RaspberryPi #KDE

    https://www.tinker.sh/kde-plamo-rpi/

    In conversation Tuesday, 01-Jan-2019 22:17:43 UTC from infosec.exchange permalink
  20. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 30-Dec-2018 23:26:12 UTC Tinker ☀️ Tinker ☀️
    • KDE

    Alright. Some progress!

    Got @kde Plasma Mobile successfully installed on a #RaspberryPi!

    Everything works fine except I can’t get the screen to rotate into portrait mode!

    Will work on that another day!

    #Phone #DIY #RPi

    In conversation Sunday, 30-Dec-2018 23:26:12 UTC from infosec.exchange permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/009/514/266/original/e1ebfbbf95d1222e.jpeg

    2. https://files.mastodon.social/media_attachments/files/009/514/269/original/59414254c9e0bbbc.jpeg
  • Before

User actions

    Tinker ☀️

    Tinker ☀️

    Tinkerer | Solarpunk | HackerProfile Pic: @PixelOccult

    Tags
    • (None)
    ActivityPub
    Remote Profile

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          7396
          Member since
          17 Dec 2017
          Notices
          27
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • Privacy
          • Source
          • Version
          • Contact

          Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.