Profile avatar
jschauma.mstdn.social.ap.brid.gy
Vell, I'm just zis guy, you know? [bridged from https://mstdn.social/@jschauma on the fediverse by https://fed.brid.gy/ ]
253 posts 40 followers 5 following
Prolific Poster
Conversation Starter

Mike Masnick once again one of the few strong voices consistently delivering critical context without holding back or mincing words: https://www.techdirt.com/2025/06/12/noem-announces-military-will-liberate-la-from-democracy-then-watches-security-throw-senator-to-ground/

👏👏 “the Court must determine whether the President followed the congressionally mandated procedure for his actions. He did not. His actions were illegal— both exceeding the scope of his statutory authority and violating the Tenth Amendment to the United States Constitution. He must therefore […]

Uhoh, Cloudflare and GCP both having issues. Better hold on to your us-east, AWS, cause you're probably next. Good thing the internet is a distributed network of networks so two companies experiencing trouble doesn't affect... oh, right.

Laura Jedeed's article on the #LAProtests is 🔥: "But let’s be clear: The protesters are not provoking the administration when they engage in these tactics. The administration provoked these protesters. [...] And when the media reports on protests like this as though the demonstrators are the […]

Good* morning**! If it’s not too much trouble, I’d like to get off this ride, please.*** * Well. ** Doom. *** Aaaaaaaaaaaah.

Apparently Trump issued an EO on #PQC, updating Biden's previous scope and requirements. The diff, so to speak, was posted on linkedin and includes: • agencies are no longer obligated to deploy PQC • no more requirement to promote adoption of NIST standard • no more requirement for procurement […]

Yes, it'll affect all of us, and the long-term damage is once again what will really hurt US life expectancy, but right now I'm trying to imagine what it must be like for new parents who don't know if they're vulnerable newborns, infants, young children, and toddlers will be able to get even the […]

Apple WWDC session on #PQC: https://developer.apple.com/videos/play/wwdc2025/314 As expected, iOS / macOS 26 will come with PQC enabled and using it for TLS; this suggests that Apple's various services and APIs will also (start to) support it. CryptoKit focus on HPKE using X-Wing ( […]

Like the Musk-Trump divorce, the order of the National Guard to suppress protests came several weeks later than I expected -- in part due to a surprising lack of large scale protests. But I do expect we're now heading pretty quickly towards the "can't you just shoot them, just shoot them in the […]

Wanted: caniuse.com but for HTTP servers. Methods, protocols, plugins, headers, ... I can haz?

Ok, it took longer than I expected -- I had this on my March bingo card -- but the Trump-Musk feud is gonna 🍿.

Ugh, OpenSSL supported keygroups and keyshare selection is a mess. If you specify "X25519:X25519MLKEM768" you might think you get both advertized and both keyshares included, but nope - only the X25519 keyshare is included (although both are advertized). "X25519:*X25519MLKEM768" means both are […]

Now you might think you’re a nerd, but my stupid brain just went “wait, wtf do people on the Enterprise not float, that ship isn’t an O’Neill Cylinder or otherwise rotates” and I guess there goes my morning reading about the Star Trek universe’s artificial gravity devices, because that’s time […]

I mean, I know that git can't expand $Id$ etc. because obviously manipulating the file it checksums at commit time doesn't work, but still, I miss when you could run `ident <file>` and get last modified time, committer, revision, and even repository path etc.

New blog post! Bootstrapping HTTP/1.1, HTTP/2, and HTTP/3 -- redirects, HSTS, Alt-Svc, ALPN, HTTPS DNS records, oh my. https://www.netmeister.org/blog/http-123.html

New blog post! Bootstrapping HTTP/1.1, HTTP/2, and HTTP/3 -- redirects, HSTS, Alt-Svc, ALPN, HTTPS DNS records, oh my. https://www.netmeister.org/blog/http-123.html

"As in a country at war, reports of human tragedy and extreme cruelty have become routine — not news." Lines are crossed, the outrageous and previously unthinkable happens, and we all... get used to it and carry on, bitter and resigned […]

Hmm, so... do random scrapers impersonate ChatGPT because they think they're less likely to be blocked than when impersonating a random browser? Or is ChatGPT just flat out ignoring robots.txt? IP blocks suggest it might be scrapers (using Azure?), but why bother impersonating ChatGPT?

Anybody know why mastodon clients do a full GET on all your profile's URLs whenever one of your post's is re-posted? You don't need the actual _content_ of the links from a user's profile information to display the profile, and it really seems like quite the wasteful resource drain.

So you thought ls(1) had a lot of command-line switches at 36 (NetBSD) / 59 (GNU)? Or maybe gpg(1), with around 375 options or so? Well, here's the list of Chromium command-line switches -- all 1513 of them: https://peter.sh/experiments/chromium-command-line-switches/

Very glad that Stevens sends out messages of support to our international students, but also so very depressed that this is necessary.

Huh, the .xxx TLD just saw a big, 5-fold jump in registered domains (prev: 6551, now: 35998). What gives? https://www.netmeister.org/tldstats/xxx/ (I should add a zonediff feature to my stats alerts to see if those are bogus auto-generated malware or crypto domains or what.) #dns

Hey, look at that: host(1) on macOS Sequoia 15.5 now includes an RFC9460 HTTPS lookup by default! (Meanwhile, Gandi still doesn't support those, which is why my main domain doesn't have it. The test record shown below is intentionally wonky: it only has an […] [Original post on mstdn.social]

CVE-2025-4575: Low severity OpenSSL (3.5 only) vulnerability in openssl x509 (marking certs as trusted when asked to reject them): https://openssl-library.org/news/secadv/20250522.txt Unlikely to have a big impact, but it's funny since this is a case of the tool doing the literal opposite of […]

Y'all ever see those "utm_" parameters in your web logs and on social media URLs and wonder wtf "utm" stands for? It stands for "Urchin Tracking Module" and comes from a web stats analysis product made by "Urchin Software Corp.", which Google bought around 20 […] [Original post on mstdn.social]

“The Light Eaters,” by Zoë Schlanger is quite interesting. There’s a bit too much “Some might say” or “Doesn’t it seem like” towards the end for my taste, but the science she cites is fascinating. This book review gives a good summary of both the book and the dilemma it presents […]

This is a fun one, albeit unlikely to have a whole lot of real-world impact. A statically compiled setuid glibc binary that calls dlopen(2) honors LD_LIBRARY_PATH. :-) https://mstdn.social/@[email protected]/114521564915324843 PoC by Solar Designer […]

You've probably seen the local root privilege escalation vulnerability in GNU screen(1): https://www.openwall.com/lists/oss-security/2025/05/12/1 The note there suggests that #NetBSD ships with a vulnerable version of screen(1). This is incorrect: NetBSD includes screen(1) in #pkgsrc as a […]

New bot posting vulnerabilities from the EU Vulnerabilities Database: @euvdfeed https://mstdn.social/@[email protected]/114515377555089146 #infosec

Ok, it may be no “Give that Wolf a Banana”, but Sweden’s #Eurovision entry by a Finnish band singing about going to the sauna slaps: https://youtu.be/WK3HOMhAeQY

The "Trump’s sanctions on ICC prosecutor have halted tribunal’s work"[1] story is a timely reminder of what I just tried to instill in my students in my class on System Administration with respect to third party services... 1] [ […] [Original post on mstdn.social]

They didn't have the normal size, so I got the... 👀 ... μtella.

You might consider yourself something of a tech support badass, but unless you can remotely repair the thrusters on a 45 year old spacecraft that 23 light-hours away, maybe you should have a seat. #NASA #Voyager […]

Fun things pop up if you're on the internet. Now we even get syslog spam to port 514. Wonder what the success rate for this is. Weird.

More #linux shenanigans... You know how for ages, Unix systems let you specify which editor other tools should invoke via the $EDITOR and/or $VISUAL environment variables, falling back to a very sensible vi(1) (or even ed(1)). The value of that environment variable is used by e.g., pw_edit(3) […]