Profile avatar
rationalpsyche.bsky.social
Penetration Tester. Art passionate. Friends call me "grandpa".
16 posts 16 followers 48 following
Prolific Poster
Conversation Starter

I recently had two use cases to try deep research. I was hoping to discover something relevant I might have missed. However, being familiar with the topics, I can say that the results were relevant. It's also fascinating to see the 'reasoning' flow, we entered a new era of progress bars.

It is very hard to accept, but it is no longer safe to move EU governments & societies to US clouds. Not only is it dangerous to do so, it is also likely flat out illegal in the near feature. We're trading convenience for utter dependence on a mad king. It should stop. berthub.eu/articles/pos...

The legality (not wisdom) of putting European private data on US clouds hinges on the availability of the US Privacy and Civil Liberties Oversight Board. Trump neutered this board, and the European parliament has taken notice & asked the European Commission what they think:

I looked at burp ai with a good dose of marketing-driven skepticism but leveraging it for payload variations is clever. Will have to try it.

My call for European governments to retain at least a core IT/communication/email/file capability that is independent of US clouds. Named after the iconic Radio Kootwijk which we built in response to the English cutting off our communications with Indonesia in 1916: berthub.eu/articles/pos...

It seems THC left Twitter and joined Bluesky! Welcome @hackerschoice.bsky.social

This is absolute insanity.

The revenge of the Mediterranean - on.ft.com/3Q1bfaM via @FT

Going forward, assuming equal access to information, being able to think in a contrarian way (and being right) might become the only asset we have left. Conventional thinking will be something AI is perfectly fine doing and it will do it faster than us.

For the first time, CSCS is offering its public guided tour in English! When? Wednesday, March 26, 2025, at 17:00. This is a unique opportunity to explore our state-of-the-art facility and discover the fascinating world of supercomputing! bit.ly/3WFwNh7 #hpc #guidedtour #supercomputing

Unlock the power of BloodHound Community Edition! 🚀 We’ve updated our custom queries to help you uncover misconfigurations and attack paths in AD. Read @emanuelduss.ch’s blog post for tips and tricks to get started. blog.compass-security.com/2025/01/bloo... #BloodHoundCE #ActiveDirectory

This is why the "hardware is cheap" argument is nonsense at scale. Always optimize, help save the planet. cs.uwaterloo.ca/news/cherito...

I wanted to watch a video in german so I generated subtitles in english with whisper. It's the first time I had such a use case and I'm amazed that it is just simply possible.

Old digital cameras turn out to be great for kids: - They come without all the invasive crap of smart phones - They boost creativity - They teach user interfaces and controls outside "push shiny moving button" - They teach basic software concepts like files (yes, knowing about 1/2

(please re-post for reach - thank you!) Learned a cool new Linux trick? Know an interesting quirk in a network protocol? Or have something else to share? Write a 1-page article for the #6 issue of Paged Out! :) pagedout.institute?page=cfp.php Soft deadline is Feb 1st.

Hackvertor now supports tags `<@space/>` and `<@newline/>` That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing

Here's my end-of-year review of things we learned out about LLMs in 2024 - we learned a LOT of things simonwillison.net/2024/Dec/31/... Table of contents:

Let’s make 2025 the year in which other Europeans and NATO become more like the Finns. Finland seizes a tanker, getting tough on hybrid warfare econ.st/4gBufbL

I don’t want a smart oven 🥴 I don’t want a smart TV 🤢 I don’t want a smart car 🤮

Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍

Ups and downs of #redteam engagements. When the standard payloads don’t cut it, innovation wins. Learn how we misused a screenshot tool to load shellcode… at the fifth attempt!… blog.compass-security.com/2024/12/a-ni...

🚨 Join us for an Exclusive Hands-On OSINT Workshop! 📅 January 31st, 2025 - 14:00 to 17:00 👥 Who’s It For: Members of OSINT Switzerland and students of CYREN ZH 📍Rämistrasse 69, 8001 Zürich & Streamed Online

Given that simps0n isn’t on Bluesky, allow me to repost a link to his excellent weekly ezine 💎 Here’s yesterday’s edition, "AppSec Ezine - 565th" 📚

TIL when you use "from module import function" python still loads the entire module. Saw this in my memory flame graph. I moved some functions with heavy deps to a separate file and it deleted a whole "flame" of memory allocations

Name a more beautiful PDF than this.

With telcos compromised think of the intel you could get decoding faxes coming and going on law firms phones.

In breaking news, water is wet, the sky is blue, and owning/pwning telco infrastructure is valuable for intelligence gathering. It's been a strategic mistake to keep our society vulnerable by fighting e2e encryption rather than embracing it and promoting democratized use of it.

🤟🏿 m.youtube.com/watch?v=yup8...

We launched our bug bounty service a little more than a year ago, and hunters have already found 30+ bugs, including juicy ones.💥 Total payouts? CHF 15'000! #BugBounty #CyberSecurity blog.compass-security.com/2024/11/a-lo...

This article by Include Security is interesting 👀 It doesn’t discuss vulnerabilities, but instead covers counter-intuitive and possibly dangerous behaviors in libraries like Elixir’s Tesla, Python’s Pyscopg, Go’s net/http/httputil and others 🔍

My latest blog post covers how a simple observation at airport security highlights the concept of Betterment and how it applies to engineering teams. Which group are you in? angiejones.tech/the-betterme...

Given that simps0n isn’t on Bluesky yet, allow me to repost a link to his excellent weekly ezine 💎 Here’s today’s edition, "AppSec Ezine - 563rd" 📚

This. For those struggling for a mobile app, Inoreader is quite nice

Last week, a number of infosec companies began posting on Bluesky. Allow me to mention just a few... @caido.io @sensepost.com @portswigger.net @sansisc.bsky.social @compasssecurity.bsky.social

[RSS] How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review https://pentesterlab.com/blog/jwt-algorithm-confusion-code-review-lessons Original->

What I'm missing are accounts for security conferences, there a starter pack would be useful!

Hide interesting headers would be even more useful if the displayed text is the same when copied to the clipboard, with no uninteresting headers @portswigger.net

I'll start off to bring stuff to bsky. Mainly, the cool work my fellow colleagues at #compasssecurity push out. Hands-on guide to voice cloning using #AI. Learn how it's done and how to stay protected. #socialengineering #phishing #ML #hacking #ceofraud blog.compass-security.com/2024/10/voic...

Sweden is prepared. “A new Swedish version of the brochure ‘In case of crisis or war’ will be sent to all households from 18 November for two weeks. Here you will find a version in English to download, order or listen to.“ www.msb.se/en/advice-fo...