101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

516
active users

#hacker

5 posts4 participants0 posts today
Die russische Regierung greift im Krieg gegen die Ukraine auch Ziele in Europa an. Nicht mit Raketen oder Bomben, sondern in Form von Hacker-Attacken. Jetzt haben Experten eine neue Kampagne aufgedeckt.#Ukraine #Hacker #Europa #HillaryClinton #SPD
Hybride Kriegsführung: Hacker nehmen Rüstungslieferanten der Ukraine ins Visier
DER SPIEGEL · Hybride Kriegsführung: Hacker nehmen Rüstungslieferanten der Ukraine ins VisierBy DER SPIEGEL

Got a new M4 MacBook Air for a personal laptop. The best part about it is getting to test my chezmoi dot files environment from scratch!

It was a lot of work to move to chezmoi, but it has been a huge life saver with all of its built-in templates and scripting. I've done so much that makes my life easier maintaining a shell environment across multiple devices.

I have different profiles for work, personal, and servers. It installs different apps or withholds secrets if need be.

The integration with 1Password is awesome as well. All of my secrets are store in 1P and chezmoi simply pulls them out on my personal systems.

github.com/mauvehed/dotfiles

GitHubGitHub - mauvehed/dotfiles: mauvehed's personal dotfiles for personal and work environmentsmauvehed's personal dotfiles for personal and work environments - mauvehed/dotfiles

Who says that #AI isn't helping people in real-life situations?

Consider yourself a bad #hacker, breaking in a company #SharePoint server. With #Microsoft #CoPilot, you're able to determine recent #pentesting reports, plain text #passwords and other crucial information for your attack right away. As if you get direct help by an insider. Amazing.

If you find an interesting sensitive file you don't have reading permission for, you can ask CoPilot to show it to you, overriding all the #security permission measures. Even better: this is not even logged as a file access. No need to clean up afterward.

Exactly the software you will need for your work. #Pentester and attackers could not have asked for a better tool. Your victims will pay for this handy service themselves. Great to get that kind of important support by Microsoft. 😉

Read about that on: pentestpartners.com/security-b

www.pentestpartners.comExploiting Copilot AI for SharePoint | Pen Test PartnersTL;DR AI Assistants are becoming far more common Copilot for SharePoint is Microsoft’s answer to generative AI assistance on SharePoint Attackers will look to exploit anything they can get their hands on Your current controls and logging may be insufficient Be careful what you keep on platforms like SharePoint Introduction SharePoint is a Microsoft platform

Ist eine ethnische Beurteilung des Chaos anhand eines einzigen Events wie der #Easterhegg wirklich sinnvoll oder nicht vielmehr Teil des gleichen kulturellen Problems? Wann hören wir eigentlich auf, #Hacker nach dem zu beurteilen, wer oder was sie sind oder woher sie kommen, und wann fangen wir endlich an, sie nach dem zu beurteilen, was sie tun? #EH22 #Manifest

Replied in thread

Zwecks Auffindbarkeit ein paar Hastags dazu:
Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
forescout.com/research-labs/su
@bsi

Recommendations
Manufacturers
Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
• Applications: proper authorization checks on web applications, mobile applications and cloud backends
Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

Users
Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
Commercial and utility installations (in addition) •
Include security requirements into procurement considerations
• Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

Replied in thread
@ekaitz_zarraga@mastodon.social

The #Guix leaders are indeed the reason I don't even give it a try despite some great people like you working on it.

I will reconsider when I'll read a public apology for this personal attack to a neurodivergent #hacker such as #RMS.

It worth to remember how that "joint stab in the back" was published while RMS was under attack because he dared defend Minsky's memory from the same sort of mob justice that was then redirected (and amplified on #BigTech social media) against RMS himself.

Some of those "leaders" who signed that "joint statement" a couple years later signed an even worse attack built on top of lies.

These sort of personal attacks have clear political goals, "incidentally" aligned with BigTech interests.

Now @zimoun@sciences.re could try to sort me among #Stallman fanboys to reinforce his beliefs, but in fact I'm pretty critical of RMS work: ultimately I think he based free software on a cold-war biased ideology, without a proper balance between communion (aka sharing strongly protected commons) and freedom. This huge error left space to #opensource and to the current use of #FreeSoftware by all sort of large corporations to abuse and subdue people.
Another (related) issue has been the total lack of a cohesive architectural design for #GNU system: RMS was too (inconsciously) fond of free market ideology to lead the movement's technically, and this lack of cohordination was turned by #ESR to the "bazaar" (not so subtle) sublimation of free market, to ease corporate exploitation of the high skilled labour of #hackers.

But in fact, with all of his political errors, he's still the most coherent and commited free software activist out there.

So I will consider Guix again when they will publish a joint apology with the same visibility the back-stab had in 2019.
guix.gnu.orgJoint statement on the GNU Project — 2019 — Blog — GNU GuixBlog posts about GNU Guix.