infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

Current stats:

* Bugs found in target: 1
* Bugs found in bug discovery tools: 4
this post | permalink
@dsp @badkeys That's a limitation of DNS, and management UI's can make configuring larger strings quite frustrating. My favorite is when parts of the base64 gibberish are mixed up in the DNS response so you can see that there is something that *looks like* your public key, yet it won't verify your messages.
this post | permalink
I had pretty good experiences with Zed so far, but this is lunacy:

https://github.com/zed-industries/zed/discussions/29395
this post | permalink
@david_chisnall @itgrrl @scottymace User story: I explicitly looked for and manually enabled the history on Android bc there were notifs that contained important info but I sometimes removed them from the screen by accident and I couldn't find them in the corresponding app (can't tell the exact app/feature).
this post | permalink
Windows: You can execute stuff by double-clicking

Also Windows: PowerShell is the way to script me!

Still Windows: If you double-click a PS script, it'll open a text editor
this post | permalink
@david_chisnall @itgrrl @scottymace "Is there some way of searching them?" I can only speak of Android: here definitely is a system-level option keep a browsable notification history.
this post | permalink
@mcr314 @badkeys Source? I doubt someone who makes a mistake like this knows what ECDSA is.
this post | permalink
@badkeys My educated guess is they couldn't fit larger keys into their DNS records...
this post | permalink
@wdormann I'd agree with that, but I don't know what level of control apps have on mobile.

@Mer__edith
this post | permalink
@wdormann As I understand they "knowing why" (as of now) doesn't imply this was *expected* behavior before.

I'd compare the persistent (not self-deleting) messages dilemma to secure deletion: below the next architectural boundary you can't really decide what's happening to your data ("were the bits of that file really deleted from the disk?"), but in special cases you take extra steps to prevent leaks ("let's overwrite a bunch of times, hopefully it helps").

@Mer__edith
this post | permalink
Next Page