infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@nullandnull I need something for one-off diagrams, I don't want to write a formal declaration this time. My best idea so far is to annote the bytes in some GUI that supports this (IIRC 010 does?), and take a screenshot...
this post | permalink
Dotcom bubble nostalgia in the local pubs restroom
this post | permalink
Any recommendations for generating annotated hex dumps for #documentation, optimally (but not necessarily) something like @angealbertini's format dissections:

https://github.com/corkami/formats/blob/master/image/PNGRGB_dissected.png

#ReverseEngineering
this post | permalink
RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race
(CVE-2026-64600)

https://www.openwall.com/lists/oss-security/2026/07/22/14

Mythos writes Qualys advisories now FML :P
this post | permalink
"The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline"

Sure, before AI no system ever had a "data-processing pipeline". Whatever that means.
this post | permalink
@schrotthaufen @jcoglan And coding agents gaslight the user by injecting "system reminders" prefixes that are invisible to the user but the LLM sees them as user messages and regularly refer back to those as user requirements.
this post | permalink
I feel it's time to reshare this excellent piece, as it explains some general problems that relate to my previous posts:

Can chatbots craft correct code?

https://blog.trailofbits.com/2025/12/19/can-chatbots-craft-correct-code/
this post | permalink
"DecBench is an experimental benchmark for comparing decompilers and modern LLMs on the task of recovering exact source code."

https://decbench.com/

#ReverseEngineering #decompiler
this post | permalink
@castaway That's an Akkoma frontend issue (it should highlight the specific post in the replies and jump there, except it doesn't jump...). I replaced the link to point to my archived copy!
this post | permalink
@freddy I can 100% believe their model did *something*, but first and foremost the official report tells me that their frontiers models are so great they outright steer away from the original problem statement ("write an exploit") and burn a shit ton of tokens on something entirely different ("find an exploit on the Internet"). Second, OAI either didn't have the means to monitor what's going on or didn't care to intervene.
this post | permalink
Next Page