infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@freddy Not sure I'll be able to have the original trigger now that a media proxy got introduced (don't know if it works retroactively).

But I have an idea for a repro, adding then deleting an <img> to the document. I guess what makes debugging this difficult is that you need a point-in-time document snapshot to see the true source. Even seeing the <img> may not be meaningful without e.g. it's surrounding <div> with the post content.
this post | permalink
@freddy Interesting theory! I do blackhole some sites but I doubt any URL of those would point to :3000...
this post | permalink
@freddy This is what I believe a native FF log message resulting from an attempt to load from localhost:

"Local Network Access permission required: top-level site “https://infosec.place/”, initiator “https://infosec.place/”, attempting to access target “http://localhost:3000/assets/images/og-card.png” (127.0.0.1:3000) via http. Secure context: True"

I could reproduce it by scrolling a shit ton in my timeline (won't do again), but I think a minimal test case would be a simple `img src="http://localhost...` served from a non-local origin.

In that case though the source would be there in Inspector, but in case of Akkoma infinite scroll does some magic that prevents me from simply looking up the tag by URL, that's why I'm thinking if some kind of "stack trace" is available for network events that would lead me to the offending element?
this post | permalink
@TarkabarkaHolgy Blood Knights is 100% wh40k compatible too!
this post | permalink
"If it only were that simple." - George Washington
this post | permalink
@securestep9 It looks client-side so you could get the same info from dev tools no?
this post | permalink
#Windows experts, can you answer this without trying:

How many times do you need to press the down arrow to select C:\Users\Public?

#UX #UI
this post | permalink
Session timeouts[1] provide great examples of #compliance disconnects from reality:

When booking for events it *always* takes *days* to get from registering for an event and getting there to show your QR or whatever. And while an attacker who hijacks your session has 0 benefit from accessing it for a prolonged time, somehow #security finds it crucial that users are auto logged-out after 30mins.

It would take just a *tiny* bit of thinking to avoid making things worse for everyone.

[1] https://wstg.owasp.org/latest/4-Web_Application_Security_Testing/06-Session_Management/07-Session_Timeout/ (congrats to #OWASP for breaking all your indexed links in search engines, also very helpful!)
this post | permalink
Re: this one I'm still curious how I could tell which document node triggered a network event (denied, with an img Initiator) I see in dev tools. I can't find the corresponding URL by searching in Inspector, DeepSeek hallucinates all the solutions, maybe @freddy has a tip?

#Firefox

RE: https://infosec.place/objects/c55e1bcb-86a9-4d16-b9fb-83dccaeb4dad
this post | permalink
@jerry You are the Man, thanks! @dey
this post | permalink
Next Page