infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@ljrk @drwhax Re: 1., the usual question we got from CISO and above on our reports is "how does it look compared to similar companies?". I agree that this is in part the "you don't have to outrun the bear" logic, but also that people in position don't want to look incompetent in front of their peers.

Another thing is that you don't get fired if you didn't follow the hackers advice, but you do get fired if you don't pass compliance which is one part BS, and the other part is easy to cheat.
this post | permalink
@lorenzofb No dox plz!
this post | permalink
@drwhax Maybe the advice of the wiser among us will be heard after all these decades: focus on robust mitigations and attack surface reduction, because the moles can't be whacked anymore.
this post | permalink
I rarely share podcasts and videos but the latest by LiveOverflow feat. s1r1u5_ about the OpenAI vs. HuggingFace incident is a real good watch and also agrees with some of my earlier points:

https://www.youtube.com/watch?v=q2KCrmQz9WE
this post | permalink
[RSS] Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)

https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/
this post | permalink
[RSS] Research: Hacking-adjacent Incident from 1966

https://jericho.blog/2026/07/27/research-hacking-adjacent-incident-from-1966/
this post | permalink
@cryptax This sounds like blaming the messenger. If the research is valid, rejecting it won't shield you from the consequences in the long run. I'd rather see this as a call to action for improving automation and scalability of analysis.
this post | permalink
[RSS] Random Windows Things Part 1: PreviousMode MitigationRandom Windows Things Part 1: PreviousMode Mitigation

https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/
this post | permalink
[RSS] Random Windows Things Part 2: Unexpected Clipboard Data BehaviorRandom Windows Things Part 2: Unexpected Clipboard Data Behavior

https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
this post | permalink
Apple MIE exploitation challenge

https://blog.calif.io/p/apple-mie-exploitation-challenge

"In this blog, we'll share the details of the two vulnerabilities behind our [MIE bypassing] exploit"
this post | permalink
Next Page