infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@schrotthaufen https://infosec.place/objects/a0c412dc-b921-4e7d-88c8-df0884ec8ebe
this post | permalink
The year is 2026. Literal trillions are spent in the hope to revolutionize the IT industry.

At the same time children have to deal with OAuth flows, One-Time Passwords and consent prompts to play Minecraft.

We really should stop fetishizing new software and stop for a brief moment to think through how software *should* work so it'd make our lives a bit better.
this post | permalink
If only search was considered in Mastodons design...

RE: https://infosec.exchange/@cR0w/116953352499158321
this post | permalink
[RSS] Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454

https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
this post | permalink
[RSS] Defender Internals - AI Assisted EDR Introspection

https://blog.deeb.ch/posts/defender-ai-introspection/
this post | permalink
At this point I'm not 100% sure LLMs are not alien psyops against our species (coincidentally I'm in the middle of Three Body Problem)
this post | permalink
@schrotthaufen Good news is that Average Joe is probably not interested in hacker blogs or similar "dual-use" content :)
this post | permalink
@root The main problem for visibility is mobile. I want a solution where the users don't have to look at domain names at all: how will Aunt Judy know if mybank.foo or my-bank.bar is the right one, esp when even legit providers rely on crappy redirectors for adtech?
this post | permalink
@schrotthaufen I like the uBlock idea! I wonder how hard it's to maintain the lists though...
this post | permalink
I've been thinking a lot about securing online transactions for laypeople.

A major issue seems to be that URLs are 1) often not visible 2) not designed for laypeople, so many of us have no idea who they are communicating with.

I'm looking for a reliable browser extension that can block site access based on domain allow-lists, extensible by country.

Any recommendations?

#security #phishing #scam
this post | permalink
Next Page