Show newer

this post will find you. you better be well while it does so. there is no escape.

What’s wrong babe? You’ve hardly created any shareholder value today

Aerospace chocolatiers prepare a Ferrero Rocher for launch into low earth orbit it

StrataVision was the 3D modeling and rendering package used to produce graphics of the original Myst. They are so proud of this that even right now if you get the latest version of it ("Strata Design 3D SE", free on Steam,) it comes with a bunch of Myst assets in its library:

This is apparently a re-captcha issue. google is turning the screws on firefox users, refusing to verify captchas unless you use their chrome browser, which includes anti-features to let google track you across the web. I should have known. Fuck google so hard.

Show thread

Incredible research at BlackHat Asia today by Tong Liu and team from the Institute of Information Engineering, Chinese Academy of Sciences (在iie.ac.cn 的电子邮件经过验证)

A dozen+ RCEs on popular LLM framework libraries like LangChain and LlamaIndex - used in lots of chat-assisted apps including GitHub. These guys got a reverse shell in two prompts, and even managed to exploit SetUID for full root on the underlying VM!

A PSA since there's some confusion on this...

There is no vulnerability in Gorilla Sessions.

The vulnerability is in Palo Alto's internal SessDiskStore, which looks similar to FilesystemStore. Early analysis came to the mistaken conclusion that the vulnerable path was in FilesystemStore, but it's not. FilesystemStore authenticates the Session.ID with securecookie, SessDiskStore does not.

realizing how i have so much better password management than most of my direct acquaintances who literally work in infosec simply by self-hosting a seafile share that holds a key-locked keepass2 database rather than paying for a service

re mastodon.social/@Viss/11228855

TOMORROW YOU WILL GRAB THE SUN WITH BOTH HANDS AND DEVOUR IT. FOR NOW DOES YOUR BODY NEED STRETCHING?

Overheard one of my students complaining to another that " #chatgpt is useless for this course" and have never felt more pleased with myself.

Show older
Computer Fairies

Computer Fairies is a Mastodon instance that aims to be as queer, friendly and furry as possible. We welcome all kinds of computer fairies!