@generalx@freeradical.zone cover
@generalx@freeradical.zone avatar

generalx

@[email protected]

but most of all, @generalx is my hero

#privacy #security #foss #abolishICE #hacktheplanet

Toots reflect the views of my other employer

Header: lawyers Denise Heberle and Bill Goodman, in a PSA for the National Lawyers Guild ("NLG Know Your Rights Reminder")

Avatar: jack of hearts

Posts spontaneously combust except polls

This profile is from a federated server and may be incomplete. View on remote instance

@aral@mastodon.ar.al avatar aral , to random

Oh look, and Signal has just told me that Jack Dorsey has joined Signal.

(a) Signal telling people on your contacts that they’ve joined Signal is a privacy violation.

(b) When the fuck did I add Jack Dorsey’s number to my contacts? Must’ve been ages ago; don’t even remember meeting him back in the day but it’s possible I guess.

🤷‍♂️

CC @Mer__edith regarding point a.

generalx ,
@generalx@freeradical.zone avatar

@aral @Mer__edith
Someone in your phone's address book is using the name "Jack Dorsey" for their Signal account name.

That's all it means.

@generalx@freeradical.zone avatar generalx , to random

I don't trust syncthing-fork anymore.

  1. App ID changed with version 2.x, seemingly for no reason.

  2. catfriend1, the original maintainer has disappeared with no public announcement.

  3. Apparently the Play signing keys were transferred to a Github user with a 5 day old account.

  4. The old repo does redirect to this new user's repo.

It could be benign and another case of FOSS devs "moving on," quietly. But my paranoia prevails.

https://github.com/researchxxl/syncthing-android/issues/16

generalx OP ,
@generalx@freeradical.zone avatar

Reason 5: in July of this year, copilot-instructions.md appeared, and commits from GitHub Copilot were allowed.

Does @fdroidorg have a stance on the usage of Copilot or GenAI code?

https://github.com/researchxxl/syncthing-android/commits/main/.github/copilot-instructions.md

@aeva@mastodon.gamedev.place avatar aeva , to random

Suppose I wanted to throw a silent rave party some day, and said event would be open to anyone to attend provided they bring their own headphones and receiver.

What would be the best form of legal broadcast such that 1) the event could happen in a small park, 2) the required receiver is relatively easy to obtain, 3) the broadcast is heard relatively synchronously, and 4) doesn't require the attendees have a radio license, and 5) doesn't require me to have an expensive license?

generalx ,
@generalx@freeradical.zone avatar

@aeva

I instantly thought of drive-in theaters, a remnant of the past that hasn't fully left. Audio is usually broadcast over FM radio.

There appear to be some commercial "drive-in" options that appear to use WiFi and/or Bluetooth.

@briankrebs@infosec.exchange avatar briankrebs , to random

This is pretty wild. Checkout.com got hacked by a group that claims to be Shiny Hunters again. Checkout said in blog post that it would not be extorted by criminals.

"We will not pay this ransom.

Instead, we are turning this attack into an investment in security for our entire industry. We will be donating the ransom amount to Carnegie Mellon University and the University of Oxford Cyber Security Center to support their research in the fight against cybercrime."

Far too many victim firms just pay up, to get back to business as usual asap. Imagine if a fraction of those victims instead paid into a fund for research that actively disrupts these groups.

https://www.checkout.com/blog/protecting-our-merchants-standing-up-to-extortion

generalx ,
@generalx@freeradical.zone avatar

@briankrebs
Is this the same Carnegie Mellon University that (unethically) hacked Tor for the FBI? And allegedly received $1M for it?

(In that event, how is that any different from the FBI paying the likes of NSO Group or Paragon for hacking tools?)

Not sure I'd applaud Checkout, just yet.

@briankrebs@infosec.exchange avatar briankrebs , to random

Was searching my Signal contacts for something something "N" and found a contact I'd not noticed before: Note to Self. One of these days I will just RTFM.

"Who is Note to Self?

This contact entry is a chat to send messages to yourself.
Use this feature to jot down a note for yourself to review later or to share messages and files with your linked devices.
All messages in Note to Self are end-to-end encrypted Signal messages.
Yes, you can send disappearing messages to yourself. The timer starts immediately."

https://support.signal.org/hc/en-us/articles/360043272451-Note-to-Self

ALT
generalx ,
@generalx@freeradical.zone avatar

@briankrebs
With one phone number registered to Signal, have multiple people be set up as a linked device. Use Note to Self to communicate among the team. Who said what is not discernible.

@evacide@hachyderm.io avatar evacide , to random

There is a lot of demand for digital privacy and security advice out there right now and lots of people are giving advice and writing guides. I beg them to do a few things:

  1. Be explicit about the threat model your advice is meant for.

  2. Do not give advice you haven't tried implementing yourself. Eat your own dog food.

  3. Get feedback on your guide from your target audience before publication.

  4. Incorporate that feedback. This is not an optional step.

generalx ,
@generalx@freeradical.zone avatar

@evacide

The Feeling When that person you helped installs (or attempts to install) Tor Browser on their work laptop ;)

@FediTips@social.growyourown.services avatar FediTips , to random

Okay, some really bad news but also a suggestion for a way forward.

The Guppe groups domain name was sold by their registrar before they could renew it. This means all Guppe groups are broken, and their web addresses point to a spam blog 😞

However, there is another group provider called FediGroups, you can find out more on their site:

➡️ https://about.fedigroups.social/home

FediGroups has features that Guppe never had, including private groups.

(More info about situation: https://github.com/immers-space/guppe/issues/118 )

generalx ,
@generalx@freeradical.zone avatar

@FediTips @citronmecha @uc

Current registrant of gup.pe:

Registrant Name: cesar garcia
Admin Name: cesar garcia
Admin Email: [email protected]

Other .pe domains of theirs:
apec2016.pe
denuncias.net.pe
mitiempo.pe
oit.org.pe
poderciudadano.org.pe
somosempresa.pe
somosperu.org.pe
swisscontact.org.pe

generalx ,
@generalx@freeradical.zone avatar

@FediTips

Is FediGroups open source? Who's behind it? @hello

@jerry@infosec.exchange avatar jerry , to random

Oh look. Farmers Insurance takes the security of my data seriously.

generalx ,
@generalx@freeradical.zone avatar

@jerry @noondlyt 2 full years of free credit monitoring and premium increases? They really do take it serious!

@generalx@freeradical.zone avatar generalx , to random

In the past year, have you given money to the homeless that you see on the street?

@nixCraft@mastodon.social avatar nixCraft , to random

Finally somebody said it better 😅🤣

ALT
generalx ,
@generalx@freeradical.zone avatar

@nixCraft
I got a chuckle out of the post, but then I realized:

The joke's on us.

This is called marketing. He's posting that on the very platform he's complaining about. Isn't it engagement farming?

@ernie@writing.exchange avatar ernie , to random

So apparently we are within the last 60 days of dial-up AOL being a thing.

https://help.aol.com/articles/dial-up-internet-to-be-discontinued

ht @mattl

ALT
generalx ,
@generalx@freeradical.zone avatar

@APBBlue @ernie @mattl
"You've got mail"

generalx ,
@generalx@freeradical.zone avatar

@APBBlue @mattl @ernie
How can you not get excited about a new message with subject:

"FW: FW: RE: FW: FWD: RE: You won't believe this!"

@ai6yr@m.ai6yr.org avatar ai6yr , to random

Head's up, the "you must confirm your profile" scam is proliferating on the Fediverse. I wonder if they are trying to gather driver's licenses and credit card numbers? It's a scam.

ALT
generalx ,
@generalx@freeradical.zone avatar
vkc , to random

[Thread, post or comment was deleted by the author]

  • Loading...
  • generalx ,
    @generalx@freeradical.zone avatar

    @vkc
    I've never cared about X11 or Wayland either - give me tty1 or give me death.

    @georgetakei@universeodon.com avatar georgetakei , to random

    Resist Fascism.

    generalx ,
    @generalx@freeradical.zone avatar

    @georgetakei
    First reads:
    "Colleagues if you remain:
    Resist Fascism
    Remember the oath you vowed to uphold."

    Second reads:
    "Here sat America's experts on democracy, human rights (yes, which includes women's, LGBTQ+, & minorities' rights), election security, freedom of expression, privacy, on countering corruption, violent extremism and disinformation, and more. You've just released them and hundreds of their colleagues into the wild...in the United States of America."
    https://apnews.com/article/layoffs-diplomats-state-department-trump-rubio-bfdb86767b7bd5b6570819d404a7782e

    vkc , to random

    [Thread, post or comment was deleted by the author]

  • Loading...
  • generalx ,
    @generalx@freeradical.zone avatar

    @vkc
    rclone with a WebDAV remote (Nextcloud):
    https://rclone.org/webdav/

    @georgetakei@universeodon.com avatar georgetakei , to random

    That moment when Elon Musk’s AI starts speaking in the first person as Musk, then the answer gets deleted by…someone.

    generalx ,
    @generalx@freeradical.zone avatar

    @georgetakei

    Narrator: @ grok was Elon all along.

    @MikeDunnAuthor@kolektiva.social avatar MikeDunnAuthor , to random

    ICE's HSI unit conducted a raid at a popular restaurant in San Diego's South Park neighborhood. About 3 dozen agents, some in full tactical gear, arrested restaurant workers while patrons there and around the area were enjoying dinner. The federal agents didn't expect a resounding rejection by the neighbors and patrons. The community spontaneously protested the ICE agents. ICE discharged three flash-bang grenades to disperse the crowd. The people instead pushed ICE agents out of their community forcing the vehicles to retreat, shouting anti-fascist slogans. This is the way it should be everywhere.

    https://www.nbcsandiego.com/news/local/ice-operation-south-park-restaurant/3837341/

    ALT
    generalx ,
    @generalx@freeradical.zone avatar

    @PapyrusBrigade @MikeDunnAuthor
    I've hypothesized before that there is no standard wear for an ERO ICE Officer. If ERO has been relying on contractors like off-duty local law enforcement, it makes even more sense. Therefore we see the plainclothes officers - and the officers who seek to intimidate by dressing in full tactical and carrying long guns. They're buying costumes, in my opinion.

    @nixCraft@mastodon.social avatar nixCraft , to random

    you might miss on some good candidates with such a gatekeeping…

    ALT
    generalx ,
    @generalx@freeradical.zone avatar

    @nixCraft
    For "LinkedIn profile" I use:

    "linkedin.com"

    This way the recruiter thinks I may have pasted improperly and they'll probably put me in the "maybe" pile instead of the "no because no LinkedIn" pile.

    Hack the recruitment planet, folks.

    @generalx@freeradical.zone avatar generalx , to random

    Here's a helpful site showing companies to avoid during your job search:

    https://aijobs.net

    generalx OP ,
    @generalx@freeradical.zone avatar

    I almost applied to a job until I noticed all postings contain:

    "Thanks to products like Duo Enterprise, and Duo Workflow, customers get the benefit of AI at every stage of the SDLC. The same principles built into our products are reflected in how our team works: we embrace as a core productivity multiplier. All team members are encouraged and expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact across our global organisation"

    Yuck.

    generalx OP ,
    @generalx@freeradical.zone avatar

    How can one be both "encouraged" and "expected"...to use AI?

    Don't lie. Just say it's expected.

    vkc , to random

    [Thread, post or comment was deleted by the author]

  • Loading...
  • generalx ,
    @generalx@freeradical.zone avatar

    @vkc @goofpunk
    The rules (based on vibes) are to:

    Complain about Twitter posts on Bluesky & Mastodon

    Complain about Bluesky posts on Mastodon

    Complain about Mastodon post on the wider fediverse

    But in seriousness, misinformation was meant to thrive on social media. It's just harder to go viral here, I think.

    @jerry@infosec.exchange avatar jerry , to random

    I rather like the new VMWare logo

    generalx ,
    @generalx@freeradical.zone avatar

    @jerry
    ESX Eye

    @Impossible_PhD@hachyderm.io avatar Impossible_PhD , to random

    The article I write for my campus newspaper is out. Have a read, if you want.

    It's called Governed by Terror, a phrase drawn form the definition of state-sponsored terrorism.

    Because I wasn't always afraid to go to work.

    https://fsutorch.com/2025/04/30/governed-by-terror/

    generalx ,
    @generalx@freeradical.zone avatar

    @Impossible_PhD
    "451 Unavailable For Legal Reasons

    Sorry, this content is not available in your region."

    Why?

    generalx ,
    @generalx@freeradical.zone avatar

    @Impossible_PhD looks like the publisher (Hearst) has a geoblock which might be blocking viewers without a USA location (based on IP address).

    https://web.archive.org/web/20250501150214/https://fsutorch.com/2025/04/30/governed-by-terror/

    generalx ,
    @generalx@freeradical.zone avatar

    @Impossible_PhD great article, but it's a shame the publisher blocks an international audience.

    vkc , to random

    [Thread, post or comment was deleted by the author]

  • Loading...
  • generalx ,
    @generalx@freeradical.zone avatar

    @vkc you did, but the person you called was moving fast and the line kept breaking up.

    @w7voa@journa.host avatar w7voa , to random

    Amazon denies the Punchbowl News report that it plans to display how much Trump tariffs add to the price of each product on the e-commerce platform.

    generalx ,
    @generalx@freeradical.zone avatar

    @w7voa

    1. Leak a proposed move
    2. Wait for comments
    3. If resistance to move exists, deny that it was to happen
    @jerry@infosec.exchange avatar jerry , (edited ) to random

    What is your favorite remote access software?

    generalx ,
    @generalx@freeradical.zone avatar

    @jerry a reverse shell.

    @evacide@hachyderm.io avatar evacide , to random

    I see that I'm in for another week of explaining that end-to-end encryption will not fix stupid.

    generalx ,
    @generalx@freeradical.zone avatar

    @evacide he's Secretary of Defense, so he probably assumed offensive strike info was allowed on Signal.

    @hacks4pancakes@infosec.exchange avatar hacks4pancakes , to random

    Just perpetually tired seeing how bad the default advice seniors give juniors about cybersecurity careers is on Reddit. They mean well, but didn’t have to fight this market.

    generalx ,
    @generalx@freeradical.zone avatar

    @jerry @hacks4pancakes and this is why we end up with APTs (advanced persistent teens).

    @stux@mstdn.social avatar stux , to random

    Let this sink in..

    The government of the US and El Salvador are making people disapear

    Without trail, without evidence

    They "cannot" and will not reverse anything even knowing what they're doing is wrong, big time

    These so called "Presidents" can make anyone disappear but cannot return them

    generalx ,
    @generalx@freeradical.zone avatar

    @stux can these Presidents make themselves disappear? Problem solved!

    @nixCraft@mastodon.social avatar nixCraft , to random

    Step 1. Put on a black hoodie.
    Step 2. Go to the cafe.
    Step 3. Take out your laptop.
    Step 4. Open a terminal window.
    Step 5. Run the htop command and yell from the bottom of your stomach, "I'M IN!"

    generalx ,
    @generalx@freeradical.zone avatar

    @nixCraft
    ls -lR /

    @briankrebs@infosec.exchange avatar briankrebs , to random

    Wow. The tech and NASDAQ giant NVIDIA's shares have tanked in after hours trading, down 7 percent right now. Might have something to do with this disclosure:

    "On April 9, 2025, the U.S. government, or USG, informed NVIDIA Corporation, or the Company, that the USG requires a license for export to China (including Hong Kong and Macau) and D:5 countries, or to companies headquartered or with an ultimate parent therein, of the Company's H20 integrated circuits and any other circuits achieving the H20's memory bandwidth, interconnect bandwidth, or combination thereof. The USG indicated that the license requirement addresses the risk that the covered products may be used in, or diverted to, a supercomputer in China. On April 14, 2025, the USG informed the Company that the license requirement will be in effect for the indefinite future.

    The Company's first quarter of fiscal year 2026 ends on April 27, 2025. First quarter results are expected to include up to approximately $5.5 billion of charges associated with H20 products for inventory, purchase commitments, and related reserves."

    Expect an extra wild ride on Wall Street when the bell rings tomorrow.

    A graphic from Google showing NVIDIA Corp. stock price tanking in after hours trading.

    ALT
    generalx ,
    @generalx@freeradical.zone avatar

    @briankrebs "THIS IS A GREAT TIME TO BUY!!! DJT"

    @stux@mstdn.social avatar stux , to random

    This is why we don’t need in

    ALT
    generalx ,
    @generalx@freeradical.zone avatar

    @stux looks like a Ram pickup truck, maybe long bed. In the US, the Raptor and Ram truck owners don't even try to fit in a single space...so at least this person gave it some effort!

    @deviantollam@defcon.social avatar deviantollam , to random

    The phrase "100% undetectable monitoring" should only appear in emails from a company that makes medical devices for diabetics or an early warning solution focused on structure fires. Not smartphone software. 😒

    @evacide I woke up to this email today. I am displeased.

    Is there any angle by which I can turn this into something good?

    Is this a spyware product deserving of unpacking or analysis, and if I led these people on and got free licenses or something out of it would that help any researchers at EFF or elsewhere to dissect it?

    ALT
    generalx ,
    @generalx@freeradical.zone avatar

    @evacide @deviantollam another question to ask about stalkerware: has @maia blogged about it [yet]?

    @nixCraft@mastodon.social avatar nixCraft , to random

    How people react when critical vulnerability announced in a popular Foo app

    • What do privacy/security-minded people hear? Run as far as possible from Foo app.

    • What stock market people do? Buy more Foo app stock.

    • Ordinary public: I don't care as long as the job gets done using Foo app

    • What bad guys do? Hack as many systems loaded with Foo app & steal personal data.

    • What does a three-letter agency think about Foo app? Good. Good. Let them install Foo app. It will make our job easy.

    generalx ,
    @generalx@freeradical.zone avatar

    @nixCraft
    and FooApp software developers: WONTFIX

    @evacide@hachyderm.io avatar evacide , to random

    So much of cybersecurity is "We must secure the Orphan Crushing Machine so that unauthorized people do not crush the orphans," and not "Why the fuck are you building an Orphan Crushing Machine in the first place?"

    generalx ,
    @generalx@freeradical.zone avatar

    @evacide
    s/so that unauthorized people do not crush orphans/so that unauthorized people cannot stop orphan crushing/

    @w7voa@journa.host avatar w7voa , to random

    CBS - SCOTUS agrees to halt a lower court order that required six federal agencies to rehire more than 16,000 probationary workers who had been fired. https://www.cbsnews.com/news/supreme-court-trump-probationary-workers/

    generalx ,
    @generalx@freeradical.zone avatar

    @w7voa this is what Chief Justice Roberts meant when he responded to Trump's call to impeach judges: "let us handle it."

    @dnsprincess@infosec.exchange avatar dnsprincess , to random

    Okay, it's finally time to admit it...

    I'm on the job search.

    I'm really struggling with self-worth. I've made it pretty far in some interviews, but haven't landed a job. I've been cut for internal candidates or other things.

    It's been really rough. I have a dog to provide for... and I need healthcare.

    I've done so much in cybersecurity. Anti-fraud SOC, teaching, sales, consulting, and more.

    I've applied to over 200+ jobs and feel like I'm getting nowhere. That's why I've been so down lately.

    Wish me luck on my upcoming opportunities...

    generalx ,
    @generalx@freeradical.zone avatar

    @dnsprincess you probably see me as another rando getting in on this trending post...but I've been to your talks at security cons. You are more than qualified. Keep looking.

    @w7voa@journa.host avatar w7voa , to random

    Awaiting reaction from the residents of the Heard and McDonald Islands after the US today imposed a 10% reciprocal tariff on products from the volcanic territory between Madagascar and Antarctica. Might be waiting a bit -- apparently the total human population is (double checks notes)...zero.

    image/png

    generalx ,
    @generalx@freeradical.zone avatar

    @w7voa didn't you hear? The McDonald Island volcano responded to the tariffs by erupting, after 75,000 years of dormancy.

    @evacide@hachyderm.io avatar evacide , to random

    In case you are wondering why my public PGP key is expired, it is because I would like to discourage people from sending me PGP-encrypted email. The number of times I have had people send me mail in the clear that they appear to have thought was encrypted is NOT SMALL.

    generalx ,
    @generalx@freeradical.zone avatar

    @evacide Awesome! Base64 encryption is easier.

    @jerry@infosec.exchange avatar jerry , to random

    The US Constitution didn’t have a complete set of test cases written before it was released.

    generalx ,
    @generalx@freeradical.zone avatar

    @jerry even if it did, this administration would fire all the test engineers.

    @briankrebs@infosec.exchange avatar briankrebs , to random

    My name keeps getting mentioned in Top 10 infosec influencers lists, or Top[arbitrary number here] security professionals to follow. Here's the thing: The group responsible for all these "awards" has tried to get me to participate in their group activities (podcast interviews, etc. I always decline or ignore). But near as I can tell their top people lists have mostly the same people on them that have somewhat thin backgrounds in the cybers. So it seems to be some kind of circular promotion thing, possibly of the paid variety, which is not something I want to be associated with.

    Some people say any publicity is good publicity, but I've never believed that. My instinct as I see these "awards" parroted by the people listed in them is to dig deeper into who the awards givers are. But in the meantime, my inclination is to send a polite note asking them to please not include me in their lists.

    Is that a dick move? What would you do?

    generalx ,
    @generalx@freeradical.zone avatar

    @briankrebs
    At the end of the day, it's SEO for those who need it. Krebs doesn't need it.