<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-13T20:51:37Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Tod Beardsley</title>
  <author>
    <name>Tod Beardsley</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1qzuk6k5w9ajvltt2f56pgy52uwddsf53ngmzqza6g9367jyc8cmsc6rvyk.rss" />
  <link href="https://yabu.me/npub1qzuk6k5w9ajvltt2f56pgy52uwddsf53ngmzqza6g9367jyc8cmsc6rvyk" />
  <id>https://yabu.me/npub1qzuk6k5w9ajvltt2f56pgy52uwddsf53ngmzqza6g9367jyc8cmsc6rvyk</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/258/798/902/039/585/original/104b3304b7b270b0.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/258/798/902/039/585/original/104b3304b7b270b0.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsz2kkujvn9yrthkd0g7l6zxv49v7xfueu50s9tu8wkkqve8ptdwlqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw3uywpd</id>
    
      <title type="html">Breaking news: Max Headroom, one of the greatest TV shows ever ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz2kkujvn9yrthkd0g7l6zxv49v7xfueu50s9tu8wkkqve8ptdwlqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw3uywpd" />
    <content type="html">
      Breaking news: Max Headroom, one of the greatest TV shows ever made, is free on Tubi.&lt;br/&gt;&lt;br/&gt;I find the terrible Tubi ads really enhance the dystopia.
    </content>
    <updated>2026-02-21T02:41:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspjdvtnkeex20a6ucq9pzg2cxh86ph83gp6l757ptv2a0n64t4eeczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwwcfy80</id>
    
      <title type="html">Computers are great. What a time to be alive. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspjdvtnkeex20a6ucq9pzg2cxh86ph83gp6l757ptv2a0n64t4eeczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwwcfy80" />
    <content type="html">
      Computers are great. What a time to be alive.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/974/184/007/001/807/original/521518d781c7e59b.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-01-28T18:40:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs263l2fl2ywkqfrd54pysegwnsr5347pecc3p0q860f4cyva3j9tczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwmcvn7f</id>
    
      <title type="html">January 1 came and went and Texas’s AI regulation went into ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs263l2fl2ywkqfrd54pysegwnsr5347pecc3p0q860f4cyva3j9tczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwmcvn7f" />
    <content type="html">
      January 1 came and went and Texas’s AI regulation went into effect.&lt;br/&gt;&lt;br/&gt;There are a couple things to like about Texas’s attempt here. There are many things to dislike.&lt;br/&gt;&lt;br/&gt;One aspect in particular: The definition of AI seems to cover just about any software application, right?&lt;br/&gt;&lt;br/&gt;&amp;gt; TRAIGA broadly defines an “artificial intelligence system” as “any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.”&lt;br/&gt;&lt;br/&gt;Maybe it’s the legalese, but I’m trying to figure out what machine-based system doesn’t function like this. Does it all hinge on “infer” rather than another verb like “calculate?”&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.gtlaw.com/en/insights/2025/6/traiga-key-provisions-of-texas-new-artificial-intelligence-governance-act&#34;&gt;https://www.gtlaw.com/en/insights/2025/6/traiga-key-provisions-of-texas-new-artificial-intelligence-governance-act&lt;/a&gt;
    </content>
    <updated>2026-01-12T13:23:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdtxgn2z65l9xrnrly07q8c50guauz0edc9yfg8vpwaqkylyx57xszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwd5d9dz</id>
    
      <title type="html">This bit makes me think it’s a different bug: “Users who ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdtxgn2z65l9xrnrly07q8c50guauz0edc9yfg8vpwaqkylyx57xszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwd5d9dz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9wgss432ej67rm9yeh6u7znaj9cjs4r4pncjs0lx7fns68m88whc3zwlkh&#39;&gt;nevent1q…wlkh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This bit makes me think it’s a different bug:&lt;br/&gt;&lt;br/&gt;“Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to &amp;gt;= 3.2.2 would still be vulnerable.”&lt;br/&gt;&lt;br/&gt;Sounds like two different vectors. Incomplete fixes often lead to multiple CVEs, a la rule 4.1.10: “To help determine whether separate Vulnerabilities exist, CNAs SHOULD consider whether the Vulnerabilities are Independently Fixable.”
    </content>
    <updated>2025-12-08T13:43:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszldd2lxgv7t207hnl9d709y83yljpl7r8dyfc9lule0k3ka8l89czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrww2xul4</id>
    
      <title type="html">I just noticed that ../ looks like eyes and an outreaching arm, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszldd2lxgv7t207hnl9d709y83yljpl7r8dyfc9lule0k3ka8l89czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrww2xul4" />
    <content type="html">
      I just noticed that ../ looks like eyes and an outreaching arm, as if it&amp;#39;s a victim drowning in quicksand.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m sure this is trenchant, somehow. cc &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1s6eewzr2zvz3ppsa6k8j2hadamsug7q4rp068wmz3grtf440xxkqr8n008&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;cR0w :cascadia: :gayint: 🏴‍☠️&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1s6e…n008&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-11-14T21:08:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswalqc3hsddgkqp9qtnxqtkvazcsuexd4438pxlr3aa809s3956vczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw7el8ww</id>
    
      <title type="html">Hey y&amp;#39;all don&amp;#39;t sleep on this one. **Agency Information ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswalqc3hsddgkqp9qtnxqtkvazcsuexd4438pxlr3aa809s3956vczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw7el8ww" />
    <content type="html">
      Hey y&amp;#39;all don&amp;#39;t sleep on this one.&lt;br/&gt;&lt;br/&gt;**Agency Information Collection Activities: Vulnerability Reporting Submission Form**&lt;br/&gt;&lt;br/&gt;#CISA wants to know what your ideal vulnerability reporting system would look like.&lt;br/&gt;&lt;br/&gt;&amp;#34;CISA previously published this ICR in the Federal Register on October 30, 2024, for a 60-day public comment period. **CISA received one comment.** The purpose of this notice is to allow an additional 30-days for public comments.&amp;#34;&lt;br/&gt;&lt;br/&gt;Man, remember October, 2024? Things were looking pretty great back then. What a time to be alive.&lt;br/&gt;&lt;br/&gt;Anyway, thanks for the extension, Kevin, ya big lug!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.federalregister.gov/documents/2025/08/20/2025-15887/agency-information-collection-activities-vulnerability-reporting-submission-form&#34;&gt;https://www.federalregister.gov/documents/2025/08/20/2025-15887/agency-information-collection-activities-vulnerability-reporting-submission-form&lt;/a&gt;
    </content>
    <updated>2025-08-21T04:53:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg3t2ej2gcayrup2dp0khrc02k8jsgwnctryz92msru9jerawhq4qzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw2q9eeq</id>
    
      <title type="html">#defcon badge fixed ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg3t2ej2gcayrup2dp0khrc02k8jsgwnctryz92msru9jerawhq4qzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw2q9eeq" />
    <content type="html">
      #defcon badge fixed&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/993/913/117/946/899/original/87b891873549d1d8.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-08T15:44:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvyrt6g6qwn7qgauq84uu7nsjna0s4sega7qv78546fll6yqvja3gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw4rxmdj</id>
    
      <title type="html">Last night at about 11:30pm, I took a practice ham radio ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvyrt6g6qwn7qgauq84uu7nsjna0s4sega7qv78546fll6yqvja3gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw4rxmdj" />
    <content type="html">
      Last night at about 11:30pm, I took a practice ham radio Technician test. I fell asleep twice. I guessed most answers (I know jack all about radio, slightly more about electrical engineering). I got 63%.&lt;br/&gt;&lt;br/&gt;I suspect I can study up enough in time to pass a the exam at &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1dqdh3ta2uxg4wz5qf7h6j0qywrxryzcyjw4vhq0n0alu83d6mgnsxm8xy4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;DEF CON&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1dqd…8xy4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; ham .&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://hamvillage.org&#34;&gt;https://hamvillage.org&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Thanks to That Texas Country Music Guy at DC512 for encouraging this side quest!
    </content>
    <updated>2025-07-21T17:46:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9r84tjes6496e5f42typm0de2fly6lnqdmy0lm9ssc024kwzudgqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwq9u7g9</id>
    
      <title type="html">It&amp;#39;s not just me, right? Post-quantum crytography aka #PQC, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9r84tjes6496e5f42typm0de2fly6lnqdmy0lm9ssc024kwzudgqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwq9u7g9" />
    <content type="html">
      It&amp;#39;s not just me, right? Post-quantum crytography aka #PQC, especially quantum-resistant cryptography, smells an awful lot like snake oil.&lt;br/&gt;&lt;br/&gt;I cannot figure out how people sell this stuff with apparent sincerity when it&amp;#39;s clearly impossible to test in production.
    </content>
    <updated>2025-06-09T18:58:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszw252jutxa6c8e9xre7exfh4rrp38qgqf0jfd0xza5lduqaez48czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwqssdhk</id>
    
      <title type="html">Say, what&amp;#39;s the first major-release film to mention either ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszw252jutxa6c8e9xre7exfh4rrp38qgqf0jfd0xza5lduqaez48czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwqssdhk" />
    <content type="html">
      Say, what&amp;#39;s the first major-release film to mention either &amp;#34;the internet&amp;#34; or &amp;#34;the world wide web?&amp;#34;&lt;br/&gt;&lt;br/&gt;(Or, alternatively, &amp;#34;DNS&amp;#34; or &amp;#34;SMTP&amp;#34; or &amp;#34;TCP/IP&amp;#34; or other uniquely internet technology, though that seems doubtful.)&lt;br/&gt;&lt;br/&gt;And I mean mention as in, either in dialogue or printed and shown on screen in a newspaper or something.&lt;br/&gt;&lt;br/&gt;There&amp;#39;s a kind of [annoying reddit thread](&lt;a href=&#34;https://www.reddit.com/r/movies/comments/o98hkx/what_was_the_earliest_reference_to_the_internet/&#34;&gt;https://www.reddit.com/r/movies/comments/o98hkx/what_was_the_earliest_reference_to_the_internet/&lt;/a&gt; ) about this that&amp;#39;s not very helpful and is fixated on WarGames which definitely doesn&amp;#39;t talk about the internet (all the comms in that movie are over dialup).&lt;br/&gt;&lt;br/&gt;A timestamp reference would be just great if you have it.
    </content>
    <updated>2025-05-24T01:33:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqr3q8grvkk7ddwxxqx7ztu9ha6j6f7xlxf50at6n0d7e37gz578qzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwkyr608</id>
    
      <title type="html">#CISA adds CVE-2025-47729 to the #KEV -- which is for the crazy ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqr3q8grvkk7ddwxxqx7ztu9ha6j6f7xlxf50at6n0d7e37gz578qzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwkyr608" />
    <content type="html">
      #CISA adds CVE-2025-47729 to the #KEV -- which is for the crazy hacked up version of Signal used by high-ranking US government officials.&lt;br/&gt;&lt;br/&gt;Wowzo. That&amp;#39;s something.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.cve.org/CVERecord?id=CVE-2025-47729&#34;&gt;https://www.cve.org/CVERecord?id=CVE-2025-47729&lt;/a&gt;
    </content>
    <updated>2025-05-12T19:10:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqasjzgnhqw96p6r4mpmh92phr7rnd9mla2nrc3rjkeyk4p6mkraszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwuuzwsg</id>
    
      <title type="html">#CISA ends RSS for #KEV. Sigh. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqasjzgnhqw96p6r4mpmh92phr7rnd9mla2nrc3rjkeyk4p6mkraszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwuuzwsg" />
    <content type="html">
      #CISA ends RSS for #KEV. Sigh.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.cisa.gov/news-events/alerts/2025/05/12/update-how-cisa-shares-cyber-related-alerts-and-notifications&#34;&gt;https://www.cisa.gov/news-events/alerts/2025/05/12/update-how-cisa-shares-cyber-related-alerts-and-notifications&lt;/a&gt;
    </content>
    <updated>2025-05-12T15:56:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2xfx8zy4fhnsu9792fur58w0lvsed5zc27y7rerea47f2f0th2lqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwevx7ls</id>
    
      <title type="html">so close #CISA. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2xfx8zy4fhnsu9792fur58w0lvsed5zc27y7rerea47f2f0th2lqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwevx7ls" />
    <content type="html">
      so close #CISA.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/468/070/726/514/583/original/45a5c3c24bb620d6.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-07T18:56:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy37tmysvtna8dq4mypg0804xp872udh24fk7s0efh37dulxqancqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwh6g08e</id>
    
      <title type="html">Welp. Let’s see which way this room goes. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy37tmysvtna8dq4mypg0804xp872udh24fk7s0efh37dulxqancqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwh6g08e" />
    <content type="html">
      Welp. Let’s see which way this room goes.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/423/125/242/360/613/original/a4ac9c38051802f3.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-29T20:25:35Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdanh0gckqhvz63cpp2tn8j5k8r2lzjzxf39p34pkwakzutw8k50gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw0qch8y</id>
    
      <title type="html">The linked article doesn’t appear to mention the Internet ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdanh0gckqhvz63cpp2tn8j5k8r2lzjzxf39p34pkwakzutw8k50gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw0qch8y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0cst02xxuf54vlscu9m59aqjd0cmk5l8wn5j68gd3zqmh0aea88qjf8v7g&#39;&gt;nevent1q…8v7g&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The linked article doesn’t appear to mention the Internet Archive.&lt;br/&gt;&lt;br/&gt;It doesn’t make the NEH cancellations any less tragic, but I don’t see the linked article drawing a link between the San Francisco Art Institute, which does perform archiving functions, and The Internet Archive.&lt;br/&gt;&lt;br/&gt;Are they connected?
    </content>
    <updated>2025-04-21T12:59:02Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs07n4vvwm247yvjl3lgj8rwzfkt0cmuvkx79vat27zq50qn39fweszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw4q0pml</id>
    
      <title type="html">l feel like i’m going to be using this a lot ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs07n4vvwm247yvjl3lgj8rwzfkt0cmuvkx79vat27zq50qn39fweszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw4q0pml" />
    <content type="html">
      l feel like i’m going to be using this a lot&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/345/087/526/277/853/original/b59dc3f1a3157fc0.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-04-16T01:39:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2zj33ln72vnsxjgss7unr253c5rhdtzkp75695hsqgpha0pvsfxgzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw74c5za</id>
    
      <title type="html">Trying to articulate levels of invasiveness with typical network ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2zj33ln72vnsxjgss7unr253c5rhdtzkp75695hsqgpha0pvsfxgzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw74c5za" />
    <content type="html">
      Trying to articulate levels of invasiveness with typical network scanning with metaphors that don&amp;#39;t come with the implied violence of &amp;#34;rattling doorknobs.&amp;#34; &lt;br/&gt;&lt;br/&gt;How&amp;#39;s this grab you:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Port Scanning - Waving at passersby, seeing who waves back.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Protocol Scanning - Waving and saying &amp;#34;Good morning,&amp;#34; noting if the reply is in English, Spanish, or something else.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Vulnerability Scanning - Chatting up strangers to see if they&amp;#39;ll reveal their birthday.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Active Exploitation - Hypnotizing victims into handing over their ATM card and PIN.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;
    </content>
    <updated>2025-02-14T18:24:11Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv7rxa7wygk0ypec0760kclkewcx49z76acadj03uy8tf3t7grtrszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwxvvuhg</id>
    
      <title type="html">Archived version of the quoted The Atlantic article is here: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv7rxa7wygk0ypec0760kclkewcx49z76acadj03uy8tf3t7grtrszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwxvvuhg" />
    <content type="html">
      Archived version of the quoted The Atlantic article is here:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://archive.ph/2025.02.07-140733/https://www.theatlantic.com/technology/archive/2025/02/elon-musk-doge-security/681600/&#34;&gt;https://archive.ph/2025.02.07-140733/https://www.theatlantic.com/technology/archive/2025/02/elon-musk-doge-security/681600/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Unrelated: If you believe there has been an intrusion in a US government system, you are encouraged to report it at &lt;a href=&#34;https://cisa.gov/report&#34;&gt;https://cisa.gov/report&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://journa.host/@w7voa/113963205109936094&#34;&gt;https://journa.host/@w7voa/113963205109936094&lt;/a&gt;
    </content>
    <updated>2025-02-07T15:39:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrafnpy98qhacqqff359es8vghpzuaucnzntwl9xhjy6q92gtrs9gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwruqy83</id>
    
      <title type="html">So check it out. KEV data is now available on GitHub, in the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrafnpy98qhacqqff359es8vghpzuaucnzntwl9xhjy6q92gtrs9gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwruqy83" />
    <content type="html">
      So check it out. KEV data is now available on GitHub, in the proper cisagov organization. I know other people mirror KEV for their projects, but who can say if they&amp;#39;re fiddling with it along the way? With &lt;a href=&#34;https://github.com/cisagov/kev-data&#34;&gt;https://github.com/cisagov/kev-data&lt;/a&gt;, you can rest assured that it&amp;#39;s the Real and True mirror of KEV.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://cisa.gov/kev&#34;&gt;https://cisa.gov/kev&lt;/a&gt; is still the actual authoritative source, but this GitHub mirror is a pretty close second.&lt;br/&gt;&lt;br/&gt;I posted about this on [LinkedIn](&lt;a href=&#34;https://www.linkedin.com/posts/todb_github-build-and-ship-software-on-a-single-activity-7290122220230623234-q92i?utm_source=share&amp;amp;utm_medium=member_desktop&#34;&gt;https://www.linkedin.com/posts/todb_github-build-and-ship-software-on-a-single-activity-7290122220230623234-q92i?utm_source=share&amp;amp;utm_medium=member_desktop&lt;/a&gt; ) since that&amp;#39;s what people do with work stuff, apparently.
    </content>
    <updated>2025-01-28T21:49:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0tqtyj8cccm49e7ptdmk88psyjhkeeqsstj60jgqt6ks04llkmwgzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwuvw7dh</id>
    
      <title type="html">98 KEVs to go until KEV #1337 Hopefully it&amp;#39;ll be a good one.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0tqtyj8cccm49e7ptdmk88psyjhkeeqsstj60jgqt6ks04llkmwgzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwuvw7dh" />
    <content type="html">
      98 KEVs to go until KEV #1337&lt;br/&gt;&lt;br/&gt;Hopefully it&amp;#39;ll be a good one.
    </content>
    <updated>2025-01-02T16:44:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr6e0a4zfw8slh3ghhek2ld2ma3xtzvz9g7cx7vrasjzhtxu0800czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwf5jch0</id>
    
      <title type="html">Near as I can tell, the activity around the #Struts2 bug, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr6e0a4zfw8slh3ghhek2ld2ma3xtzvz9g7cx7vrasjzhtxu0800czyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwf5jch0" />
    <content type="html">
      Near as I can tell, the activity around the #Struts2 bug, &lt;br/&gt;CVE-2024-53677, is just ham-handed runs of some generalized PoC, and nobody&amp;#39;s actually exploiting this yet (since exploitation would be very application/path specific).&lt;br/&gt;&lt;br/&gt;Most of the news last week was all &amp;#34;exploitation happening, patch and rewrite everything now!&amp;#34; but not seeing any reports of successful (or even possibly successful) this morning.&lt;br/&gt;&lt;br/&gt;Tell me I&amp;#39;m wrong!&lt;br/&gt;&lt;br/&gt;(The PoC identified by SANS at &lt;a href=&#34;https://isc.sans.edu/diary/31520&#34;&gt;https://isc.sans.edu/diary/31520&lt;/a&gt; isn&amp;#39;t specific to some particular application -- it&amp;#39;s on the user to define upload_endpoint and assumes no auth or session or anything.)
    </content>
    <updated>2024-12-23T13:52:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy5un8z7radeuwe8xqye2z23tw40kacqqj0u3kjeku46h3hytz8nqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwsl96l5</id>
    
      <title type="html">That’s a nice bit of CVE lore! We should make these more ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy5un8z7radeuwe8xqye2z23tw40kacqqj0u3kjeku46h3hytz8nqzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwsl96l5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsytuhna977q6srd5kzgr53k6fc46gzksvaek06nyl540lkfzlqsaqjs4kpe&#39;&gt;nevent1q…4kpe&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That’s a nice bit of CVE lore! We should make these more obvious and prominent than a single blog post. &lt;br/&gt;&lt;br/&gt;And yes, having a small set of always-valid-but-test CVEs would be nice to publish. That’s a neat idea. &lt;br/&gt;&lt;br/&gt;Hey would it be cool to make them Luhn-formula-like so you can detect truncation?&lt;br/&gt;&lt;br/&gt;Something like&lt;br/&gt;&lt;br/&gt;CVE-2024-12342&lt;br/&gt;CVE-2025-12343&lt;br/&gt;CVE-2026-12340&lt;br/&gt;&lt;br/&gt;(all the digits add up to modulo 0)&lt;br/&gt;&lt;br/&gt;cc &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1wug9fkx7va4z2glakhnf056u9fj74e2y7u858v7sj7cgp4eav6ys5nghe4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;zmanion :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1wug…ghe4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2024-12-01T14:59:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0lkw0nea8gzgxmas4d3znlv3fnvze032lgyp0d0tjzygwd8l8k8gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw2dk6hr</id>
    
      <title>Nostr event nevent1qqs0lkw0nea8gzgxmas4d3znlv3fnvze032lgyp0d0tjzygwd8l8k8gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw2dk6hr</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0lkw0nea8gzgxmas4d3znlv3fnvze032lgyp0d0tjzygwd8l8k8gzyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw2dk6hr" />
    <content type="html">
      I’m not pirating movies, I’m just training my model.
    </content>
    <updated>2024-11-27T23:53:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0nqg2um4t7llqg06p0p69wkew4pvvtpp0vtfal5wvgmm9w4ze9tszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwyh5hyl</id>
    
      <title type="html">Weirdly, all NCSC employees also have licenses to kill. Seems a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0nqg2um4t7llqg06p0p69wkew4pvvtpp0vtfal5wvgmm9w4ze9tszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwyh5hyl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvsjhwyg8cwkx6xt35sya84xdh4vwgqyylcxp4xjqvntfns0nk3xqde8rv0&#39;&gt;nevent1q…8rv0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Weirdly, all NCSC employees also have licenses to kill. Seems a little excessive.
    </content>
    <updated>2024-10-15T17:43:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxnjxwnfmez3ft7vxldccska32nvdrzzemfsa6kte3fdnyc9z2a9szyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwjt7ywq</id>
    
      <title type="html">depends on what you’re testing though doesn’t it? Sounds like ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxnjxwnfmez3ft7vxldccska32nvdrzzemfsa6kte3fdnyc9z2a9szyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwjt7ywq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdpnv84fck7kx23ett9g2dgx5tjnuewjugrq7rcmywf7kftqg6m7srduw5x&#39;&gt;nevent1q…uw5x&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;depends on what you’re testing though doesn’t it?&lt;br/&gt;&lt;br/&gt;Sounds like DNS CNAME &#43; Apache vhosts is the way to go. Mastodon apparently doesn’t do well with non-443 since fediverse things all assume 443 is where it’s at. &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/mastodon/mastodon/discussions/20279&#34;&gt;https://github.com/mastodon/mastodon/discussions/20279&lt;/a&gt;
    </content>
    <updated>2024-10-15T00:07:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspfn6gj4gm6nqy5l664lryesj4ukvz2lucngxvx64d63qjfslydjszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwec43zn</id>
    
      <title type="html">Man. The archive.org outage is really chapping my hide. Good job, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspfn6gj4gm6nqy5l664lryesj4ukvz2lucngxvx64d63qjfslydjszyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwec43zn" />
    <content type="html">
      Man. The archive.org outage is really chapping my hide. Good job, jerks.&lt;br/&gt;&lt;br/&gt;Hey &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1wug9fkx7va4z2glakhnf056u9fj74e2y7u858v7sj7cgp4eav6ys5nghe4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;zmanion :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1wug…ghe4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; we should think about reviving the CVE reference archival effort again. It&amp;#39;s almost as if someone predicted this exact circumstance.&lt;br/&gt;&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1umd6j4jrnjqdvn9kqttvsgxwzw38s92zn2lsuq0d73neh7mjxa3sa8wfr7&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;internetarchive&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1umd…wfr7&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; , good luck.
    </content>
    <updated>2024-10-11T18:50:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg2m69mvx3vyevumv5wv4wy4t20jwrwlhqd9z0ehvxsfawlk5yvwczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw6pv74j</id>
    
      <title type="html">Agreed. 2FA is becoming a real disappointment.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg2m69mvx3vyevumv5wv4wy4t20jwrwlhqd9z0ehvxsfawlk5yvwczyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrw6pv74j" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfx4f0vkcwsmgsn0pw9qzkfjl6p030v3n0q86hmt894ywjar97ukq3g7eta&#39;&gt;nevent1q…7eta&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Agreed. 2FA is becoming a real disappointment.
    </content>
    <updated>2024-09-04T01:16:56Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspzeyxl3ju8xk60upeyly8f8pv4njy3ft2danrneyfpfsyxn4j82szyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwurhclq</id>
    
      <title type="html">So this is neat. 1) Some (all?) antispam/counterphishing email ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspzeyxl3ju8xk60upeyly8f8pv4njy3ft2danrneyfpfsyxn4j82szyqqtjm263chkfnaddfxng9qj3t3e4kpxjxdrvgqthfqk8t6gnqlrwurhclq" />
    <content type="html">
      So this is neat.&lt;br/&gt;&lt;br/&gt;1) Some (all?) antispam/counterphishing email scanners are blind to #QRCode content. &lt;br/&gt;&lt;br/&gt;2) You can draw working QRCodes with Unicode character sets, thus avoiding an image parser entirely, even if the scanner could process images in the first place. &lt;br/&gt;&lt;br/&gt;3) By providing QRCode links, the attacker encourages the victim to use their personal device rather than the workstation, making defensive tracking more complicated.&lt;br/&gt;&lt;br/&gt;I think it’s hilarious that a format designed SPECIFICALLY for machine vision is being used to evade machine interpretation.&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@patrickcmiller/113067302631450126&#34;&gt;https://infosec.exchange/@patrickcmiller/113067302631450126&lt;/a&gt;
    </content>
    <updated>2024-09-02T13:39:28Z</updated>
  </entry>

</feed>