Tootfinder

Opt-in global Mastodon full text search. Join the index!

@frankel@mastodon.top
2026-07-19 16:55:05

Guest author Peter Firmstone continues to explore and analyze the theme of #Security Baked Into the #JVM.
Today's focus in on the Safe Codebase #Audit

@TobiasFrech@ijug.social
2026-09-18 08:15:53

From this perspective, today is a good day! Thanks to a team effort we succeeded in getting the #trivy warnings down to zero before the QS cycle starts.
#security #DevSecOps

graph showing normal and high trivy warnings going from 30 to 0 on the latest build
@dankeck@a11y.social
2026-08-15 22:16:58

"Think of a wheelchair user who must share her PIN with a stranger to use an out-of-reach payment kiosk. Or a blind person who can’t independently access their own medical records because access is lacking…
Any system designed to be used independently is a #privacy and #security risk without

@crell@phpc.social
2026-08-13 15:16:09

Websites/apps that require you to enter a 2FA code sent by text or email that disable or impair copy-paste:
Fuck you, please go bankrupt fast and make room for companies that don't hate their users.
#Security #Rant

@mgorny@social.treehouse.systems
2026-09-18 13:48:58

Remember the time when I took #security vulnerabilities seriously, rather than shrugged and whatever'd?
#Linux

@larsfosdal@mastodon.social
2026-09-18 09:38:31

Old MacDonald's Server Farm
A-I-A-I-O
And on that farm an LLM
A-I-A-I-O
With a breakout here and a breakout there
here a break, there a break, everywhere a breakout
Old MacDonald's Server Farm
A-I-A-I-O
#AI #LLM #Security

@pixelpusher220@dmv.community
2026-08-19 03:40:36

reason 343521562 to never use Comcast
Comcast enabling WIFI motion tracking ability on all Xfinity routers.
Free, but *supposedly* Opt-In.
#Privacy #Security #WifiMotionTracking

@frankel@mastodon.top
2026-08-09 16:54:35

Guest author Peter Firmstone continues his brilliant series of #Security baked into the #JVM, with his third post: two Subjects, one call
This part covers the two kinds of identity a call carries, how SPIFFE manages process credentials without keystores, and how three identity layers coexist on a singl…

@patrick_townsend@infosec.exchange
2026-08-16 18:13:09

Signal – Don’t forget to configure for privacy
In a business or non-profit environment, there is a good chance that your management team is using Signal. And why not? It brings security and privacy to messaging, file sharing, video and phone calls. Not only can you do one-to-one communications, you can create and manage groups. Sensitive business conversations can remain secret. What’s not to like about that?
Out-of-the-Box Signal needs attention to the configuration settings to get the best privacy. If you are a CISO or IT specialist, you can help your management team configure Signal for the best privacy.
After installing Signal on a mobil phone or desktop, review the configuration settings and adjust them as needed. Here is a free guide that will get you started:
#Security #Privacy #Signal

@michabbb@social.vivaldi.net
2026-09-13 00:59:32

🔐 Hermes Vault: a local-first credential broker and encrypted vault for AI agents. It scans for plaintext secrets, brokers policy-gated access and proves audit integrity.
#opensource #security #MCP

@cyrevolt@mastodon.social
2026-07-09 19:57:34

I can't stop saying the NVRAM vars are a tough #UEFI attack surface, and if processed wrong, may undermine all #security:
kb.cert.org/vuls…

@jake4480@c.im
2026-08-24 20:20:39

Security by antiquity ftw
#security

@khalidabuhakmeh@mastodon.social
2026-08-26 12:13:53

If you are in Sweden and want to do more #dotnet #security work, Sustainsys is hiring for a Senior .NET Developer. Seems like a great opportunity. Let them know you heard about the position from Khalid. :)

@curiouscat@fosstodon.org
2026-06-24 14:49:06

"The TSA has an important job to do. Their actions at airports have been very poor. This creates lots of loss to travelers – waste. And their actions show a disrespect for people and the risks that exist. The #security theater is not what we need. We need evidence based security measure while maintaining a focus on the value stream of people flying."

@kubikpixel@chaos.social
2026-08-29 14:45:09

If you ask me, it's advertising #propaganda and not a real call for respectful #security. Above all, AI is only so "smart" to what amount it is fed with #data in which context.
«Time is runn…

@publicvoit@graz.social
2026-07-22 12:03:42

This is what cve.org is showing when I don't allow JavaScript execution for a third party domain (mitre.org) in my LibreWolf browser: "Service is currently unavailable." 🤦‍♂️
I guess the #security community should do better than that.
And yes, when JavaScript is disabled for cve.org, I do get a helpful message that informs me that the web site can't work without JavaS…

Website of https://www.cve.org/ showing an "Service is currently unavailable." message instead of the page content.
@frankel@mastodon.top
2026-06-28 16:27:49

This week, I'm happy to welcome a new guest blogger, Peter Firmstone from Down Under 🇦🇺.
He's written a whole series about #security baked into the #JVM. Today's post answers the question: why fork @…

@mgorny@social.treehouse.systems
2026-07-03 14:54:58

Dependency cooldowns are a nice idea, but I dare say they're a short-term solution.
They resemble the idea of avoiding poison by waiting for someone else to start eating first. That works, provided that someone actually eats first, and that the poison works fast. But eventually it leads to that awkward silence at the table when nobody wants to risk the first bite.
Adapting dependency cooldowns means basically waiting for "someone else" to notice the problem. At some point when large enough number of projects adapts them, we're going back to square one — except with an artificial few-day delay.
#security #FreeSoftware

@cyrevolt@mastodon.social
2026-06-20 11:44:04

Some more #UEFI entertainment, I'm just waiting for it. 😹
Seriously though, #firmware #security has become such a problem because many vendors just can't even get updates right, still disco…

@frankel@mastodon.top
2026-08-23 16:15:59

Guest author Peter Firmstone continues to explore and analyze the theme of #Security Baked Into the #JVM.
Today's focus is on multi-Subject dispatch: how up to sixteen user Subjects cross a call on the #JERI

@khalidabuhakmeh@mastodon.social
2026-08-20 12:36:06

If you're keeping up with #oauth and #app #security, our resident specifications expert, Joe DeCock, summarizes the standards landscape as of summer 2026.

@stephane_klein@social.coop
2026-06-26 13:19:17

« J'ai découvert cc-safety-net : des hooks pour sécuriser les agents IA »
#security

@geant@mstdn.social
2026-07-21 11:45:27

Nancy Beers' keynote at #SecurityDays 2026 had the whole room on its feet, playing games and laughing together.
We spoke with her recently to learn more about what "Play More Today. Secure Tomorrow" means for security culture, from how a simple box of LEGO bricks can make abstact discussions come alive, to why she believes cybersecurity can't exist in silos.
🔗 Re…

Woman on stage presenting
@ruth_mottram@fediscience.org
2026-06-22 16:11:38

More than mildly alarmed listening to this episode on the #Arctic #Europe and #Russia #Ukraine and #HybridWar, #Security and lots of other very very interesting items. *Essential* listening for anyone concerned with European security.
Mildly Alarmed: Russian nukes and spies in the Arctic, with The Barents Observer
podcasters.spotify.com/pod/sho
Media file: anchor.fm/s/111aff124/podcast/

@pixelpusher220@dmv.community
2026-09-04 23:29:34

#Security #PasswordManager
Random question for those who use a browser plugin for a dedicated manager like BitWardon or LastPass or whatever.
How does this handle security vs the built in browser manager?
I know the in browser ones are not recommended and curious how having a plug-in to the BitWarden/LastPass 3rd party is different?

@mgorny@social.treehouse.systems
2026-07-07 01:38:06

Honestly, what kind of scam #Akamai / #LInode is? They give you a form to report malicious activity from their network, you file it, you get "Error message to be decided", and it turns out they've banned you in the meantime; all their websites give you "Access denied".
And they host an exploit since 2021 at least: #security #abuse

@ErikJonker@mastodon.social
2026-09-03 06:36:49

Reading this, people could actually think Anthropic helps them keeping their data safe. However you still have to trust Anthropic itself that has access to all your data when using their AI or am i misreading it?
#AI #Anthropic #EFS #privacy #security

@pixelpusher220@dmv.community
2026-08-12 20:56:59

#BigTech #Billionaires #EatTheRich #Security #Win10 #TechSupport
So some press covered Zuckerberg's mega yacht not responding to a distress call and rightfully saying the Law Of the Sea requires aid to be rendered if possible.
Now, there's apparently a Win10 zero-day vulnerability in the wild. A vulnerability that Microsoft HAS A FIX FOR.
And yet they won't allow you to run it if you haven't paid up for support.
They should be REQUIRED TO RELEASE the fix to all.

@randombaywatch@mastodon.social
2026-09-07 12:42:30

#BikiniBeauty
Season 3 Episode 14 "Strangers Among Us"
#Security #RandomBaywatch #lvdlpx #Baywatch #BaywatchKittens #Gorgeous #BaywatchBabes #hot #sexy #swimsuit #BaywatchBoobs #Headlights #Bikini #Beauty #StrangersAmongUs