Shane Milton ☁️

148 Followers
205 Following
372 Posts

I am:
- married to an amazing woman
- a dad
- a Christian
- a cloud architect
- building SkyNet in Azure
- a Colts fan

He/him
Posts = Opinions
Favs/Boosts != Endorsements

PronounsHe/Him
About Mehttps://about.me/jaxidian
GitHubhttps://github.com/jaxidian
Fowl Site🐦 @Jaxidianhttps://twittodon.com/share.php?t=jaxidian&[email protected]

!!! UPDATE YOUR PHONE NOW !!!

RCE exploit

Samsung Galaxy phones including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 series
Vivo phones including those in the S16, S15, S6, X70, X60, and X30 series
Google Pixel 6 and 6 Pro, Pixel 6a, Pixel 7 and 7 Pro
Any wearables that use the Exynos W920 chipset
Any vehicles that use the Exynos Auto T5123 chipset

Project Zero reported 18 vulnerabilities in Exynos modems in late 2022 and early 2023. Four of the vulnerabilities, including CVE-2023-24033, involve internet-to-baseband remote code execution
Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number. With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.

Project Zero is making a “policy exception to delay disclosure for the four vulnerabilities that allow for internet-to-baseband remote code execution.” This is “due to a very rare combination of level of access these vulnerabilities provide and the speed with which we believe a reliable operational exploit could be crafted.”

https://9to5google.com/2023/03/16/google-exynos-modem-vulnerabilities/

Google: Turn off VoLTE, Wi-Fi calling due to severe Exynos modem vulnerabilities on Pixel 6, more

Google found severe vulnerabilities with Exynos modems used on the Pixel 6 and Samsung phones that warrant disabling VoLTE & Wi-Fi calling...

9to5Google

Currently fighting with #Microsoft #Azure, specifically can't get a custom domain working on a Static Web App. I've managed to nail DNS for Azure Front Door in front of a suite of AAD B2C implementations as well as IaC to drive DNS updates from custom Private Endpoints, but I can't get a fricken Static Web App to work.

The error message is clearly worthless.

https://learn.microsoft.com/en-us/answers/questions/1190071/static-web-app-custom-domain-validation-keeps-fail

Static Web App Custom Domain validation keeps failing with "Unknown error" - Microsoft Q&A

I'm attempting to host a 1-page (HTML) static web app, about as simple as possible. Everything's gone great except for adding a Custom Domain to it. No matter what I do, it keeps failing validation and the error message is "An unknown error has…

Here's a less-tiny view of the same conversation:
It's fun playing with Bing's GPT-4 bot and getting it to talk about things that it's not supposed to talk about. 😛

You don't need separate accounts to interact with different kinds of Fediverse servers.

For example, if you have a Mastodon account you can follow PeerTube accounts such as @theatticdwellers or @alliterative and their videos will appear in your Mastodon timeline as if they were Mastodon posts.

If you reply to a PeerTube video within Mastodon, the reply will also appear as a comment below that video on PeerTube. (And comments made on PeerTube will appear as replies on Mastodon.)

So today, if I were in an interview and I was asked how I would implement Fizzbuzz in .NET as a REST API, saying that I would type "What would dotnet 6 code look like for a Fizzbuzz implementation via REST APIs?" into a chat box would probably not get me the job. How many years until that becomes the right answer?

To be honest, even though this tool is trying to replace me (heh, fat chance), I'm pretty intrigued by this!

*sigh* Time to yet again restart the counter on "number of days since Indiana has not been a national embarrassment."

#HoosierMast #Indiana

https://www.wfyi.org/news/articles/indiana-senate-bill-ban-books-prosecute-teachers-librarians

Indiana Senate passes bill to ban 'bad' books, ease prosecution of teachers, librarians

Senate lawmakers passed a bill Tuesday that would strip teachers and school librarians of a legal defense against charges that they gave harmful books to students.

WFYI

My kid is in a club at school, and they meet 4x a week for 4 hours. So all the parents chip in and stock a "snack cabinet" (granola bars, juice boxes, etc.) because teenagers are hungry goblins.
I went to fill the cabinet and noticed a padlock on it, apparently someone had been "stealing."
I admit, this triggered me.
I spoke to the coach and told him that perhaps he should talk to the kids and find out if one of them is food insecure instead of locking up some two dollar box of granola bars.
The look on his face, I could tell it kinda clicked, he didn't even think of that, just assumed it was some punk kid breaking rules.
People who grow up with wealth don't even realize that it changes the way they think. Luckily, he's a cool guy, and he was horrified that one of 'his kids' might be hungry at home. Sometimes it just takes one comment to open up someone's eyes to their privilege.

As I tell my own children: If you see someone stealing food, no you didn't.

It feels like the more Mastodon instance shutdowns we see, the more important it gets to think about how to enable migrating posts. Migrating a user's follows/followers is good, but for a user to lose their entire post history is pretty severe. And the longer you use a server, the more painful it gets to lose that history of everything you've ever written.
Sunday punday.