R.C.

@RichardoC@infosec.exchange
21 Followers
145 Following
735 Posts

Foxes have eaten
the peaches
that were on
our tree

and which
we were
saving
for later

Forgive me
revenge is coming
so wet
and so cold

More details about the Gaussfest in London on the 7th September

https://www.extremeelectronics.co.uk/the-gaussfest/

High voltage, tesla coils, electrostatic machines and another Victorian/Edwardian pumping station to look around.

and a chance of seeing a working mercury rectifier.

I can't think of a better day out :)

Cybersecurity Risk Assessment Request

With the new EU legislation Cyber Resiliency Act (CRA), there are new responsibilities and requirements put on manufacturers of digital products and services in Europe. Going forward these manufacturers must be able to know and report the exact contents of their software, called a Software Bill of Material (SBOM) and they have requirements to check … Continue reading Cybersecurity Risk Assessment Request →

daniel.haxx.se

Them: “Let’s start with the CISO and their concerns.”

Me: Hi. I’m Wolf. I’m the CISO and I’m concerned about anything with electricity.

TIL there's hundreds of very popular npm modules that have been abandoned due to users deleting their accounts, and they get put in https://www.npmjs.com/~nopersonsmodules

Some of these modules have hundreds of millions of monthly downloads (some from substack and dominictarr), definitely low hanging fruit for someone to pick up and move to a foundation.

npm | Profile

There's a post going around LinkedIn about how easy it is to generate a fake photo with cheap GenAI tools that looks like a receipt and, oh no, people can lie on their expenses. And I think this panic really sums up the LinkedIn crowd:

  • It's a threat model that doesn't make sense.
  • It starts from assuming an adversarial relationship between employers and employees.

The threat model doesn't make any sense because about half (and most of the high-value things) I claim on expenses have email receipts already. If someone wants to submit a fake receipt, there are much easier ways than using GenAI to create a fake picture.

But, more importantly, it assumes that your employees are willing to commit fraud for a few tens of dollars, in sufficiently large numbers for it to impact your company. If your relationship with your workforce has deteriorated to that extent, then you're in serious trouble.

Update: the children have now been allowed to remain in the UK. While this is cause for celebration the system that made the initial decision and caused this family unimaginable stress still needs dismantling.

https://www.theguardian.com/uk-news/2025/jul/09/home-office-reverses-decision-send-children-brazil?

#HostileEnvironment #UKpol

Parents rejoice as Home Office reverses decision to send children back to Brazil

Officials had sent letter warning Guilherme Serrano, 11, that staying in UK could lead to him being prosecuted

The Guardian
I made an LED hat by weaving LED pebble strings with poly rattan. Pure braiding, no glue involved. 475 LEDs in total, controlled by a @wizard Pixelblaze. More pictures 👇🧵

Last weekend there were several actions in Germany. Local groups took in used (donated) solar panels that were replaced in big solar plants. These panels are 20 years old but still deliver a lot of power (7-8A at 30V). You could get them for free, test them, clean them up, get some help to put new connectors on them, register them with the city, get 200€ grant, use that to buy a micro inverter and go home with a balcony solar power unit, effectively for free. Bam. They handed out 1000 sets.

1/2