S1m

@S1m@infosec.exchange
159 Followers
99 Following
400 Posts

FR/EN

Account dedicated to #Offsec/#Infosec/digital stuff

Involved in
#UnifiedPush #MollyIm

Githubhttps://github.com/p1gp1g
Codeberghttps://codeberg.org/s1m/
Liberapayhttps://liberapay.com/S1m/
Bloghttps://s1m.fr

At #OSPOsForGood today during #UNOpenSourceWeek, Adriana Groh made several insightful comments during the panel “The Role of Open Source in Digital Public Infrastructure”:

"At the #SovereignTechAgency, we focus on the software that developers need to develop software. We call that 'infrastructure,' which is a different understanding to what many hear when we talk about #DPI. Both things are extremely important and exist at the same time. We need to understand how they are connected..."

1/

Getting ready to issue IP address certificates

Is there anything public available on which IPs will be able to get certs? I mean, obviously private/reserved ranges won't be available, but how about all those "cloud" services that rent IPs by the hour (or second)? Is it expected to be "normal" that someone could release an IP back into a pool and yet still have a valid certificate for almost-a-week, or will Let's Encrypt certificates only be available for IPs that are slightly less ephemeral?

Let's Encrypt Community Support

We are happy to share that 62 projects will receive grants from the NGI Zero Commons Fund. We congratulate the selected projects and look forward to their contributions to increasing society's digital autonomy.

Ranging from browser-based cellular networking to decentralised social media, and professional print, these projects are showing that a bright digital future is not only possible but already being built.

Come over and meet the projects!
https://nlnet.nl/news/2025/20250624-announcement-grants-CommonsFund.html

#FOSS #NGIZero #NGI

NLnet; 62 new projects contribute to digital commons

We're absolutely thrilled to announce a new era of high-speed syncing for the open source ecosystem!

DAVx⁵ 4.5 will ship with full Push support (instant sync) for your Contacts, Events & Tasks!

We've worked on this for almost 3yrs from the first line of writing a draft for a (hopefully new) standard, to the work on a @nextcloud extension until the final DAVx5 implementation.

Videos:

Shorts version: https://www.youtube.com/shorts/fWhaLgcrcvI

https://www.youtube.com/watch?v=3TWb5U6pPYg

Full announcement:

https://github.com/bitfireAT/davx5-ose/releases/tag/v4.5-ose

Good explanation of why breaking encryption so that the government can read messages is a bad idea. But the fact that you have to explain it again and again is depressing. https://labs.ripe.net/author/flindeberg/end-to-end-encryption-architecturally-necessary/

#deltachat is secure against server-side group membership changes but for a very different reason than #signal which keeps encrypted group membership data in a central store.

Delta Chat has _no_ central store but implements a rigidly tested #p2p group membership model where servers play no role https://github.com/chatmail/models/tree/main/group-membership

Both signal and delta chat are safe against recently published attacks against #whatsapp that can add members to chats, breaking end to end encryption. https://arstechnica.com/security/2025/05/whatsapp-provides-no-cryptographic-management-for-group-messages

models/group-membership at main · chatmail/models

Formal specifications for chatmail. Contribute to chatmail/models development by creating an account on GitHub.

GitHub

I finally found the perfect bug to play with wrapwrap and get RCE on Monero forums  

After that, very classic exploitation steps. The only twist is that I didn't expect Laravel to unserialize() session cookies when the session driver is set to Redis (at least this version).

https://swap.gs/posts/monero-forums/

#php

Getting RCE on Monero forums with wrapwrap

breakpoint of no return

🫧 Happening Now: The #OWI online Kick-off launch 🫧
Come join:
https://cscfi.zoom.us/meeting/register/eATIpDQ5TZidh4Jzkim6FQ#/registration
Welcome! You are invited to join a webinar: Official Kick-off: The Open Web Index – OWI is officially ready for public use . After registering, you will receive a confirmation email about joining the webinar.

Be among the first to get access to the federated European Open Web Index - OWI. Join a community of Open Web Search & AI experts who pioneer European open source solutions in the information retrieval and machine learning domains. The Open Web Index not only aims to establish transparent web search as a public good, but also sets out to drive innovation in the scientific, economic and diverse cultural developments across Europe. Learn more at https://openwebsearch.eu/ On June 6, the developer and management team of the OpenWebSearch.eu consortium – makers of the OWI – welcome you to learn about onboarding opportunities and explore best practice use cases for inspiration. Your key take-aways: - Get introduced to the Open Web Index and its significance in the digital landscape - Learn how to access and use the Open Web index, including what to expect and what not to expect - Understand the differences between research and commercial licenses, and learn about the possibilities for raw data access - Discover real-world applications of the Open Web Index through compelling use cases - Learn how to join and engage with the Open Web Search community - Get hands-on with a tutorial on our index access tools Owilix and MOSAIC Don't miss this opportunity to be part of the Open Web Index launch and gain valuable insights into how it can benefit your work. Register now and join us for this informative and engaging event! Legal Clarification: This Zoom instance is hosted by CSC - IT Center for Science, one of the OpenWebSearch.eu consortium partners. Find out more at https://csc.fi/en/ For CSCs privacy policy see https://csc.fi/en/security-privacy-data-policy-and-open-source-policy/privacy/

Zoom

Really enjoyed David Gerard's amusing take on how programming with AI becomes like a gambling addiction for many.

"Large language models work the same way as a carnival psychic. Chatbots look smart by the Barnum Effect — which is where you read what’s actually a generic statement about people and you take it as being personally about you. The only intelligence there is yours."

"With ChatGPT, Sam Altman hit upon a way to use the Hook Model with a text generator. The unreliability and hallucinations themselves are the hook — the intermittent reward, to keep the user running prompts and hoping they’ll get a win this time."

"This is why you see previously normal techies start evangelising AI coding on LinkedIn or Hacker News like they saw a glimpse of God and they’ll keep paying for the chatbot tokens until they can just see a glimpse of Him again. And you have to as well. This is why they act like they joined a cult. Send ’em a copy of this post."

https://pivot-to-ai.com/2025/06/05/generative-ai-runs-on-gambling-addiction-just-one-more-prompt-bro/

Generative AI runs on gambling addiction — just one more prompt, bro!

You’ll have noticed how previously normal people start acting like addicts to their favourite generative AI and shout at you like you’re trying to take their cocaine away. Matthias Döpm…

Pivot to AI

Privacy vs Security: Yandex is spying on their users in an insecure way, Meta (Facebook, Insta) in a more secure way. Both of them are a threat against user privacy

This is yet another example showing that there are reasons to be more suspicious against proprietary apps. We should avoid installing GAFAM apps, and reducing as much as possible our dependency on their services is healthy

https://localmess.github.io/

#InfoSec #Privacy #Android

Covert Web-to-App Tracking via Localhost on Android