cynicalsecurity 

1.5K Followers
275 Following
9.2K Posts
IT Security, cynically aged. Maths. Some nukes. Four languages. Longing for Symbolics and Connection Machines. Keeper of Ancient Computing Lore. Ⓐ
Butterflyplacehttps://bsky.app/profile/cynicalsecurity.bsky.social
Homepagehttp://arrigotriulzi.ch/
First 0day1986

Preparing ossobuco with risotto on an electric hob (not induction) is really challenging… the one thing I miss most from my Italian and UK kitchens is the gas hob.

Factoring in the response delay of the standard electric hob is really non-trivial.

I have never really cooked anything difficult on induction but it does give the impression of better response to power changes.

While we must move off gas hobs for the good of the planet, I have to admit I’ll miss them. I guess new generations brought up to cook with electric hobs will deal with it much better.

I’m a cooking dinosaur… 

I need to run a, secure, e2e instant messaging server for a small group of people (< 10).

The requirements are:

* iOS / Android client with push notifications
* Linux & BSD clients
* on-prem private server

What do people recommend?

[Edited to explain I want to run it on-prem for a closed group of people - sysadmins actually on a delicate project]

@cynicalsecurity for every ethical business model, there is a more profitable unethical business model...
@buherator @cynicalsecurity @jpmens I built a solution based on that feature with a YubiHSM to generate short term certificates for security agents to log into machines, do their job, and get out, without worrying about permanent accounts or certificate management. Worked great 🙂
Scalable and secure access with SSH

Visit the post for more.

Engineering at Meta
There is currently an insane spy thriller running in #Hungary ICYMI:

https://www.direkt36.hu/en/titkosszolgalati-nyomasra-tortent-hazkutatas-a-tiszat-segito-informatikusoknal-aztan-kibukott-egy-gyanus-muvelet-a-part-ellen/

A 90min interview with the whistleblower was released too that reveals even more pieces of the puzzle. The whole thing screams for a movie (and long prison sentences).
Inside the covert operation to bring down the party threatening Viktor Orbán’s rule - Direkt36

According to documents obtained by Direkt36, a secret operation was carried out to bring down the IT systems of the Hungarian opposition party Tisza. IT specialists affiliated with the party planned to expose this, but then police officers, pressured by the Hungarian secret services, raided them, apparently on trumped-up charges.

Direkt36 - Direkt36 is a non-profit investigative journalism center with the mission to hold powerful people and institutions accountable.

Sometimes I wonder… I come from two Milanese industrialist families who worked hard to keep their factories going (and failed in one case due to, literally, natural causes aka a dam disaster) and, reading the responses to my LinkedIn post about salary dumping in Ticino, I cannot reconcile it with anything I have ever heard from my parents or grandparents.

This bizarre concept that it is the workers and the international treaties which somehow "force" the companies to use cheap labour is spectacular.

Of course my families tried to run a profit but, in one case, literally financed one of the most skilled workers to set up their own shop and become a supplier with a guaranteed 5-yr 100% purchase cover before they could work alone (their family is still in business!), the other spent literally almost all their fortune to provide for the worker families hit by the disaster.

I should add that my grandfather's idea of "owner luxury" was going on holiday in Rimini for two weeks, having a large apartment in a new development towards Milan Linate airport, and driving an Alfa Romeo Alfetta, not "two yachts, three Ferrari, five villas." That might explain things...

Having said this I was brought up in a left-wing family and the only comment when I said I was an Ⓐ was "perhaps too much?" which is fair :)

Also, ironic that parsing CSV dumps of Azure logs triggers #NannyTerminal on #macOS

Yay NannyTerminal on macOS!

If you paste “dangerous commands” now #macOS 26.4 prompts you saying “this could be dangerous”…

I do effing security, not “sekurity” or “theatrical representations of sekurity”, of course I paste “dangerous commands” like a ten line awk script to parse data…

I was waiting for a quiet moment to switch to Ghostty and… I’ll do it in the middle of a double IR storm ‘cos I effing need to paste whatever I want in my Terminal window, and fast.

We were just notified today that one of our teammates is going to be let go.

We've been working together for over 3 years, and he's been a great teammate.

I don't know his full skill set, but we're a Ruby shop, and I know he's got some PHP experience under his belt as well.

If you know of any open positions for a senior role in Ruby or PHP, let me know.

Plz boost.

#GetHiredFedi #Getfedihired #gethiredbyfedi