Dennis Mansell

81 Followers
246 Following
100 Posts

Helping organisations liberate themselves from techno-feudalism by joining the commons, with self-managing, cross-functional teams and by doing #Scrum, #kanban and #humancentereddesign

Building Fonetic: Safe, private AI translation, transcription and description for use in public spaces. #FLOSS #cooperative

ex-mariner, ex-founder, tech-nerd, corporate consultant and anarcho-activist. I use double spaces, partly out of principle and partly from #dysgraphia.

websitemansell.nl
gravatar.comgravatar.com/dennmans

Purely for a thought experiment, lets imagine a crawler that's running off a remote controlled, possibly malware infected device. Lets also suppose that the crawler software itself is not vulnerable - but the device it infected, is.

What if we could access that device? What if we could... I dunno... disable the crawler, and patch the hole it came through?

What if we could disable the applications that host the crawler "service"? Or if not disable outright, guide them into a state where they don't start, and need to be not only reinstalled, but their data wiped first?

Imagine the possibilities! What if this would allow us to alert the - probably unsuspecting - owner of the device that their device is being abused?

That's an interesting thought experiment, I think.

Na Leuven en Gent is er ook in Antwerpen een camerawandeling aangekondigd! Deze wordt georganiseerd door @XR_Antwerp en het concept is hetzelfde als de andere: een infosessie rond OpenStreetMap, de wetgeving rond camera's en een discussie rond de maatschappelijke impact, gevolgd door een wandeling waar we de camera's die we tegenkomen in kaart brengen.

🔗 https://osmcal.org/event/4620/

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

Je verzint dit niet. In de aankondiging van GPT-NL laat TNO weten dat ze alles met CoPilot doen tenzij het niet anders kan https://gpt-nl.nl/nieuws/launching-customers/#:~:text=Copilot%2C%20tenzij
De eerste use cases van GPT-NL

In februari zijn we gestart met partijen die willen investeren in de toekomst van GPT-NL. We voeren met deze organisaties zogeheten ‘Feasibility Studies’ uit: een onderzoek naar de deployment van GPT-NL binnen een specifieke use case én binnen de organisatie. De financiers van deze studies zien het belang in van de doorontwikkeling en de investering in kennis en kunde in Nederland.

GPT-NL

@berniethewordsmith theoretically, I would expect anything derived or remixed from a work with CC-SA, GPL, AGPL and EUPL license to have a public license by the fact of the licenses' copyleft clause.

That would require proof that any copyleft-licensed work was used at all. Unlike the NYT case where the specific copyrighted content has to be found.

My hope is that the EU gets its act together and insists that any LLM trained on copyleft data is published more libre than the original works.

"Er..." [Zarquon] said, "hello. Er, look, I'm sorry I'm a bit late. I've had the most ghastly time, all sorts of things cropping up at the last moment."
He seemed nervous of the expectant awed hush. He cleared his throat.
"Er, how are we for time?" he said, "have I just got a min—"
And so the Universe ended.

#HitchhikersGuide #DouglasAdams #quotes #quote #bot

@quinn don't worry about it. Europeans variously conquered the world and extinguished cultures and ecosystems, the US has simply taken over the lead in systematic oppression. We should change that system, navel-gazing won't do that.
@Daojoan Unfortunately there is only labour and capital. Corner offices are for labourers who are made to believe that they are capitalists.

RE: https://mastodon.social/@Tutanota/116130138605094270

Today the EU Parliament said NO. ❌

Voluntary scanning by Outlook, Gmail, LinkedIn, etc. might come to an end on April 6 in the EU. Keep pushing everyone! 👏🥳

Tijd voor een Open Source licentiemodel. Als de overheid zou samenwerken met leveranciers in #coop 's, zou je zowel de big-tech licenties omzeilen als een entiteit hebben voor aansprakelijkheid...

https://ibestuur.nl/markt-en-overheid/inkoop-en-aanbesteding/twee-grote-it-aanbestedingen-van-het-rijk-stilgelegd?tid=TIDP15178186XC62751833132480EB9197FCEA9F195E5YI5&utm_campaign=IB_NB_Wekelijks&utm_medium=email&utm_source=ibestuur&utm_content=855_10-03-2026

Twee grote IT-aanbestedingen van de rijksoverheid stilgelegd

De directie Informatievoorziening en Inkoop (DI&I) is door de rechtbank in Den Haag teruggefloten bij twee grote IT-aanbestedingen. Het sublicentiemodel dat de rijksoverheid hanteert en de voorwaarde dat resellers de financiële risico’s voor datalekken en AVG-schendingen dragen, is volgens de rechter disproportioneel en verstoort de marktwerking.

iBestuur