Dan Guido

@dguido@infosec.exchange
1,022 Followers
81 Following
8 Posts

Pedro Pascal as Quokkas.

A thread.

OMG who did this? I am crying

Wow, just look at that timeline 🔥

#Testing a new encrypted messaging app's extraordinary claims

https://crnkovic.dev/testing-converso/

Testing a new encrypted messaging app's extraordinary claims

How I accidentally breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger called Converso.

crnkovic.dev
👀
“We perform a survey of open-source implementations and find 36 weak Fiat-Shamir implementations affecting 12 different proof systems. For four of these—Bulletproofs, Plonk, Spartan, and Wesolowski’s VDF—we develop novel knowledge soundness attacks accompanied by rigorous proofs of their efficacy. We […] demonstrate that a weak F-S vulnerability could have led to the creation of unlimited currency in a private blockchain protocol”
https://eprint.iacr.org/2023/691
Weak Fiat-Shamir Attacks on Modern Proof Systems

jack dorsey hardly ever actually posted on twitter. but jack's been actually posting on bluesky!

turns out he's an RFK Jr fan. the bluesky regulars are ragging the shit out of him and discussing the crunchie->qanon pipeline. hope jack's enjoying it!

i remember trying and failing to write a piece on Jack and bitcoin for Foreign Policy. he does not appear to have a personality.

having done the research, i am convinced the man is actually a chatbot that was sent back through time. literally a boring person's idea of an interesting person.

the missing ingredient on bluesky was obviously a billionaire who sucked to bully

@campuscodi Not quite right! Our security audit of cURL had 15 findings, and you can find the full report here:
https://github.com/trailofbits/publications/blob/master/reviews/2022-12-curl-securityreview.pdf

We also designed a threat model! https://github.com/trailofbits/publications/blob/master/reviews/2022-12-curl-threatmodel.pdf

This blog post about 4 issues were just a fun side-story to the main audit. Some of these bugs were found outside the audit and reported afterward.

publications/2022-12-curl-securityreview.pdf at master · trailofbits/publications

Publications from Trail of Bits. Contribute to trailofbits/publications development by creating an account on GitHub.

GitHub

I just released a #Prometheus exporter for #mastodon that others may find useful:
https://github.com/andrew-d/mastodon_exporter

It currently supports metrics for number of local accounts, number of posts, number of resolved/unresolved mod reports, and a histogram of how long it took to resolve reports on the instance.

I'm planning to use it to graph the number of posts on our instance over time, and to set up alerting so that a new report doesn't get lost, along with tracking report SLAs to keep ourselves honest 😃

This is my first time writing a Prometheus exporter, so feel free to submit PRs and I'd appreciate any feedback from those that do test it!

I run it on my Postgres database using something like:

DATABASE_URL="host=/var/run/postgresql user=mastodon database=mastodon" /path/to/mastodon_exporter --web.listen-address=localhost:9393

Boosts are appreciated to reach other Mastodon admins that may find this helpful.

#mastoadmin #monitoring

GitHub - andrew-d/mastodon_exporter: Prometheus metric to export data about a Mastodon instance

Prometheus metric to export data about a Mastodon instance - GitHub - andrew-d/mastodon_exporter: Prometheus metric to export data about a Mastodon instance

GitHub
×

Pedro Pascal as Quokkas.

A thread.

@Pandamoanimum That's Burt Reynolds.
@feijoa @Pandamoanimum I mean I can see why you might be confused, but that is definitely Pedro
@Pandamoanimum this made me realise I have insufficient Pedro Pascal in my life rn. Thank you for your service.

@Pandamoanimum

This.

This is what I am on Mastodon for.

Thank you!

@Pandamoanimum Ok, yeah, this one does have strong Burt Reynolds vibes... I saw it before, but I get it now...

https://wandering.shop/@Catvalente/110783340452587153

cc: @Catvalente

Catherynne M. Valente (@Catvalente@wandering.shop)

Attached: 1 image I’m showing Anchorman to my nieces & trying to explain that in the 70s the men people thought were hot looked exactly like that, exhibit: Burt Reynolds Nieces: ok but that’s just Pedro Pascal everyone loves Pedro Pascal? Me: WHAT THE FUCK IT IS I WAS NOT PREPARED FOR THIS EXISTENTIAL REVELATION TONIGHT

The Wandering Shop
@Pandamoanimum I have no idea who's Pedro Pascal, but I love Quokkas, so any excuse to post more Quokkas' photo is good with me!
@Pandamoanimum I have no idea what a Quokka is, but I approve this thread
@Pandamoanimum Bookmarking this for emergencies. 🙏
@Pandamoanimum the one and only Javi Gutierrez!!!
@Pandamoanimum Another absolutely top tier thread.
@Pandamoanimum The sort of things that make internet a better place.
@Pandamoanimum are you telling me that Oberen Martell in GoT wasn’t a quokka?!!!😱