Gonçalo Ribeiro

@goncalor@infosec.exchange
344 Followers
443 Following
3.4K Posts
Defend. Pwn. Infosec. Free software. Vim nerd. #rustlang #electronics
websitehttps://goncalor.com
GitHubhttps://github.com/goncalor
@Eetschrijver @selzero Here's the first one (alt text took me awhile):
Spotted a reverse engineering boutique at Zurich main station

We are here

(by Dan Meth https://www.danmeth.com/)

You MUST listen to RFC 2119.

Eric Bailey: It turns out you can just pay people to do things. I found a voice actor and hired them with the task of "Reading this very dry technical document in the most over-the-top sarcastic, passive-aggressive,...
https://jwz.org/b/ykqi

The world is cruel
therefore I won't be

Sometimes a women needs a hobby

🎨by techranova

🗓️ 02/07/2025

O ano está em:
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣀⣀⣀⣀⣀⣀⣀⣀⣀⣀ 50%

Strong Password Policy 101
Edit: for bonus points it messes with your OCD. There's a method to the madness

We use these signs at the museum when we pull a specimen from exhibit for study.

Someone on my staff attached this one to my office door. That’s the kind of people I hire, apparently.

#museum #MuseumLife

×
#VibeCoding your MFA
@beyondmachines1 Talk about vibe coding the pipeline. 
@beyondmachines1 chat is this real?
@kae_bytheocean no clue. But I'm thinking Debug = True
@beyondmachines1
Even then: When would the frontend ever get the code?
@kae_bytheocean
@oneiros @kae_bytheocean seemed like a great idea at development debug time 🤷

@beyondmachines1

Where did you get this image from, if you didn't take the screenshot yourself?

Also, why did you assume it was vibe coding?

@AVincentInSpace I didn't. It was shared with me.
And I'm truly hoping that it's vibe coding, the alternative is scarier.
@beyondmachines1
The alternative is that it's a joke. Quit catastrophizing.
@AVincentInSpace Sure, let's go with that.

@beyondmachines1

I'm not going to accept that this is a public facing page without proof, and neither should you. In its current form, it is nothing more than ragebait. That you're spreading.

@AVincentInSpace whatever helps you sleep better. 🫡
"x0cx0x" sure is an interesting way to censor the first six digits of a phone number
@dzamie not ai generated, just typical OCR errors (probably the OCR software included in mastodon)
I suppose "ai" is just a synonym for "general-purpose LLM" these days, yeah
@beyondmachines1 i took like a whole minute to understand this T~T
@beyondmachines1 I fear it's real, isn't it?
@beyondmachines1 What application is that, smh? I'm not sure the people know the purpose of sending a code to your phone XD
@beyondmachines1
Perhaps it is the number of an entirely different code. 
@ozzelot That is so evil
@beyondmachines1 The correct code has arrived at the phone and this is for internal use by people who have access to the DB and have no intention to bother with phones, I assume
@ozzelot that's what we call a back door. And having a back door is always a bad idea.
@beyondmachines1
Well, if it weren't for little old security through obscurity, it would be a front door!
@beyondmachines1 is this real?
@lunch I'm putting my money on Debug = True
@beyondmachines1 really streamlines the authentication process
@boscoandpeck we need HX, Hacker eXperience
@beyondmachines1 😂 I can see the job listing now for a full stack hx developer
@beyondmachines1 Your alt-text needs a little tweak, the 'xxx-xxx' looks a little messed up.
@beyondmachines1 Better UX, that.
@chief everyone is happy. Customers, hackers, everyone!

@beyondmachines1 About 15 years ago I had a bank account in Qatar. They had SMS authentication for transfers.

The form asked you for your Qatar Id - easy as it was displayed at the top of the webpage then invited you to put in a phone number for the SMS authentication message to be sent to. You could use any phone number - your own, the wife or even a co-worker. I tried!

@X31Andy I bet there are such implementations even now
@beyondmachines1 accessibility feature here I come
@beyondmachines1 Please don't ask me how long I had to stare at this before I realized what was wrong 🤦
@OpenComputeDesign like looking for my glasses while i'm wearing them 🤷‍♂️
@beyondmachines1 did you vibe code the alt text too?
@impossibleibex Obviously, one has to be consistent
@beyondmachines1 One step better, but still a hellscape, is when they're all individually typed, impossible to paste to, boxes.
@beyondmachines1 I don't get this please help 😭

@mason @beyondmachines1
It took me a minute - the code that is being sent as an SMS...

...is already displayed on the screen.

@mason Apparently instead of just telling you it sent a code to your phone for verification, it also tells you the code, which defeats the purpose.
@oscherler They kept the phone-number hidden thogh, so it's not all bad. :-D @mason
@oscherler Oh now I just noticed haha

@mason @beyondmachines1 « We sent the code 012345 to your phone, please check your phone and write down 012345 below. Remember, the code is 012345 »

Useful, don't even have to check my phone.