Gonçalo Ribeiro

@goncalor@infosec.exchange
342 Followers
446 Following
3.4K Posts
Defend. Pwn. Infosec. Free software. Vim nerd. #rustlang #electronics
websitehttps://goncalor.com
GitHubhttps://github.com/goncalor
trying nobara on my old origin PC laptop. It's not really that old, but Microsoft thinks it a quad core system with over 1TB of SSD, and 32GB of ram can't run win11 because it lacks a TPM, so now it gets to become my Linux playground before I commit to LInux on my primary desktop. I really hope this goes well.

> AI assistance was used to help structure and format this vulnerability report.

That was a really stupid idea.

Faking a JPEG | Lobsters

This is so dumb i'm sorry
--
#comics #kevincomics #hbo #hbomax

I received an email earlier this week from EA asking if I wanted to be added to a public acknowledgement page they were creating for individuals who responsibly disclosed vulnerabilities to them.

For all the shit people give EA, of the 100+ companies I contacted in the last two years, they were the only company I would say had a decent incident response.

They fixed the issue within 12 hours after validating it as critical, and proactively provided me multiple updates over time.

When the IR was done on their side, they reached out again with some more information about the potential impact if the issue hadn't been solved quickly, and also offered me a reward.

I did not have to keep chasing anyone for updates, I wasn't asked for non-disclosure, or offered money in exchange for it, and people replied instead of ignoring me.

I wasn't blamed for their mistake, either, or reported to the authorities.

Unfortunately, at least one or multiple of the things mentioned above are present in most of my other incidents reported; it's a real shit show out there.

#cybersecurity #infosec #responsibledisclosure #vulnerability #ea #electronicarts

A programming fact that still amazes me is that the HTTP header which containers the referring url is called "referer", because the developer spelt "referrer" wrong and the spell checker didn't catch it, so it made it into the official standards and they just never changed it lmao
×
@quixoticgeek The Albuquerque "ART" bus line is another example. They cut down all the mature trees in the median and side walks to add a bus lane without impacting the car lanes. They built raised platforms that slope so wheel chairs roll off. All seating is just spots to lean. The shade structure never shades the platform but does shade the street where no one can use it. No protection from the wind, rain or snow. But it does take a pretty picture.
@astronot @quixoticgeek what a description! Looking at the picture, I'd agree with you.

@astronot @quixoticgeek

it is horrible and many were against it

my thought is the mayor at the time must have gotten kickbacks

@quixoticgeek TLC Plumbing got the contract for the bus lane. Why a plumbing company for road work? Because the Mayor's wife is on their board. Strange that the stops were placed next to vacant lots that mayor and his cronies owned.

Painting pavement to "protect" the bus lane.
Lanes that end with no signage.
Buses sometimes on the left of platforms. Sometimes on the right.
Conflicting signage all in English (we are majority Hispanic).
So many accidents every week.

@quixoticgeek electric buses sourced from a company in china that never made electric buses before. Charging incompatible with local electric. Batteries with less than 40% of spec. So buses can't finish one run on a charge.
So much corruption but no one was ever charged and we are still dealing with consequences years later.
None of the signs meet federal road safety standards.
Local shopping district collapsed between construction and the new buses that make it impossible to cross the street.