Harry Sintonen

1.8K Followers
235 Following
2.6K Posts
Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests
PGPhttps://sintonen.fi/pgpkey.txt
Researchhttps://sintonen.fi/advisories/
Githubhttps://github.com/piru
I believe this is the #RoadToVostok start shelter location: https://maps.app.goo.gl/5jtEsNdGhAfnWT7w5
Bevor Sie zu Google Maps weitergehen

It's good to know that when the apocalypse comes, our computing needs are still covered.

#roadtovostok

For years, I've highlighted the threat of services either being forced to divulge all content to third parties or becoming unavailable entirely due to policy or legal changes that apply to the service provider.

We've seen both for years now. Some AI models pulled are just the latest manifestation of this. It remains to be seen if this will lead to actual implementation of sovereign platforms and systems, or at least avoiding full monoculture.

I am not holding my breath.

McSweeney's on "AI finances" goes harder than most business publications.

https://www.mcsweeneys.net/articles/ai-economics-for-dummies

AI Economics for Dummies

“Xavier owns an apartment that he rents out at a loss of $1 billion/month. Seeing this success, he decides to make financial commitments to construct $850 bi...

McSweeney's Internet Tendency
Don't be like #AMD when dealing with security issues https://www.youtube.com/watch?v=4HjWHNLRMB0
AMD Gaslights Security Researcher, Changes Rules Retroactively

YouTube
OggVorbis code is fugly. Function consuming >32KB stack space (everyone has large stacks right?), using alloca() to dynamically allocate stack space all over, no checking for memory allocation failures from malloc(), realloc() etc. 😐
The simplest of all possible modifications to the original RoguePlanet.cpp (literally interchanging two letters in the source code) defeats the detection and re-enables the exploit in current, fully patched Windows 11 with Definition Update 1.453.20.0 installed.

#Github Security Advisories program is struggling under the load of new submissions. Delays in CVE assignment up to a month are being reported. Apparently, May 2026 was the highest volume month ever, and they are working through a backlog.

source: https://www.openwall.com/lists/oss-security/2026/06/10/9

It is not very hard to figure out what is going on: The amount of AI-assisted reports is flooding the systems. Considering the asymmetric nature of the situation (limited human resources processing increasing number of reports), it is unlikely the it is getting any better soon.

If just tracking and assigning issues is getting this hard, it can't bode well for actually fixing and patching them.

#infosec #cybersecurity

oss-security - Re: How to request CVE numbers?

Apple blames EU rules as it withholds new Siri AI from European devices

The decision to keep Siri AI out of the bloc “is Apple’s and Apple’s only,” responded Commission spokesperson Thomas Regnier.

POLITICO