Harry Sintonen

1.5K Followers
234 Following
2.5K Posts
Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests
PGPhttps://sintonen.fi/pgpkey.txt
Researchhttps://sintonen.fi/advisories/
Githubhttps://github.com/piru
In other news: UK Biobank health data listed for sale in China, government confirms https://www.bbc.com/news/articles/cpvxgl3n138o
UK Biobank health data listed for sale in China, government confirms

The government said medical data of 500,000 people was affected but no personally identifiable information had been made available.

Finnish medical data is available for researchers, unless if you specifically opt-out. I have, you should, too.

https://findata.fi/en/about-findata/your-data-rights/#how-can-I-exercise-my-rights

#privacy #medicaldata #secondaryuseofdata

Your data rights

Secondary use of social and health data means that client and register data from social and health care services are used for purposes other than the primary reason for which they were originally…

Findata

If you upgraded to #OpenSSH 10.1 or later and suddenly have trouble connecting to a server, try: ssh -o ipqos=af21 user@host

If that works, then the network is unhappy about the Expedited Forwarding IP QoS (this is the new default IPQoS for interactive connections with OpenSSH 10.1 and later. -o ipqos=af21 restores the IPQoS used by earlier OpenSSH versions).

OpenSSL will likely say that you should check version as well - but would it be that terrible to keep these negative defines around, even if the support is fully axed?

#OpenSSL 4.0.0 removed all traces of SSL3 support - including the OPENSSL_NO_SSL3_METHOD define that indicates that SSL3 methods are not available.

This define is used by a lot of code to see if they should try to use SSLv3_client_method() or not. Example: https://github.com/mirror/wget/blob/8775506f632f14404e4755dbae679dea07abf12a/src/openssl.c#L229

I've tried to report a security vulnerability to @signalapp for months now (first attempt was 2025-11-23 to the official security-at email address). I haven't gotten any response from them, even after repeated attempts. This is highly frustrating.

Is there a way to reach them? I don't need any kind of special treatment, just someone acknowledging that the message has been received would be okay.

#signalapp

So... Anthropic spent weeks claiming that it couldn't publicly release its Mythos AI model because of its alleged offensive hacking capabilities and.... some AI nerds from Discord just found it and accessed it? Anthropic is a fucking joke. https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users
If this sounds bloody obvious to you, that is because it is. Yet, it seems to be forgotten by many these days.
Not every security adjacent bug is an exploitable vulnerability.
The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/