Ossi Herrala

@oherrala
176 Followers
223 Following
758 Posts

During days I'm developing advanced techniques to escape from isolated or segregated IT and OT networks helping critical infrastructure and enterprises secure their assets. Co-founder and R&D lead in SensorFu.

During nights I'm mostly sleeping, but also coding, hacking, building fiber optic home network and practicing ham radio (POTA/WWFF, QRP, digital modes, antenna building).

See my ham radio Mastodon account: https://mastodon.radio/@oh8hub/

Co Founderhttps://sensorfu.com/
Ham radio (OH8HUB)https://mastodon.radio/@oh8hub
GitHubhttps://github.com/oherrala

Posti lähetti minulle sähköpostia 19.1. otsikolla "Tärkeää: OmaPostin verkkoversion kirjautuminen muuttuu – tietoturva vahvistuu"

Leipätekstissä Posti kertoo, että "Jatkossa OmaPostin verkkoversioon kirjaudutaan sähköisellä tunnistautumisella."

Muutoksia luvattiin helmikuussa ja ne on tapahtunut.

Ennen OmaPostiin kirjauduttiin käyttäjätunnuksella ja salasanalla. Nyt sinne kirjaudutaan sähköpostiosoitteella ja salasanalla.

Tietoturva on selkeästi vahvistunut!

#tietoturva

Q: Why did you need to wait in a long line at Radio Shack to buy a 6502 microprocessor?

A: Not enough registers.

[video] Kotimaan Teknokatsaus / Domestic Techno Inspection. Short documentary by Tero Vuorinen (English subtitles, 22 January 2026).

https://youtu.be/HqqA2zkSVGg?si=4mPaB4474dxNLyEP

#KotimaanTeknokatsaus #DomesticTechnoInspection #SamuliKemppi #TeroVuorinen #techno #electro #electronic #documentary #Helsinki #Finland

Kotimaan Teknokatsaus / Domestic Techno Inspection. Short documentary by Tero Vuorinen

YouTube

me: move fast and break things

my dentist: what

New blog post! A close look at Tahoe menu icons. With 109 illustrations! https://tonsky.me/blog/tahoe-icons/
It’s hard to justify Tahoe icons

Looking at the first principles of icon design—and how Apple failed to apply all of them in macOS Tahoe

tonsky.me

woah!
Apparently Farscape is all on Youtube. Official channel has all the episodes. Did not expect that.

https://www.youtube.com/watch?v=yJQlHnZwToU&list=PLcBQS2xdzwLA5tv8kP2lODaP_nfh8siNn&index=1

#Farscape #SciFi #Youtube

Farscape S1E1 FULL Episode | Pilot

YouTube
All I saw was cheesecake boat and ocean for at least 5 minutes

The yearly cost of radio amateur license in Finland is going to almost double beginning of 2026.

The Finnish Transport and Communications Agency #Traficom increases their basic frequency fee and due to this radio amateur license will cost 35€ per year instead of old 18€ per year.

This cost increase is for every callsign in use so especially clubs running multiple repeaters, APRS and other automatic sites will take a big hit on their budget.

https://www.traficom.fi/en/news/traficom-service-fees-increase-1-january-2026

Traficom service fees to increase from 1 January 2026 | Traficom

Service fees charged by the Finnish Transport and Communications Agency Traficom will increase as of 1 January 2026. The increases will apply, for example, to consumer service fees and supervision fees charged to organisations. Fee increases will mainly range from approximately 10 to 20 per cent. Prices will increase in the areas of aviation, maritime, road and rail transport, as well as for domain name and frequency fees.

Traficom

the UNIX v4 tape reminded me of this story by Ali Akurgal about Turkish bureaucracy:

Do you know what the unit of software is? A meter! Do you know why? In 1992, we did our first software export at Netaş. We wrote the software, pressed a button, and via the satellite dish on the roof, at the incredible speed of 128 kb/s, we sent it to England. We sent the invoice by postal mail. $2M arrived at the bank. 3-4 months passed, and tax inspectors came. They said, “You sent an invoice for $2M?” “Yes,” we said. “This money has been paid?” they asked. “Yes,” we said. “But there is no goods export; this is fictitious export,” they said! So we took the tax inspectors to R&D and sat them in front of a computer. “Would you press this ‘Enter’ key?” we asked. One of them pressed it, then asked, “What happened?” “You just made a $300k export, and we’ll send its invoice too, and that will be paid as well,” we said. The man felt terrible because he had become an accomplice! Then we explained how software is written, what a satellite connection is, and how much this is worth. They said, “We understand, but there has to be a physical goods export; that’s what the regulations require.” So we said: “Let’s record this software onto tape (there were no CDs back then—nor cassettes; we used ½-inch tapes) and send that.” Happy to have found a solution, they said, “Okay, record it and send it.” The software filled two reels, which were handed to a customs broker, who took them to customs and started the export procedure. The customs officer processed things and at one point asked, “Where are the trucks?” The broker said, “There are no trucks—this is all there is,” and pointed to the tape reels on the desk. The customs officer said, “These two envelopes can’t be worth $2M; I can’t process this.” We went to court, an expert committee examined whether the two reels were worth $2M. Fortunately, they ruled that they were, and we were saved from the charge of fictitious export. The same broker took the same two reels to the same customs officer, with the court ruling, and restarted the procedure. However, during the process, the unit price, quantity, and total price of the exported goods had to be entered—as per the regulations. To avoid dragging things out further, they looked at the envelope, saw that it contained tape, estimated how many meters of tape there are on one reel, and concluded that we had exported 1k to 2k meters of software. So the unit of software became the meter.

RE: https://infosec.exchange/@jviide/115180291441974796

To recap, NPM allows 2FA TOTP token reuse within the token’s validity window.

I reported this and was told it’s a “known low-risk issue” and that they “don’t consider this to present a significant security risk.”

So, let’s look at how this seemingly small issue could be leveraged by a phisher. 1/