René Mayrhofer  🇺🇦

1.4K Followers
386 Following
3.4K Posts

Prof. for networks and security at #JKULinz + dabbling in Android platform security at #Google. This account will mostly carry IT security stuff, occasionally politics and other comedy.

Screeching voice of the minority. I will not cooperate with fascists or nazis - traditional or neo; Austrian, German, US, Russian, or otherwise. I will not help build surveillance and oppression states. Never again.

"I need privacy, not because my actions are questionable, but because your judgement and intentions are."

Statements are only my own opinion, not my employers'.

This is currently my primary infosec account in the #Fediverse. It should be #searchable through https://tootfinder.ch. Previous Twitter posts are available in archival form at https://twitterarchive.mayrhofer.eu.org/.

Homepagehttps://www.mayrhofer.eu.org
Universityhttps://jku.at/ins

Liftoff! Returning to the Moon
Image Credit & Copyright: NASA/Bill Ingalls; Text: Ogetay Kayali (MTU)

Explanation: We are one small step closer to returning to the Moon. A new chapter in human exploration began Wednesday when NASA's Artemis II launched aboard the Space Launch System (SLS) from Kennedy Space Center. Carrying four astronauts, the Orion spacecraft's planned lunar flyby will be the first in over half a century. This historic test flight, echoing the legacy of Apollo while pushing beyond it, will carry its crew farther from Earth than any humans since 1972, looping around the Moon before returning home. During the approximately ten-day journey, Orion's systems--from life support to navigation--will be tested in deep space, while astronauts observe the lunar surface, including shadowed regions of the far side rarely seen with such perspective. After looping around the Moon, the astronauts will return to Earth, ending their journey with a Pacific Ocean splashdown.

https://apod.nasa.gov/apod/ap260402.html #apod

Heavy drama in the open-source world of...

...Office Document Software.

Nextcloud, originally a fork of ownCloud, has launched Euro-Office, a fork of OnlyOffice (pissing off OnlyOffice). Collabora is weighing in and issuing comments against both OnlyOffice and Euro-Office while, itself, forking Collabora Office Desktop from the Document Foundation's LibreOffice. Document Foundation has now resumed LibreOffice Online which competes against Euro-Office and OnlyOffice.

(I think I've got all that right 😅 Correct me if I haven't! 😂)

❤️‍🔥❤️‍🔥❤️‍🔥 I unironically love this!!!! ❤️‍🔥❤️‍🔥❤️‍🔥

Document software may appear boring on its face, but Microsoft Office is a big reason why folks still stay with Microsoft OS and don't (can't...) move to Linux. MS Office 365 is often used as a bridge to allow folks to move to Linux while still using Microsoft products in the browser but that solution still keeps them tied to closed source solutions.

Development of Free and Open Sourced Software (FOSS) office products, both desktop apps and online web apps, is a core and key element to allowing FOSS solutions to thrive - both for individuals and organizations.

This level of drama and fighting is indicative of a lot of effort and attention being thrown into this arena. I'm confident over time it'll settle and different projects will merge back together or at the very least borrow and build upon each's efforts.

Read and get your fill of the drama here: https://www.theregister.com/2026/04/02/eurooffice_forks_onlyoffice/

#FOSS #digitalSovereignty #installParty #Linux #diDay

Forking frenzy ensues after Euro-Office launch sparks OnlyOffice backlash

: Meanwhile, Collabora splits from LibreOffice Online amid claims TDF ejected 'all Collabora staff and partners'

The Register

RE: https://graphics.social/@metin/116335353888270814

For anybody (still) using #LinkedIn on a regular basis (and I understand that there are reasons for it), you may want to do that with #Firefox for the moment. At least the extensions scanning seems to be done only on Chrome browsers according to https://browsergate.eu/how-it-works/, even if all the other profiling is probably browser agnostic.

I personally take this as an opportunity to ignore that platform completely for the time being. My account will remain as a defense against identity theft, but is fully dormant as of now.

#CyberSecurity
#SupplyChain
#CERTEU

A compromised version of Trivy gave attackers access to the European Commission’s europa.eu platform hosted on AWS.

We have published our analysis – what happened, who is affected, and what to do – in full transparency and in agreement with the European Commission.

https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain

European Commission cloud breach: a supply-chain compromise

European Commission cloud breach: a supply-chain compromise

LinkedIn Is Illegally Searching Your Computer

Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm. The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.

BrowserGate

People keep assuring me that LLMs writing code is a revolution, that as long as we maintain sound engineering practices and tight code review they're actually extruding code fit for purpose in a fraction of the time it would take a human.

And every damned time, every damned time any of that code surfaces, like Anthropic's flagship offering just did, somehow it's exactly the pile of steaming technical debt and fifteen year old Stack Overflow snippets we were assured your careful oversight made sure it isn't.

Can someone please explain this to me? Is everyone but you simply prompting it wrong?

It's a good thing programmers aren't susceptible to hubris in any way, or this would have been so much worse.

Probably going to get a viral blog out of this experience, I'm trying to report a 4tb exposed cloud bucket to a company using their responsible disclosure programme... but they replaced the people with a GenAI ticket system that refuses to discuss the case as it thinks exploring open buckets is unethical and against its rules.

New, by me: A popular Canadian money transfer app exposed thousands of driver's licenses and passports to the open web. Anyone with a link was able to view the data in their browser.

The data goes back to September 2020, and was updating daily until the server was secured this week.

https://techcrunch.com/2026/04/02/canadian-money-transfer-app-duc-expose-drivers-licenses-passports-amazon-server/

Exclusive: Money transfer app Duc exposed thousands of driver's licenses and passports to the open web

An exposed Amazon-hosted server allowed anyone to access reams of customer data without needing a password.

TechCrunch
  • Claude code source "leaks" in a mapfile
  • people immediately use the code laundering machines to code launder the code laundering frontend
  • now many dubious open source-ish knockoffs in python and rust being derived directly from the source

What's anthropic going to do, sue them? Insist in court that LLM recreating copyrighted code is a violation of copyright???

"Top Brussels official urges Europeans to work from home and drive less"
https://www.politico.eu/article/europeans-urged-to-work-from-home-and-drive-less-as-eu-warns-of-long-crisis/

Some excerpts:

"The more you can do to save oil, especially diesel, especially jet fuel, the better we are off"

"...work from home where possible, reduce highway speed limits by ten kilometers [an hour], encourage public transport, alternate private car access ... increase car sharing and adopt efficient driving practices."

"Longer term, he urged EU countries to double down on building more renewables, saying 'this must be the time we finally turn the tide and truly become energy independent.'"

Top Brussels official urges Europeans to work from home and drive less

Energy commissioner says the oil crisis triggered by Iran war will bring lengthy upheaval, in a speech reminiscent of the Covid pandemic.

POLITICO