F. Maury ⏚

@x_cli@infosec.exchange
755 Followers
266 Following
3.9K Posts

Network and Protocol Security Specialist. I am currently freelancing on missions in the following domains: system, network, software and security engineering. I have a strong interest for applied cryptography, and I am used to give trainings and to write press articles and blog posts.

I am an antispeciesist, and member of L214, a French NGO fighting for animal rights. I also fight for LGBTQIA+ rights.

I am a RNG (Random Network Guy/Girl): do not expect better posts than those produced by an infinite number of monkeys.

#infosec #cybersecurity #network #crypto #linux #antispeciesism #author #privacy #podcast #devops #secdevops #devsecops #lgbt #fedi22 searchable

PronounsAny pronouns :nonbinary_flag:
OccupationNetwork Guardian Angel
Websitehttps://broken-by-design.fr/about
Podcast (Devops)https://pod.broken-by-design.fr
Position on AIKill it now
It’s time to leave rsyslog behind: https://www.rsyslog.com/rsyslog-goes-ai-first-a-new-chapter-begins/

Even if they go back on that, it’s proof enough that they can not be trusted. Not now, not ever. No critical piece of a system should rely on people who believe in the LLM illusion.

Sadly all of ./play.it infrastructure is currently relying on rsyslog for centralised logging management. If you use something else, and are happy with it, suggestions are welcome.

Right now our top candidates for a replacement are:
- syslogd, the original one
- syslog-ng (it seems powerful, but its documentation is awful)

Our needs are very basic, mostly we want to be able to tell the logging system to store logs in specific paths based on the process name, like sending rspamd logs to /var/log/mail/rspamd.log or unbound logs to /var/log/network/unbound.log.

Logs rotation is already handled by logrotate, so we do not need the syslog daemon to include the ability to handle that itself.

Being packaged in Debian is a non-negotiable requirement.
rsyslog Goes AI First — A New Chapter Begins - rsyslog

After 24 months of focused evaluation and careful experimentation, we’re excited to announce a major shift in the evolution of rsyslog: we’re going AI First. This marks the beginning of a strategic transformation in how we design, develop, and support rsyslog and its ecosystem. While today’s post is just a short announcement, it lays the […]

rsyslog

Pour info, le paiement des missions "sous 10 jours", chez #Malt... bah il y a des petites lignes. Les petites lignes, c'est que si t'es pas éligible, bah tu seras payé•e un jour... dans 30 à 60 jours.

Les conditions d'éligibilité, c'est le truc le plus anti-social que tu puisses imaginer : plus tu factures, plus t'es éligible.

Donc les riches sont payé•es rapidement, et, par contre, celleux qui galèrent et qui facturent peu, bah, iels suceront des cailloux en attendant de pouvoir se payer à manger.

#freelance #classisme

Yop,
Je viens de réuploader ma présentation éclair effectuée à Pass the Salt 2025, à propos du déploiement de secrets dans les infrastructures virtualisées en utilisant AF_VSOCK. J'ai ajouté des sous-titres en anglais et en français pour celleux que ça intéresse !

https://peertube.stream/w/eidYHtjaeE6nZtTbpy722r

#pts25 #terraform #systemd #secrets #infosec #vault

Kiki's Secret Delivery Service over AF_VSOCK

PeerTube

Hey,
I just reuploaded my lightning talk at Pass the Salt 2025 about secret deployment in virtual infrastructures using AF_VSOCK. I added subtitles in English and French for those interested.

https://peertube.stream/w/eidYHtjaeE6nZtTbpy722r

#pts25 #terraform #systemd #secrets #infosec #vault

Kiki's Secret Delivery Service over AF_VSOCK

PeerTube

Kiki's Secret Delivery Service over AF_VSOCK

https://peertube.stream/w/eidYHtjaeE6nZtTbpy722r

Kiki's Secret Delivery Service over AF_VSOCK

PeerTube
Fouilles à nu, mains sur les parties génitales, pénétrations avec une matraque… Disclose a enquêté sur les violences sexuelles commises lors de contrôles d’identité et de palpations de sécurité. Au moins 45 victimes depuis 2012.
https://disclose.ngo/fr/article/palpations-illegales-quand-les-controles-de-police-tournent-au-viol
Disclose.ngo

Disclose est un média et une ONG de journalisme d’investigation.

Disclose.ngo
#MeTooPolice : Après les révélations de Disclose, l’association NousToutes lance un vaste appel à témoignages pour les femmes et hommes victimes de violences sexistes et sexuelles commises par des membres des forces de l'ordre
👉 https://form.typeform.com/to/OVQKAFso
#MeTooPolice

Turn data collection into an experience with Typeform. Create beautiful online forms, surveys, quizzes, and so much more. Try it for FREE.

a blog post by my friend eevee which is, y’know, preaching to the choir about exactly what you think, but. yeah. https://eev.ee/blog/2025/07/03/the-rise-of-whatever/
The rise of Whatever

This was originally titled “I miss when computers were fun”. But in the course of writing it, I discovered that there is a reason computers became less fun, a dark thread woven through a number of events in recent history. Let me back up a bit.

Mon commentaire après cette première participation à la conférence : Pass the Salt, c'est vraiment le feu 🔥
#pts25

😇🤣

I'll be presenting a lightning talk on secret provisioning using Terraform anywhere between 16h30 and 18h at #pts25
×

Last but not the least, let's end our program review with the PRIVACY session and 3 great talks 🤩

- @rafi0t will share the results of his last research about dirty tricks and code from some of the world's largest websites 🔍
- @x_cli will review the current state of the metadata from popular Instant Messaging applications 🎯
- and we will finally learn from Sihem Bouhenniche how easy it is (or not!) to fingerprint Android devices without specific permission 👾

⚠️ Available seats are disappearing quickly!
🎟️ Book your free seat: https://pretix.eu/passthesalt/2025/
📖 Schedule: https://cfp.pass-the-salt.org/pts2025/schedule/
📍 Lille, FR | 📅 July 1 to 3, 2025

Relays appreciated 🙏