Elektrine lite

← Feed

Wladimir Palant

WPalant@infosec.exchange

<p>Software developer and security researcher, browser extensions expert. / searchable</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurty" class="mention hashtag" rel="tag">#<span>cybersecurty</span></a> <a href="https://infosec.exchange/tags/cryptography" class="mention hashtag" rel="tag">#<span>cryptography</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="tag">#<span>privacy</span></a></p>

Posts

  • View post

    RE: https://hachyderm.io/@evacide/117334019442909852 I recommend that you read this article and think long and hard about it. If your first reaction is “half of this is probably not true” then you are part of the problem and this is something you have to fix. If victims speak out in the only way they feel they can, then you have to take this seriously and listen, then think about the structures that enabled their abusers and your role in those. Also, if you want to keep your faith in humanity...

  • View post

    I see news that the #FTAPI data exchange platform has been hacked. And that name actually rings a bell, I’ve written about it a while ago: https://palant.info/2018/07/11/ftapi-secutransfer-the-secure-alternative-to-emails-not-quite/ Back then I found that their claims of data being end-to-end encrypted should be taken with a grain of salt. We might find out now just how large of a grain.

  • View post

    Remember when you had to resort to hacks like this one in order to have some basic privacy? https://palant.info/2009/03/02/getting-rid-of-flash-cookies/ Adobe Flash EOL was six years ago, though it got phased out before that already. A great win for the web platform.

  • View post

    RE: https://hachyderm.io/@evacide/117389459796477111 It was of course to be assumed that the reason Russian government pushes Max messenger down everybody’s throat is so that they get full visibility into the communication. So no real surprises here but still good to see this analysis despite Max developers going to great lengths to make analysis harder.

  • View post

    We are going to see lots of open source projects deciding on how to deal with fascists within their community. After decades of conditioning people to view tech as a neutral, politics-free zone, very often they will make the wrong decision. You cannot have an open and welcoming community if you allow fascists or discuss that they might actually be “merely” racists or find other excuses not to take a decisive action. See paradox of tolerance. If projects are being forked over this matter, I gues...

  • View post

    As things are going, it is unfortunately unavoidable that military will be using “AI” without understanding the limitations of this technology. This scares the hell out of me. https://arstechnica.com/ai/2025/10/army-general-says-hes-using-ai-to-improve-decision-making/

  • View post

    RE: https://infosec.exchange/@WPalant/115380794950758884 Gotta love the world we are living in now. report put together by a special operations command analyst and found it had been generated with the help of artificial intelligence (AI) — and that a chatbot the analyst had used inaccurately identified the material the ship was carrying. The report, according to one of the sources, was “entirely false.” But it also “almost started a war,” the source said. https://edition.cnn.com/2026/09/18/p...

  • View post

    What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (M...

  • View post

    I have an extreme urge to reimplement Gtk’s ColumnView instead of dealing with the original. Not because of bugs but because of policy decisions. The former can get fixed, the latter won’t be. Like: I’ve never had to deal with a list widget where it was a policy decision not to expose the currently focused row. Some dev: “I need to know the currently focused row to display a context menu.” Gtk devs: “That’s not how you do it, register your context menu for individual cells, then you won’t need t...

  • View post

    Reading this article and (remarkably) its comments is fun: https://arstechnica.com/ai/2026/08/the-new-instagram-logo-is-the-perfect-embodiment-of-ai-slop/ I mean, I do create an occasional icon containing text. I know some issues to watch for but I am by no means a designer, so I probably do a rather bad job. Reading how people perceive this hack job of a logo is remarkably helpful, I’ve learned a few new things to avoid. Also, it helps boost my self-esteem – my icons may not be great, but at l...

  • View post

    Has been a while since I updated my collection of Chrome extension manifests. Just uploaded another snapshot: https://codeberg.org/palant/chrome-extension-manifests-dataset Since my last snapshot (January 2025) there has been an outright explosion of extension numbers. With 250k it’s now almost twice as many extension manifests despite no changes on my end. The Chrome Web Store spammers have been very busy… There have been reports about hundreds of “misleading” VPN extensions in CWS (as in: tr...

  • View post

    And I thought that the “expert” hired by a certain German publishing house was bad, putting his considerable academic reputation on the line with some complete bullshit arguments (as in: contradicting CS Theory 101 course to support his employer’s line of argumentation). That was a while ago, so I guess that he used students to play the role of cheap text generators. Nowadays that is no longer necessary of course. https://www.404media.co/show-how-3m-is-0-at-fault-expert-witness-used-chatgpt-to-...

  • View post

    One really has to wonder how some decisions were made. So somebody at #BMW thought: “You know, those suckers who paid $50,000 or more for our cars? We should really milk them some more. They probably get bored waiting for their car to start up anyway, let’s show them some ads! We’ll call it a special surprise for the drivers, no way they’ll object then.” Yes, totally reasonable. Way to destroy a brand’s reputation… https://www.theautopian.com/bmw-is-showing-commercials-on-their-cars-dash-scree...

  • View post

    @hans I thought cracking encryption involves typing on a keyboard really fast? 🤔

  • View post

    Hollywood has some weird obsession with computer displays. A spy needs to copy data? They attach some fancy device to the display. Need to shut down a computer? They shoot the display of course. And never mind that a computer virus will always produce visible glitches on the display.

  • View post

    @cR0w Could you please add the image text to the alt text? E.g.: A toy steering wheel mounted on the dash of the passenger side of a car. Above it the text: “When slopoholics think they’re in control of their machine of lies”

  • View post

    LLMs are quickly eroding the concept of truth. I’m sure that more known people have had to refute claims about them for a while but now it happened to me as well. A researcher from a respectable university contacted me asking for an interview regarding “my position” on a particular topic. The issue: the cited position is the exact opposite of what I’ve always said, and I’m pretty sure that there are zero online sources confirming it to be mine. But whichever LLM they’ve consulted constructed a...

  • View post

    #OperaBrowser sending me spam to an address that I definitely didn’t give them, asking me to promote their ad blocking feature? Because … checks notes … I wrote an article about malicious ad blocking extensions that has the necessary keywords. “Since your site already covers tools and tips that help people have a better time online.” Not even mentioning my name because why would they bother finding it, I’m just some random blogger from the internet that their automated tools brought up. That’s...

  • View post

    That’s some really evil shit: https://lemmy.world/post/49794261 So Tesseract (an alternative Lemmy client) downloads a blocking/filtering list from its servers, something that most people likely weren’t aware. This “feature” was introduced November last year (version 1.5.0) and is described as “Tesseract attempts to filter out as much baseline toxicity as possible” in the settings option allowing it to be disabled. The list currently contains 544 (!) individual users and 2282 (!!) regular expr...

  • View post

    Some very good points on Linus Torvalds’ problematic AI take: https://drewdevault.com/blog/AI-in-Linux/ Yes, Linux is an extremely influential project, and simply denying the responsibility that comes with this influence is very cheap.

  • View post

    @simsa03@gnusocial.jp Other people’s mental health is not up to you to decide. That’s an even worse take than your first post, you are blocked.

  • View post

    @simsa03 Is your mental health affected by cat videos?

  • View post

    Content warnings serve a purpose. Yes, that includes politics. You may feel that a topic is too important to “hide” it. But please understand that people are currently getting bombarded by horrible politics news from all directions. This is not sustainable, and it’s often a choice between muting this at least temporarily or burning out. So: please don’t be an asshole and use content warnings. People ask for them for a reason, not to annoy you or to downplay the importance. (I fully acknowledg...

  • View post

    I have been rethinking my life’s choices lately. I’ve spent years building a knowledge base for Firefox extension developers. Despite all its flaws, and development complexity definitely was one of them, the Firefox extension ecosystem was meant to provide functionality that browser developers didn’t think about. Then Chrome came along and forced Mozilla to abandon its extensibility approach for one which was neatly limited to functionality that browser developers decided to allow. They had goo...

  • View post

    RE: https://infosec.exchange/@WPalant/115633275489771501 It seems that I should start looking for a replacement for this laptop after all. Any recommendations, any other company with good hardware that can be repaired?

  • View post

    Don’t get your hopes up that Ford rehiring some engineers is a sign of the industry recognizing just how detrimental the whole “AI” thing is. https://www.independent.co.uk/tech/ford-ai-automation-humans-hiring-artificial-intelligence-b3004733.html It’s telling that Ford is only re-hiring “greybeards,” their most experienced engineers. A junior has no chance of getting their job back, nor will they ever get a chance to become one of those experienced engineers. Ford isn’t interested in building...

  • View post

    RE: https://floss.social/@gcmd/116590103974336547 In case you are wondering what I’ve been up to lately: I’ve been contributing to Gnome Commander. Thing is, I care about file managers. Next to web browsers and editors they are essential work tools for me. And Gnome Commander has been recently rewritten in Rust, making it easy to contribute to. Things have been in a rather dire state however, so I’ve been fixing lots and lots of bugs while also adding occasional features. There is still work t...

  • View post

    RE: https://mstdn.social/@jschauma/116610268796045193 So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place. But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In othe...

  • View post

    Has been a while since I’ve been releasing software. So it’s interesting to watch the news after Gnome Commander 2.0 release. I mean, there are the obvious LLM-generated articles flooding the zone with shit. And then there is the seemingly well-written article featuring a Windows screenshot of a Linux application, crediting Midjourney for it. At which point the realization dawns that the content is merely an approximate translation of a proper human-written article.

  • View post

    Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…