Dr. Christopher Kunz
christopherkunz@chaos.social
<p>Security (web, infra, app) nerd, has accepted that VR will never be a mass market, writer @heise Security <br />All toots are IMHO & not my employer's opinion. <br />PGP fingerprint: C882 8ED1 7DD1 9011 C088 EA50 5CFA 2EEB 397A CAC1</p>
Posts
-
View post
Das Kunzsche Lemma: Jedes Problem in der Informatik lässt sich auf ein Problem der WebPKI zurückführen.
-
View post
CrowdSec writes to me: „Monthly alert quota exhausted for christopher-kunz's account Your Community plan has reached its monthly quota of 500 alerts.“ At 3:32 am on September 1. Well…. „Premium raises your alert quota to 10k/month/Security Engine“, they also upsell me. Yeah right. That would take me all the way to midday on the 3rd! Guess I‘ll have to take a deep dive into the alerting behavior.
-
View post
ChatGPT can modify various formats, and I tried to have it consistently modify a .STL file multiple times in the same manner. I.e.: "This STL has a roman numeral V on it - please replace it with a IV". Unfortunately, consistency was not achievable and the results were unsatisfactory. See the pic. The LLM also fails at geometry changes with specific constraints ("keep this part perfectly round"). I should probably have spent the time learning a little Blender.
-
View post
So apparently Mindgard reported a trivial RCE in Cursor (if a repo opened by Cursor includes a git.exe file, that file is executed) in December 2025 (!) via HackerOne, and getting Cursor's attention required calling them out on LinkedIn. They ghosted Mindgard, prompting them to disclose. This is a 7-month window for attackers. Coordinated Disclosure is dead. Let's switch back to FD. Who owns securityfocus.com these days? https://mindgard.ai/blog/cursor-0day-when-full-disclosure-become...
-
View post
"Software-Update Ursache von IT-Problemen der Berliner Justiz", titeln wir in der Meldung zum gestrigen Ausfall. Das Update wurde "zurückgenommen", lässt die Berliner Justizverwaltung mitteilen. Gleichzeitig behebt Microsoft im heutigen Patch 621 CVEs. Cherrypicking bei Updates und selektiver Rollback, weil Legacy-Software nicht mit einem Update klarkommt, wird künftig schlicht nicht mehr funktionieren. Das ist ein simples Rechenexempel. Digitale Resilienz muss bei Update...
-
View post
RE: https://chaos.social/@Lilith/116917560042690115 Vor allem, weil "Responsible Disclosure" ein guilt tripping beinhaltet, wie es nur ein Kampfbegriff aus Redmond tun kann...
-
View post
As it turns out, Aldi-Nord in Germany is offering mini air coolers (you know, like in this article: https://heise.de/-11346708) from tomorrow. Retail price: 12.99 EUR. Essentially the same device is marketed with aggressive ads for prices between 59.99 and 69.99 EUR (prices vary randomly) by shady businesses. This exact model is available on Alibaba for around 4.50 EUR (minimum order of 5,000) - so Aldi's still turning a profit, but not ripping customers off. I might even get one.
-
View post
So it begins.
-
View post
Ein weiterer Grund, warum man der Google-AI-Zusammenfassung kein Stück vertrauen darf: Sie befindet sich bei der Erkennung von Black Hat AIEO auf dem Stand, den SEO etwa im Jahr 2002 hatte. Exhibit A (2026, koloriert). Der angebliche Test ist natürlich Spam auf einer Domain, die sonst reichlich Potenzmittel und weiteren Kram "testet". Way to go, Google. Way to go. *slow clap*
-
View post
Well, this is fun. If you end up on one of the "Airabreeze" or "Jetterix" or the other products marketed by Commerce Core, UAB, and you start filling out the order form, entering an e-mail address or, gods forbid, a phone number, an XHR fires in the background, adding you to Commerce Core's (or Rara Digital's) CRM. I just received an e-mail reminder that I haven't finished my order - and I'll doubtlessly receive more spam soon. #jetterix #airabreeze #commerce...
-
View post
DDosia's config today looks like the tour schedule for a music group that has seen better days. They're playing small venues all over Germany, shying away from the big stage.
-
View post
Ich habe dem NDR ein paar Infos zu den Wunderkühlern gegeben und daraus wurde folgendes Stück: https://www.ndr.de/ratgeber/verbraucher/fake-klimaanlagen-zu-wucherpreisen-die-grosse-abzocke-bei-hitze,klimaanlagen-100.html
-
View post
Der Verfassungsschutzbericht 2025 ist auch online. Man kann da auch schön das Framing mittels toxischer Rhetorik erkennen. Dobrindts Vorwort nennt erst den Linksextremismus und dann "Daneben bleibt der Rechtsextremismus die größte Bedrohung für unsere freiheitliche demokratische Grundordnung." Das erweckt den Eindruck, dass der Linksextremismus eine ähnlich große Bedrohung der FGDO sei wie der von rechts. Dem ist aber nicht so, wie die Zahlen zeigen. 1/2
-
View post
Die Innenministerkonferenz will Indymedia komplett verbieten. Weil wir als Gesellschaft derzeit keine drängenderen Extremismus-Probleme haben. In 85 Seiten der Beschlusssammlung wird kein einziges Mal das Wort "rechtsextrem" erwähnt. Die haben im wahrsten Sinne des Wortes die Schüsse nicht gehört. https://www.innenministerkonferenz.de/IMK/DE/termine/to-beschluesse/2026-06-19_DOK/Freie_Beschl%C3%BCsse.pdf?__blob=publicationFile&v=1
-
View post
So this kind of flew under my radar during the hot weekend. It seems that one of the two owners of Mullvad made a € 450K donation to the Örebro party, a populist party with a strong "Sweden for the Swedes" & "we support remigration" sentiment. https://www.flamman.se/techprofil-ger-miljoner-till-orebropartiet/ I'm a little wary of VPN providers supporting populist orgs, to put it diplomatically. I'm wondering if someone has more clue on this party, and their connec...
-
View post
Chip hat sich, na sagen wir mal, von meiner kürzlichen Berichterstattung zur Midea Portasplit und zu den Fake-Klimageräten "inspirieren" lassen, im oberen Teil des Artikels aber noch was zu Fakeshops reingerührt. Naja, kann man machen. Die Screenshots zu der massiven Werbekampagne dieser "Klimageräte" sind allerdings extrem on point, die wirken total echt. Und bewegen sich. Und sind klickbar. Halt, warte...
-
View post
Für den NDR Kiel habe ich eine Einordnung zum Datenabgriff beim Klinikdienstleister Unimed gegeben. https://www.ndr.de/nachrichten/schleswig-holstein/uksh-cyberangriff-mutmasslich-ein-erpressungsversuch,uksh-146.html
-
View post
Na, das wird die Lage sicherlich entspannen. /s
-
View post
Kundendienst-Deutsch, Lektion 12: Kundendienst: &quot;Wir brauchen noch mehr Informationen: Tritt das Problem noch immer auf?&quot; Deutsch: &quot;Dieses Ticket kann die nächste Schicht bearbeiten.&quot;
-
View post
Flipper One is a chunky boi!
-
View post
I wrote a thing about curl and the woefully underfunded open source universe: https://www.heise.de/en/opinion/Comment-Open-source-developers-are-working-themselves-sick-on-AI-bugs-11308553.html @bagder
-
View post
Stellt sich heraus: Einem großen US-Techkonzern die Kontrolle über mobile Betriebssysteme UND Websuche UND Formular-Spamschutz anzuvertrauen, kann nach hinten losgehen. Who could have thought? Zum Glück vertrauen wir nicht einem anderen US-Techkonzern die Kontrolle über CDN UND dDoS-Schutz UND Bot-Schutz UND Formular-Spamschutz und Tunnel UND öffentliches DNS-Resolving an, weil: Das wäre ja total unsinnig! #werironiefindetdarfsiebehalten #krautfair
-
View post
@noujoum@ohai.social "Unsere 51 Vermessungsämter arbeiten seit den 1960er Jahren komplett mit Open-Source-Arbeitsplätzen." Okayyyyy....
-
View post
Sooo... is Copy Fail fixed in the current Debian kernel package? *squints* *squints harder* *gets prescription for reading glasses* *buys reading glasses* *misplaces reading glasses* ...yup. well hidden though.
-
View post
OK, I&#39;m officially locked in a time loop. CAs fuck up their stuff, we&#39;re supposed to compile kernels ourselves for maximum security and there&#39;s a new ProFTPd mod_sql vulnerability each week. It&#39;s Groundhog Day again...
-
View post
Wenn ihr aus gegebenem Anlass mehr zu DNSSEC wissen wollt: Passwort Folge 37 geht tieeeef ins Detail (Gast: Peter Thomassen von deSEC). https://passwort.podigee.io/37-dnssec-die-dns-security-extensions
-
View post
Dass ich im Bayrischen Rundfunk mal Julia Klöckner verteidigen würde, hatte ich nicht auf meiner 2026er Bingokarte. Und doch tat ich es gestern - um den &quot;Signal-Hack&quot; ein wenig einzuordnen. Aus meiner Sicht wichtig: Selbst wenn es politisch opportun erscheint, &quot;höhö die Doofe lässt sich phishen&quot; zu machen, ist das unangebracht. Dass Shaming die Situation rund um Social Engineering verschlimmert, ist schließlich sattsam bekannt. https://www.br.de/nachrichten...
-
View post
May the Fourth be with you! What better way to symbolize that... the Red Sun still prevails!
-
View post
Good morning everyone! From today, it shall be known that the Red Sun did, in fact, prevail over DNSSEC resolution in the .de zone. This Windows LPE is now giving Liz Truss and her lettuce a run for their money.
-
View post
@mweagle And there's one problem in computer security: 1. How do we save the private keys for this?