Elektrine lite

← Feed

Jan Schaumann

jschauma@mstdn.social

<p>Vell, I&#39;m just zis guy, you know?</p>

Posts

  • View post

    So what&#39;s the over/under that this Vercel KVM escape 0-day is - a Vercel only thing - an AWS Firecracker only thing - an actual all-KVMs affected thing ? https://nitter.cf/rauchg/status/2106402024804020657#m (The overall vibes I&#39;m getting here make me skeptical.)

  • View post

    The real joke is of course that he probably first wanted to rename it to &quot;American Intelligence&quot;, but then he wouldn&#39;t be able to tell who&#39;s bootlicking or not when saying &quot;AI&quot;. As always, it&#39;s a loyalty test and fealty signal.

  • View post

    New plonk just dropped.

  • View post

    Quick reminder: Models Don&#39;t Go Rogue https://mail.cyberneticforests.com/models-dont-go-rogue/ (Now AI companies and their cultists on the other hand...)

  • View post

    Tee hee, HN stumbled upon my AI rant blog post and boy is that a different discussion from Lobsters. ✌️

  • View post

    There isn’t a 10% chance that AI will kill all humans in the future via Skynet or the Paperclip Maximizer. But there’s a 100% chance it’s already doing so: mandating water wasting, air polluting, fossil fuel powered data centers, environmental regulations are lifted for these companies and even their feeblest greenwashing commitments to carbon neutrality or renewable energy sources are pulled while record heat and wildfires kill more and more people to teach AI how to spell “strawberry”.

  • View post

    Dear journalists: it&#39;s not &quot;AI escaped&quot;, it&#39;s &quot;AI companies failed to restrict the programs&quot;. Programs that did exactly what they were instructed to do. By those companies. Place the blame where it belongs.

  • View post

    Hey kids! It&#39;s the start of the Fall semester, and I&#39;m again teaching &quot;Advanced Programming in the UNIX Environment&quot;. The syllabus and all course materials including all code examples are available here: https://stevens.netmeister.org/631/ As usual, we&#39;ll be using #NetBSD as our main platform. All video lectures are public and available for free on YouTube: https://www.youtube.com/playlist?list=PL0qfF8MrJ-jxMfirAdxDs9zIiBg2Wug0z I&#39;ll be posting individual lecture vid...

  • View post

    This has absolutely entered my vocabulary. On the off-chance that you haven&#39;t seen this definition yet: Meat proxy 1. A person who forwards AI-generated text, code, or other output without reading, understanding, or validating it. The person acts only as a relay between the AI system and the intended recipient. https://sfisms.org/meat-proxy (Also: sf-isms.)

  • View post

    AI is notoriously verbose, often producing pages and pages of output that then, inevitably, the recipient feeds back into _their_ AI to summarize. AI companies are charging customers by the token, both input and output. It&#39;s almost as if there was some sort of connection there.

  • View post

    You&#39;re right - AI _is_ useful. Your use of it provides an important signal to me: 1) For writing: &quot;I didn&#39;t care to put the effort in to write this myself.&quot; 2) For coding: &quot;I don&#39;t care if I understand the solution.&quot; 3) For vuln impact analysis: &quot;I don&#39;t understand the code base nor the attack vector.&quot; Or shorter: &quot;I do not care about the details.&quot; This, of course, on top of the other ethical problems with AI. It&#39;s a strong signal,...

  • View post

    I&#39;ve used the same metaphor (&quot;using AI for assignments is like paying somebody to go to the gym for you&quot;) for my students for a long time now. https://www.schneier.com/blog/archives/2026/07/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide.html (Going forward, I may also have to play &quot;Hacks&quot; Season 5 Episode 6 for my students on the first day of the semester.)

  • View post

    So, uhm, at this point, seems like local privilege escalation vulnerabilities are numerous enough that you can pretty much assume that any local user can become root and escape most containers, yes? &quot;FragGap&quot; LPE via IPv4/IPv6 UDP corking path https://blog.qwerty.or.kr/en/posts/cdf3008a-c1a4-4eca-a373-aa3a2bcf1489/ https://github.com/qwerty-po/security-research/tree/cve-2026-53362 https://github.com/sgkdev/ipv6_frag_escape

  • View post

    OpenAI now announces that its latest model is _so_ advanced that it considers itself too dangerous to be used by anybody and consequently has deleted itself. The crowd goes wild at the prospect of buying stock in a company that now focuses 100% of its tremendous efforts and compute power on _not_ building AI. It&#39;s difficult work, but for the sake of mankind, no sacrifice is too stupid.

  • View post

    RE: https://mastodon.social/@nixCraft/116953574480188144 Lol, nice. I&#39;ve said it before: linux kernel CVEs are no longer meaningful. You can&#39;t assess 432 new CVEs. You basically have to sit and wait to see which ones get a logo and a website or which ones become KEVs to prioritize.

  • View post

    Really looking forward to the first large-scale OpenAI / Anthropic API outage, where 85% of the industry will be flopping around trying to remember how to hello-world on their own while execs google &quot;how to write an email&quot;.

  • View post

    The whole &quot;We JuST DoNt KnOw iF Claude iS ConsCiOuS&quot; pitch annoys me to no end. The language Anthropic uses — first person narrative, assigned agency and intentions, use of human cognitive vocabulary and so on — consistently aims to imply consciousness. &quot;The program utilizes temporarily stores frequently accessed information relevant to multiple contexts&quot; is a lot less magical than &quot;Claude thinks in its J-space&quot;, &quot;privately notices&quot;, has &quot;intentions...

  • View post

    No, virtually everybody, when I ask a question on Slack I don&#39;t need you to copy that question into your AI bot and then paste the answer it gave you back to me. Goddammit. Srsly, what makes people think I (a) can&#39;t do that myself, and (b) want a 3K words sycophantic &quot;summary&quot; full of emojis and a 50/50 chance of confidently misleading all of us?

  • View post

    Oh, goodie. KVM Guest-to-Host escape &quot;Januscape (CVE-2026-53359)&quot; -- https://github.com/V4bel/Januscape https://www.openwall.com/lists/oss-security/2026/07/06/7

  • View post

    A few notes on Post-Quantum Certificates: - Yes, Merkle-Tree Certificates (MTCs) are smaller than ML-DSA certs, but still pretty large - MTCs come in two flavors: standalone and landmark-relative; servers will need to support both - clients need to update landmarks frequently; how will non-browsers handle that? - web-PKI (MTCs) and private PKI (ML-DSA) are diverging Things are getting more complex... https://www.netmeister.org/blog/pqc-certs.html #pqc #mtc #cryptography

  • View post

    I miss Web 1.0. You click a link, you get to the website, you read the content. What a concept.

  • View post

    This is wild. Anthropic ordered via export control directive &quot;to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.&quot; https://www.anthropic.com/news/fable-mythos-access

  • View post

    New OpenSSL advisory: https://openssl-library.org/news/secadv/20260609.txt 1 high, 5 medium, 12 low severity The high (CVE-2026-45447) was explicitly noted as discovered with help from Claude. What&#39;s more interesting is again the confirmation that vulnerabilities are increasingly identified independently by multiple people: CVE-2026-34182 (independently found by 4 different people), CVE-2026-35188 (2), CVE-2026-9076 (2), CVE-2026-34181 (2), CVE-2026-42766 (4).

  • View post

    So people are totally now using AI models for regular stuff that you can do via shell scripts and cron, because why do something for free when you can burn tokens and at the same time actively forget how to use the normal tools at your disposal? 🤦 🙏 🤦

  • View post

    @evacide@hachyderm.io hard same. All of them and all the fucking time. It&#39;s not like there&#39;s a shortage of reasons, and why pick and choose.

  • View post

    You know, I was going to let this domain expire... https://istheinternetonfire.com/ Originally set up for Heartbleed in 2014; hadn&amp;#39;t remembered to update it since the CrowdStrike incident two years ago. I guess I&amp;#39;ll just set it to a permanent &amp;quot;yes&amp;quot; going forward. #CopyFail #DirtyFrag

  • View post

    #DirtyFrag status/advisories: AlmaLinux: https://almalinux.org/blog/2026-05-07-dirty-frag/ Debian: https://security-tracker.debian.org/tracker/CVE-2026-43500 https://security-tracker.debian.org/tracker/CVE-2026-43284 Gentoo: https://bugs.gentoo.org/974307 RedHat: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2026-43284 https://access.redhat.com/security/cve/cve-2026-43284 nothing yet on CVE-2026-43500 Rocky: https://kb.ciq.com/article/rocky-linux/rl-dirty-frag-mitigation SUSE / OpenSUSE:...

  • View post

    This is the start of the Fall semester for my class &amp;quot;Advanced #Programming in the #UNIX Environment&amp;quot;. Syllabus and all course materials including all code examples available here: https://stevens.netmeister.org/631/ All video lectures are public and available for free on YouTube: https://www.youtube.com/@cs631apue/videos If you want to follow along, I&amp;#39;ll be posting weekly links in this thread throughout the semester.

  • View post

    Congrats! Your new job is: arguing with a bot. Multiple bots. And people outsourcing their brain to bots. But mostly bots. Sometimes you have to social engineer the bots to do your bidding. Sometimes you have to pit the bots against each other. But make no mistake, it&amp;#39;s arguing with the bots. That, and email. And meetings. How beauteous mankind is! O brave new world, That has such people in&amp;#39;t.

  • View post

    Btw, there&amp;#39;s _no_ way we&amp;#39;re done here with #DirtyFrag and #CopyFail. Everybody is aiming their LLMs at this attack path through the page cache now, and there&amp;#39;s bound to be other ways. Be ready to rinse and repeat a few more times before the dust settles, so I guess keep an even closer eye on linux kernel commits for a while. (And no, I don&amp;#39;t know how this will be sustainable.)