Raphaël Vinot
rafi0t@social.yoyodyne-it.eu
<p>I have various notes about the French administration.</p><p>I also write code and stuff.</p>
Posts
-
View post
Hey, quick question for the #infosec folks: are you still using securelist.com (the Kaspersky blog)? And if yes, have you looked at your traffic when you browse it? I just added support for websocket traffic on #lookyloo and it is pretty insane. They use yandex webvisor and afaict, the WS session calls home and sends enough data to replay your whole session (mouse movment, scrolling, ...), on top of everything they can get about your browser. Example: https://lookyloo.circl.lu/tree/7849cb0d-ae...
-
View post
@frenchtoast@better.boston they're noobs. What about the Waffel Houses?
-
View post
I find it so absolutely hilarious and on brand that the whistleblower in the Edouard Philippe embezzelment case is franco-german. https://www.radiofrance.fr/franceinter/podcasts/l-info-de-france-inter/le-maire-du-havre-edouard-philippe-vise-par-une-enquete-pour-detournements-de-fonds-publics-5402614
-
View post
maybe pushing code as quickly as possible with zero domain knowlege and ignoring all existing research is not the best idea after all it&#39;s hard to tell but clearly there is not way to know
-
View post
OH yesterday from a non-tech person, at a tech event: &quot;I was at the local chapter of the MEDEF (french bosses union) and we did a poll with our member asking if using AI increased their benefits, and ~70% said no.&quot; With a very strong undertone of &quot;WTF nerds?&quot;
-
View post
RE: https://infosec.exchange/@lcamtuf/116517194178120536 This, but on everything, with whichever AI gave free token that day, and nobody bother paying for an audit. That&#39;s software dev right now.
-
View post
RE: https://infosec.exchange/@lerg/116524161473318491 To every techie lolsobing at &quot;HR is writing code, we&#39;re all gonna die&quot;: maybe we should have thought about it before now. We&#39;ve been fighting tooth and nails since forever to make sure that there would be no regulation whatsoever on writing software. So wen we do a terrible job, it doesn&#39;t have any bad repercussion (on us). The consequence is that for everyone else, software is kinda shit, and more...
-
View post
Just heard Michael Moore (Anthropic) on Planet Money saying that with their cyber cyber tools and best practices, they can *assure* to fine all the bug before the code goes to prod. I&#39;m looking forward seeing them being sued because they didn&#39;t.
-
View post
In todays&#39; AI PRs fun: &quot;here is a thing, I tested it against mock data, so you should test it against real data before merging it.&quot; The non-mock data is public (the mocked data isn&#39;t, amusingly enough), it is just that they cannot be arsed to do more than the prompt. (the code is simple, and by looking at it, I&#39;m pretty sure it will most probably work, but folks, at least try)
-
View post
Bon, la TBM vous êtes sympa, mais 3 interruptions de traffic sur le tram sur les 4 derniers jours, ça va pas le faire. Sans compter l&#39;augmentation des tarifs, et avec la fermeture du pont de pierre tout l&#39;été...
-
View post
well, at least, if your bank website is responding right now, it&#39;s probably really your bank. #cloudflare
-
View post
RE: https://infosec.exchange/@da_667/116518148479614779 The safest day on the internet in recent memories was when cloudflare shat itself and all the phishing sites were down.
-
View post
Oh FFS seems the website for ANTS (National Agency for Secured Documents) was letting you get data from another user by just changing the ID in the request. 19M accounts leaked (~1/3 of the french population). Also, if that&#39;s how it worked, how the fuck can you not notice it for long enough that the attacker was able to get everything. This is 🥖excellence francaise🥖 for you all. https://frenchbreaches.com/blog/fuite-massive-a-lants-jusqua-19-millions-de-donnees-sensibles-exposees (FR...
-
View post
Just spotted that one today: EFTA00718363.pdf, modified on the 9th of February to unredact "elon" 🤷
-
View post
Welp, les Francais, si vous avez utilisé SOONCARE de YMED avant le 2026-04-06, tout est dans la nature. Ce qui est rigolo, c&#39;est que ce messge clairement automatique ne mentionne pas sooncare, donc sans fouiller, aucune idée de ce qui a été poppé...
-
View post
RE: https://mastodon.ar.al/@aral/116330105563818936 oh, we can tell.
-
View post
Seems we've reached the plot point "hero left behind enemy lines" of Wag the dog?
-
View post
In case you missed, you can bet on murder*. *offer only available for countries where the C-Suite doesn&#39;t live https://www.404media.co/with-iran-war-kalshi-and-polymarket-bet-that-the-depravity-economy-has-no-bottom/
-
View post
Todays cursed mimetype: text/plain; charset=gzip+enc wat
-
View post
Not everyone need to learn to code. Especially when &quot;learn to code&quot; means &quot;prompt an AI&quot;.
-
View post
So. Hear me out. The existence of a &quot;dignified transfer&quot; implies an &quot;undignified transfer&quot;, where they kick the coffin down the staircase. I don&#39;t make the rules.
-
View post
RE: https://vmst.io/@vmstan/116200819973767850 Hahaha
-
View post
Not sure if it is a bug, but surely it is confusing. If you run tor and require a specific country code for the exit node, with strict node to 1 (--ExitNodes {&lt;CC&gt;} --StrictNodes 1) it will properly raise an error if the CC in invalid (say FOO), but if the CC exists *and* and there are no exits in that country, it will simply fallback to whatever, without any warning.
-
View post
RE: https://indieweb.social/@Outpost/116251600317479260 so hmmm maybe people take note.