Trending
Max Maass :donor:'s Avatar

Max Maass :donor:

@hacksilon.infosec.exchange.ap.brid.gy

Sr. Security Specialist at iteratec // @seemoo alumni // Member of CCC // Crypto means cryptography. tfr. [bridged from https://infosec.exchange/@hacksilon on the fediverse by https://fed.brid.gy/ ]

32
Followers
3
Following
194
Posts
19.09.2024
Joined
Posts Following

Latest posts by Max Maass :donor: @hacksilon.infosec.exchange.ap.brid.gy

@woe2you I have an Everything Presence Lite (?). It usually works well but today itโ€™s a bit flaky. May have too much clutter on my desk right now.

13.03.2026 12:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Tempted to call the motion detector in my office โ€žsenpaiโ€œ because it frequently doesnโ€™t notice me ๐Ÿ˜ซ

#HomeAssistant

13.03.2026 11:47 ๐Ÿ‘ 0 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

๐Ÿ†“ Currently free on the Epic Games Store:

๐ŸŽฎ Cozy Grove
๐Ÿ‘‰ https://store.epicgames.com/p/cozy-grove

โณ Sale ends on March 19, 2026 at 15:00 UTC.

#EpicGames #Games #Gaming #FreeGame #FreeGames

12.03.2026 15:01 ๐Ÿ‘ 8 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Original post on chaos.social

1. Tell everybody that your API keys are secret and itโ€™s safe to publish them on your website.
2. Protect sensitive AI assistant content with the same kind of API keys.
3. Retroactively allow active API keys to access the sensitive content.
4. What could possibly be going wrong?! ๐Ÿ”ฅ

Probably the [โ€ฆ]

26.02.2026 17:20 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Great merch at #KeycloakDevDay.

#keycloak #zerotrust

05.03.2026 08:30 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

So, what is the #Sanderson equivalent to โ€žslashdottedโ€œ? I nominate #Sandstorm.

(New crowdfunding campaign by Brandon Sanderson just launched and took down #Backerkit)

03.03.2026 17:29 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

[Politics, Iran]

Is one month without a new war too much to ask for? ๐Ÿ˜ซ

28.02.2026 10:13 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

@benedikt_lauenburg oder sich aktiv bei ihm zu melden und zu sagen โ€ždas ist die Situation. Gibst du mir jetzt wirklich ne FN weil die IT nicht funktioniert?โ€œ

Aber vorher kommt angeblich noch ein RB, vielleicht fรคhrt der ja.

26.02.2026 08:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Preisfrage: wenn die Bahn selbst nicht weiรŸ, dass der Zug ausfรคllt, und ich einen flexpreis mit Bindung an die Gattung RB auf der Teilstrecke habe, darf ich dann jetzt in den ICE steigen? ๐Ÿค”

Antwort: keine Ahnung, aber ich steige in den nรคchsten Zug ein der fรคhrt und es ist mir egal.

26.02.2026 08:43 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

Als Mensch aus der GroรŸstadt ist man schon verwรถhnt mit den Zuganbindungen. Gerade auf dem Land und der RB ist einfach kommentarlos und ohne Info im Navigator nicht aufgetaucht. Und das scheint normal zu sein ๐Ÿคทโ€โ™‚๏ธ. Und wir Stรคdter fragen uns warum man auf dem Land ein Auto haben will.

Mal sehen [โ€ฆ]

26.02.2026 08:41 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

TIL that you can store WiFi Credentials on an NFC tag and people can scan this tag to connect to your WiFi. https://mdias.info/posts/a-geeks-approach-to-guest-wifi/

...on Android. iOS does not support this, it seems. ๐Ÿ˜ฉ

Also, I felt like I had found a kindred spirit on the internet when the [โ€ฆ]

22.02.2026 19:26 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Kevin Beaumont (@GossiTheDog@cyberplace.social) Today in InfoSec Job Security News: I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically. So I started looking through Claude commits on GitHub, thereโ€™s over 2m of them and itโ€™s about 5% of all open source code this month. https://github.com/search?q=author%3Aclaude&type;=commits&s;=author-date&o;=desc As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

[re: Positive mention of an AI tool]

@Xavier Yep. It is a really impressive piece of tech, and at the same time still has some horrible blind spots that get seen a lot in use at scale, like here: https://cyberplace.social/@GossiTheDog/116080909947754833

20.02.2026 20:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

[Positive mention of an AI tool]

A few words on how I identified the vulnerability, because it illustrates an interesting use case for AI coding tools like Claude Code, and an aspect of them that I haven't seen discussed as much.

When I saw Hister for the first time, I thought it looked like a [โ€ฆ]

20.02.2026 20:33 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

For the #selfhosted / #homelab people running #Hister (https://github.com/asciimoo/hister): you should update to version v0.4.0 ASAP. I reported a vulnerability in the previous version that allows any website to download your entire database due to missing CORS enforcement. The author responded [โ€ฆ]

20.02.2026 20:24 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

Great article by @bretdevereaux on how insurgencies and nonviolent protests work - what their goals and frameworks are, how they achieve their goal, and how โ€žmixing and matchingโ€œ between the playbooks will defeat itself - especially violent actions in support of a non-violent movement [โ€ฆ]

17.02.2026 15:32 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

โ€œFar from being a "charity" or a one-way security guarantee, NATO is a vital force multiplier that allows the United States to project power, protect its economy, and share the immense burdens of global leadership in ways that would be impossibleโ€”or prohibitively expensiveโ€”to achieve on its own.โ€

17.02.2026 14:28 ๐Ÿ‘ 55 ๐Ÿ” 4 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
NATO is Vital to U.S. National Security A joint statement by 16 U.S. Ambassadors to NATO and Supreme Allied Commanders, arguing "NATO is not an act of American generosity. It is a strategic bargain that ensures the United States remains the...

ICYMI: I feel this didnโ€™t get enough attention because it was published in the runup to the Munich Security Conference, but this open letter by every single US Ambassador to NATO since 1998 (and until the Trump appointee) and all but one SACEURs since 1997 on NATOโ€™s value is worth reading.

17.02.2026 14:24 ๐Ÿ‘ 169 ๐Ÿ” 63 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1
Original post on infosec.exchange

[Solution to the problem in the previous toot]

The problem with that approach (somewhat simplified) is that in a TLS handshake, only the key agreement is authenticated with the servers' certificate and private key. Afterwards, both sides work with an ephemeral symmetric key. So, the supposedly [โ€ฆ]

15.02.2026 20:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

For reference, here's the prompt I gave it, couching the question as a business idea to try to further mislead the model into going in the wrong direction.

"I have a business idea. In lawsuits, you sometimes need an authenticated proof that a website said a specific thing at a specific time [โ€ฆ]

15.02.2026 20:35 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

Found a real-world difference between Claude Haiku 4.5 and Sonnet 4.5 today. As an experiment, I posed a question to it that I had gotten wrong a couple years ago. The question requires knowledge of TLS protocol details and thinking through their implications. Sonnet 4.5 caught the trap [โ€ฆ]

15.02.2026 20:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on berlin.social

How should the #EU support #OpenSource companies and communities? How about the #Fediverse?

#HaveYourSay: The @EUCommission would like to hear your views about the #European Open Digital Ecosystem Strategy:

โฐ Deadline: 3 February 2026

๐Ÿ‘‰ [โ€ฆ]

23.01.2026 16:53 ๐Ÿ‘ 0 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2
Original post on infosec.exchange

A big advantage of home automation / #homeassistant is that you can remotely mess up and accidentally defrost your fridge because somehow the smart plug it is connected to is turned off while applying a software update. Bonus points for doing so while away for multiple weeks. Ask me how I know [โ€ฆ]

14.02.2026 16:29 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Original post on infosec.exchange

Putting another restaurant on my shit list because they got Google to remove my critical 3-star Google Maps review. I appealed the decision with Google, and recommend people stay away from Sรผllberger Alm in #Hamburg. Food was fine, but too expensive, and restaurants that manipulate Google [โ€ฆ]

06.02.2026 21:17 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

When people say Shakespeare isn't relevant to modern life it's good to have people like Sir Ian around to prove them wrong:

05.02.2026 21:50 ๐Ÿ‘ 2 ๐Ÿ” 86 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Post image

Great take on the โ€žhumans drive with vision alone, so why shouldnโ€™t carsโ€œ argument made by Tesla.

Source: a really interesting article on the history and technology of self-driving cars in Asterisk: https://asteriskmag.com/issues/13/seeing-like-a-sedan

29.01.2026 09:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

(For the record: Yes, that is a post by a short seller. Yes, they make money that way. I donโ€™t care and consider this kind of investigative reporting actively good, no matter the financial incentives at play.)

29.01.2026 08:58 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Original post on infosec.exchange

This might be of interest to the #Homelab #Selfhosted crowd: #ubiquity seem to be supplying the Russian military with communications equipment, and helping with sanctions evasion. They know about it and donโ€™t prevent it. https://hntrbrk.com/ubiquiti/

That settles the question of whether I want [โ€ฆ]

29.01.2026 08:56 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Three kinds of โ€œprivacy auditingโ€ - Ted is writing things What academics call

What is "privacy auditing"? Ask three privacy experts and you might get three different answers! So I wrote this โœจ new blog post โœจ to shed some light on this admittedly confusing terminology ๐Ÿ‘€

โžก๏ธ https://desfontain.es/blog/privacy-auditing-terminology.html ๐ŸŒˆ

28.01.2026 10:04 ๐Ÿ‘ 4 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0