Caligin Tsukihara is a user on octodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Caligin Tsukihara @caligin@octodon.social

errm, does this mean that using maven is a risk? github.com/snyk/zip-slip-vulne
I'm tempted to say that as long as you only use dependency from trusted publishers and from a trusted repository it's alright but I'm pretty sure I'm minimizing the issue here.

after being away from java and spring for a while this was quite a good overview of what's new in the core framework: youtu.be/0V-3kUMfWCc

Conversation here reminded me of this awesome piece by James Mickens:

schneier.com/blog/archives/201

It's not often I get to describe #infosec writing as simultaneously informative and fucking hilarious but Mickens fills the bill.

tech tribalism, security exploits Show more

One of the Patreon sketches from the other night that I thought turned out cute!

finally bottled my latest . it's a truffle stout, so I called it "Proof of Wort"

holy shit.

reddit.com/r/Python/comments/8
twitter.com/x0rz/status/994116

"The ssh-decorator package from Python pip had an obvious backdoor"

sends host + username + password to an external website

There are two natural paths to progress as a programmer:

1. Pick up farming, because all software is terrible.
2. Get into infosec, because f*** all software.

@bugshiv good to know, I actually have no idea how device ids work so didn't think about it

About 7 hours ago, Amazon's Route53 #DNS service suffered a #BGP hijack lasting about 2 hours:

doublepulsar.com/hijack-of-ama

Only confirmed victim so far is a cryptocurrency site, lol.

Because I live in fear that there exist people who don't know about this: godbolt.org/

Want to know what a compiler actually does with your code? Find out, with nice highlighting of sections! Supports C, C++, Haskell, Go, Swift, Rust, and various other languages.

See. Explore. Understand.

a truffle ! I don't really know what I'm doing but I'm sure the result will be interesting!

til ham+cheese+mustard sandwiches from eat are tastier than the ones from pret

Sen. Catherine Cortez Masto

we are ๐™ž๐™ฃ๐™จ๐™ž๐™™๐™š

went snowboarding last week, got on the slopes right in time for the end of the season on the Dolomites
weather was great, sunny clear sky with soft snow

This was kind of delightful: holeybeep.ninja/

It's a half-joking vulnerability disclosure for a privesc bug in `beep` of all things (CVE-2018-0492). Lots of ridiculousness in the text.

But their recommended patching method is a poker-faced usage of an unpatched issue wherein `patch` can be told to call `ed`, which allows arbitrary command execution: rachelbythebay.com/w/2018/04/0