David Schuetz *Looking for work*'s Avatar

David Schuetz *Looking for work*

@darthnull.infosec.exchange.ap.brid.gy

Information security, Scouting, making, cryptography puzzles, python, public infrastructure nerd. Also: http://keybase.io/DarthNull. [bridged from https://infosec.exchange/@darthnull on the fediverse by https://fed.brid.gy/ ]

29 Followers  |  1 Following  |  142 Posts  |  Joined: 13.11.2024  |  2.0945

Latest posts by darthnull.infosec.exchange.ap.brid.gy on Bluesky

@ivory Is there any way (or are there plans) to display BlueSky quote posts in the timeline? I can see the quoter, through a bridge, but the quoted post is just a big url.

Or do I just need to follow them through a different bridge, and that’ll take care of it for me?

06.08.2025 22:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The sweet smell of a great sorrow lies over the land
Plumes of smoke rise and merge into the leaden sky
A man lies and dreams of green fields and rivers
But awakes to a morning with no reason for waking

#lotd

06.08.2025 14:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

My first full day of paid work since being laid off a while back (it's a short-term contract). And so far I've managed to break my standing desk while rearranging cables for the new corporate laptop.

It's now at kneecap height, and I’ve got crippling vertigo from crawling underneath it and back […]

04.08.2025 16:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Neurotypicals: "Just break big tasks into smaller steps!"

ADHDer: breaks task into 108 micro-steps, gets overwhelmed by the long list, abandons task, start to research road building in the Roman Empire for 6 hours.

#adhd

04.08.2025 11:26 β€” πŸ‘ 41    πŸ” 120    πŸ’¬ 8    πŸ“Œ 1
Original post on infosec.exchange

I just realized something amusing. I’ve used a lot of programming languages over the years, but the ones I spent the most time in (for work and hobby) all start with P: Pascal, Perl, PHP, and Python.

Python is by far the most used, Pascal was
high school and college (a lot of it was a BBS I […]

02.08.2025 15:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A large plush stuffed toy based on the character Moopsy from Star Trek: Lower Decks.

A large plush stuffed toy based on the character Moopsy from Star Trek: Lower Decks.

This is the best gift…

02.08.2025 00:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
D.K. MacKinnon πŸ‡¨πŸ‡¦πŸ“ΈπŸ (@dkmackinnon@mstdn.ca) Lab-grown diamonds have become massively popular in recent years, giving the traditional, mined version a run for its money. https://www.cbc.ca/news/business/lab-grown-diamonds-1.7592336

It drives me crazy that people (and this article too) still call dirt-found diamonds β€œreal,” implying that lab-grown are fake.

They’re 100% genuine diamonds.

And champagne is champagne, no matter where the fuck you bottle it. https://mstdn.ca/@dkmackinnon/114919262525558959

26.07.2025 17:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

When an #ADHD person says β€žI forgotβ€œ what we often mean is:

* I remembered 5 times but at the wrong time
* I fully planned to do it but I felt overwhelmed
* I shamed myself for not doing it that I did not do it

26.07.2025 04:55 β€” πŸ‘ 5    πŸ” 77    πŸ’¬ 1    πŸ“Œ 0
Original post on infosec.exchange

This looks really interesting - Expel did a survey of Fortune 1000 cybersecurity job postings (5000 of them!) and found that, basically, they all suck (my summary).

* 8% offered remote.
* 10% addressed mental health.
* Pay is lower than related / adjacent fields.

Huh. Maybe the problem isn’t […]

23.07.2025 23:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
When users did not see an AI overview, the authors write, they clicked on links 15 percent of the time. When they did see one, that number fell nearly by half, to 8 percent.

The study also found that people are likelier to stop browsing after encountering an AI overview, suggesting that the overview has satisfied their curiosity. Researchers saw that outcome 26 percent of the time when AI overviews were displayed, up from 16 percent when they were not.

When users did not see an AI overview, the authors write, they clicked on links 15 percent of the time. When they did see one, that number fell nearly by half, to 8 percent. The study also found that people are likelier to stop browsing after encountering an AI overview, suggesting that the overview has satisfied their curiosity. Researchers saw that outcome 26 percent of the time when AI overviews were displayed, up from 16 percent when they were not.

A new Pew study offers data to back up what we have suspected for a while now: AI answers are draining all the traffic out of the web https://www.platformer.news/google-ai-overviews-pew-research/?ref=platformer-newsletter

23.07.2025 00:25 β€” πŸ‘ 5    πŸ” 39    πŸ’¬ 2    πŸ“Œ 1
Original post on meow.social

Another fun interaction with the transphobic coworker …

HIM: (angrily) I’m listed as β€œMrs.” in the company directory.
ME: What? That’s crazy. Must’ve been a typo. I’ll fix it.
HIM: Thank you.
ME: No problem. (waits until he’s walking away) It sucks to get misgendered, amirite?
HIM: Heh, yeah […]

17.07.2025 11:03 β€” πŸ‘ 3    πŸ” 10    πŸ’¬ 3    πŸ“Œ 0

Mongo need polysyllabic vocabulary.

16.07.2025 00:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

My son (and his twin sister) just turned 18. So I spent some time yesterday helping him with "adulting” - selecting adult primary physician, registering to vote, etc.

And the Selective Service website registration is broken. It's broken again this morning. I've done some quick searches but […]

09.07.2025 14:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

🚨 macOS Ollama[.app] folks: be SUPER CAREFUL with this app.

The Ollama folks have been ignoring an important vulnerability for over 6 months.

https://www.imperva.com/blog/hijacking-ollamas-signed-installer-for-code-execution/

☝🏽 Great work by Imperva researcher Ron Masas.

08.07.2025 10:29 β€” πŸ‘ 0    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Sarah Taber (@sarahtaber@mastodon.online) If you started paying attention to the US in 1960, this sure feels like the darkest timeline. But unfortunately, purges against Black & brown people are normal US behavior. You know what's NOT normal US behavior? This is the first time there's been a mass movement to STOP a purge in real time.

@darthnull @sarahtaber wrote on this subject. https://mastodon.online/@sarahtaber/114797148334315746

07.07.2025 18:56 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

There was a good thread a couple days ago about the difference between historical systemic racist attacks in the US and today’s, with the main thesis being that this time the pushback is happening in real time, rather than months or years later.

Of course I didn’t save the thread. Did anyone […]

07.07.2025 14:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Original post on fedi.simonwillison.net

Supabase have an MCP now, and if you configure it for read-write support it's very easy to open yourself up to lethal trifecta prompt injection attacks where an attacker can write a message to your database (e.g. in a support ticket) with instructions that cause your MCP client to retrieve and […]

06.07.2025 04:23 β€” πŸ‘ 11    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
trmnl.stephenyeargin.dev

For the last month or so, I've been building a handful of plugins for my @trmnl and decided to give them a proper landing page.

πŸ–ΌοΈ https://trmnl.stephenyeargin.dev/

04.07.2025 18:48 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Original post on defcon.social

Finally getting around to something I’ve always wanted to do. Fix the @ShmooCon videos for 2008, 2009, and 2010. Each talk is a series of many small video files.

Because I’m in the process of transcoding to AV1 and adding captions to #ShmooCon, I’m finally going to manually join all the […]

02.07.2025 07:14 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Marketing image of iPad menu bar in Pages

Marketing image of iPad menu bar in Pages

So many of the YouTuber reviews of iPadOS 26 are 'wow, I didn't know these iPad apps had all of these features' upon seeing the menu bar.

Just enforces the point: a menu bar is an educational tool with discoverability built in, just as much as anything else […]

[Original post on mastodon.social]

01.07.2025 08:15 β€” πŸ‘ 6    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0
A fake advertisement by β€œhell” (imitating the β€œshell” logo, the oil company) saying β€œWe're changing the oceans into rainbows for LGBT+ pride” (the background of the image looks like an oil spill, which always looks like a rainbow on the floor. In case you're blind and this is how you're finding out that oil spills look like rainbows, please let me know)

A fake advertisement by β€œhell” (imitating the β€œshell” logo, the oil company) saying β€œWe're changing the oceans into rainbows for LGBT+ pride” (the background of the image looks like an oil spill, which always looks like a rainbow on the floor. In case you're blind and this is how you're finding out that oil spills look like rainbows, please let me know)

thank you, satan

29.06.2025 19:04 β€” πŸ‘ 1    πŸ” 30    πŸ’¬ 0    πŸ“Œ 0
Original post on mastodon.social

> On November 28th, 2012, Randall Munroe published an xkcd comic that was a calendar in which the size of each date was proportional to how often each date is referenced by its ordinal name (…) "In months other than September, the 11th is mentioned substantially less often than any other date […]

19.06.2025 14:35 β€” πŸ‘ 2    πŸ” 71    πŸ’¬ 4    πŸ“Œ 0
1/3 of gen X is now older than the character Fish.

1/3 of gen X is now older than the character Fish.

Shit.

26.06.2025 03:37 β€” πŸ‘ 0    πŸ” 8    πŸ’¬ 2    πŸ“Œ 0

I love the @CARROT severe thunderstorm alert siren.

25.06.2025 19:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

@atpfm #askatp I’m an old-school programmer hobbyist who learned BASIC in the 80’s, got a Computer Science degree in the 90's, and mostly wrote lots of tools for administration, quick problem solving, and little personal / work apps. Though I can probably program in anything, I fear my mind […]

25.06.2025 17:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@xabean I’ve no idea. That does look like 8 bits per pixel, not 24. But I’m not steeped in the nomenclature so maybe I’m misinterpreting it.

Anything weird about the cable? USB-C but speed limited due to a defect or something, that’s reduced the bit depth to compensate?

22.06.2025 02:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@xabean Not 8 bits per color, but *per pixel*? Like 256 colors? Like…VGA? Wtf.

22.06.2025 02:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on fedi.simonwillison.net

... and Atlassian are the latest company to be added to my collection of examples of the lethal trifecta in action: their newly released MCP server has been demonstrated to allow prompt injection attacks in public issues to steal private data […]

19.06.2025 23:00 β€” πŸ‘ 1    πŸ” 11    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

I had a friend pack an old CO2 cartridge (for an air rifle) with black powder and attached a 6’ long slow fuse. We lit it and retreated to a hill about a 100 yards away.

We heard the blast reflecting off houses in adjacent neighborhoods. It was so loud, my sister said it woke up the kid she was […]

19.06.2025 14:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@paulc Yes, I know that too. Just haven’t managed to change our habits.

Maybe this’ll be a catalyst. :)

19.06.2025 00:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@darthnull.infosec.exchange.ap.brid.gy is following 1 prominent accounts