Posts by h3artbl33d@exquisite.social
 (DIR) Post #B57dtFNWmrAJLXUq80 by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       @Rairii @PLA_906114 Indeed. I am aware of the history - exactly the reason why if a Microslop desktop is a must, so is VeraCrypt. Encryption that can be bypassed shouldn't be referred to as encryption.
       
 (DIR) Post #B57eYgHfepw2fJVwAK by h3artbl33d@exquisite.social
       1 likes, 0 repeats
       
       @Rairii @PLA_906114 Yeah - I believe that it is (or was?) an option to disable the TPM in the group policy editor and enforce the combination of a passphrase + keydrive.Perhaps I am a bit much of a tinfoil hat wearer, but I do not trust BitLocker at all. I do not trust Microslop or their sloperating system. Still, need to encrypt all the things, so this is where VeraCrypt comes in for me. The least worst option.
       
 (DIR) Post #B57g2UhLOkYfNFIoQi by h3artbl33d@exquisite.social
       1 likes, 0 repeats
       
       @PLA_906114 @Rairii Indeed. At the very least: foundational technology that is supposed to protect us all should be open source. Closed source is not acceptable there, period.
       
 (DIR) Post #B5IQXZW64UY2lfOjSK by h3artbl33d@exquisite.social
       0 likes, 1 repeats
       
       #OpenBSD 7.9 coming soon... And it is going to be one heck of a release.If you want to tinker with it already, go -current.
       
 (DIR) Post #B5c3hD6Rqd1wMfE6Ea by h3artbl33d@exquisite.social
       1 likes, 1 repeats
       
       Hey fellow #OpenBSD crowd :flan_coffee:  I am worried about @tedu - can't get a hold of him, last CVS commits were somewhere 2025, no Fedi activity, websites down, etc.Just wanted to make sure he is okay, regardless of the reason for being inactive.
       
 (DIR) Post #B5cTGe5627J31daUfg by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       @FritzAdalis @khm @prahou @mischa Just spoke with someone whom received an email from tedu dated on the 26th of feb
       
 (DIR) Post #B5cTGeXoJMH6Sh1QQa by h3artbl33d@exquisite.social
       1 likes, 0 repeats
       
       @FritzAdalis @khm @prahou @mischa Also: see: https://exquisite.social/@h3artbl33d/116458582853362527I don't care whether tedu moved on from OpenBSD, is chilling out on a beach and surfin' the tides - or moved to a cabin in the woods.Just want to make sure he is alive and okay - especially since I think he is US based.
       
 (DIR) Post #B5fZOvWeF2Modzgd5E by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       @rqm @OpenBSDAms @mischa already runs the latest snapshot on -current, all locked and loaded for the imminent release of 7.9!So does OpenBSDonApple.wiki!
       
 (DIR) Post #B5oxbRVjIGYudrOgi0 by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       On the other hand - it did accept 150 random characters as passwords. And parsed them correctly. Now unto trying more... substandard character sets :flan_set_fire:
       
 (DIR) Post #B5xqFlzRWMQgWueedk by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       @davidrevoy @prahou Well well.cc @exquisite
       
 (DIR) Post #B6Kd2DTVhoo6wz0CRs by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       Today I learned that FCKGW-RHQQ2-[...]was a special key for Winslop XP pre-SP2. It was already widely known to be a VLK (Volume License Key), but it was allowlisted in the internals. It pretty much disabled WPA (Windows Product Activation) which did not phone home using this VLK.Oh, how the times have changed.
       
 (DIR) Post #B6STW1mmHmVf6iGozo by h3artbl33d@exquisite.social
       0 likes, 1 repeats
       
       Whoop. Exquisite.social  is now on #OpenBSD 7.9 (-release):OpenBSD 7.9 (GENERIC.MP) #449: Wed May  6 13:17:25 MDT 2026#MastoAdmin
       
 (DIR) Post #B6STW3q2ecJDTPoSMS by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       Switching from -current to -stable was on my todo list. We've ran with the April 20 snapshot, until 7.9 hit the mirrors.Then it was as simple as:sysupgrade -n -R 7.9Might not have been possible or wrecked havoc if we'd been on a newer snapshot.
       
 (DIR) Post #B6lb9U7NkZkHJletAe by h3artbl33d@exquisite.social
       0 likes, 1 repeats
       
       We are seeing an increased number of account signups on our #Mastodon instance. They are fake and very likely to be a part of the Russian LLM-backed campaign. The reason for joining tends to be very broad and vague: I'm looking to join a friendly Mastodon community and participate in discussions.The email addresses used in these signups are valid (as they are able to verify it), but seem to be automatically generated.The IP addresses they use either stem from a VPN, Tor exit node or a compromised webhosting thing (we do not log IP addresses - except during the registration, which is deleted once an account is approved or denied). One positive consequence: this is really helpful to maintain our blocklist :flan_XD: :flan_molotov: These bots end up being blocked by our pf(4) across the infrastructure. #MastoAdmin
       
 (DIR) Post #B7OI4MZP68zkilqu9Y by h3artbl33d@exquisite.social
       0 likes, 1 repeats
       
       Imagine falling head over heels for someone. Feeling that intense crush - basically defying gravity. After finding the courage, you ask them out. Three lovely dates, you spend more and more time together and decide to move in.And then you find out that they are spooks, passing along everything you tell them to an unknown number of parties. The most private details you have ever shared. Sensitive documents they could get their hands on. Your social circle graphed out.This is basically the real life scenario of using an AI agent. Right now, it is SearchLeak - but this isn't the first and sure as heck won't be the last.It isn't just that these AI agents contain vulnerabilities, it is a fundamental problem, granting whatever application full permissions to do literally anything. Do not use AI agents. Do not use AI at all.#AI #LLM #Security #Agentic #Vulnerability #Microslop #Microsoft
       
 (DIR) Post #B7UVTEgOcznmlGx6jw by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       Almost done with migrating ~ 150 websites from a couple of Serverpilot VPS'es. What an extremely crappy and shitty platform that is. Their salespitch includes "App Isolation" - but there is nearly none. One badly managed website was able to take the whole VPS down, due to it having no resource control at all. Already got several huge conpliments on how migrated websites were much more stable, performant and resilient. #SysOpLife #SysOp #Server #Management
       
 (DIR) Post #B7UVTEuZmH91TFaQqG by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       There are various ways how proper app isolation and resource limitations can be implemented:Linux: if you are hosting multiple websites with a control panel (DirectAdmin, cPanel, etc) - use CloudLinux. Enable LVE, CageFS, DB Governor and make sure all the accounts have CageFS enabled. Can be done through cgroups too.BSD: Use jails, VMs, etc.Just getting each account their own PHP-FPM pool is insufficient. Sites are still sharing the system resources and filesystem. Exploiting a vuln somewhere in the application or stack might just lead to a full server compromise, rather than it being limited to the exploited site.
       
 (DIR) Post #B7UVTFAWoxuAGj3Ahs by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       WordPress is extremely popular - the WP core itself is quite decent in the terms of security - for an average website that does not have a large threat model.The problem, however, is that there is very little quality control on the ecosystem. Extremely poor and badly designed plugins are extremely common and expose the (WP) website to a huge attack surface.With no proper isolation between sites, it is rather easy to exploit a vuln and bilaterally move towards the other sites hosted on the same machine/VPS/VM.
       
 (DIR) Post #B7UVTFXZRIKvQBpZce by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       For instance, the plugin 'Really Simple SSL' is tens of thousands of lines of code that can be trivially achieved in the webserver config with 5 or 6 lines.But that specific plugin doesn't even begin to scratch the surface. Others are soooo much worse - and they are still available in the WP plugin repo. Not even a small warning.
       
 (DIR) Post #B7UVTFtu6GCWXSHPQu by h3artbl33d@exquisite.social
       0 likes, 0 repeats
       
       And the bad thing is that "shared webhosting" often includes email as well. Meaning that - even with proper isolation - a compromised website might compromise the mailboxes too.