Discussions related to Infosec.pub

1317 readers
2 users here now

founded 3 years ago
MODERATORS
1
 
 

This is a proposal to add a “dataleaks” community. E.g.

name: databreaches
display name: Data leaks and breaches 🖧👁

description:

Information about data breaches, data leaks, ransomware attacks, and other related stories.

Rationale:

  1. infosec.pub is the only thematic instance in the fedi for security related chatter. It should be the top go-to place to report data breaches. (Although this is disputed as some think infosec.pub is a general purpose node).
  2. there does not exist a single community in the open free world for discussing data breaches. There are only cloudflare-centralised locations (piefed.world/leaked, lemmy.zip/databreaches). Those well informed about Cloudflare can see the irony. There WAS !dataprotection@infosec.pub according to lemmyverse, but it’s gone. It would be too broad for data leaks anyway but I wonder what happened to it.
2
 
 

Is there something requiring people to login to view anything posted from infosec.pub?

I created this post in mildly infuriating from this account but cannot click the share and share the link. You're just taken to a login page. To share it I had to find the lemmy.world link.

Thanks!

The link https://infosec.pub/post/51688004

3
 
 

I assume community creation is blocked because people have no sense of constitution and “take the piss” by creating communities that are wildly irrelevent to infosec. The fedi has a shit-ton of general purpose nodes, which makes for a lousy organisation. There are precious few thematic instances with a strong constitution to devote to a topic or region.

As a first step to clean up the mess, the infosec orthoganol communities could be switched to announcement-only to prevent future posts from users. Not locked wholly, so that the moderator can announce the new home.

I put some initial effort into separating out the communities that are out of place on an infosec node. Judging mostly by names, these communities could probably be targetted for gradual phase out:

3d_printing ← redundant with suppo.fi/c/3dprinting
A3_Antistasi
Arma_Antistasi
ITYSL
IlovePokemon
Islam
Senserva
adsb
aerospace ← it’s not aerospace security according to sidebar
aghora
allanholdsworth
ambitious_builds
americana
amogus
amsterdam ← redundant with feddit.nl/c/amsterdam
androidfoss ← questionable
artisanvideos
askanamerican ← redundant with discuss.online/c/AskUSA
autisticpride
cats ← redundant with lemmy.sdf.org/c/cats
coffee ← redundant with feddit.uk/c/coffee
colorado ← redundant with 50501.chat/c/Colorado
cum_tribute_nsfw
cynic
django
donoperinfo
egg_irl
engineeringporn ← /could/ be on-topic but no side-bar
ergonauts
eris
espresso
florida ← redundant with 50501.chat/c/Florida
fortcollins
foss ← redundant with hilariouschaos.com/c/foss
fosslemmyapps
fountainpens ← why does this dead off-topic group have 122 subscribers? And why is it highly ranked when sorting by “active”? free
fuzzing
guitar_virtuoso
guitaramps
guix ← questionable
hailcorporate
homestead ← it’s not household security
indonesia
ingsoc
ishakhan
jeremy ← redundant with fedia.io/jeremy
julia_community
justleftreddit
kansas ← redundant with midwest.social/c/kansas
legalnoids
lemventory
los_angeles
loveland
machinists
manchesterunited
mangadle ← redundant with rollenspiel.forum/c/mangadle
materialismo
memes ← redundant with slrpnk.net/c/memes
metroidvanias
miguns ← redundant with fedia.io/MIguns
mutualism ← no sidebar nyc ← redundant with fedia.io/nyc
offset
padel
pnw
pocket_operators
raspberrypi_news ← redundant /enough/ with midwest.social/c/raspberrypi
rule34dle
splunk
sweetrobin
tallyho
the_flea_at_mit
transhumanism
triangle_nc
unitedkingdom ← redundant with feddit.uk/c/unitedkingdom
voyager ← redundant with fedia.io/voyager
warhammer ← redundant with lemmy.cafe/c/warhammer
waymonad ← could be remotely related.. not sure wikomaya
windsorco
wings_of_a_feather
writemore
xmonad ← could be remotely related.. not sure
zettelkasten

Note that I did not look at many sidebars for infosec relevance and did not look exhaustively for redundant groups. I also only searched the open free world (not centralised instances like those in cloudflare). If any of the above groups are actually infosec-related, I apologize. This is just a quick 1st take.

FWIW, slrpnk.net is a thematic instance that tries to shed off-topic communities and there’s some chatter about it in !meta@slrpnk.net.

4
 
 

The !Wireless community is dead. Looks like someone did some community-name-squatting by restricting the topic exclusively to enterprise-related chatter.

Networking has some activity. But annoying that they hi-jacked a perfectly good name for networking broadly. It should be renamed to “enterpriseNetworking”. We should not need to create a separate community absurdly named “enterprise_and_nonenterprise_networking” just to coexist.

5
4
submitted 6 days ago* (last edited 6 days ago) by daveyOsborn to c/infosecpub
 
 

I tried to crosspost this post to !wikipedia@discuss.tchncs.de and got blocked with something like “language not allowed”.

It’s really a shitty error because the Lemmy software has a history of hard-coded slur words and no sense of word boundaries so the slur filter regular expression gets copious false matches. And to worsen matters the software does not state which word is banned.

But then there is also a pull-down menu to select language. Setting that to an unwanted language, or failing to set it at all can result in a “language error”. English is apparently accepted in many (if not all) of the discuss.tchncs.de communities.

So I have no idea if it’s a slur filter problem or a problem with the language selection.

(update) the lang field was “English” by default, so I proactively deselected it by choosing “unselected”. Then it posted. It’s quite annoying because in the past I have encountered bans on the reverse (where I had to change unselected to English to get it accepted).

(update 2) LOL in this forum it’s that way. I could not update this post herein without changing unselected to English.

6
 
 

Federation broke after I upgraded to lemmy 0.19.19 (I tend to apply security updates relatively fast). Unfortunately, that broke federation due to some issues in the release. The issue is described here: https://github.com/LemmyNet/lemmy/issues/6581 - they've not released a fixed version yet, but that was easy enough to sort out manually.

There was also an image issue. I don't know what happened there, but imagemagick was consistently failing - once I restarted the containers, that problem seems to have gone away. I don't know if it will return or was something held over from the update - perhaps an unclean restart. I'll keep an eye on it, but let me know if you see it again.

7
 
 

Seems like the content is missing is something wrong with the server? If i jump over to lemmy.world there's a lot more activity.

8
 
 

For example, in this post: https://infosec.pub/post/47804372

The image is downscaled to 100x100 pixels, making it unreadable. If you look at the same post on another instance, the quality will be much better.

Also, it seems that infosec.pub doesn't show any votes and comments from other instances on that post.

9
 
 

Scrapers are getting so bad that the lemmy containers are falling over, so I've disabled anonymous access to allow legit users to continue using the service. I will work on improving filtering so I can reenable anonymous access. Apologies for the inconvenience.

10
16
Why is Lemmy.ml blocked? (self.infosecpub)
submitted 10 months ago by jaz to c/infosecpub
 
 

I'm new to the Lemmiverse so I'm just starting to learn the history among instances, but I don't understand blocking Lemmy.ml as it's the developer's instance, which also hosts several other significant communities. Just curious why that instance is blocked because I didn't find anything by searching. Thanks.

11
12
 
 

When I query my own copy of the LV DB for “infosec security netsec opsec sigsec hack phreak 2600 digital crypt stego defen defcon” (it does a logical OR on all those tokens), results are:

baseurl = lemmy.securitycafe.ca
   desc = A Lemmy instance for the InfoSec community and users of securitycafe.ca
   tags = []

baseurl = digipres.cafe
   desc = A community notice board and discussion space for all things digital preservation, including digital-GLAM, and digital information records management.
   tags = []
   
baseurl = lemmy.dbzer0.com
   desc = Be Weird, Download a Car, Generate Art, Screw Copyrights, Do Maths
   tags = ["anarchist","adhd","neurodivergence","anarchism","pirate cove","hosted in eu","fuck around and find out","anti-cryptocurrency","pro-lgbtq","antifa","pro-science","SFW","anti-tankie","filesharing","AI","copylefts","anti-copyrights","acab"]

baseurl = crazypeople.online
   desc = A digital retreat from a world gone mad.
   tags = ["neurodivergence","friendly","general purpose","moderated","lemmy","lgbtq friendly","english","general","small instance","powered by renewable energy","acab","anarchist","music","memes","weed","pokemon","racing"]

No hit on infosec.pub because tags and description are empty fields. Of course if I search the baseurls themselves then infosec.pub hits, but it’s a bit incidental. Infosec.pub may not be as findable as @jerry@infosec.pub might want it to be.

(note about the results: if anyone is wondering why so few records resulted in that query, Cloudflare instances are filtered out of my searches. The unfiltered list in this sample query is larger)

13
7
Some images are broken (self.infosecpub)
submitted 1 year ago by abacabadabacaba to c/infosecpub
 
 

Some images from other instances are broken when viewing through infosec.pub, e.g. https://infosec.pub/post/31437828. It is also not trivial to get the original image URL.

14
10
submitted 1 year ago* (last edited 1 year ago) by jerry to c/infosecpub
 
 

I set up tesseract (https://t.infosec.pub/) and voyager (https://v.infosec.pub/) in addition to the existing https://old.infosec.pub/.

15
 
 

I have no idea why this is a thing, but it’s come to my attention that there are several accounts here that are engaging in vote manipulation. This is fair warning that if it continues, I’ll be suspending the accounts involved.

16
 
 

I usually wouldn't care about this kind of semi-trivial issue, since it's so hard to prevent that it's pretty much inevitable, but anyway: There's a long-time infosec.pub user that has multiple accounts and likes to make comments and then upvote their own comment from their alts.

And, also, predictably, they have some childish behavior in the comments in addition, adjacent to the desire to bolster their own comments so they can "win" the discussion.

Is this something the infosec.pub community cares about or wants to do something about? I'm pretty sure I've reported them in the past without much coming of it.

17
6
Future of Infosec.pub (self.infosecpub)
submitted 2 years ago* (last edited 2 years ago) by Typewar to c/infosecpub
 
 

It seems like Lemmy took off 2 years ago with the announcement of Reddit's API blocking 3rd party apps. Many instances popped up, and some disappeared equally fast. More people have now moved over since the actual announcement becoming alive.

I'm a bit new to the decentralized hosts with federation/mesh social networks on the web, and are wondering if anyone with long time experience using something like Mastodon would shine a perspective on how these services usually operate? Does popular instances suddenly disappear, resulting in people losing contact with each other? losing progress, reputation, communities and their history? Since it's open source, and it's meant to be run by the people, for the people. How is the stability and long-term plan for Infosec.pub? I would like to stick around this service for hopefully many years.

Most of the instances in the instance section (https://infosec.pub/instances) is gone. I would be interested to see the statistics on how long all these instances lived before they were shut down, and compare those numbers to the big instances people are signing up to.

Lastly, there seems to be no way to migrate your account to another instance [1], so long-term reliability is indeed important.

18
 
 

I am attending a webinar in a few days, and to get credit for attending I need to participate in the pulling questions. The application is Zoom, and I do not know when or how many pulling questions there will be. Does anyone know of a way to auto respond to the pulling questions? I have time, and am totally willing to slap something together in python, so if you have an idea of where to start that would be amazing

19
14
submitted 2 years ago by jerry to c/infosecpub
 
 

Hi all. As requested, I just added the mlmym interface to infosec.pub. It approximates the old style reddit interface.

So far, it has some.... quirks. For example, as far as I can tell, you cannot post with an "undetermined" language.

20
13
submitted 2 years ago* (last edited 2 years ago) by jerry to c/infosecpub
 
 

Hi all. Lemmy 0.19.9 released today and it has some fixes I want to get in place sooner rather than later. I will be installing the upgrade in about an hour. The downtime should be minimal, but it’s also possible it goes horribly wrong and I have to run a recovery.

Edit: the upgrade is complete. It was quite painless.

21
8
submitted 2 years ago* (last edited 2 years ago) by skaffi to c/infosecpub
 
 

Hey @jerry@infosec.pub and everyone else,

Would it be possible to have mlmym installed for Infosec.Pub?
It's a front-end that perfectly replicates the classic, old.reddit.com interface.

Besides the familiarity being nice for many, as well as it being more compact than even the compact-style themes we currently have available, I think the most important feature is that, unlike most other offerings, including the default that we're using, mlmym works perfectly without javascript enabled.

A bunch of other instances already have it installed. If you want to try it out, SDF is one such instance.

I don't know how big of a hassle it is to install, but I know I would appreciate it a lot!

22
 
 

The pact is a declaration of intent to block any Meta-governed instances that try to federate. There are some useful stats here about which, and how many instances have already committed to the pact. All types of Fediverse instances have signed, including some Lemmy instances, though it seems to be especially Mastodon instances that have signed it.

Is this something you have an opinion on, or already made a decision about, @jerry@infosec.pub? Is it something we should discuss as a community?

23
24
8
submitted 2 years ago* (last edited 2 years ago) by Natanael to c/infosecpub
 
 

Hi all!

On reddit I'm the main moderator for a cryptography subreddit, https://www.reddit.com/r/crypto and I'm considering migrating it.

There's a few cryptography subreddits (one named cryptography which is the main option), the main difference with the one I run is we're a bit stricter about being on topic and thus maintaining higher quality discussions (in part because we're under a heavy flood of spam bots, so we need to filter strictly). We got plenty of people over there who are professional cryptographers

I see there's also a cryptography forum on this instance, but it's very scattered and doesn't really have very high quality posts. I wouldn't want to just take over an existing forum here, if I move the reddit community I'd like to recreate /r/crypto as a new forum here and establish it with all the same rules, etc.

Is there interest from the admins for that here? And how dedicated are the admins to maintaining this instance in the long term? (I don't want to have to move the forum multiple times)

And how much interest is there from the lemmy community?

(sidenote - this time around I'd handle moderation from a separate account, not from my main)

25
view more: next ›