Josh Chessman
beansb.bsky.social
Josh Chessman
@beansb.bsky.social
39 followers 34 following 400 posts
Technologist and lover of science (fiction and otherwise) https://www.linkedin.com/in/Josh-Chessman
Posts Media Videos Starter Packs
I don't see how this could possibly go wrong. I think #AI has some really amazing uses (if anyone can ever figure out how to make it profitable) but I'm not sure this is one of them.
#chatgpt #erotica #whatcouldgowrong
ChatGPT erotica coming soon with age verification, CEO says
Sam Altman claims new tools can detect mental distress while relaxing limits for adults.
arstechnica.com
I hate #BPF (Berkeley Packet Filter) but it's mostly unrelated cousin #eBPF is pretty cool. And now it has a new use - helping hide a #rootkit. Bad that #AWS infrastructure was hacked but silver lining that we discovered a new use for eBPF?
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
Synacktiv uncovered LinkPro, a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.
thehackernews.com
#AI struggles to make money. Costs are high and it turns out that if you train people to expect things for free they expect things for free. If 95% of your customers don't pay the other 5% is going to have to pay a lot. Guess we will see how valuable AI really is. #openai #llm #genai #costs #free
ChatGPT: so popular, hardly anyone will pay for it
: If you build it, they will come and expect the service to be free
www.theregister.com
I've expressed my opinions on Roku in the past and this isn't improving my feelings towards them. While I wish I believed it would make a difference I seriously doubt it. Whatever the punishment it won't be close to enough to stop the actions. #pii #underage #children #data #cutitout
Roku accused of selling children’s data to advertisers and brokers
Florida claims Roku ignored clear signs its users were minors, collecting and selling viewing habits, voice recordings and precise locations.
www.malwarebytes.com
It seems so rare that bad actors are caught these days that it is heartening when it does happen. PowerSchool hacker Matthew Lane got 4 years in prison for the cyberattack in 2024. While deserved I do wish companies were better punished for their poor security as well. #security #cybersecurity
PowerSchool hacker gets sentenced to four years in prison
19-year-old college student Matthew D. Lane, from Worcester, Massachusetts, was sentenced to 4 years in prison for orchestrating a cyberattack on PowerSchool in December 2024 that resulted in a…
www.bleepingcomputer.com
I dabble with #passkeys a bit but don't use them everywhere. While they offer improved security in many ways it is important to remember that they are not a panacea for security. There are still risks, especially as vendors have to deal with both #passwords and passkeys. #security #cybersecurity
How Attackers Bypass Synced Passkeys
Synced passkeys expose enterprises to cloud takeover, browser hijacks, and downgrade attacks.
thehackernews.com
F5 is saying it isn't a big deal but I'd say a nation state getting access to your source code, undisclosed vulnerabilities, and more is a really, really, really big deal. No supply chain compromise has been identified (yet) but still concerning. #f5 #big-ip #hackers #security #cybersecurity
F5 says hackers stole undisclosed BIG-IP flaws, source code
U.S. cybersecurity company F5 disclosed that nation-state hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code.
www.bleepingcomputer.com
There is a reason I back haul all my Internet traffic over a VPN when I'm not at home and this is the reason. I'm not doing anything particularly interesting but I don't need everyone and their professor seeing my traffic. #vpn #security #encryption #unencrypted
Oh goody, a new reason to worry about the safety of 2FA, at least in theory. Could an app steal enough of the correct screen pixels to get a 2FA code? Apparently at least in theory though I do wonder about how the timing would work. #android #2fa #security
Pixel-stealing “Pixnapping” attack targets Android devices
Imagine if a rogue app could glimpse tiny bits of your screen—even the parts you thought were secure, like your 2FA codes.
www.malwarebytes.com
Is it really a requirement to work 25 hours a day or is it a self-fulfilling prophecy that if you say you have to you have to? If a VC invested in a company where the CEO only put in 40 hours a week would it succeed? We will likely never know since VC's won't invest in that company. #VC #work #life
CEO of $8 billion AI company says it’s ‘mind-boggling’ that people think you can work 38 hours a week, have work-life balance, and be successful | Fortune
Cerebras cofounder Andrew Feldman warned aspiring entrepreneurs they need to be working “every waking minute,” echoing the likes of Zoom CEO Eric Yuan and LinkedIn’s Reid Hoffman.
fortune.com
#OpenAI released new jail breaking protections which were immediately overcome. Turns out using an LLM to protect an LLM doesn't always work the way you expect. Maybe they need an LLM to protect the LLM that is protecting the LLM?
#llm #ai #jailbreak #guardrails #oops
Researchers break OpenAI guardrails
The maker of ChatGPT released a toolkit to help protect its AI from attack earlier this month. Almost immediately, someone broke it.
www.malwarebytes.com
For reasons that I fail to understand there are still orgs running web apps that require #IE so vendors like Microsoft provide a compatibility-mode within Edge that leverages Windows built-in #MSHTML rendering engine. Who would have though that would be a #security issue? #web #ie6 #wtf
Microsoft restricts IE mode access in Edge after zero-day attacks
Microsoft is restricting access to Internet Explorer mode in Edge browser after learning that hackers are leveraging zero-day exploits in the Chakra JavaScript engine for access to target devices.
www.bleepingcomputer.com
Nothing to worry about folks, there is no AI bubble! Brian Sozzi of @yahoofinance.com says so. "I talk to CFOs and they walk me through their thinking, which seems logical. They aren't foaming at the mouth with wild-eyed predictions of grandeur similar to the late '90s." #skeptical #ai #bubble
Is the AI stock bubble about to explode?
Stop with the AI bubble talk, please!
finance.yahoo.com
I remember when most things were ad supported (TV, newspapers, magazines, etc.). Then we were told subscription fees would do away with ads. Now we seem to have the worst of all possible worlds: subscription fees and ads. So much for the ad-free future we were promised. #ads #amazon #subscriptions
People regret buying Amazon smart displays after being bombarded with ads
“I’m about to just toss the whole thing…”…
arstechnica.com
Criminals changing direct deposit is not a new scam but that doesn't mean it isn't an important one to be aware of. Especially with them now sitting in the middle to bypass MFA requests. #mfa #cybersecurity #workday #scams #security
Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits
Among other things, the scammers bypass multi-factor authentication.
arstechnica.com
Interesting new tool from @Microsoft.com. Apparently their CoPilots are so good that they want your boss to know if you aren't actually using it. Because, you know, that's not creepy.
#ai #copilot #microsoft #vivainsights #adoption #wtf
Microsoft adds Copilot adoption benchmarks to Viva Insights
: Viva Insights turns AI guzzling into a leaderboard
www.theregister.com
More bad news from #SonicWall. If you backed up your SonicWall config to their cloud it appears it has been stolen. I'd say SonicWall doesn't seem to be able to catch a break but at some point you have to wonder if something else is up. #firewall #cloud #backup #security
SonicWall: Firewall configs stolen for all cloud backup customers
SonicWall has confirmed that all customers that used the company's cloud backup service are affected by the security breach last month.
www.bleepingcomputer.com
McKinsey is out with a report on how software vendors can monetize AI (who knew AI needed to make money). It isn't exactly looking good. Turns out orgs want pricing consistency but there's that whole making money thing that no one has figured out yet.
#ai #mckinsey #pricing #money
www.mckinsey.com
I'm as happy as anyone that this happened but it does beg the question of why it took so long for the police to do ANYTHING about it? Stories abound of people calling the police with the location of their stolen device and the authorities having no interest. #theft #police #wtf #smuggling
One stolen iPhone uncovered a network smuggling thousands of devices to China
Turns out Apple’s ‘Find My’ feature isn’t just for when your phone slips down the side of the couch.
www.malwarebytes.com
I try not to be too negative about #AI (though it's difficult) but I do think there is a crash coming and that it will be ugly. I'm seeing more and more commentary that leads me to believe I'm right. #crash #dotcom #bubble #boe
Bank of England smells hint of dotcom bubble 2.0 in AI froth
: UK central bank warns of 'sudden correction' in tech stocks
www.theregister.com
Apple is poking @Microsoft.com's security, again. And, deservedly so. I wasn't impacted by last years @crowdstrike.com #fiasco but my brother ended up taking four days to get home. Personally, I'm a #Linux guy but I use some Apple products and if I had to move off Linux I'd probably go #mac.
Apple turned the CrowdStrike BSOD issue into an anti-PC ad
Apple returns to mocking PC security
www.theverge.com