Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Wikipedia Operator Says OpenAI's 'Rogue' Bots May Be Linked to a May Outage
    by BeauHD on 05/10/2026 at 9:00 pm

    The Wikimedia Foundation says it found evidence that "rogue" OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here's a summary of what Wikimedia observed (via The Verge): Wiki editing: We've identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in "sandbox" areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents. Etherpad probing and use: Agents we believe to be operated by OpenAI made some unsuccessful attempts to compromise our public Etherpad, a note-taking tool we host as a community service. Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination. Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May. Read more of this story at Slashdot.

  • Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch
    by BeauHD on 05/10/2026 at 8:00 pm

    An anonymous reader quotes a report from 404 Media: In the immediate weeks before Muse's launch, Meta engineers found several security vulnerabilities in the company's viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse's intended environment and access Meta's own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team "mad dash" to fix "a sudden spike in reported KVM escapes," according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta's end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta's own critical infrastructure. A "KVM escape," then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users' virtual machines. According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker -- that is, a normal Muse user -- to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. [...] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn't delay Muse's launch, leading to what they described as "half-baked protections being rushed out to enable the launch. Many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch." Muse is called "Hatch" internally and in Meta's codebase. Read more of this story at Slashdot.

  • Norway Plans Temporary Ban on Smart Glasses
    by BeauHD on 05/10/2026 at 7:00 pm

    Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports: Torgeir Micaelsen, Norway's minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it." "We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored," he said. Norway's Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill "as soon as possible," while tasking an expert group with drawing up permanent regulations on the issue. Read more of this story at Slashdot.

  • Mac Users Reclaim 12GB+ of Storage With Apple Intelligence Removal Tool
    by BeauHD on 05/10/2026 at 6:00 pm

    A new open-source command-line tool called RemoveMacAI lets macOS 27 users disable Apple Intelligence and reclaim around 12GB or more of storage. MacRumors reports: In macOS 27, Apple removed the toggle to disable Apple Intelligence wholesale, and simply disabling individual features doesn't remove the models from your Mac's drive. As explained by the developer, RemoveMacAI gets around this by using a configuration profile to switch off Apple's own asset management service and remove the models. It then configures the system so attempts to download the removed models are redirected to a closed local port, preventing them from immediately coming back. And it does all this without disabling System Integrity Protection (SIP) or manually deleting files from protected system locations, unlike some older tools have. The tool can free up roughly 12GB of space depending on which models are present on your Mac. That said, some users are reporting cases of Apple Intelligence models having taken up a lot more space, which they've now reclaimed. Read more of this story at Slashdot.

  • Anthropic Reports Florida Woman's Claude 'Diary' Threat to Law Enforcement
    by BeauHD on 05/10/2026 at 5:35 pm

    A Florida woman was arrested on a felony charge after Anthropic's human review team flagged and reported a Claude conversation in which she allegedly threatened to "shoot up" the Lee County Sheriff's Office and later mentioned acquiring a new gun. Tom's Hardware reports: Anthropic monitors chats for key phrases and content that could be deemed threatening, the arrest report says, and depending on severity, they can be elevated for human review. In this case, the team decided to report its findings to law enforcement. The Bonita Springs woman was detained at home without incident, and an LCSO intelligence detective took over the case from there. The arrest report is not yet in the court file, but our own check shows court records listing the Sept. 30 felony charge under Florida Statute 836.10: written or electronic threat of a mass shooting or act of terrorism. No comment from Anthropic on the case is currently on record. Anthropic's public privacy policy, effective Sept. 10, says that disclosure to law enforcement may occur where it has a good-faith belief "that disclosure is reasonably necessary to ... prevent serious harm to any person or to property." Its government requests report for the latter half of 2025 uses a narrower standard for emergency disclosures, the "danger of death or serious physical injury to a person," and lists zero emergency requests from law enforcement in that period, though it doesn't count referrals Anthropic makes on its own. Read more of this story at Slashdot.

  • Sam Altman: 'The World Should Accept Some Bad Things Happening' For the Benefits of AI
    by BeauHD on 05/10/2026 at 4:00 pm

    OpenAI CEO Sam Altman says society should accept some negative consequences from AI in exchange for the technology's broader benefits and widespread public access. "I think there's a lot of daylight," Altman told Decoded co-author and Politico senior tech reporter Brendan Bordelon. Asked about where he differs between Anthropic and its CEO Dario Amodei, Altman said, "we believe that the world should accept some bad things happening for the benefits of this technology and people having the agency." From the report: Altman agreed with Amodei's call last month to slow the development of the most advanced AI models. His company has followed Anthropic in endorsing new state laws that impose stricter safety requirements than what the maker of ChatGPT had previously supported -- a subtle shift from its prior state strategy. And OpenAI lobbyists recently endorsed a bipartisan House proposal that would require top AI companies to embed outside safety evaluators. Despite the convergence, Altman tried to distinguish his firm's regulatory stance from Anthropic's, referencing a criticism about regulatory capture that tech advisers close to President Donald Trump have applied to Anthropic. "I disagree, but I understand the perspective of people who are like, 'This technology is going to get so powerful, and it's so dangerous, that a single lab in San Francisco should have it and make sure nothing bad happens, and kind of figure out how to dole out the benefits,'" said Altman. He called it "a completely unacceptable trade-off" that runs counter to the "lighter-touch regulatory stance" backed by OpenAI. "I wouldn't take a trade of saying, 'We'll make sure there's no major hacks, there's no misuse of this technology, there's zero scams, there's zero all the other bad things that will happen,'" said Altman. "Because I think people will do tremendously -- orders of magnitude more -- good stuff than bad stuff." The OpenAI CEO later added that he does not accept "the really catastrophic risks," including the potential for "a serious loss of control to AI." Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress