Remote
Jörn Franke
@jornfranke@social.anoxinon.de
Interested in #science #data #nosql #cloud #geospatial #radio #games #simulation and #analytics supported by #environmental #sustainable #opensource #software #europe
789 Followers
6404 Following
48 Posts
Joined January 31, 2026
Website:
Codeberg:
social.darc.de:
Keyoxide:
$argon2i$v=19$m=4096,t=3,p=1$QVBFb3pmVW14U2tWK1V6YzlWZE80Zw$kTWjd24yB+vSgiJcXHQLfk/eRH00AQqW59es9mYzQig
Replying to
@briankrebs@infosec.exchange It could be also that the vulnerabilities were put by AI there in the first place and now they need to fix because they lost control.
Open post
Replying to
@neu3no@netzkms.de Ich nutze Podman, weil es sowieso Teil von fast jeder Linux-Distribution ist (Docker ist bei keiner dabei). Podman ist per Default sicherer (rootless) und hat einige interessante Funktionalitäten (podman.systemd/Quadlet). Man kann es zum größten Teil als Drop-in-replacement für Docker nutzen (gibt auch Wrapper-Pakete).
1
0
0
0
Open post
Replying to
@_elena@mastodon.social You have been referenced in a German IT magazine on that issue (behind paywall): https://social.heise.de/@ct_Magazin/116839474830468838
Edit: They said you were one of the first documenting the disappearing source code
Open quoted post Open quoted post
Quoting
heise+ | Kurznachrichtendienst W Social: Mehr Marketing als Souveränität
Mitte Juni 2026 hat W Social seine öffentliche Beta gestartet, mit einer Menge Versprechen, die nicht alle einer näheren Betrachtung standhalten.
2
0
0
0
Open post
Replying to
@concretedog@mastodon.social @jamesb@fedi.duckduckpigeon.co.uk btw. in tabbed mode of Libreoffice you find the feature in a slightly different location: https://help.libreoffice.org/latest/en-US/text/shared/01/qrcode.html
2
0
3
0
Open post
Replying to
@shadow53@floss.social Then, there is the cost risk - all of them make a big loss at the moment (https://www.wheresyoured.at/premium-ais-circular-psychosis/) This means you will in the very near future pay 100-1000x more money. On top of that you will spend even more money because the more code you generate the more token you have to spend in the future for AI to go through your code.
The cost risk is real: https://finance.yahoo.com/sectors/technology/articles/ubers-anthropic-ai-push-hits-223109852.html
3
1
1
0
Open post
Replying to
@grimm Die Projektkosten eines Atomkraftwerks, die häufig ein vielfaches der Summe sind, sind auch nicht drin. Wartungskosten wurden auch nicht kalkuliert. Das ein Atomkraftwerk, welches temporär abgeschaltet wird, Gigawatt an externer elektrischer Energie zur Kühlung benötigt auch nicht. Versicherungen wie einige sagen auch nicht. (Wer hat eigentlich Tschornoby Auswirkungen bezahlt?).
3
0
0
0
Open post
Replying to
3
1
0
0
Open post
Replying to
@arminhausf @evawolfangel Es wurde nicht nachgewiesen, dass es bessere Patches schreiben kann. Es wurde auch nicht nachgewiesen, dass die Patches nicht zu neuen Sicherheitslücken führen (da es den Kontext in dem das System deployed wird nicht kennen kann).
Macht aber nix! Wenn es schief läuft ist halt der "Human-in-the-loop" Schuld. Und nicht die schlechte Technologie.
3
1
0
0
Open post
Replying to
@filippo Quote from a paper that you cite: ", our most
time-efficient architectures can potentially enable run-
times of 10 days for ECC–256 with ≈ 26,000 qubits, and
97 days for RSA–2048 with ≈ 102,000 qubits"
This is for one key! If all "substantial engineering challenges" are solved.
It was not the scope of your post, but a broader assessment at Confidentiality, Integrity, Availability risks with some concrete estimations would help (which is maybe more a job for a IT Security Risk Manager).
3
2
1
0
Open post
Replying to
@bsi siehe auch https://www.redhat.com/en/blog/navigating-mythos-haunted-world-platform-security
"Functionality vs. Security: Some vulnerabilities identified by AI are actually functionality bugs with no meaningful exploit path."
2
0
1
0
Open post
Replying to
@bsi Die Kernellücke in BSD ist Panikmache. Niemand macht NFS über Internet verfügbar. Niemand sollte NFS ohne Authentifizierung und ohne Firewallregeln im privaten Netzwerk haben. Klar das solche Lücken einfach über Defense-in-Depth abgedeckt werden können => deswegen auch 20 Jahre keinen Fix (war sicher vorher bekannt). Dazu null Investionsbereitschaft von Softwarefriremn in Security (nur in Security wo ihr Geschäftsmodel bedroht wird)
2
1
1
0
Open post
Replying to
@bsi Meines Erachtens falscher Fokus (unbegründete Panik). Statdtdessen sollte man sich auf Microsegmentation, Internet Egress Filtering, besseres Patch Management, bessere Ausbildung, bessere Software ohne Sicherheitslücken, minimale Zugriffsrechte usw. fokussieren. Dann kann man viele Sachen abfangen, obwohl Lücken in der Software vorhanden sind.
Dazu müssen auch die großen Softwarefirmen für ihre Sicherheitslücken, über die das BSI regelmäßig berichtet, zur Verantwortung gezogen werden.
2
0
0
0
Open post
Replying to
@filippo I found no good argument for this. There is just a bogus comment that nobody asked the Manhatten project to create a small nuclear explosion. It has nothing to do with the topic and they of course did various tests and experiments to validate what they are doing.
It is a typical distraction from the fact that they even cannot solve small problems on QC.
2
0
1
0
Open post
Replying to
@milan@social.tchncs.de could be a good complement for wanderer.
It is based on Spring Boot so it should be easy to have SSO there.
One thing though is that the dependencies are outdated (security risk): https://codeberg.org/fitpub/fitpub/src/branch/main/pom.xml
Additionally, Java 25 LTS should be the Java version to be used (not 17)
1
1
0
0
Open post
Replying to
2
0
0
0
Open post
Replying to
@shadow53@floss.social I would ask to measure that it indeed brings improvement and have additional validation (unit testing, static code analysis, fuzzing etc.) that it does not decrease quality. Static code analyzers give you also statistics on duplicated code and code complexity. They can be indicator that things go wrong. Additionally, you can collect number of incidents (if LLM would work they should go down).
1
2
0
0
Open post
Replying to
1
0
1
0
Open post
Replying to
@thomasfuchs Maybe via the WDR archive: https://www.ard.de/die-ard/presse-kontakt/archive/archivzugang-wdr-100.html
While they ask for a "research question", it does not really define it, so anyone can ask a "research question".
You can request if they have the shows and check them there. If you want a copy then you have to pay a fee (not sure how much).
1
0
0
0
Open post
Replying to
@wezm Is this not a bit redundant given WebUSB https://developer.mozilla.org/en-US/docs/Web/API/WebUSB_API ?
I mean not every serial port is USB, but probably most of them relevant for browser use cases are.
1
3
0
0
Open post
Replying to
@bsi Others are able to reproduce Mythos capabilities with cheap open source models: https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier
Mythos just uses trivial techniques (paraphrasing outputs of static code analyzers, fuzzers. formal logic etc.). The problem is that companies do not invest in secure software (as you can see from the BSI announcements - Microsoft, Citrix etc. do on purpose not invest in security). Investing in Mythos is waste of money - instead invest in proper security
1
0
0
0
Open post
Replying to
@bsi Siehe https://cyberplace.social/@GossiTheDog/116390978622304265
Antrophic Mythos ist ein Marketinggag
1
0
0
0
Open post
Replying to
@bsi Da kommen allerdings dann keine neuen Lücken bei raus. Nur bekannte die nicht gefixed wurden, weil Geld gespart werden soll oder weil schon komplett abgedeckt durch Defense-in-Depth. Das Problem sind hier die Investitionen - bekannt sind die alle schon.
Der technische Anthropic Bericht übertreibt die Kritikalität, spart mit Details (ohje alles so schlimm können wir nicht teilen) und einige Fixes für kritischen Sicherheitslücken wurden durch ahem "update der Dokumentation" gefixt (botan)
1
2
1
0
Open post
Replying to
@georgetakei@universeodon.com @pluralistic@mamot.fr warns against this since ages, e.g. https://pluralistic.net/2025/06/24/price-discrimination/#
or in his book on "Enshittification"
1
0
0
0
Open post
Replying to
@TheLastOfHisName Try to use flatpaks - this will install everything you need and does not lead to incompatibility with other software https://www.siberoloji.com/how-to-install-applications-from-flatpak-on-linux-mint/
1
0
0
0
Open post
Replying to on vmst.io
@csara@vmst.io maybe https://european-alternatives.eu/ can give some inspiration
@european_alternatives@mastodon.social
1
0
1
0
Open post
Replying to
@Liberapay@mastodon.xyz Hope you can move your infrastructure to a European cloud provider in the future
1
0
0
0
Open post
Replying to
@shadow53@floss.social See also on cost risk: GitHub will start charging Copilot users based on their actual AI usage (https://arstechnica.com/ai/2026/04/github-will-start-charging-copilot-users-based-on-their-actual-ai-usage/) GitHub Copilot has finally released a preview of usage-based billing based on current usage. (https://www.reddit.com/r/GithubCopilot/comments/1tbb5bj/github_copilot_has_finally_released_a_preview_of/?rdt=59236) how much is too much to spend on ai tools (https://www.marketplace.org/story/2026/04/24/how-much-is-too-much-to-spend-on-ai-tools) AI Is Too Expensive (https://www.wheresyoured.at/ai-is-too-expensive/)
0
0
0
0
Open post
Open post
Replying to
@pluralistic@mamot.fr ok thx this seems to just check the domain. Anyway I found a way around. thank you
0
0
0
0
Open post
Replying to
@pluralistic@mamot.fr It is good to have the threads also here as it seems your website is down
0
5
0
0
Open post
Replying to
0
0
0
0
Open post
Replying to
@bsi@social.bund.de Es ist sehr zu begrüßen, dass es sicheren Cloudstandards wie C5:2026 gibt. Allerdings kocht hier jedes europäische Land sein eigenes Süppchen (e.g. SecNumCloud) oder kocht gar keins.
Das schadet Europa und bringt uns nicht voran - unsere Softwareindustrie wird dadurch gelähmt.
Ich erwarte daher, dass das BSI mit höchster Prirorität mit allen europäischen Ländern zusammenarbeitet und schnellstmöglichst (innerhalb von 12 Monaten) endlich EUCS fertigstellt: https://www.enisa.europa.eu/publications/eucs-cloud-service-scheme
0
0
0
0
Open post
Replying to
@kuketzblog@social.tchncs.de Wireshark liest verschlüsselten Traffic auch nur mit wenn es das Zertifikat hat: https://wiki.wireshark.org/TLS
Hat man aber meistens nicht wenn es Richtung Internet geht. Man kann sich aber z.B. per eBPF in die openssl Bibliothek einklinken und dann geht es (sofern sniffer auf dem gleichen Rechner ist und man entsprechende Rechte hat): https://codeberg.org/ZuInnoTe/rust-ebpf-localnet-kernel-filter-study/src/branch/main/uprobe-libcall-filter
Es gib da auch: https://www.heise.de/news/Ausgehenden-Traffic-unter-Linux-kontrollieren-Little-Snitch-ist-da-11250677.html
0
0
0
0
Open post
Replying to
@milan@social.tchncs.de e.g. Spring Boot is 3.2.0, which was released Nov 2023 (More than 2 1/2 years ago, https://mvnrepository.com/artifact/org.springframework.boot/spring-boot/3.2.0) Spring Boot 4.1.0 is about to be released this week. Other dependencies maybe also outdated
0
0
0
0
Open post
Replying to
@filippo Cryptographic experts might be confident in the security of lattice, but I would be not confident in their secure implementation. It took decades to get the implementation right for classical algorithms and they are still often wrongly implemented. This is a big security problem.
0
4
0
0
Open post
Replying to
@bsi@social.bund.de Ihr wisst schon, dass Ihr eine Plattform namens https://opencode.de habt? @zendis@social.bund.de
0
2
0
0
Open post
Replying to
@filippo Do not get me wrong. I believe we need to be crpyto-agile as at the moment it is even a mess to update the algorithm of one application to a latest version. Here I also agree with Bruce Schneier (https://www.schneier.com/blog/archives/2026/04/google-wants-to-transition-to-post-quantum-cryptography-by-2029.html) However, one should not do this in panic mode and get that one first right before moving to so impacting changes in an organisation.
0
0
0
0
Open post
Replying to
@pluralistic@mamot.fr hmm ok thank you - I just checked. If I open pluralistic.net then it works, but this link does not (it comes from your thread): https://pluralistic.net/2026/06/15/
0
3
0
0
Open post
Open post





