Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

kasperd

@kasperd@westergaard.social
akkoma 3.20.1-21-gd25da5b1-michael
  • Open on westergaard.social
Currently testing this platform to decide whether it's the future of social networking.

Curriculum Vitae:
PhD degree from Aarhus University
Worked at Google Zürich and London
Partner at Intempus Timeregistrering - until it was acquired by Visma
Operating nat64.net/
149 Followers
144 Following
50 Posts
Open post
kasperd @kasperd@westergaard.social
· 1w ago
Replying to
I still find security vulnerabilities manually and sometimes a CVE gets assigned. This year I reported two security vulnerabilities in two different open source projects. One got assigned a CVE and was fixed. The other has as far as I know not been fixed. I really don't care if the projects assign CVE numbers or not as long as the vulnerabilities get fixed.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
I think that game was lost the moment you granted the AI access to install arbitrary software.
9
1
4
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
I have personally been fighting the trend of listing required skills that are not really required. When we have been hiring I have said that we should rather have a very short list of required skills and use a wording about the following skills will be a plus for the rest of them. We have had many applicants who did not have nearly the skill level we were looking for. And more than once have we interviewed candidates who did not have a clue about the things they put in their CV. One thing that can really put me off about a candidate is when they overestimate their own skills. Maybe such a candidate is more likely to apply, but they are not likely to get the job if I am interviewing them. A candidate acknowledging their own limits is a quality that I appreciate, but they do also have to have some skills that we can use.
6
2
2
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
I just want to add what I think is a too often ignored advantage of using copy-paste rather than manually typing the text again. Using copy-paste will significantly reduce the risk of introducing typos into the text you are copying. I know my opinion on this might not be given much weight, after all I am just a human and humans are fallible.
5
3
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
In the past I have worked with some servers which had the interesting property that as soon as you plugged in the power cord the power supply would deliver full power to the fans even if the motherboard was not powered on yet. We repeatedly forgot to push the power button and then wondered why it took so long for the machine to be reachable on the network.
9
1
4
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
Yes, that’s what the original joke was implying. Numerous times I have seen people make typos when manually type short things and each time I am thinking that they should have seen that coming and used copy-paste instead of typing it manually. So what I am saying is that sometimes it’s lack of thinking that leads to somebody not using copy-paste.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
The majority of people who click on ads click right next to the close button.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
My 78 year old dad has been complaining how some TV stations have started using AI generated subtitles for movies. The experience he has been having is that during the movie he has slowly been getting more and more annoyed with the poor quality of the subtitles which are hard to follow. And then at the very end of the movie they announce that the subtitles were AI generated.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
Enjoy your vacation. I hope that for some appropriate duration prior to July you only merge bugfixes and no new features in order to minimize the risk of any new vulnerability being introduced just before leaving for vacation.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
This could describe how different people think of software development. But it may very well apply in other fields as well.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
If you already knew the answer when creating the poll it would be unfair if none of the options is the actual correct answer. So I have to assume the number is actually one of the listed options. It’s unlikely to hit exactly on a nice round number. And the larger the number the less likely this becomes. Hitting exactly 100 is 10 times as unlikely as hitting exactly 10. By this logic the most likely answer is 1.
1
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
I read this out of context and I figured out the meaning before I reached the note at the end.
1
1
1
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
In a previous job I was working with tape backups. We did test restores and we found that the drives often had a ridiculously low throughput when reading. When asked to troubleshoot this the vendor said our usage of the drives was atypical.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
If nothing can go wrong, then why are you testing it?
1
2
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Clearly AI doesn’t understand the performance characteristics of the target CPU. I am waiting for somebody to suggest the solution to that is that the next generation of CPU cores gets designed by AI.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
As for the white bar could it be that they intended to display an ad, but you are using an adblocker?
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Yes, I was implicitly assuming that an upgraded kernel with the fix would installed before the next reboot. I could have been explicit about that when asking the question.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Is this command sufficient to protect a system: rm "/lib/modules/$(uname -r)/kernel/crypto/algif_aead.ko"
1
2
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
They also had an incident last week: https://www.githubstatus.com/incidents/zsg1lk7w13cf
Incident with Pull Requests
githubstatus.com

Incident with Pull Requests

GitHub's Status Page - Incident with Pull Requests.

1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
The follow up question is whether it is tech in general or just the management decisions of certain companies.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Could a library written in Rust be used by applications written in C? Assuming the application was written to be dynamically linked against a library written in C, would it be meaningful to write a drop-in replacement library in Rust which the application could use instead without even recompiling the application?
1
2
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
I never heard of that thought experiment before. After reading a little bit about it my conclusion is that believing in it is not rational. And it’s even less rational to believe that it’s inevitable.
1
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Maybe take it a step further and define IP addresses for this purpose which networks can route locally if they have some alternative way of reaching the site in question. This alternative way may not work in all cases, but I think it would be good to have in case anyone can make it useful. The default behavior for those IP addresses would be a no route to network response, which is still better than pointing to localhost. I don’t think the discard prefix is intended for this purpose, at least not from my reading of the specification. And when I looked into the discard prefix in the past I don’t think the behavior was consistent. From some networks the packets would be silently dropped but from other networks you’d get an ICMPv6 error back.
0
0
1
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
I do not agree with the assertion that a centralized system can give guarantees about user privacy.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
Criminals who broadcast their location are a bit easier to locate. And phone companies might have noticed some disturbances and helped track down the criminals.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 4mo ago
Replying to
I think the existence of the PSL is a symptom of a design flaw in how cookies are handled. This is not a curl problem as curl wasn’t where cookies originated. And as for URLs without a trailing dot I think it’s a problem that the server doesn’t get to know what domain the client appended. Imagine a client simply sending Host: www. How is the server supposed to know which site the client wants without knowing what the client had appended. The domain search feature is inherently incompatible with the TLS security model. I think it would have made more sense to make the trailing dot mandatory in https URLs as it would have better aligned with the security model of TLS. But I recall having seen cases where adding a trailing dot to https URLs would break things. I understand that the intention is for curl to handle all of the corner cases correctly, and I think that makes sense for a project like curl. I can imagine how frustrating it can be, and at times I guess you just want to reject those corner cases.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
I absolutely agree IPv4-mapped addresses have no place in DNS. The one place I have seen them used on the wire is as source address when some NAT64 gateway translates ICMP error messages into ICMPv6. I also think that’s wrong (they should be using their NAT64 prefix instead), but it’s not harmful in the same way that IPv4-mapped addresses in DNS are. I can’t come up with any scenario where IPv4-mapped addresses on the wire would be a good idea.
0
1
1
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
That command would take forever. I’d go with urandom or even a usermode generator optimized for speed rather than high quality of randomness. If it’s an SSD I’d just TRIM it and not use any randomness.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3w ago
Replying to
Would it have helped if the authorized_keys file contained hashed versions of the public key? As far as I recall it worked that way when using SSH protocol version 1.
0
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
This reminds me of an issue that I saw several years ago with SPF records on some domains. I was using the Python library for validating SPF records, but I think the behavior I observed was according to specification. The domains with problematic records were IPv4-only, but I think the same could happen to IPv6-only domains. While doing validation the library may need to do AAAA or A lookups depending on the source IP of the incoming mail. And the absence of record can cause a failure. The result was that SPF records which were valid as long as mail originated from an IPv4 address would be considered invalid when a mail originated from an IPv6 address. Crucially, the library reports this as the SPF record as being faulty and not as the origin failing SPF validation. In essence by sending spam from an IPv6 address spoofing one of those domains the end result could be that the SPF record was entirely ignored.
0
0
1
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
My preferred approach is to boot a Linux system and repartition the disk.
0
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
I remember the time when a computer with 8MB of RAM could run a browser. I’d like to hear a really good explanation of why a computer with 512MB of RAM cannot even start Chrome. I did once or twice write a TSR program for DOS that consumed only 16 bytes of memory. Not GB, not MB, not KB. Once the TSR had been loaded the memory usage had literally only increased by 16 bytes.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 4mo ago
Replying to
There are other HTTP libraries.
0
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
When I see products advertised as either recyclable plastic or recycled plastic I can’t help but think that they are really only suggesting that this plastic gets used twice rather than only once.
0
1
1
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
At least my representative opposes, but maybe I could email some of the other members from Denmark to ask them to explain their position.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 1mo ago
Replying to on mastodon.social
Setting it in the web interface should be safe if you use a direct Ethernet cable between your laptop and the device for configuring the password. But if you instead plug the device into your switch, are you really sure there is not a single potentially malicious device on your LAN? Somehow proving that you have physical access to the device is the desired level of security, and using the serial port seems like the closest you get using this hardware. Something based on buttons on the device could possibly be better, but this particular hardware looks like the reset button is the only button present. The console port looks like a USB-C port. Does that mean this device has a built in USB to serial adapter? That’s probably convenient if you want to access the port from a laptop. But it might make it problematic if you are using one of those remote console devices with Ethernet and several serial ports.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 5mo ago
Replying to
I disagree with the assertion that new applications should avoid IPv4-mapped addresses in general. New applications should be designed with an IPv6-first mentality, by that I mean that one should first decide on what’s a good design if you don’t need to support IPv4 at all. And once you have that design you can decide how to add IPv4 support, and doing so must not compromise the design you want for IPv6. In some situations it will add complexity to listen on two separate sockets. And more complexity increase the risk of bugs including security vulnerabilities. For that reason I think one need to decide on a case-by-case basis what is the best design for a particular application. Mandating a more complex design is not how we get developers to fix the few applications which still lack IPv6 support.
0
1
1
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
The listing on https://haveibeenpwned.com/PwnedWebsites still says 154k.
haveibeenpwned.com
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
I agree in principle, though I am not sure if Firefox or Chromium is the best starting point. Each have their own advantages.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 1mo ago
Replying to
I don’t think it’s sufficient for your only backup to be a different location within the same hosting provider. A provider could go out of business or they could delete your account for some reason. You could choose to have your master on a hosting provider with a backup in your own office. Or you can choose two different hosting providers. In all cases you should go for geographical diversity as well. There is no need for the backup to be in the same city as the master. A different DC within the same city might be insufficient. Elsewhere in the thread there was somebody who mentioned having used two different OVH DC, which both happened to be in the same building. When using multiple hosting providers you will probably at some point experience a problem with communication between the two, and they might be pointing fingers at each other with you having no way to know who is right and who is wrong. If you want to be prepared even for that you’d need three hosting providers and a plan for how to continue operation if any single of the three providers goes away.
0
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 4mo ago
Replying to
If the information has to be stored, I think /etc/passwd would be the obvious place to put it. The format of /etc/passwd was amended once changing the field with name into a comma-separated list of fields of which name is now the first. Something similar could be done again to include a birth date field.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3w ago
Replying to
I think that's an understatement. Some lawyers have put their signatures on AI generated documents and submitted them to the courts without even reading the documents.
0
1
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
If that’s what it takes to teach people to use #! I am ok with that.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 2w ago
Replying to
The part which caught my attention was "no longer". Now I wonder why it was permitted in the first place, but I am not sure I want to know.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
What makes a site think it’s ok to show a button called “WITHDRAW CONSENT” to a user who never consented to anything?
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 2mo ago
Replying to
Microsoft does not exactly have the best track record when it comes to guarding user privacy. Take for example the 2011 incident where Microsoft was caught snooping on users’ Google searches. The system you describe sounds like it was designed to be centralized. A much better ecosystem would be one where there is a few different payment handlers who both service providers and users can choose between. There will probably need to be a little bit of money exchanged between them in case users aren’t distributed the same way as service providers. It should be possible to get paid even if user and service provider picked different payment handlers.
0
2
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
Forgeries do exist so one has to be careful where one is buying storage media from. Personally I have no idea whether the one depicted is real or not.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
I think the answer to that question is no.
0
0
0
0
Open post
kasperd @kasperd@westergaard.social
· 3mo ago
Replying to
My guess is that it’s probably just because it’s not being interpreted by the shell so alias doesn’t apply. It doesn’t have to be sudo many other commands could have the same effect such as env or nice.
0
0
1
0
Open post
kasperd @kasperd@westergaard.social
· 1w ago
Replying to on universeodon.com
They may very well understand the science fiction and identify with the villain.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:42:50 UTC