
Bit of a shot in the dark - I just got a half dozen alerts for accounts which have supposedly been found with valid credentials on the dark web....

Mmmmmmm, I'm triggering PW resets anyway.
New Entra "Leaked Credentials"
Bit of a shot in the dark - I just got a half dozen alerts for accounts which have supposedly been found with valid credentials on the dark web....
I don't usually link to Reddit but damn... Entra leak is a big deal
Details of our SuperNote Nomad research which led to the disclosure of a 0-click RCE vulnerability
🥳🥰 Thanks!
🎉🎉🎉 Every little bit counts!
Reddthat Update: April 2025 (v0.19.11 - Unexpected Downtime)
So much has happened since the last update, we've migrated to a new server, we've failed to update to a new lemmy version, automated our rollouts, fought with OVH about contracts. It's been a lot.
Strap in for story time about the upgrade, or skip till you see the break for the next section.
So good news is that we are successfully on v0.19.11.
The bad news is that we had an extended downtime.
Recently I had some extra time to completely automate the rollout process so Reddthat didn't rely solely on me being on 1 specific computer which had all the variables that was needed for a deployment.
As some people know I co-manage the lemmy-ansible repository. So it wasn't that hard to end up automating the automation. Now when a new Version is announced, I update a file/files, it performs some checks to make sure everything is okay, and i approve and roll it out. Normally we are back online within 30 seconds as t
Max severity RCE flaw discovered in widely used Apache Parquet
Could be worse, I could be using parquet...
You can block instances yourself. Check your Settings then click the Block tab, then enter in the domain under Block Instance.
Defederating has wider ramifications and just because there are a few bad users or opinions people don't like doesn't mean that everyone should be blocking them.
We have a few of those users too who regularly get into fights or who might be classed as mean, so if that's the case then we would be blocked too.
Standards that one server has cannot be enforced by another server.
Also no dog-piling onto this thread which I'll be locking if it happens.
Federation between Onion and Standard Domains that way tor users would not be isolated
This is the hardest part as you would need to be both have an onion and have a standard domain, or be a tor-only Federation.
You can easily create a server and allow tor users to use it, which unless a Lemmy server actively blocks tor, you'd be welcome to join via it. But federation from a clearnet to onion cannot happen. It's the same reason behind why email hasn't taken off in onionland. The only way email happens is when the providers actively re-map a cleanet domain to an onion domain.
This is what Lemmy would need to do. But then you would have people who could signup continuously over tor and reek havok on the fediverse with no real stopping them. You would then have onion users creating content that would be federated out to other instances. & User generated content from tor users also is ... Not portrayed in the best light.
I'm sure someone will eventually create an onion Lemmy instance, but it has it's own problems to deal with.
This is especially true for lack of moderation tools, automated processes, and spammers who already are getting through the cracks.
I can confirm the sections around downvotes as Reddthat has the stance exact what you are talking about (re your child comments)
A downvote disabled instance creates it's own algorithm/feed/ranking based purely on all other metrics, because as far as the data is concerned, it sees every post having 0 downvotes. It does not take into account external instances.
I can answer the first point.
We've already tackled part of that problem with the Parallel Sending feature that can be enabled on instances with a tremendous amount of traffic. Currently the only instance that makes sense to enable that is LemmyWorld and the only reason is so servers in geographical far away can get more than 3-4 activities/second.
With that feature, servers that eventually house and generate the biggest amounts of traffic will be able to successfully communicate all of those activities to everyone else who needs them.
I predict a 10x increase is well in our grasp of easily accessible by all of our current systems. 1000x? That's a different story which I don't have the answers too.
Reddthat admin here, it's mainly upto the moderators discretion to what happens with offtopic posts. But as we (I?) prioritise discussion over just a post, even comments like these are welcome. If a personal were to constantly post off topic comments or posts then we'd probably just delete them all and be on our day. There is nothing stopping people from posting to every community, but with enough eyes they get reported to us, then acted upon.
Looks like the savings I've made on the server has been eaten up with our increased S3 storage. Not surprising considering we have just over 2TB stored now. We saved about $20/m! (I've gone and updated the list of items and their costs in our Funding post -> https://reddthat.com/post/25633)
HI from the other side? Was it really that quick?
Thanks! I gave the server some extra coffee this month. ☕
It seems that way, I'll have to do some extra math on our flows to double check but with the new server it should be completely in the black! Until our S3 costs go up of course.
Also I managed to get it so I get billed in AUD this time so we won't be at the behest of the exchange rate.
Once the dust has settled after the migration I'll write up a big announcement on the last year. We're just shy of 2TB of storage now (I'm so glad we went with S3 compatible storage, otherwise we'd have been in trouble!). & Hopefully LW will turn on their parallel sending. I think they are super hesitant because it hasn't really been tested at any serious level, so if there is a way to have it only for reddthat I think they would work with us. That'll shave an extra 4€ off our bill each month too.
Upcoming Migration to new server 21st/22nd
We just successfully upgraded to the latest Lemmy version, 0.9.10, probably the last before the v1 release.
This addresses some of the PM spam that everyone has been getting. Now when that user is banned and we remove content it also removes the PMS. So hopefully you won't see them anymore!
Over the next couple days will be planning for our migration to our new server as our current server's contract has ended. I expect the down time to last for about an hour, if not shorter. You'll be able to follow updates for the migration by our status page at https://status.reddthat.com/
Normally this update would be a week in advance and more nicely formatted that turns out the contract ends on the 25th and I don't want to get charged for another month at a higher rate when I just purchased the new server.
See you on the other side,
EDIT:
22 Mar 2025 02:42: I'm going to start the migration in 5 mins (@ 3:00)
22 Mar 2025 03:01: that was the fastest migration I've ever done.
😁👍 Happy to be a sacrifice for the greater good
I can't wait! We'll finally get to do a real world test for the parallel sending features!! And if all goes well I'll get to save 5 Euro a month!
Thanks LW
Some people donate a small amount occasionally, some people sign up for recurring and let it go for 2-3 months and then remove it, and some people donate a heap all at once. So it's more of an indication based on the last 12 months.
Currently we only have about $70-$80 in recurring donations. Which is $40-50 short. So moving down to a cheaper main server is needed.
The eu server is a tiny batching proxy which is for accepting all of Lemmy World's activities.
I've talked about in my a couple previous updates. Lemmy (used to) send all activities sequentially, and because LW was in EU and we are in AU the network latency was 200-300ms depending on routing and response time. This meant that if LW created more than 3 requests per second we wouldn't be able to process them fast enough and would eventually fall behind. Which is exactly what happened. At one point we were up to 7 days behind from LW.
The batcher/queue service accepts 100 activities and then forwards them to our server. And because it takes next to no time at all to process them we easily caught up with LW.
The main server is where everything runs.
Sounds like you turned off the specific language that the community users or, we haven't federated with that community yet! It sounds more likely that we haven't federated yet so let's check that.
If you go to Search (on reddthat web interface) and type in: [email protected]
that triggers the search/federation.
It should then show up and you should be able to subscribe. It will then start pulling in all the posts (so you might only see a few immediately).
If it's a language problem then you can fix that in your account settings. (As if you don't have a language selected it will not show any posts with that language).
:s Fixed!
Reddthat Update: March 2025
Hello Reddthat! We are back for another update on how we are tracking. It's been a while eh? Probably because it was such smooth sailing!
In the middle of February we updated Lemmy to v0.19.9 which contained some fixes for federating between Mastodon and Lemmy so hopefully we will see less spam and more interaction from the larger mastodon community. While that in of itself is a nice fix, the best fix is the recent thumbnail fix! Thumbnails now have extra logic around generating them and now have a higher chance of actually being created! Let us know if you think there has been a change over the past month-ish.
Reddthat has been lucky to have such a great community that has helped us stay online for over a year and if you can believe it, in just a few more months it will be 2 years, if we can make it.
Our costs have slowly increased over the years as you can all see by our transactions on OpenCollective (https://opencollective.com/reddthat). We've
Unique 0-click "deanonymization" attack targeting Signal, Discord and hundreds of platform
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform - research.md
Interested in Anti-Cheat analysis? I highly recommend checking out Guided Hacking’s Anti-Cheat section. I’ve been reversing Black Ops Cold War for a while now, and I’ve finally decided to share my research regarding the user-mode anti-cheat inside the game. It’s not my intention to shame or promote ...
A nice in-depth article on game hacking
Lemmy is still saving thumbnails and (previously) sometimes the whole image! The majority of image issues have been cleared up in my opinion and it works very well. Nearly all of our hosts allow hotlinking as it's basically required for our use cases.
Lemmy also knows when the image is another Lemmy instance (through "magic", or just cross posting). So if you upload once and then use that same link on all other posts then that would still be the same.
The problem I think you have is your usecase also includes posting externally to Lemmy. & to some extent, you don't want those images tied to your Lemmy account. If my users post via my instance then they are welcome to also hotlink the images externally. This is only possible because Reddthat uses a CDN and caches the images as much as possible.
Even if we didn't use a cdn there are plenty of VPS' and proxy software that we could use which would transparently function in the same way. You could even setup your own VPS, some image hosting software like https://chibisafe.moe/ or https://github.com/nokonoko/Uguu or https://github.com/hauxir/imgpush
To sum up:
The 3rd option you can do completely anonymously via crypto.
Bad Apple but it's 6,500 regexes that I search for in vim
There's no reason I should exit vim just to watch a video
From Pegasus to Predator - The evolution of Commercial Spyware on iOS
My talk explores the trajectory of iOS spyware from the initial discovery of Pegasus in 2016 to the latest cases in 2024. The talk will ...
My talk explores the trajectory of iOS spyware from the initial discovery of Pegasus in 2016 to the latest cases in 2024.
The talk will start with an analysis how exploits, infection vectors and methods of commercial spyware on iOS have changed over time.
The second section of the talk is all about advances in detection methods and the forensic sources which are available to discover commercial spyware. This talk will also include a Case Study about the discovery and analysis of BlastPass (one of the latest NSO Exploits).
The third part will discuss technical challenges and limitations of the detections methods and data sources.
Finally, I will conclude the talk with open research topics and suggestions what Apple or we could technically do to make the detection of commercial spyware better.
The commercial spyware landscape on iOS has evolved significantly since the discovery of Pegasus in 2016. In this talk, we’ll explore that evolution through four main areas:
Breaking NATO Radio Encryption
We present fatal security flaws in the HALFLOOP-24 encryption algorithm, which is used by the US military and NATO. HALFLOOP-24 was meant...
We present fatal security flaws in the HALFLOOP-24 encryption algorithm, which is used by the US military and NATO. HALFLOOP-24 was meant to safeguard the automatic link establishment protocol in high frequency radio, but our research demonstrates that merely two hours of intercepted radio traffic are sufficient to recover the secret key. In the talk, we start with the fundamentals of symmetric key cryptography before going into the details of high frequency radio, HALFLOOP-24, and the foundation of our attack.
High frequency (HF) radio, also known as shortwave radio, is commonly used by the military, other government agencies and industries that need highly robust long-distance communication without any external infrastructures. HF radio uses frequencies between 3 and 30 MHz. These frequencies enable skywave propagation, where the radio signals are reflected by electrically charged particles in the upper atmosphere. While this effect enables communication across very large distan
Maintenance: Tuesday 31st 00:00~01:00 UTC
Let's bring in the new year with some maintenance.
We are going to update Lemmy to the latest version 0.19.8
To perform this there will be a downtime of 30 to 45 minutes while our database updates.
Unless everything goes wrong we'll be up within the hour.
See you on the other side.
Tiff
Edit 1:
We are all done!
Edit 2:
Frontends didn't start correctly and should be sorted now
Reverse engineering the ESP32 Wi-Fi hardware registers
Merry Christmas Reddthat!
What's your plans for today, tomorrow, and the next year?
Famous FDIV bug on Pentium deep dive
Attached: 1 image Intel launched the Pentium processor in 1993. Unfortunately, dividing sometimes gave a slightly wrong answer, the famous FDIV bug. Replacing the faulty chips cost Intel $475 million. I reverse-engineered the circuitry and can explain the bug. 1/9
Read the whole thread, great look at the original Pentium and some pretty pictures to match!
Reddthat Update: December 2024
Hello Reddthat-thians!
As always here is our semi-whenever there is news update. I would, as always like to thank you all for being here and for the kind support we received last time I made an update.
We hit a few couple of milestones this last quarter:
The latest update brings some fixes to Lemmy as well as new features such as Private/Invite only communities. I can't wait to see what this does to help people find safe spaces and to self regulate. Edit: that's in 0.20.0. The only new features (worth talking about imo) are parallel sending and allowing people to have 1000 characters in their bio.
This update is not live yet as the update requires a 30-60 minute database update that I want to test on a backup to make sure we can saf
Making a trading Gameboy: A pocket exchange and algo trading platform
An exchange and algo trading station in your pocket!
A nice in-depth post on the hardware too!
Redbox HDDs are finding their way into the hands on individuals and they were not cleaned!
OH HEY BAD NEWS: when someone opens up the hard drive of a redbox unit, they can pull a file which has a complete list of titles ever rented, and the email addresses of the people who rented them, and where and when
when someone opens up the hard drive of a redbox unit, they can pull a file which has a complete list of titles ever rented, and the email addresses of the people who rented them, and where and when