soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 (cringe EU-brained military girl) [we/us; q=1.2; use_third_person=true; details_link=<none>, it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
@freya@social.highenergymagic.net
hey so. looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years experience administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. I'm also 26, so I started when I was 11, explaining the no jobs so far. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at https://status.highenergymagic.net. Three machines, 72 docker containers. One running most of them, one running Mastodon+glitchsocial, one running the uptime monitor. encrypted root on ZFS, alpine linux, gVisor on supported containers, plan to move to Kata. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status. Currently using gVisor, docker compose, and kata containers in production, experience with Linux, docker, Net/Open/FreeBSD, Cisco IOS, Juniper Junos, Mikrotik and UniFi, configuring and administering Asterisk, plus extensive experience with IBM AIX and Sun Solaris. #fedihired #infosec #cybersecurity #linux #unix #docker #sre #DevOps #GetFediHired
Please boost for reach, any job offers please DM me.
A source wants to reach you safely. With most messengers that starts with a problem: they need your phone number, you get theirs, and a server in the middle logs that you two talked.
Zerion skips all of that. You share a QR code or link, the connection runs device to device over Tor, and no record of the contact exists outside your two phones.
Source code and protocol docs are public. Verify before you trust: https://github.com/zerionproject/Zerion
People who have been around the tech world longer than I have: I've been reading for a while how some people seem to feel like the industry peaked somewhere in the 2000s and that it all went downhill from there.
There was one hype after the next and people just kept on jumping on the bandwagon because everyone was doing it. I've read this sentiment about containers, Kubernetes, the Cloud in general but there are probably more.
Do you feel that LLMs are more of the same of this or does this feel qualitatively different? If so, how? I'm trying to find some perspective in all this as I haven't been around the block for long enough to have it myself.
Boosts appreciated.
boostedMajor #CyberSecurity alert! Over 400 AUR packages have been hijacked in an unprecedented supply chain attack dubbed the 'Atomic Arch' campaign. This campaign utilized a Rust credential stealer aimed at developer machines. Stay informed and vigilant! #ArchLinux #InfoSec #DataBreach 400+ AUR Packages Hijacked in Major Arch Linux Supply Chain Attack
https://www.squaredtech.co/400-aur-packages-hijacked-in-major-arch-linux-supply-chain-attack?fsp_sid=11863
PSA regarding a change in how Secure Boot will work in Fedora soon. The change isn't urgent, but it is something you should take a look at.
If you have any questions about this, please ask in our forum. 🙏
➡️ https://fedoramagazine.org/expiration-of-microsoft-secure-boot-keys/
Forum: https://discussion.fedoraproject.org/c/ask/6
#Fedora #Linux #OpenSource #Cybersecurity #InfoSec #SecureBoot
ATT limited some tracking. Meta Pixel was a workaround. Fingerprinting is another one — and it doesn't need any permissions at all. While this isn't limited to just iOS — Android can be mined as well, Loupe is an open source iOS app that shows you the raw data your phone hands out by default. The third tier of signals is genuinely creepy.
https://blog.ppb1701.com/what-your-phone-is-handing-out-before-youve-said-a-word
#privacy #fingerprinting #adtech #apple #android #bigtech #ios #tracking #userhostile #infosec #metapixel #blog
#Github Security Advisories program is struggling under the load of new submissions. Delays in CVE assignment up to a month are being reported. Apparently, May 2026 was the highest volume month ever, and they are working through a backlog.
source: https://www.openwall.com/lists/oss-security/2026/06/10/9
It is not very hard to figure out what is going on: The amount of AI-assisted reports is flooding the systems. Considering the asymmetric nature of the situation (limited human resources processing increasing number of reports), it is unlikely the it is getting any better soon.
If just tracking and assigning issues is getting this hard, it can't bode well for actually fixing and patching them.
Built something I’ve wanted for a while...
An open-source Docker container that makes running a Tor relay actually simple and reliable.
One command. Self-healing. Multi-arch. Runs everywhere from Raspberry Pi
to VPS 
🔗 https://github.com/r3bo0tbx1/tor-guard-relay
If you care about privacy infrastructure:
🧱 Try it out
🐛 Report bugs
💡 Suggest features
⭐ Star it to help others discover it
Maintaining this in my free time, donation info’s in the README (and please support @torproject, @eff and @privacyguides too).
Protecting privacy, one relay at a time
✨
#Tor #Privacy #OpenSource #Docker #FOSS #SelfHosting #Infosec
The Net-NTLMv1 Rainbow Table is now complete and ready to share!
#InfoCon hosts several tables, as well as word lists, old school style.
Check out https://infocon.org/ for the torrent files.
#InfoSec #Hacking
onion-relay v2.0.0 is out, and it's been a long road from v0.0.1 ⬇️
ℹ️ What started as "one command to run a relay" is now a hardened, production-tested AIO stack: guard, exit, and bridge (obfs4) in a 16.8 MB image.
What's new in v2.0.0:
🩺 health + status tools now expose build_version & config_source
⚡ healthcheck.sh fails fast on missing/empty torrc
🔒 DirPort now defaults to 0 (disabled) in ENV-generated configs
What the project has grown into since launch:
🔑 Happy Family support (Tor 0.4.9+ FamilyId, 🪦 RIP MyFamily lists)
🧰 6 busybox only diagnostic tools
🌍 Battle-tested across 10+ countries: https://relays.brokenbotnet.com
🔐 35+ security fixes, CVE coverage, weekly automated rebuilds
🐋 Works with Docker CLI, Compose, Cosmos Cloud & Portainer
https://github.com/r3bo0tbx1/tor-guard-relay
If you care about privacy infrastructure:
🥢 Try it out
🐛 Report bugs
💡 Suggest features
⭐ Star it to help others find it
Still maintaining this in my free time, donation info
in the README. And please support @torproject
@eff and @privacyguides too.
Protecting privacy, one relay at a time
✨
#Tor #Privacy #OpenSource #Docker #FOSS #SelfHosting #Infosec
📜 Scrolls volume 32 is out! Go check it out for the latest #indieweb, #fediverse and #infosec / #cybersecurity stuff.
https://shellsharks.com/scrolls/scroll/2026-03-06
Have a great weekend!
Delta Chat is a messaging platform that works over email.
Setup is similar to a email client.
Messaging is decentralized and interoperable.
Supports end-to-end encryption via PGP.
PGP encryption keys are created automatically.
Default desktop client is based on Electron.
Electron is based on the Google Chromium web browser.
Website: https://delta.chat
Mastodon: @delta
#DeltaChat #Messaging #Privacy #InfoSec #E2EE #OpenPGP #PGP #OpenSource #FOSS #CyberSecurity #Encryption #FreeSoftware
Cryptomator is a client-side encryption tool for cloud storage services.
Data protected via AES-256 encryption.
Individual and business features.
Managed and self-hosted options.
ENCRYPTED
File content.
File/Folder name.
NOT ENCRYPTED
File/Folder access/creation/modification timestamp.
Number of files/folders in a folder/vault.
File size.
Website: https://cryptomator.org
Mastodon: @cryptomator
#Cryptomator #Encryption #InfoSec #Privacy #CyberSecurity #FreeSoftware #FOSS #FLOSS #OpenSource
NEWSCARD Publish and fetch permanent named records via Network News
Newscard creates a decentralized, encrypted, named record paste bin.
[git repo] https://codeberg.org/OCTADE/newscard (use most recent version only)
With a single command, name the card, snarf the file and encrypt it.
With another command, push the encrypted file to the public network.
With another short command, snarf a file from the network.
Only users knowing the name [key] of the record will be able to decrypt it.
If a strong passphrase is used to name the file, it will be very secure.
This is useful for quickly snarfing, encrypting, and publishing a text file:
$~: card enc [passphrase] [file]
$~: card put [passphrase]
It is useful for retrieving a text file with just a key:
$~: card get [passphrase]
$~: card show [passphrase]
If and when you want the general public to access the record just share the keyword.
Newscard uses nine (9) (NINE) layers of encryption with OpenSSL chacha20 cipher.
Newscard generates 9 each of: cipher keys, salts, key iteration parameters.
It would be nice if something like this were added to the ActivityPub protocol, such that keyword[@]host.url would do the same thing. Then secret text records could be stored securely for later retrieval or revelation.
#NewsCard #Pastebin #Usenet #NNTP #NetworkNews #Encryption #Cryptography #Messaging #Anonymity #Protocols #OpenSource #FreeSoftware #BlackHackJack #Censorship #Retro #InfoSec #Ciphers #Codes #FOSS
@infostorm@a.gup.pe @crypto@a.gup.pe @infosec@a.gup.pe @selfhosting@a.gup.pe
NEWSCARD Publish and fetch permanent named records via Network News
Newscard creates a decentralized, encrypted, named record paste bin.
[git repo] https://codeberg.org/OCTADE/newscard (use most recent version only)
With a single command, name the card, snarf the file and encrypt it.
With another command, push the encrypted file to the public network.
With another short command, snarf a file from the network.
Only users knowing the name [key] of the record will be able to decrypt it.
If a strong passphrase is used to name the file, it will be very secure.
This is useful for quickly snarfing, encrypting, and publishing a text file:
$~: card enc [passphrase] [file]
$~: card put [passphrase]
It is useful for retrieving a text file with just a key:
$~: card get [passphrase]
$~: card show [passphrase]
If and when you want the general public to access the record just share the keyword.
Newscard uses nine (9) (NINE) layers of encryption with OpenSSL chacha20 cipher.
Newscard generates 9 each of: cipher keys, salts, key iteration parameters.
It would be nice if something like this were added to the ActivityPub protocol, such that keyword[@]host.url would do the same thing. Then secret text records could be stored securely for later retrieval or revelation.
#NewsCard #Pastebin #Usenet #NNTP #NetworkNews #Encryption #Cryptography #Messaging #Anonymity #Protocols #OpenSource #FreeSoftware #BlackHackJack #Censorship #Retro #InfoSec #Ciphers #Codes #FOSS