kris's avatar
kris
kris@nostrsec.net
npub15a8n...hd0k
Avocations in long distance trail running & privacy technology. Current & past vocations in information security & cloud engineering - *nix grey beard
kris's avatar
kris 2 months ago
And then we splurge and eat well. #runstr image
kris's avatar
kris 2 months ago
50K training day in the books. Beautiful conditions today. Took a PR and pushed a little over planned HRT. Ate shit half mile from the finish. A bloody (literally) good day πŸ˜‚ for a #runstr
kris's avatar
kris 2 months ago
Headed out to mediate with my steps for the next 6+ hours. Grateful for the ability to have the time and means to train my body and more importantly mind to embrace discomfort, pain, while recoginzing joy in doing so. Max volume, max long today. Self supported #runstr 50K on the path to 100K race. Resilience building. #nostr encouragement welcomed. image
kris's avatar
kris 2 months ago
The section quoted below is poorly worded. The feature was improperly designed/deployed if it exposed the email in the browser that the password reset was sent to. But thank you for the quick disclosure. Perhaps use this as a teaching moment on #nostr responsible disclosure of #security issues from the community. Incentivize it with a Bitcoin bug bounty in the future. Alby is still a fundamentally valuable service for me personally. " ... publicly exposed by their owner. Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker. View quoted note β†’
kris's avatar
kris 2 months ago
Hrm. Apple services just took a hit.
kris's avatar
kris 2 months ago
She is so beautiful after grooming πŸ’• #GreatPyrenees image
kris's avatar
kris 2 months ago
This went well. Nutrition was on point. No issues. 50K train next week. Less than month out to taper for 100K. #runstr
kris's avatar
kris 2 months ago
The hardest step is often one: the first. Headed out for 5 hour train. 100K is nigh. Stay healthy. Stay on plan. #runstr image
kris's avatar
kris 3 months ago
A good day not be on the mines and take a non planned PTO day. This guy in the kayak though. The captain was image not pleased πŸ˜‚
kris's avatar
kris 3 months ago
Oof. That one is in the books. 5 hour long next week. Stay healthy. Stay on plan. Prep for 100k. #runstr image
kris's avatar
kris 3 months ago
Citizenlab continues to do good work. Another analysis demonstrating nation states, Hybrid warfare methodologies, which will continue to accelerate. Examine what is occuring in context to general sociatal topics: oligarchy, deviseness amongst us with labeling each other into two camps, the enshitificaiton of social media and technology as a whole. TLDR: What happened (one line): A coordinated, AI-enabled influence operation called β€œPRISONBREAK” used >50 inauthentic X (Twitter) profiles to push narratives urging Iranians to revolt after the June 2025 strikes β€” including an AI-generated/deepfake video of the Evin Prison bombing.
kris's avatar
kris 3 months ago
Big long today. 100K is in sight. Stay healthy. Stay on plan. But first let's geek out on getting Haven πŸ’― implemented. We are close. To the sounds of the Church of Armin. #runstr #nostr
kris's avatar
kris 3 months ago
Haven blossom test
kris's avatar
kris 3 months ago
Well that was painful: Cloudflare Alby LNURL Nostr integration debugging. Cloudflare transform rule response header + Security rule Allow + cache rule bypass for .well-known Ugh 😩
↑