Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Charlie Stross boosted
Brian Greenberg :verified:
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange  ·  activity timestamp 2 days ago

Prediction markets sell themselves as truth engines. Put money on outcomes, strip away noise, and let prices reveal reality. The Venezuela strike exposes the cost of that logic. When someone can profit from a covert military operation before the public knows it happened, markets stop forecasting the future and start rewarding proximity to power. This isn’t information discovery. It’s monetized access.

The political problem is simple and corrosive: greed gets institutionalized. When insiders are encouraged to leak or act early because there’s money on the table, restraint becomes irrational. Journalism delays publication to protect lives. Markets pay you to move first and ask questions never.

The ethical problem runs deeper. Prediction platforms don’t just reflect reality; they reshape incentives inside governments, corporations, and security institutions. They quietly ask every insider: do your job, or place your bet?

And the security problem may be the most dangerous of all. Classified plans, military actions, and diplomatic moves become market signals. Prices move faster than accountability. Risk is no longer mitigated; it’s priced.

Efficient markets are not moral systems. When everything becomes tradable, even secrecy turns into a commodity. And when insiders win, the public doesn’t gain clarity. It absorbs the risk.

TL;DR
🧠 Prediction markets reward access to secrets
⚡ Greed displaces ethics and restraint
🎓 Security decisions become financial signals
🔍 Truth priced by markets is not the same as a public good

https://www.theatlantic.com/technology/2026/01/venezuela-maduro-polymarket-prediction-markets/685526/

#MarketEthics #Politics #Crypto #Power #security #privacy #cloud #infosec #cybersecurity

The Atlantic

The Polymarket Bets on Maduro Are a Warning

Get ready for the golden age of insider trading.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 2 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 2 days ago

#curl 8.18.0 has been released. This release fixes 1 medium and 5 low level vulnerabilities:
- CVE-2025-14017: broken TLS options for threaded LDAPS https://curl.se/docs/CVE-2025-14017.html
- CVE-2025-14524: bearer token leak on cross-protocol redirect https://curl.se/docs/CVE-2025-14524.html
- CVE-2025-14819: OpenSSL partial chain store policy bypass https://curl.se/docs/CVE-2025-14819.html
- CVE-2025-15079: libssh global knownhost override https://curl.se/docs/CVE-2025-15079.html
- CVE-2025-15224: libssh key passphrase bypass without agent set https://curl.se/docs/CVE-2025-15224.html

I discovered the last 2 vulnerabilities.

Download curl 8.18.0 from https://curl.se/download.html

#vulnerabilityresearch #vulnerability #cybersecurity #infosec

curl - Download

curl - libssh key passphrase bypass without agent set - CVE-2025-15224

curl - libssh global knownhost override - CVE-2025-15079

curl - OpenSSL partial chain store policy bypass - CVE-2025-14819

curl - bearer token leak on cross-protocol redirect - CVE-2025-14524

curl - broken TLS options for threaded LDAPS - CVE-2025-14017

  • Copy link
  • Flag this post
  • Block
Brian Greenberg :verified:
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange  ·  activity timestamp 2 days ago

Prediction markets sell themselves as truth engines. Put money on outcomes, strip away noise, and let prices reveal reality. The Venezuela strike exposes the cost of that logic. When someone can profit from a covert military operation before the public knows it happened, markets stop forecasting the future and start rewarding proximity to power. This isn’t information discovery. It’s monetized access.

The political problem is simple and corrosive: greed gets institutionalized. When insiders are encouraged to leak or act early because there’s money on the table, restraint becomes irrational. Journalism delays publication to protect lives. Markets pay you to move first and ask questions never.

The ethical problem runs deeper. Prediction platforms don’t just reflect reality; they reshape incentives inside governments, corporations, and security institutions. They quietly ask every insider: do your job, or place your bet?

And the security problem may be the most dangerous of all. Classified plans, military actions, and diplomatic moves become market signals. Prices move faster than accountability. Risk is no longer mitigated; it’s priced.

Efficient markets are not moral systems. When everything becomes tradable, even secrecy turns into a commodity. And when insiders win, the public doesn’t gain clarity. It absorbs the risk.

TL;DR
🧠 Prediction markets reward access to secrets
⚡ Greed displaces ethics and restraint
🎓 Security decisions become financial signals
🔍 Truth priced by markets is not the same as a public good

https://www.theatlantic.com/technology/2026/01/venezuela-maduro-polymarket-prediction-markets/685526/

#MarketEthics #Politics #Crypto #Power #security #privacy #cloud #infosec #cybersecurity

The Atlantic

The Polymarket Bets on Maduro Are a Warning

Get ready for the golden age of insider trading.
  • Copy link
  • Flag this post
  • Block
Brian Danger Hicks and 1 other boosted
Doomfrent Curdles
Doomfrent Curdles
@diffrentcolours@tech.lgbt  ·  activity timestamp 4 days ago

New year, new password reset at work...

My new password is "NCSC advises against regular password expiry"

Actually TBF that was my old one, my new one is "NCSC advises against regular password expiry2"

#NCSC #passwords #InfoSec

  • Copy link
  • Flag this post
  • Block
mhoye boosted
Sascha Block
Sascha Block
@SaschaBlock@devhub.social  ·  activity timestamp 4 days ago

I’m looking for 2 people to sanity-check the approach (10 minutes).

If you work with #requirements, #compliance, or #audits: what would you need to try this on a real spec?
Boost welcome 🤗

#DSL #opensource #itsecurity #requirementsengineering #infosec

  • Copy link
  • Flag this post
  • Block
Sascha Block
Sascha Block
@SaschaBlock@devhub.social  ·  activity timestamp 4 days ago

I’m looking for 2 people to sanity-check the approach (10 minutes).

If you work with #requirements, #compliance, or #audits: what would you need to try this on a real spec?
Boost welcome 🤗

#DSL #opensource #itsecurity #requirementsengineering #infosec

  • Copy link
  • Flag this post
  • Block
Sascha Block
Sascha Block
@SaschaBlock@devhub.social  ·  activity timestamp 4 days ago

Fediverse check: who can actually see this? 👋

I’m building dsl-core: an open-source #DSL that makes requirements machine-readable and verifiable (ambiguity / atomicity / consistency).

❓ What would be the first meaningful use case for you?
Repo: https://github.com/rock-the-prototype/dsl-core
(Boost welcome 🙏)

#opensource #itsecurity #requirementsengineering #infosec

GitHub

GitHub - rock-the-prototype/dsl-core: Core Specification for the Audit-by-Design DSL - Human- and machine-readable domain-specific language (DSL) for defining, validating, and auditing atomic requirements (AFOs) in regulated software environments. Open specification, free to use and extend.

Core Specification for the Audit-by-Design DSL - Human- and machine-readable domain-specific language (DSL) for defining, validating, and auditing atomic requirements (AFOs) in regulated software e...
  • Copy link
  • Flag this post
  • Block
Doomfrent Curdles
Doomfrent Curdles
@diffrentcolours@tech.lgbt  ·  activity timestamp 4 days ago

New year, new password reset at work...

My new password is "NCSC advises against regular password expiry"

Actually TBF that was my old one, my new one is "NCSC advises against regular password expiry2"

#NCSC #passwords #InfoSec

  • Copy link
  • Flag this post
  • Block
Graham Sutherland / Polynomial boosted
Shodan Safari
Shodan Safari
@shodansafari@infosec.exchange  ·  activity timestamp 6 days ago

ASN: AS4766
Location: Gunsan, KR
Added: 2025-12-18T18:47

#shodansafari #infosec

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Shodan Safari
Shodan Safari
@shodansafari@infosec.exchange  ·  activity timestamp 6 days ago

ASN: AS4766
Location: Gunsan, KR
Added: 2025-12-18T18:47

#shodansafari #infosec

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block

bonfire.mavnn.eu

News and community around mavnn.eu projects.

bonfire.mavnn.eu: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1-beta.11 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Public Groups
  • Code of Conduct