Posts
3780
Following
723
Followers
1598
"I'm interested in all kinds of astronomy."
repeated

๐Ÿ—ฏ๏ธ + ๐Ÿ”Œ =

0
1
0
repeated

friendly neighbourhood garbage collector

A few weeks ago, someone reported an obsrvation on the iocaine bug tracker: ClaudeBot appeared to have figured out how to remove the poison ID from poisoned URLs.

That was a worrying development, so I set out to do some experiments in The Lab. I wasn't unprepared for this development, and had a few tricks lined up to address it. I wanted to test which one works.

After two and half weeks of experiments, I'm happy to report that Claude has not started to remove iocaine's poison IDs from URLs. The bot merely fails at the basic task of resolving relative URLs.

Both the built-in script and Nam-Shub of Enki generate relative URLs, and only include the poison ID if the entry URL didn't have one. Thus, whenever ClaudeBot hit a poisoned URL, it failed to resolve the poison-ID less relative URL, and constructed an URL that did not have one.

The straightforward fix for this is to not trust the crawlers to be able to resolve relative URLs.

1
1
0
repeated
Edited yesterday

There's a new Windows 0day LPE that has been disclosed called BlueHammer. The reporter suggests that it's being disclosed due to how MSRC operates these days.

MSRC used to be quite excellent to work with.
But to save money Microsoft fired the skilled people, leaving flowchart followers.
I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MSRC requirement now. ๐Ÿ˜‚

Anyway, yeah, it works. Maybe not 100% reliably, but well enough...

1
7
0
repeated

Thousands of CEOs said AI had no impact on productivity. We use AI to catch 200 bugs/week where we used to find 15, and generate $8M per sales rep.

95% of the company pushed back when we started. At unprompted, Dan Guido explains how our 140-person team went AI-native.
https://www.youtube.com/watch?v=kgwvAyF7qsA

1
2
0
Are We Idiocracy Yet?

https://idiocracy.wtf/
0
0
1
repeated

Before its launch, we audited WhatsApp's Private Processing TEEs and found 8 high-severity issues (patched). The enclaves yielded to injected config files, unmeasured ACPI tables, spoofed firmware levels, and stale attestation reports.

TEE security is only as good as the implementation details. Four lessons and the full report: https://blog.trailofbits.com/2026/04/07/what-we-learned-about-tee-security-from-auditing-whatsapps-private-inference/

0
3
0
repeated

@buherator I think your configuration might be borked. We do not force a restart. You should only get this error if the binary file on disk changed while browsing. In that case, Firefox is unable to create a new process due to API incompatibility. Do you use multiple Firefoxes in parallel?

1
1
0
@freddy I simply use the Debian package (so I guess a lot of users have the same experience), and your explanation clears up why this is happening, thanks!

I guess the solution is to use a FF distribution that doesn't rely on the system updater then.
1
0
1
#pol #sigint
Show content
โ€œIn any matter where I can be of assistance, I am at your service.โ€

https://www.bloomberg.com/news/articles/2026-04-07/viktor-orban-offered-to-help-vladimir-putin-call-transcript-shows

Leaking intercepted Orban-Putin comms is an especially nice touch right when J.D.Vance is visiting Budapest...
0
3
1
@freddy I don't think it will help as I browse in p0rn mode. Also, I tried to look up docs, but support.mozilla.org is down for me... Why isn't there a config switch to disable forced restart[1]? I'm a grown adult, I can decide when I want to restart my browser.

[1] https://www.reddit.com/r/firefox/comments/16ug51m/is_there_any_way_to_stop_firefox_from_forcing_a/
1
0
0
@cure53 I guess they want NASA to still be thing at least until they land
1
0
0
repeated

I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf

0
3
0
repeated

Firefox added split tab views and absolutely killed it. I didn't even know I needed this feature and now I cannot live without it. Awesome work. Right click on a tab and select "Add Split View" to try it out.

0
2
0
repeated

If your Open Source project sees a steep increase in number of high quality security reports (mostly done with AI) right now (#curl, Linux kernel, glibc confirmed) please tell me the name of this project.

(I'd like to make a little list for my coming talk on this.)

12
8
0
repeated

One thing that's odd about this package is the amount of internal, anthropic-specific tooling that's in it. Aside from the sort of comical gating behind the USER_TYPE='ant' env var, normally in a well designed package you would expect that it would provide proper hooks so that internal tooling could just be a set of plugins rather than in the source itself.

Claude code does have a number of extension points: agents, hooks, plugins, skills, and tools - even if their structure is somewhat, ah, gestural.

Some things could potentially become features (like the MagicDocs thing, even if that's a comically expensive idea, i'll write more about that later tho), but there are also some things that make no sense to be in here. Like in the startBackgroundHousekeeping task there is an 'ant'-gated task to clean their .npm-cache directory.

There are even notes in here like "this used to block the whole event loop" which you think might have indicated that they might have, say, "just written some separate cron task that runs totally outside claude code." So it seems like "writing claude code with claude code" leads to a collapse of separation of concerns, where anthropic can't really manage the distinction between their projects to the point of inlining the devtools - this can also be seen in comments re: code duplication with Cowork, which i'll also get to later. It also confirms what they say publicly, that they just have claude code sessions running 24/7 (where having a task run every 24 hours makes sense)

1
1
0
@floyd Oh then you are one of the few lucky foreigners who enjoy Tรบrรณ Rudi, glad to hear that! :)

@stf
0
0
1
suffrage
Show content
@light Criminals can be stripped of voting rights around here, but doesn't really change the equation as these people are a tiny minority of the voting population.

"Morality" is difficult: e.g. is it moral to vote if you don't have the slightest idea of rules/stakes/etc?
0
0
0
repeated

Cat ๐Ÿˆ๐Ÿฅ— (D.Burch) pawโ paw

ad Is your shitposting quantum ready?

4
7
0
Show older