Posts
4174
Following
733
Followers
1624
"I'm interested in all kinds of astronomy."
repeated

This is so cool: 4 alternatieve Fields Medals for

Excellence in mathematics research by somebody who is currently over the age of 40.

Excellence in mathematics research with approaches that are not mathematically rigorous (construed broadly).

Excellence in leadership in the mathematics community (construed broadly).

Excellence in exposition of mathematics to a popular audience.

https://esander1789.github.io/afm/

0
2
0
repeated

I found a device/bandwidth breakdown in some obscure page of the router's admin interface

the dishwasher's used 700+GB in the last howeverlong, my laptop using 43GB in the same time period

my partner got this dishwasher a few years ago after reading many reviews; I've never liked it much but I liked it even less after discovering you had to use the app – via the internet – to do a rinse cycle or a self-clean

I'm not sure how it could have become compromised; we keep all our stuff up-to-date, I don't let untrusted stuff on the network, and the only android device we have is an MP3 player / e-reader for the kid for which you can only install apps via sideloading APKs via miniSD

Then again, it's a dishwasher company writing software in the age of vibecoding, so who knows, maybe it self-compromised

7
9
1
I wanted to look up how "shotgun" as a reaction is used and after lots of irrelevant results I found this wonderful, barely readable #SmallWeb site giving me the explanation:

slangwall

https://sites.pitt.edu/~emk4/comp1/shotgun.html
1
0
3
repeated

If you run a peertube instance, you should have gotten an alert to update. Either way, it's time to update - there's a security fix out for a high severity vulnerability. Some operators got hit last time this happened. Don't let that happen to you. Patch your OS while you're at it. And drink some water. And then go for a walk. And call your mom.

2
13
0
repeated
Edited 6 hours ago

Oh more at Mozilla

Senior Security Engineer (Add-ons) (https://www.mozilla.org/en-US/careers/position/gh/7583571/). This involves building code-review / malware detection pipelines for addons.mozilla.org - really cool team. The same team is also looking for an engineer to implement extension APIs within Firefox, a Senior Platform Engineer (https://www.mozilla.org/en-US/careers/position/gh/7921750/).

Reminder we're active looking for candidates from diverse backgrounds and with perspectives different from our own. Questions? Just ask me :)

1
8
0
@vathpela I'd be very happy with infinite s/n, how do I do that? :)
1
0
0
repeated
repeated
Hmm.

The announcement by Meta that they'll start selling AI compute potentially broke one of the pet narratives of the AI bubble: compute is so scarce that we need to spend all the money to build more. That story is the justification for crypto-turned-AI companies with poor fundamentals like CoreWeave to continue existing.

Nothing about stock or commodities prices makes any sense anymore so maybe tomorrow their stock will be up 2x.


0
3
0
Has anyone compared Watts/bug stats of LLMs vs. fuzzers?
2
2
3
repeated

wow imagine being exposed to radio waves how will they ever recover

4
3
0
repeated

Given the LLM rubbish I just read, TempleOS isn't looking so bad

0
3
0
repeated

RE: https://infosec.exchange/@trailofbits/116850092020510927

If your goal is to provoke an over reaction in policy circles and further restrictions on defenders, keep framing llm advances from an attacker's perspective like this:

"The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. "

0
2
0
@realmurphy @codinghorror @jwz @bovaz @mjg59 The avg internet user relies on social media for news curation, with all the known consequences. I still hold that RSS is good enough, consumerism winning over DIY (let's call it that...) is rooted much deeper than a protocol spec.
0
0
1
@codinghorror @bovaz @mjg59 @jwz Was it really RSS, or the applications built around it? IIRC Google Reader was pretty popular during it's time, until vendors started to push ppl away from syndication (incl. killing Reader) in general.
1
0
1
repeated
I'm a software developer looking for job. I can code in python (good) and java (basic), but i'm an expert at programming in C. You could also say that i can code in C++, though i really prefer doing C over C++.

I'm experienced at software reverse engineering, especially in radare2, to which i've contributed since 2013. In r2 I've co-authored ESIL (evaluable string intermediate language) for instruction emulation and analysis. I've also written most parts of the r_io API as well as a few plugins. At the moment I live in germany, but relocating within the EU for a job after the probationary would be ok for me.

Previously i've worked for an US-american business, for which i've created components of an analysis pipeline for finding potential security vulnerabilities in firmware. One of the things that I've created during that time was a program, that could automatically find code and data sections of a binary of unknown format. You could destroy the elf header of a binary, throw it at the tool, and it would give you almost perfect section boundaries. This was followed by a script that would invoke cpu_rec in order to determine the correct ISA amd create a script to load the target correctly into r2 for further analysis. I was working on an elf-builder tool, which would allow customers to load the binary into any SRE tool, when someone decided the company would go "agentic" and that they no longer need me.

I'd love to analyse malware or develop software for embedded systems, but i'm also open to other jobs, where i can make use of my experience and skills.

#getfedihired
0
7
0
repeated

KERNSEAL makes the linear page cache overflow in https://cyberstan.co.uk/fuse-readdir-oob/ deterministically unexploitable. Serial log below 👇

0
1
0
repeated

1/3 🧑‍⚖️ Today, the Court of Justice of the EU has upheld a € 4.1 billion antitrust fine against Google for abusing the dominant position of its Android mobile operating system to thwart rivals.

💰 The judgment confirms the European Commission's finding that Google abused Android to strengthen the market position of Google Search, the Chrome browser and other Google products.

1
3
0
repeated

klist.exe Revisited: Internals and Further Use Cases https://jakeotte.com/posts/klist-revisited.html

0
2
0
Show older