Posts
4470
Following
738
Followers
1658
"I'm interested in all kinds of astronomy."
repeated

Growing up with the phrase “Wikipedia isn’t a valid source,” only to end up in a daily life where everyone says, “Just ask ChatGPT.”

3
17
0
@VoltPaperScissors @inselchaos Still very cool, Pocket Encrypt already looks like a spy gadget (IMO that's really important when teaching cryptography :))!
1
0
2
@VoltPaperScissors @inselchaos Pringles Enigma! Brilliant! Although as I understand the Enigma part is not delivering electricity (yet)?
1
0
2
@VoltPaperScissors @inselchaos This looks amazing! Does the multi-rotor part actually work??
1
0
2
repeated

Packing my DIY encryption prototypes for my workshop at @inselchaos. It's a fun tech-related topic that you can explore with low-tech materials.

3
2
0
repeated

Mondays in a nutshell.

1
4
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

Programming is understanding.
- Kristen Nygaard

This is a post about AI.

0
2
0
@notsoloud The version I read mentions bruises too - they must've liked it rough...

@tschenkel @juergen_hubert @TarkabarkaHolgy
0
0
2
repeated

RE: https://grapheneos.social/@GrapheneOS/117179231167297908

Apple: "We had to work on MTE stability and security improvements for 5 years, but we finally ship it with the iPhone 17 and enable it by default."

Google: "We shipped MTE hardware for 3 years and only academics enabled this optional feature to demonstrate practical attacks against it, so we decided to no longer ship it on the latest Pixels."

1
8
0
repeated

New video: Process Memory Map in Code (Part 3).
MemMap now enumerates threads, finds each TEB via NtQueryInformationThread and PHNT, and reads thread stacks with ReadProcessMemory.

Full write-up: https://trainsec.net/library/windows-internals/process-memory-map-in-code-thread-stacks-and-tebs-part-3/

0
1
0
repeated
Edited yesterday

Interesting links of the week:

Strategy:

* https://assets.publishing.service.gov.uk/media/6a50d66b1228eb26a4cab76c/National_Risk_Register_2026.pdf - I rave about the HMG risk register but it's a new year and there is still much to worry about
* https://www.whitehouse.gov/wp-content/uploads/2026/08/NSSTS-082026.pdf - the US strategy for tech supremacy
* https://www.wired.com/story/silicon-valley-doesnt-get-why-you-hate-ai/ - @WIRED makes some great points on AI scepticism
* https://codeberg.org/ethical-foss/open-slopware#operating-systems - slop free software!
* https://ar.al/2025/06/25/web-numbers/ - @aral writes small...
* https://www.linkedin.com/pulse/i-spent-day-learning-wargaming-ive-stopped-thinking-since-nicholls-0wh8e - making incident exercises fun
* https://home.treasury.gov/news/press-releases/sb0616/ - the US continues their great policy of going after activists
* https://web.archive.org/web/20260828071449/https://cavallette.noblogs.org/2026/08/10083/2 - who exactly are noblogs and why you should care...
* https://simonwillison.net/2026/Aug/28/just-a-rumour-of-a-bug/ - more thoughts on bugs 🤖
* https://www.csis.org/analysis/cyberattacks-us-water-sector-and-iran-question-escalation-or-opportunism - more reporting on rain
* https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/ - once you've secured water, BES is next
* https://www.cyber.gc.ca/en/news-events/joint-guidance-isolating-vital-systems - put your OT in a box say ASD and CCCS
* https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai - NCSC drops some guidance on agentic AI 🤖
* https://www.gov.uk/government/statistics/uk-public-survey-of-risk-perception-resilience-and-preparedness-2026 - HMG's report on public perception of risk, resilience and preparedness
* https://ieeexplore.ieee.org/document/11644378 - paper on UK NIS readiness
* https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/ - having spent years, presumably improving encryption, @matthew_d_green is worried that threat actors may go dark
* https://www.cyberleagle.com/2026/08/if-computer-is-not-accountable-who-is.html - @cyberleagle.bsky.social asks the awkward question, "who do we prosecute?"

Standards:

* https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/ - new ETSI standards, in support of EU CRA

Threats:

* https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot - another day, another botnet
* https://securelist.com/honeymyte-coolclient-driver-rootkit/ - another day, another rootkit from @Kaspersky
* https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/ - another one for luck, this time from my friends at @TalosSecurity
* https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ - @citizenlab reporting on global surveillance
* https://www.mdsec.co.uk/2026/08/when-it-snows-it-pours-anatomy-of-a-servicenow-red-team/ - more from MDSec on SNow
* https://insights.bridewell.com/hubfs/Reports/Defending%20Against%20DPRK%20IT%20Workers%20-%20An%20Implementation%20and%20Operational%20Guide.pdf - what to do to avoid meeting a .kp colleague at the water cooler

Detection:

* https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a - SOC lessons from CISA
* https://maldbg.com/interlock-esxi-decryptor-internals - don't pay the ransom
* https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/ - scissors are essential for DFIR
* https://www.elastic.co/security-labs/ai-coding-agent-audit-cursor-hooks - if you don't fully trust your AI, how do you keep an eye on it?

Bugs:

* https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/ - too social network
* https://www.usenix.org/system/files/usenixsecurity26-kim-daewoo.pdf - side channels in vSwitch
* https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ - are the NetScalers still in the room @index?

Exploitation:

* https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf - so, nothing that clever then... 🤖
* https://tmpout.sh/5/ - new @tmpout
* https://exploitation.ashemery.com/ - a nice little course on exploitation
* https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse - replicating CrowdStrike's excellent work on turning EDR into a footgun
* https://smolbox.remyhax.xyz/ - why not play with AI in someone else's container? 🤖

Hard hacks:

* https://boschko.ca/g1-ble-rce/ - thank @boschko, for when the robots rise...
* https://blog.n0p.me/2026/08/2026-08-21-fortitool-fortios-decryption/ - dump FortiOS
* https://www.usenix.org/conference/usenixsecurity26/presentation/anwar - who cares what the date is...
* https://0x434b.dev/breaking-secure-boot-without-breaking-the-crypto/ - untrusted boot from @434b

Data:

* https://datarepublican.com/dsa-explorer/ - if you're in the US, what data are they keeping on you? 🤖

Nerd:

* https://lists.debian.org/debian-vote/2026/08/msg00360.html - @debian sadness 🤖
* https://littlefedi.org/ - @stefano's bit of the Fediverse
* https://eater.net/ - a little bit of light CPU design, just for fun!

,

0
4
0
European Citizens' Initiative - Stop Killing The Internet: No Digital ID & No Age Verification

https://eci.ec.europa.eu/066/public/#/screen/home

Please sign!
0
5
2
repeated

watching what's happening to Debian (and Linux, and open source in general)

1
7
0
repeated

And on the topic @kenshirriff is posting about, here's my old macro photo of an Ampex core memory module.

3
3
0
repeated

It sure is strange just how many actually legitimately criminal terrorist orgs have their shit behind Cloudflare, or host actual pedophile rings on Telegram, but it's Autistici/Inventati that gets taken down.

2
5
0
repeated

Before semiconductor RAM, most computers used magnetic core memory. This is the 128 KB core stack from the computer on Spacelab, the Space Shuttle's experimental laboratory. Let's take a closer look...

5
12
0
@TarkabarkaHolgy @tschenkel @juergen_hubert TIL! Still, I find the test incredibly stupid both from the perspective of the future relationship and country governance.
1
0
2
@TarkabarkaHolgy added to my Kids Entertainment list thx!
0
0
1
Show older