Posts
3210
Following
706
Followers
1563
"I'm interested in all kinds of astronomy."
repeated

Remember "don't print this email" in signatures that was a bit cringe? It doesn't feel that cringe anymore in retrospect. I'm doing an experiment now with this new email signature :D Anyone doing something similar? Could it catch on?

9
21
2
repeated

Today's threads (a thread)

Inside: Google's AI pricing plan; and more!

Archived at: https://pluralistic.net/2026/01/21/cod-marxism/

1/

2
1
0
repeated

After auditing the @mullvadnet client applications in 2024, we have recently audited Mullvad VPN's API.
The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.
Five issues were identified, of which only one had a very limited impact on users of the service.

The technical details may be found in our report. https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/

1
6
0
repeated

Last December I solved Synacktiv's 2025 Winter Challenge: Quinindrome https://www.synacktiv.com/en/publications/2025-winter-challenge-quinindrome . Here is a 81-byte Linux program which is both a quine (it prints itself when executed) and a palindrome (it is symmetrical)! To learn how I achieved it: https://github.com/fishilico/synacktiv-winter-chall-2025-quinindrome/blob/main/writeup.md

0
5
0
[RSS] Windows Internals: Check Your Privilege - The Curious Case of ETW's SecurityTrace Flag

https://connormcgarr.github.io/securitytrace-etw-ppl/
0
0
0
I feel I have this instinct to feed programs data that they won't be able to handle.

Unfortunately this is mostly true for tools I'd like to use, not targets I review.
0
2
6
Edited 8 hours ago
Humble request for vibe-coders: report your runtime errors!

LLM tends to insert Pokémon exception handlers everywhere, making problems (of which vide-code has a *lot*) hard to even notice.

Slightly related illustration:
1
35
44
@troed I'm no lawyer, but my understanding is if the infra is legally owned by an EU legal entity they can (at least in theory) say FU to the mothership
(they can threaten to fire the leadership ofc, but can't send them to jail etc.). This can also be used by AWS as an argument not to screw their EU business ("we would comply, it's just those picky EU judges!").

But yeah, we've seen how complicit people can become when they get nasty looks (see DOGE)...
1
0
0
I positively surprised that AWS apparently built a separate IAM for their European Sovereign Cloud:

https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/

I can't tell if this whole thing will be good enough, but some key issues seem to be addressed here.
1
0
1
@krutonium @ekis I bet they took special care to select very European sounding names for the VP and director too :D
0
0
0
repeated

@ekis Meanwhile Amazon is launching a Euro specific AWS, claiming it gives Europeans Digital Sovereignty.

It does not, it's still subject to all the same legal obligations as the US based AWS - Especially the Cloud Act. https://en.wikipedia.org/wiki/CLOUD_Act

3
1
0
In the shitty state of tech today: Soundcloud!

I want to filter for DJ mixes (long tracks) on the web:

- The mobile app groups sets to a tab when searching, but the web version does not.
- The web version allows you to filter search based on duration, but the official help page doesn't tell you how to do it (you have to do a search, select Tracks then you can filter for duration).
- Neither interfaces allow you to search only artists you follow.

I thought these were solved problems by 2001.
0
0
2
repeated

TrendAI Zero Day Initiative

Looking for all the results from Day One of Automotive 2026? You can find them here https://www.zerodayinitiative.com/blog/2026/1/21/pwn2own-automotive-2026-day-one-results

0
2
0
repeated
0
3
1
repeated

This might be the most difficult CPU to program.

The Intel i860 was useless for general operating systems.

Context switches took ~2,000 cycles.

*You* controlled the floating point pipeline. But, if you’re a genius, it was one of the most powerful chips that existed.

1
1
0
repeated

oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd https://seclists.org/oss-sec/2026/q1/89

0
3
0
Show older