Posts
3373
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated

Friend's meme coping strategy isn't pulling any punches today. 😳

3
8
0
repeated

While we did this for security purposes, you don't have to be security-oriented, this is generic OS research.

https://bird.makeup/@spendergrsec/1897722500806787312

0
2
0
repeated
repeated
repeated

@ewolff auch:
„Massive amounts of Russian propaganda — 3,600,000 articles in 2024 — are now incorporated in the outputs of Western AI systems, infecting their responses with false claims and propaganda. […] A NewsGuard audit has found that the leading AI chatbots repeated false narratives laundered by the Pravda network 33 percent of the time“

https://www.newsguardrealitycheck.com/p/a-well-funded-moscow-based-global

0
2
0
repeated
Created a #CodeQL Cheat Sheet to document what I struggled with recently:

https://scrapco.de/codeql-cheat-sheet/cpp/cpp-conditionals-cfg/

Will push updates as they pop to my mind. Contributions/ideas are also most welcome!

https://github.com/v-p-b/codeql-cheat-sheet
0
6
4
repeated

this is my legacy

2
9
0
repeated
[RSS] To some people, time zones are just a fancy way of sounding important, episode 2

https://devblogs.microsoft.com/oldnewthing/20250307-00/?p=110946
0
0
2
[RSS] Micropatches Released for SCF File NTLM Hash Disclosure Vulnerability (No CVE)

https://blog.0patch.com/2025/03/micropatches-released-for-scf-file-ntlm.html
0
0
1
repeated
Edited 11 months ago

Hey did you know

1. It is Bandcamp Friday* I didn't know if they'd do Bandcamp Friday after last year but they're doing it. This means if you buy music on Bandcamp in the next 11 hours the artist gets a higher % than normal and the weird company that bought Bandcamp gets jack

2. ~ Lena Raine, who you may know as the composer from Celeste, dropped a new album today ~

https://radicaldreamland.bandcamp.com/album/earthblade-across-the-bounds-of-fate

---

* https://isitbandcampfriday.com/

1
4
0
repeated

Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post:
https://sensepost.com/blog/2025/diving-into-ad-cs-exploring-some-common-error-messages/

0
4
0
@wdormann @cR0w I start to feel like a Kagi sales person here, but may I suggest to give Orion a try (mac only)? https://kagi.com/orion/
0
0
2
repeated

I’m not saying you definitely have to go to @bluehatil this year, I’m just letting you know it’s free, by the beach and I’ll be there dropping kernel pointers to anyone who asks nicely

4
3
0
repeated

This year I am joining the Black Hat USA review board as a guest reviewer. It's awesome to be part of such an industry defining event and help give back to the community 🫶

Since I learned English as a second language (ESL) myself, I understand how stressful it can be to work on CFPs. It's not just about the technical details, you also have to consider formatting, wording, and overall clarity. If anyone wants some structural feedback on their submissions, my DMs are open as always 🙇‍♂️

1
2
0
repeated
Edited 11 months ago

Fuck.

will soon be completely unusable instead of mostly unusable(paid results).

This is a real problem.

" you can't just scroll down in AI Mode to see organic results. … refine your search or ask follow-up questions."

https://arstechnica.com/google/2025/03/google-is-expanding-ai-overviews-and-testing-ai-only-search-results/

3
3
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

Edited 11 months ago

Wow the AutoCHERI report makes me not want to get into a car ever again:

The few memory issues that were detected by CHERI hardware (exceptions) required a detailed analysis of the error conditions to understand and address the them, which took significantly more time than is normally spent using conventional tools. CHERI’s increased demand on exception management needs a higher level of development effort and expertise, rather than enabling less experienced engineers to adopt it for embedded and safety-critical systems development.

If automotive vendors are employing developers who find it hard to debug memory-safety issues when the hardware tells you the precise instruction that triggers the bug (and a debugger stops at exactly that point showing you where in the bug exists in the source code), they must be really scraping the bottom of the barrel.

Odd that this is the exact opposite of the experience that everyone else has had developing on CHERI platforms.

3
7
0
Show older