Posts
2584
Following
627
Followers
1397
"I'm interested in all kinds of astronomy."
repeated

smbfs is a fuck

2
2
0
repeated
Edited 25 days ago

Please remember that what you see on social media is what people choose to present, not an accurate representation of their life. Few people post about the horror.

Don't put off seeing friends because "they're having fun" or "they're busy" and "you'll see them later". You do not know that any of these things are true.

0
6
0
repeated
repeated
repeated

I probably sound like a broken record at this point, but we're not sold yet on the world-ending nature of Next.js CVE-2025-29927.

The fact that the bug isn't known to have been successfully exploited in the wild despite the huge amount of media and industry attention itā€™s received sure feels like a reasonable early indicator that it's unlikely to be broadly exploitable (classic framework vuln), and may not have any easily identifiable remote attack vectors at all.

https://www.rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/

1
2
1
repeated
Edited 26 days ago
0
1
1
repeated

I published a correction to my slides/blogposts regarding rename(). I have incorrectly stated that rename("./a", "./b") was racy. It is not.
For most situations this is not a huge deal, but I still feel bad that I misled you all, so beers are on me.

https://gergelykalman.com/corrections-regarding-rename.html

1
3
0
repeated

Micropatches Released for SCF File NTLM Hash Disclosure Vulnerability (No CVE) https://blog.0patch.com/2025/03/micropatches-released-for-scf-file-ntlm.html

1
3
0
repeated

I have too many reasons to worry about this but thatā€™s not really the point. The thing Iā€™m worried about is that, as the only encrypted messenger people seem to *really* trust, Signal is going to end up being a target for too many people.

Signal was designed to be a consumer-grade messaging app. Itā€™s really, really good for that purpose. And obviously ā€œexcellent consumer gradeā€ has a lot of intersection with military-grade cryptography just because thatā€™s how the world works. But it is being asked to do a lot!

Right now a single technical organization is being asked to defend (at least) one side in a major regional war, the political communications of the entire US administration, the comms of anyone opposed to them globally, big piles of NGOs, and millions of ā€œordinaryā€ folks to boot.

(There is no such thing as ā€œordinary userā€ cryptography BTW. Those ordinary users include CEOs, military folks, people doing many-million-dollar crypto trades through the app, etc. Itā€™s a lot to put on one app and one non-profit.)

On top of this, itā€™s only a matter of time until governments (maybe in the US or Europe) start putting pressure on the infrastructure that Signal uses ā€” which is mostly operated by US companies. Iā€™m not sure how this will go down but itā€™s inevitable.

2
5
0
repeated

Jeff Hicks šŸ¶šŸŽ¼šŸ·šŸ–„ļø

If you are at the Microsoft MVP Summit this week, and in the Windows Server space, please add your voice for the release of eval ISOs of Windows Server on ARM. We need these for *local* testing, training, and development.

0
4
1
repeated

Trigon: developing a deterministic kernel exploit for iOS by @alfiecg_dev

https://alfiecg.uk/2025/03/01/Trigon.html

0
1
0
repeated

The Hackerā€˜s Choice

PRE-RELEASE: I wrote a Linux Binary Runtime Crypter - in BASH šŸ˜…. Would love you fine people to TEST it _BEFORE_ release: https://github.com/hackerschoice/bincrypter

3
7
0
repeated

The first round of the CFP for Recon Montreal will end this Friday March 28, during that phase we preselect a few talk. The CFP end on April 25. https://recon.cx/2025/cfp.html

0
6
0
"you can do it with a couple of lines of idapython<END OF MESSAGE>" - /u/annoyingasshole

I'm not even making this up :D

https://www.reddit.com/r/ReverseEngineering/comments/24ar8w/ida_importing_map/
0
1
2
repeated

ā€œThe real problem with sharing Top Secret data over Signal is not the security of the app, itā€™s the security of the phone. And mobile phones are not secure against state level threat actorā€ | @thegrugq is correct, BUTā€¦
https://alecmuffett.com/article/113007

0
1
0
repeated

Frida 16.7.0 is out w/ brand new APIs for observing the lifecycles of threads and modules, a profiler, multiple samplers for measuring cycles/time/etc., MemoryAccessMonitor providing access to thread ID and registers, and more šŸŽ‰ https://frida.re/news/2025/03/13/frida-16-7-0-released/

0
2
0
repeated

A code generation tool that gets you 80-90% of the way there is like a boat that gets you 80-90% of the way.

You'll need to be a strong swimmer.

3
6
0
repeated

The Practical Limitations of End-to-EndĀ Encryption

Internet discussions about end-to-end encryption are plagued by misunderstandings, misinformation, and some people totally missing the point. Of course, people being wrong on the Internet isn't exactly news. XKCD: Duty Calls "What do you want me to do? LEAVE? Then they'll keep being wrong!" Yesterday, a story in The Atlantic alleged that the Trump Administration accidentally added their editor, Jeffrey Goldberg, to aā€¦

http://soatok.blog/2025/03/25/the-practical-limitations-of-end-to-end-encryption/

7
6
0
repeated

When Signal was designed, our threat model was protecting the communications of civil society, journalists, just regular citizens ...

The threat model of military operations & sharing your hate of Europeans was not what Signal was designed for. Ephemeral messages and cryptographic deniability are not fit for communications that require accountability.
But I appreciate their effort to make government more efficient by adding journalists to the chat instead of requiring to go through FOIA.

13
48
0
Show older