Posts
2844
Following
683
Followers
1507
"I'm interested in all kinds of astronomy."
@acsawdey it's complicated... if you squint, pointing out bugs is a form of help, but the P0 disclosure process (designed to incentivize other large corps) doesn't seem to work with highly popular, but underfunded OSS.

I don't know the solution, but shiting on individual developers code is probably not it.
1
0
5
"Last week the @FFmpeg account began taunting security researchers. Foolish thing to do, as it ignores the asymmetry of their attack surface vs ours.

So as an exercise I found a stack-based buffer overflow on software that he wrote." - @ortegaalfredo

https://threadreaderapp.com/thread/1991974275532636263.html

Normally I'm all for these stunts, but this one...
2
2
2
@Viss That memory probably also comes from the mushroom colony that is consuming you right now.
0
0
2
@Viss Wasn't that X-Files and a large underground mushroom colony?
2
0
1
@freddy But seriously, I just added a comment to my query and I swear it got slower...
0
0
1
@freddy Is that even a requirement these days?
1
0
0
on the back of the envelope, counting with an avg. yearly salary of $75k for a teacher in the US, the projected $4.8 trillion AI market by 2033 would equal ~7M years of teacher salary every year.

#weirdunits
0
0
1
@d_olex Yeah I get that. My point is (but I'm unsure about history here) that when Java or first browser JS engines were shipped inefficient solutions were probably necessary, and now we try to reduce that debt, while in case of your modern examples we probably have cheaper solutions that work better, but burning GPUs is sexier.
1
0
1
@d_olex Good question, but I'd argue that bytecode solves existing problems, while in case of LLM/blockchain I mostly don't see that. Also, isn't JIT specifically a thing to improve performance, meaning less resource consumption? A related observation is that many use-cases for LLMs can probably be solved much cheaper, today. E.g.: better IDE features; more QA for web search results; better education so people can write and understand an email.
1
0
0
#select goes brrrr....
1
0
8
repeated
Edited 8 days ago

EBury SSHD backdoor?? on 400,000 hosts?

Let's fuck around and find out. (Why +s on the .so file???)

Dissect, understand & ridicule. Join the group effort at https://thc.org/ops or SSH straight into the server and check ~/ebury:

ssh -o "SetEnv SECRET=lYQkdQHIuQyTJngVtIskqRLx" root@adm.segfault.net (password is 'segfault')

3
7
0
repeated

Calling for the help of the fediverse!
Help spread the word of our browser extension Consent-O-Matic that helps automate answering those ever-present cookie consent pop-ups.

It's developed by researchers at Aarhus University in Denmark and free to use for Chrome/Edge, Firefox and Safari including for iOS.

Also, it's open source, so if you have a bit of technical skill, you can help us improve the rule set for greater coverage.

https://consentomatic.au.dk

19
36
1
repeated

🚀 radare2-6.0.6 is out! (codename 'siesso’)

That's the first release after which comes with tons of awemazing bug fixes and all the new features presented during the conference!

🔗 https://github.com/radareorg/radare2/releases/tag/6.0.6

See details below 👇

0
3
0
repeated
@kagihq "I don’t think I need to list the large number of tasks where LLMs can save humans time" - I naively thought this would be the whole point of the post? It'd be also important to back up that "large number of tasks" with data (e.g. time to result with/without LLM).
0
0
0
repeated

BINGO TIME! With CVE-2025-58034, Fortinet secures the crown in my Insecurity Appliance Bingo. This is technically a "high" severity vuln, but since it's being actively exploited and has landed a spot on CISA KEV, I'm admitting it.

https://cku.gt/appbingo25

Reaching a bingo took longer than expected, with FortiNet and Ivanti sitting at 5/6 vulns since about July. But now, there is a well-deserved winner.

I'm now taking new vuln class and vendor suggestions for next year's edition.

3
12
0
@tmr232 So you didn't see the highlight either? Took me a while to realize that it's the _text color_ that changes, and once I knew that I started seeing it! But since I expected the background to change I basically went color blind!
1
0
0
every time I take a selfie I admire influencers a bit more - this shit ain't easy!
0
0
2
Show older