Posts
2929
Following
697
Followers
1538
"I'm interested in all kinds of astronomy."
I updated the structure of the #Ghidra documentation that I host so now you can access the latest of both version 11.x and 12.x:

https://scrapco.de/ghidra_docs/

I'm still looking for the docs of the new features in 12. If you think something is missing from the web that is available in the source lmk!
0
0
3
repeated

Frederik Braun � 🔜 #39C3

Edited 6 days ago

Do I know anyone working on freedesktop.org / mesa? A security contact would be ideal :)

Edit: Resolved

1
6
0
GitHub Actions Has a Package Manager, and It Might Be the Worst

https://nesbitt.io/2025/12/06/github-actions-package-manager.html
0
1
3
@mttaggart No worries, SpaceX can put your telescopes to space cheaply so you can avoid Starlink satellites!
0
0
1
@alphaville @pancake as I understand it's not "function" register but "special function" register. RISC-V CSRs are provided as specific example:

https://book.rvemu.app/hardware-components/03-csrs.html
0
0
1
repeated
@zcutlip I pulled my hair a lot because of that pile of shit until I found this article and while the tech remained the same, at least I started to understand the idea behind it:

"makes perfect sense when you are in the business of breaking stuff so people have to pay you for fixing it."

https://dzone.com/articles/why-you-should-avoid-jsf
0
0
1
@zcutlip That "security" is sometimes "job security": no one in their right mind would use JSF (that produces the exact behavior you describe) unless they can bill by the hour after they locked in the bank with their software built on a (brain)dead framework.
1
0
1
repeated

okay so like a month ago @trashpanda sent me one of those 'spycam finder' doodads that you see going for like 80-100 dollars online that supposedly 'find spy cameras and gps trackers'. I've always been curious if they actually work or whats inside. So I just tore the thing open and this is what I found:

7
4
0
"The benefit of having an actual memory space for special function registers is they can be seen, named, references created to them, data types applied at the location, as well as default values supplied for a given binary sample. We plan to do the same for other processors such as the PowerPC."

I hope this is the reason why my PPC-AS pull request is open for more than a year now :)
1
0
0
repeated

Frederik Braun � 🔜 #39C3

New blog post: Why the Sanitizer API is just `setHTML()` - https://frederikbraun.de/why-sethtml.html

1
6
0
@bontchev @adamshostack My favorite example: programmers are taught to use prepared statements, so at first it seems their app doesn't have any SQLi's. Until they add a feature where the user controls result set ordering: you can't use bound variables for field names, so there's a vuln 90% of the time (IME, with wildly different dev teams).
0
1
2
@pancake That's terrible and unfortunately far from unique. Sorry for your mom :(
0
0
1
repeated

Zuckerberg has blown 77 billion – enough money to revitalize entire countries – on an idea so overwhelmingly, obviously stupid that I have never once heard anyone, from the Thanksgiving avuncular table to the most wretched depths of social media, say they liked it or even tried it. He was so sure that it would revolutionize the world that he renamed his extremely famous company after it. And now he's on to the next thing that he's so very, very sure about.

The world needs direction from sober people who aim to improve the human condition, not the whims of a handful of billionaire princelings who absolutely, positively cannot be dissuaded from failing at unprecedented scale while chasing their own vainglory off the edge of a cliff.

19
38
0
repeated

Punchcards weren't only used for code. These Department of Defense punchcards from 1966 have a microfilm window used for technical drawings — in this case, a rotary telephone switch, and a font!

1
3
0
repeated

Portugal has modified its cybercrime law to establish a legal safe harbor for good-faith security research and to make hacking non-punishable under certain strict conditions.

https://www.bleepingcomputer.com/news/security/portugal-updates-cybercrime-law-to-exempt-security-researchers/

1
10
0
Fuck cancer (and bureaucrats) :(

https://bontchev.nlcv.bas.bg/bye.html

Get yourself checked!
1
2
4
repeated

I look at the impact of AI on future election campaigns. We're in for a wild run. Who deploys it first, wins. https://techletters.substack.com/p/techletters-insights-weaponising

1
1
0
@LukaszOlejnik they are already using it in Hungary (elections next April), I can collect some articles if interested. But I think you are overestimating the sophistication: we just see the dumbest made up lies, not any form of political argument.
0
0
1
Show older