Posts
3275
Following
709
Followers
1570
"I'm interested in all kinds of astronomy."
[RSS] [reddit] Do any security researchers use Anki or spaced repetition in their workflow?

https://old.reddit.com/r/ExploitDev/comments/1qjjn3q/do_any_security_researchers_use_anki_or_spaced/
0
0
2
[RSS] Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) - watchTowr Labs

https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/
0
1
0
getting things merged into Ghidra

RE: https://chaos.social/@weirdunits/115937461017927780
0
0
1
repeated

TrendAI Zero Day Initiative

Whew! They had to swap out the master control board during the attempt, but Hank Chen of InnoEdge Labs successfully demoed their exploit of the Alpitronic HYC50 in Lab Mode. Using screwdrivers during a attempt is always crazy to see. He's off to disclose what occurred.

0
2
0
@mttaggart @gdupont This whole thing reminds of kids playing war games on the playground. they are playing "revolution" now. they heard revolutions need constitutions, and they happen to have these text writing toys and potato stamps so they worked *really* hard to produce a "constitution" that they can show their shareho^W parents and the enemy kids over at the sandbox.
0
0
1
repeated
@lazyb0y ...until you try to touch it :)
0
0
3
repeated

Remember "don't print this email" in signatures that was a bit cringe? It doesn't feel that cringe anymore in retrospect. I'm doing an experiment now with this new email signature :D Anyone doing something similar? Could it catch on?

11
32
2
repeated

Today's threads (a thread)

Inside: Google's AI pricing plan; and more!

Archived at: https://pluralistic.net/2026/01/21/cod-marxism/

1/

2
2
0
repeated

After auditing the @mullvadnet client applications in 2024, we have recently audited Mullvad VPN's API.
The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.
Five issues were identified, of which only one had a very limited impact on users of the service.

The technical details may be found in our report. https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/

1
6
0
repeated

Last December I solved Synacktiv's 2025 Winter Challenge: Quinindrome https://www.synacktiv.com/en/publications/2025-winter-challenge-quinindrome . Here is a 81-byte Linux program which is both a quine (it prints itself when executed) and a palindrome (it is symmetrical)! To learn how I achieved it: https://github.com/fishilico/synacktiv-winter-chall-2025-quinindrome/blob/main/writeup.md

0
6
0
[RSS] Windows Internals: Check Your Privilege - The Curious Case of ETW's SecurityTrace Flag

https://connormcgarr.github.io/securitytrace-etw-ppl/
0
1
0
I feel I have this instinct to feed programs data that they won't be able to handle.

Unfortunately this is mostly true for tools I'd like to use, not targets I review.
0
3
7
Edited 8 days ago
Humble request for vibe-coders: report your runtime errors!

LLM tends to insert Pokémon exception handlers everywhere, making problems (of which vide-code has a *lot*) hard to even notice.

Slightly related illustration:
3
74
104
@troed I'm no lawyer, but my understanding is if the infra is legally owned by an EU legal entity they can (at least in theory) say FU to the mothership
(they can threaten to fire the leadership ofc, but can't send them to jail etc.). This can also be used by AWS as an argument not to screw their EU business ("we would comply, it's just those picky EU judges!").

But yeah, we've seen how complicit people can become when they get nasty looks (see DOGE)...
1
0
0
I positively surprised that AWS apparently built a separate IAM for their European Sovereign Cloud:

https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/

I can't tell if this whole thing will be good enough, but some key issues seem to be addressed here.
1
0
1
Show older