Posts
3540
Following
721
Followers
1584
"I'm interested in all kinds of astronomy."
Tired me: shit my code doesn't handle this special case, how could I be so stupid?

Me after sleep: The code actually handles the special case, I just commented out the relevant part for some reason...

Also #ProTip: Always `git status` after getting back to your after some time
0
0
0
repeated

@jerry @zackwhittaker Pulse Secure's problems started way before Ivanti. I was at NetScreen when we acquired Neoteris in 2003 - back then, the SSL VPN product was *fantastic*. The Juniper acquisition was the beginning of the decline - Pradeep didn't give a shit about anything that didn't run JunOS, so ScreenOS and Secure Access were among the many red-headed stepchildren that came into the product portfolio by acquisition and then were completely neglected.
When we found out the (rebranded) Pulse Secure line was being sold, I was initially excited at the chance to be something other than a wart - but Siris was chasing that 10x return and when they couldn't get it by generating more revenue, they started cutting headcount. Many of the developers, QA, and support engineers who understood the products were let go long before the Ivanti acquisition... which compounded the problem of an aging codebase and increasingly complicated set of bolt-ons as Siris chased the latest buzzwords.
This whole China debacle was *entirely* predictable and *entirely* avoidable. The incentives in the security industry are just fucked. (@haroonmeer absolutely nailed this back in 2019, btw: https://m.youtube.com/watch?v=GHuQC1qLnJ4 )

1
8
0
repeated

If I use a LLM on a tiny bit of a 0day exploit, is that an AI enabled cyber weapon?

0
1
0
repeated

@cR0w "Infosec isn't a sprint, it's a marathon!"

No, infosec is a hamster wheel with a giant motor attached to it. And if you stop running, the wheel keeps turning and you die tumbling.

2
6
0
[RSS] Total Recall - Retracing Your Steps Back to NT AUTHORITY @MDSecLabs

https://www.mdsec.co.uk/2026/02/total-recall-retracing-your-steps-back-to-nt-authoritysystem/
0
3
4
repeated
Edited 11 days ago

New challenge. I did repair this today at work.

Please hide your deductions and guesses behind a CW to not spoil it for others. Googling is fair game.

Please don't just write a single word as answer, instead describe your observations and deductions so we all can learn about electronics.

If you are familiar with this kind of device, try to figure out the specific make and model instead of just saying something like 'Audio amplifier'.
Solution will be posted on Monday.

3
1
0
repeated

This should be obvious for everyone by now, but if you're not from US you must assume that all your use of US AI services (#ChatGPT, , etc) is fed directly to US intelligence services.

"We may share your Personal Data, including information about your interaction with our Services, with government authorities ... in compliance with the law (i)" (OpenAI)

"We may disclose personal data to governmental regulatory authorities as required by law" (Claude)

"We will share personal information outside of Google ... to: Respond to any applicable law, regulation, legal process, or enforceable governmental request" (Gemini)

The amount of valuable information fed to the systems voluntarily is staggering. It's not a matter of "if" it is happening, but "of course it is". It would be outright negligent if they werenโ€™t capturing and disseminating it all.

https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act#Without_a_court_order

1
10
0
repeated

"Never have, never will." Promise, shmomise.

This is some bullshit, Mozilla.

https://github.com/mozilla/bedrock/commit/d459addab846d8144b61939b7f4310eb80c5470e#diff-a24e74e4595fa85440a2f4e7e5dcfe68aba6e1e593aef05a2d35581a91423847

And the explanation is bullshit, too, and sounds rather annoyed at having to explain to us silly users that *of course* you have to "share some data with our partners".

https://blog.mozilla.org/en/firefox/update-on-terms-of-use/

0
3
0
repeated

A very good use of Gorton.

6
6
1
repeated

*long drag on cigarette* Kid, this is Mastodon. We're all the algorithm here. You. Me. Everybody. Now get out there and boost somebody's bullshit.

3
14
0
@tmr232

"- Didn't you have ads in the 20th century?

- Well, sure, but not in our commit messages. Only on TV and radio. And in magazines and movies and at ball games, on buses and milk cartons and T-shirts and bananas and written on the sky. But not in commit messages. No, sir-ee!"
0
0
1
repeated
repeated

Team member @sigabrt was able to bypass Apache FOP Postscript escaping to reach GhostScript engine.

https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html

0
2
0
repeated

In case anyone was still under the assumption that US Big Tech and the Trump regime aren't one and the same:

The US has ordered its diplomats to lobby against EU attempts to regulate US tech companies ๐Ÿšจ

We need ethical open alternatives.

https://www.reuters.com/sustainability/boards-policy-regulation/us-orders-diplomats-fight-data-sovereignty-initiatives-2026-02-25/

2
7
0
[RSS] From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)

https://boschko.ca/unitree-go2-rce/
0
2
1
repeated

Michael Kohl ๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡น๐Ÿ‡ญ

Edited 12 days ago

A tale in 3 pictures. In which our hero wonders if he can and doesn't stop to ask if he should.

4
25
1
[RSS] Building a Custom Architecture and Platform: Part 2

https://binary.ninja/2026/02/26/quark-platform-part-2.html

#BinaryNinja
0
0
1
Show older