Posts
3712
Following
724
Followers
1597
"I'm interested in all kinds of astronomy."
repeated
Edited 2 days ago

Sometimes I wonder… I come from two Milanese industrialist families who worked hard to keep their factories going (and failed in one case due to, literally, natural causes aka a dam disaster) and, reading the responses to my LinkedIn post about salary dumping in Ticino, I cannot reconcile it with anything I have ever heard from my parents or grandparents.

This bizarre concept that it is the workers and the international treaties which somehow "force" the companies to use cheap labour is spectacular.

Of course my families tried to run a profit but, in one case, literally financed one of the most skilled workers to set up their own shop and become a supplier with a guaranteed 5-yr 100% purchase cover before they could work alone (their family is still in business!), the other spent literally almost all their fortune to provide for the worker families hit by the disaster.

I should add that my grandfather's idea of "owner luxury" was going on holiday in Rimini for two weeks, having a large apartment in a new development towards Milan Linate airport, and driving an Alfa Romeo Alfetta, not "two yachts, three Ferrari, five villas." That might explain things...

Having said this I was brought up in a left-wing family and the only comment when I said I was an Ⓐ was "perhaps too much?" which is fair :)

1
2
0
There is currently an insane spy thriller running in #Hungary ICYMI:

https://www.direkt36.hu/en/titkosszolgalati-nyomasra-tortent-hazkutatas-a-tiszat-segito-informatikusoknal-aztan-kibukott-egy-gyanus-muvelet-a-part-ellen/

A 90min interview with the whistleblower was released too that reveals even more pieces of the puzzle. The whole thing screams for a movie (and long prison sentences).
4
18
9
repeated

okay I can finally show off these things- Sun SPOTs, weird little java on metal microcontrollers from 2005/2006!

http://nug.only9fans.com/penny/SunSPOTs/

4
4
0
repeated
repeated

Project Zero Bot

New Project Zero issue:

vpu driver open and close instance ioctls race causing UAF

https://project-zero.issues.chromium.org/issues/463672550

CVE-2026-0112
0
3
2
Who would win: the Balrog or Yoda?
18% Balrog
27% Yoda
54% the nerds
1
0
0
repeated
@mttaggart Plus the store-now-decrypt-later threat model is not really affected by the time of the first practical quantum attack (you just store more data). I think the original announcement is more about the good rate of pqc adoption rather than q-computing breakthroughs...
0
0
1
repeated

@james_inthe_box @campuscodi VPNs have that problem where they don't solve the problem that the people selling VPNs say they solve

1
2
0
@freddy Not that I know of unfortunately. Your post reminded me of this one and took me a while to even find the video I watched a couple yrs back... It's concise, works by listening only and the seek should already be at the end of the ad segment :)
0
0
1
@timb_machine I'm even more concerned that we forget about basic maintainability too...
0
0
1
repeated
Edited 4 days ago

Coding with LLMs and agents is a generational opportunity to throw the last decade's hard won lessons on secure coding and appsec out of the window. Definitely something that trust and safety teams, threat actors and possibly even your parents are seizing on with glee when they bypass all of your policies and procedures around installing new software, data governance, validated designs, code reviews, principles of least privilege and regular security assessments. Best of luck.

1
2
0
repeated

Alisa Esage Шевченко

I popped a Pwn2Own $40k target with a directory traversal in hypervisor

Plenty of buffer overflows there, too
https://bird.makeup/users/abantdogal/statuses/2036132328599089230

0
1
0
Your periodic reminder that security tools are attack surface too.

#trivy
0
4
9
To celebrate the trivy/litellm/??? supply chain compromise, here's some good old #ska #music:

https://www.youtube.com/watch?v=42QloZAhM44
0
1
0
repeated

i love that we went from "zero trust" as a fundamental buzzword to "trust autonomous nondeterministic agents everywhere in your stack"

11
30
0
Show older