Posts
3986
Following
731
Followers
1608
"I'm interested in all kinds of astronomy."
@troed If you could pour the 100 best sw engineers in the world to a similar case that wouldn't be effective either (the current management tier is likely insufficient to handle the numbers).

The initiative is good though, it's just easy to have the wrong expectations about short-term results.
0
0
0
repeated

RE: https://mastodon.social/@marver/116617742819891906

If you don't recognize "Starlette":

"Starlette is the foundation of the FastAPI Python framework."

... and everything uses FastAPI.

1
5
0
@troed Keep in mind that - as described in The Mythical Man-Month - suddenly throwing human resources to a project doesn't necessarily help to reach its milestones.
1
0
0
repeated

Patch Starlette now! If you're run it via uvicorn or other common ASGI servers then a host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:

https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/

0
6
0
[RSS] CVE-2026-9082 | Drupal SQL Injection Vulnerability

https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9082/
0
0
0
[RSS] CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox

https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

This is another writeup of a Windows sandbox escape that multi-collided during P2O
0
0
0
[RSS] Advisory X41-2026-002: Request Host Header not Validated in Starlette

https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/

This can lead to auth bypass!
0
1
0
[RSS] Striga: Lifting x86 to LLVM IR with Python

https://secret.club/2026/05/21/striga.html

New from secret club!
0
0
0
@schrotthaufen Kids these days won't know how it is to move your friends 3rd floor apartment without an elevator, half-drunk on a narrow staircase. Sad!
1
0
0
@schrotthaufen that must be a beast of a washing machine :D
1
0
0
@jonny @danluu These are unfathomably large numbers so to get a grip I looked up Shell's yearly profits (x*10^10 USD where 0<x<4), and with a wild estimate it'd take ~50 years for them to pay off this kind of money (while not investing in anything else)
0
2
5
repeated

@danluu part of the argument is that not just that it might not be profitable now, but that the amount of profitable that it would need to be to justify the amount of capital expenditure that has already been made and is promised is numerically impossible. JPMorgan estimated 1.2 trillion in AI debt back in december 2025, goldman sachs estimates another 500 billion in 2026. Where is the evidence that inference is profitable enough to pay off 1.7 trillion? If it was really profitable, all the publicly traded AI companies would be screaming this at the top of their quarterly reports.

2
2
1
Edited 3 days ago
A bunch of local companies had an incident when a datacenter fire triggered an extinguisher without proper nozzles installed and the shock wave of the gas killed a bunch of HDDs at once.

Now I wonder if I should move my speakers further away from my desktop machine...

https://soundcloud.com/djfernandamartins/tough-waves-36-rudosa
1
0
1
@sassdawe It's just a guess, but Yubico seems to have something similar to what I have in mind: https://www.yubico.com/works-with-yubikey/catalog/secure-disk-for-bitlocker/
1
0
0
@sassdawe Can't you use an external hw token that you could just touch when needed?
1
0
0
Edited 3 days ago
I just noticed a maybe lesser emphasized parental instinct: letting children do stuff very inefficiently.

Helping in the kitchen, driving a screw, planting a flower.

Because that's how we learn things and improve.
5
19
68
Show older