Posts
4365
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
@0x57e11a Is this not a reasonable place to park?
0
0
1
repeated

A mysterious hacker has stolen more than $70 million worth of Bitcoin from Coldcard hardware wallets: https://bitcoinmagazine.com/news/coldcard-wallet-exposed-after-bitcoin-hack

The attackers exploited a vulnerability in the wallet's firmware that produced weak and easy to guess private keys: https://blog.coinkite.com/entropy-technical-backgrounder/

0
2
0
repeated

ใ‚ทใƒฃใƒใ‚ณ๐ŸŒต

ใ‚‰ใใŒใ

4
6
0
repeated

Insane and inhumane: "YC founder asks desperate job seekers to tattoo themselves for an interview"

https://sfstandard.com/2026/07/30/lemonlime-tattoo-job-interview/

2
6
0
repeated

After a short induced hiatus, it's back...

First up this weekend is interesting talks from :

Threats:

* https://media.ccc.de/v/emf2026-215-1-north-korean-agent-looking-for-a-job - job hunting, .kp style

Exploitation:

* https://media.ccc.de/v/emf2026-93-1-they-forgot-what-happened-last-time - @Rairii's pokes the Redmond beast some more
* https://media.ccc.de/v/emf2026-206-1-breaking-in-to-buildings-with-boobs - a guide to social engineering the physical world

Hard hacks:

* https://media.ccc.de/v/emf2026-57-1-obd-ii-obviously-broken-design-too - getting into ODB-II
* https://savvycan.com/ - CANbus packet parser
* https://media.ccc.de/v/emf2026-56-1-lock-picking-robot - robotic approaches to locks
* https://safetyfic.com/how-to-unlock-tsa007-lock-forgot-combination/ - how to change the code on a TSA combination lock?
* https://www.amazon.co.uk/tsa-key-007-master-luggage/ - want a TSA master key?
* https://lpubelts.com/ - how hard to pick is my lock?
* https://media.ccc.de/v/emf2026-47-1-building-a-tiny-paging-network - build your own pager network with @sammachin

Crypto:

* https://media.ccc.de/v/emf2026-59-1-how-not-to-make-a-random-number-generator - return 42;
* https://en.wikipedia.org/wiki/Euclidean_algorithm - finding the common factor
* https://en.wikipedia.org/wiki/Euler%27s_factorization_method - more on common factors

Data:

* https://media.ccc.de/v/emf2026-88-1-building-a-mostly-local-mildly-judgemental-home-assistant - Mark J Cox takes us on a journey to build your own home assistant ๐Ÿค–

Nerd:

* https://media.ccc.de/v/emf2026-124-1-infrastructure-review - a review of the EMF Camp 2026 infrastructure
* https://media.ccc.de/v/emf2026-230-1-an-sres-guide-to-camping-in-extreme-conditions - vanlife reliability engineering from @donna_156
* https://phones.emfcamp.org/ - the EMF phone book
* https://media.ccc.de/v/emf2026-46-1-the-orphan-source-incident - more about the 2024 orphan source incident
* https://media.ccc.de/v/emf2026-277-1-reverse-engineering-007-nightfire - updating Nightfire via reverse engineering
* https://media.ccc.de/v/emf2026-100-1-automated-game-hacking - parsing and compiling game logic

,

0
3
0
repeated

Genuinely having a great time reading @tara 's exploration of purpose-built business machines (in the vein of the IBM 5280): https://www.tara.sh/posts/2026/2026-07-24_cobolito400_essay/

Honestly her site is one of my favorite little blogs. There's a fully essay behind the post!

As an industry, I know we're not going back, but it's neat reflecting on how different engineers over the decades have thought about _data_ and data portability as a first-class citizen.

1
3
0
@floyd I did! Although apparently I'm much less anally-fixated than the author (but I do love Breakfast of Champoins) :D
0
0
1
[RSS] Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape

http://www.darknavy.org/blog/patch_in_exploit_out_how_deepsec_reconstructed_the_pwn2own_microsoft_edge_sandbox_escape/
0
1
1
repeated

Coldcard devices used predictable RNGs, and apparently this has consequences. ๐Ÿ˜‚

0
2
0
repeated

I'm pleased to announce a new release of the bindings for @HexRaysSA IDA Pro! This release adds compatibility with latest SDK (v9.4), and a couple of bug fixes. Thanks to @raptor and @yegor for their contributions.
https://github.com/idalib-rs/idalib.git

0
4
0
repeated

Happy Sys Admin Appreciation Day to all to who observe it.

0
3
0
repeated

This made us think

0
5
0
repeated

IFIN - The Independent Federated Intelligence Network

Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples.

https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698

1
5
0
repeated

anyone experienced with high-speed (~150m) cabling and possibly also somewhere half-way injecting solar-based PoE? is this a thing?

4
2
0
[RSS] LLMs won't break symmetric crypto

https://www.bfswa.blog/p/llms-wont-break-symmetric-crypto
0
2
0
Anthropic choosing an asshole as the logo for Claude is the most honest marketing move in recent history.
2
0
4
repeated

Osma A ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡บ๐Ÿ‡ฆ

Somehow, we have ended up in a universe where companies brag about deploying multibillion dollar software systems with an objective to break decades old IT security legislation, and nobody holds their executives to account.
https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/

0
2
0
repeated

: three critical in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch!
๐Ÿ‘‡
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

0
3
0
repeated

For the nerds in the back:

Not understanding how your program works is not an excuse for it doing the bad shit it was literally programmed to do.

6
9
0
@codinghorror CEOs often work for minimal wage for tax reasons around here. But even that case is much better than simply asking your billionaire friends to push literal peanuts your way along with a job contract 2 years before you run for office.
2
0
2
Show older