Posts
4687
Following
742
Followers
1664
"I'm interested in all kinds of astronomy."
repeated

I've just discovered a nice Unix trick. Let's see if you know about it.
Watch the screenshot. How is this possible?

11% Docker with AppArmor
22% Shell running as UID0 with unshare
55% /etc/shadow, /root are not in the same namespace
11% Missing Unix capability for /etc/shadow and /root
1
1
0
repeated

Just dropping this here: P = NP if P = 0 or N = 1.

My agents are finalizing a Lean proof

3
2
0
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5

https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
0
0
0
[RSS] Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)

http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html
0
0
0
[RSS] Probabilistic analysis of MTE tagging schemes

https://dustri.org/b/probabilistic-analysis-of-mte-tagging-schemes.html
0
0
1
[RSS] From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities

https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/
0
0
0
[RSS] A Mere Mortal's Introduction to JIT Vulnerabilities in JavaScript Engines

https://trustfoundry.net/blog/jit-vulnerabilities-javascript-engines
0
0
2
repeated

Language Matters:

The words we use influence how people think. Shifting language shifts mindsets.

"Vulnerability" sounds like weather: unpredictable, nobody's fault. "Product defect" names something a manufacturer built and could have prevented. Keep it only where it's a term of art, like CVE.

7
9
0
repeated

RE: https://mastodon.social/@monkeydom/117382425456803989

yet more examples of the rollout of passkeys being user hostile in that it does not explain anything to users and does things that may have serious consequences without consent

3
5
0
I recently learned to distinguish rabbits from hares (from a shitpost ofc) and now I feel slightly offended because my emoji keyboard shows a rabbit but it clearly renders as a hare in the app. πŸ‡
0
1
3
repeated

Newsletter: Regulators race to reassure the crypto industry as the its flagship Clarity Act legislation collapses, SBF tries his luck with the Supreme Court, and crypto PACs unleash $30 million against Sherrod Brown.

https://www.citationneeded.news/issue-110/

2
4
0
repeated
2
8
0
repeated

Aaron Swartz was charged on July 14th, 2011 with wire fraud and computer fraud (under the Computer Fraud and Abuse Act). He potentially faced 30 years in jail and a fine of 1 million dollars or more. The theory was that he exceeded authorized access by automated scraping through 4.8 million JSTOR articles.

Contrast with...

AI crawlers crawl trillions of documents, often ignoring any ToS the prohibit automated scraping.

OpenAI downloaded pirated books from Library Genesis and created internal datasets that became the foundation for GPT-3's training.

Meta torrented 80+ TB of data from Anna's Archive for Llama 4. There are records of internal discussions at Meta that the data set was known to be pirated content.

Where is the federal prosecutor to throw charges at OpenAI and Meta? That's right. No charges.

1
9
0
"This 3-day training focuses on macOS Vulnerability Research (VR) for beginner to intermediate students. While intermediate topics will be discussed, the course focuses on bringing security researchers up to speed with macOS’s unique protections and vulnerabilities"

Great content from my friends, now in Budapest:

https://macosvuln.training
0
1
1
repeated
repeated
repeated

New series: implementation security for autonomous defense systems.

Their intelligence runs on embedded hardware in the field, where an adversary can recover a device and study it with no time limit.

What happens if someone can study it without constraints?
πŸ”—Part 1: https://www.eshard.com/blog/autonomous-systems-are-changing-the-defence-threat-model

0
1
0
repeated

Hashing several values together is easy to get wrong, and the mistakes can lead to forgeries. TupleHash only works with Keccak. Outside SHA-3, people roll their own multihashing, often insecurely.

We built SequenceHash to fix that for any hash function, with length-suffix encoding and protection against length-extension attack. https://blog.trailofbits.com/2026/10/02/sequencehash-multihashing-for-the-rest-of-us/

0
2
0
repeated

In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available.

These are defects (like XSS, SQLi) that keep appearing year after year. Their recurrence is not a technical mystery; it is a business and incentive failure.

The presence of an unforgivable vulnerability signals that customer safety was not treated as a non-negotiable requirement.

3
1
0
repeated

Ryan Castellucci (they/them) πŸŽƒ nonbinary_flag

Our systems detected a minor irregularity in your account, please shitpost to restore full access.

9
9
0
Show older