Posts
2570
Following
630
Followers
1414
"I'm interested in all kinds of astronomy."
repeated

When Signal was designed, our threat model was protecting the communications of civil society, journalists, just regular citizens ...

The threat model of military operations & sharing your hate of Europeans was not what Signal was designed for. Ephemeral messages and cryptographic deniability are not fit for communications that require accountability.
But I appreciate their effort to make government more efficient by adding journalists to the chat instead of requiring to go through FOIA.

11
47
0
"A shell script for Linux that obfuscates + encrypts + packs any binary."

https://github.com/hackerschoice/bincrypter
0
2
5
repeated

It finally happened - I got phished. Impact is limited to the Mailchimp mailing list for my blog, brief blog post with details here and more to come later: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/

14
11
0
repeated

When you get invited to the NatSec group chat....

3
21
1
repeated

Today, Wiz (Woogle?) released an advisory detailing an attack chain they’ve dubbed IngressNightmare, which, if left exposed and unpatched, can be exploited to achieve remote code execution by unauthenticated attackers. The advisory, covering five separate vulnerabilities, was published after a brief embargo period, once the Kubernetes folks got their patches together.

You can find a brief writeup and search queries for runZero at: https://www.runzero.com/blog/ingress-nightmare/

2
4
0
repeated

this is a text block, can you guess which spot that goes in? thats right, the div hole. and how about this spacer? that one, it goes in there too. up next, we got this picture, can you guess where that goes? thats right, it goes in the div hole. and up next, an unordered list. hmm. i think that goes in, the div hole. now i also got this ordered list right here, do you see a tag that would fit the ordered list? thats right! its the div hole. ‘kay. up next, its the underline, we all know what tag that goes into, right? thats right,. the div hole. and up next , we have the audio ., you guessed it, it goes in the div hole.

-carrie

0
5
1
ICYMI my RSS->Bsky cross-poster now handles images:

https://github.com/v-p-b/rss2bsky.py
0
0
1
repeated

Open source maintainers, did you receive your first vulnerability report? Don't panic! Handling vulnerability reports doesn’t have to be stressful. Read on to find out how you can tackle security issues efficiently and confidently with the right tools and approach. https://github.blog/security/vulnerability-research/a-maintainers-guide-to-vulnerability-disclosure-github-tools-to-make-it-simple/

0
3
0
repeated

Project Zero Bot

New Project Zero issue:

Linux >=4.12: USB CDC-ACM: missing size check in acm_ctrl_irq() leads to OOB write

https://project-zero.issues.chromium.org/issues/395107243

CVE-2025-21704
0
2
4
#test
Show content
5 images, let's see how bsky (and my x-poster) handles this...
0
0
0
repeated

Here's the paywall-free version of today's insane must-read: The Atlantic's Jeffrey Goldberg was added to a Signal chat including SECDEF, VPOTUS, and others that discussed the Houthi strikes. In addition to being illegal, it's just dumb. A foreign adversary's dream come true

https://archive.is/JEYep

1
3
0
repeated
#test
Show content
0
3
7
#test
Show content
2
2
12
"Safari 1day RCE Exploit, might be patched in iOS 16.5.1/macOS 13.4.1
Confirmed exploit works on macOS 13.3.1, iOS 15.8.2."

https://github.com/wh1te4ever/WebKit-Bug-256172
1
0
0
repeated

current status: scrawling "FUN JIT COMPILER PROBLEM" in sharpie on a big cardboard box, then putting it on my front lawn and seeing who jumps into it

https://www.mattkeeter.com/projects/prospero/

0
5
0
repeated
repeated

If you are trying to delete your 23andMe data and get an obnoxious reply asking for ID, tell them no, that's what your password is for, and they will do it. And if they then send you an obnoxious reply saying they will delete everything except the stuff they are required to keep by law, check out this article by actual lawyer @AugustB

https://bourniquelaw.com/2024/10/09/data-23-and-me/

0
19
0
[RSS] The case of the critical section that let multiple threads enter a block of code

https://devblogs.microsoft.com/oldnewthing/20250321-00/?p=110984
0
1
4
Show older