Posts
2567
Following
630
Followers
1412
"I'm interested in all kinds of astronomy."
repeated

https://www.andrea-allievi.com/blog/a-minikvm-to-rule-all-machines-remotely/ Finally after hours and hours of assembling a YouTube video... MiniKvm 1.0 is there :-) Have fun and let me know if you find it useful...

0
3
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

When I was a student, I read a lot about how Silicon Valley companies were looking for 'problem solvers' rather than people with experience with specific technologies. At the time, this struck me as odd because problem solvers are not rare. Most people can solve a problem if you explain it to them. Indeed, the lesson from most of the formal verification classes was that a sufficiently detailed description of a problem is indistinguishable from a solution to that problem.

The real rare skill is working out which problems are the right ones to solve. Without that, you keep falling down dead-end rabbit holes and chasing local optima.

Everything I've seen in the last decade or so indicates what happens when problem solvers end up in senior leadership positions. You get companies that are great at solving completely the wrong problems.

0
7
0
repeated

This is outrageous. Where are the armed men who come in to take the spammers away? Where are they? This kind of behavior is never tolerated in Cascadia. You phish like that they put you in jail. Right away. No trial, no nothing. Cloudflare sites, we have a special jail for Cloudflare sites. You use QR codes: right to jail. You are domain squatting: right to jail, right away. Too many URL parameters: jail. Too few: jail. You are asking for gift cards, Monero, Bitcoin: you right to jail. You text a journalist? Believe it or not, jail. You receive a text, also jail. Send, receive. You use a hyphen in your domain name, believe it or not, jail, right away. We have the best users in the world because of jail.

3
3
0
repeated

smbfs is a fuck

2
2
0
repeated
Edited 1 month ago

Please remember that what you see on social media is what people choose to present, not an accurate representation of their life. Few people post about the horror.

Don't put off seeing friends because "they're having fun" or "they're busy" and "you'll see them later". You do not know that any of these things are true.

0
6
0
repeated
repeated
repeated

I probably sound like a broken record at this point, but we're not sold yet on the world-ending nature of Next.js CVE-2025-29927.

The fact that the bug isn't known to have been successfully exploited in the wild despite the huge amount of media and industry attention it’s received sure feels like a reasonable early indicator that it's unlikely to be broadly exploitable (classic framework vuln), and may not have any easily identifiable remote attack vectors at all.

https://www.rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/

1
2
1
repeated
Edited 1 month ago
0
1
1
repeated

I published a correction to my slides/blogposts regarding rename(). I have incorrectly stated that rename("./a", "./b") was racy. It is not.
For most situations this is not a huge deal, but I still feel bad that I misled you all, so beers are on me.

https://gergelykalman.com/corrections-regarding-rename.html

1
3
0
repeated

Micropatches Released for SCF File NTLM Hash Disclosure Vulnerability (No CVE) https://blog.0patch.com/2025/03/micropatches-released-for-scf-file-ntlm.html

1
3
0
repeated

Jeff Hicks 🐶🎼🍷🖥️

If you are at the Microsoft MVP Summit this week, and in the Windows Server space, please add your voice for the release of eval ISOs of Windows Server on ARM. We need these for *local* testing, training, and development.

0
4
1
repeated

Trigon: developing a deterministic kernel exploit for iOS by @alfiecg_dev

https://alfiecg.uk/2025/03/01/Trigon.html

0
1
0
repeated

PRE-RELEASE: I wrote a Linux Binary Runtime Crypter - in BASH 😅. Would love you fine people to TEST it _BEFORE_ release: https://github.com/hackerschoice/bincrypter

3
7
0
repeated

The first round of the CFP for Recon Montreal will end this Friday March 28, during that phase we preselect a few talk. The CFP end on April 25. https://recon.cx/2025/cfp.html

0
6
0
"you can do it with a couple of lines of idapython<END OF MESSAGE>" - /u/annoyingasshole

I'm not even making this up :D

https://www.reddit.com/r/ReverseEngineering/comments/24ar8w/ida_importing_map/
0
1
2
repeated

“The real problem with sharing Top Secret data over Signal is not the security of the app, it’s the security of the phone. And mobile phones are not secure against state level threat actor” | @thegrugq is correct, BUT…
https://alecmuffett.com/article/113007

0
1
0
repeated

Frida 16.7.0 is out w/ brand new APIs for observing the lifecycles of threads and modules, a profiler, multiple samplers for measuring cycles/time/etc., MemoryAccessMonitor providing access to thread ID and registers, and more 🎉 https://frida.re/news/2025/03/13/frida-16-7-0-released/

0
2
0
repeated

A code generation tool that gets you 80-90% of the way there is like a boat that gets you 80-90% of the way.

You'll need to be a strong swimmer.

3
6
0
repeated

The Practical Limitations of End-to-End Encryption

Internet discussions about end-to-end encryption are plagued by misunderstandings, misinformation, and some people totally missing the point. Of course, people being wrong on the Internet isn't exactly news. XKCD: Duty Calls "What do you want me to do? LEAVE? Then they'll keep being wrong!" Yesterday, a story in The Atlantic alleged that the Trump Administration accidentally added their editor, Jeffrey Goldberg, to a…

http://soatok.blog/2025/03/25/the-practical-limitations-of-end-to-end-encryption/

7
6
0
Show older