Sébastien Duquette
@sduquette.bsky.social
📤 33
📥 65
📝 39
software & security
https://ekse.github.io/blog/
LLM generated text is so boring, everything looks the same. I'm at the point where if I see a blog is LLM-generated I close the tab and move on.
1 day ago
1
1
0
reposted by
Sébastien Duquette
Émilio Gonzalez
14 days ago
Cette année au nsec CTF, nous avons demandé aux gens d’autodéclarer les flags trouvés par un agent IA. Nous avons aussi demandé à la communauté leur opinion sur le rôle+impact des agents IA dans les CTFs Plus de 40% des participants ont répondu au sondage! J’ai écrit un blogpost qui analyse le tout
loading . . .
Retour sur nsec 2026: le pouls de la communauté sur l’agentic CTF
Si vous avez assisté à la cérémonie de fermeture, passez directement à la section Sondage de rétroaction, la première section répète les…
https://res260.medium.com/northsec-et-le-pouls-de-la-communaut%C3%A9-sur-lagentic-ctf-d1e55d9308cb
1
3
3
This is such a bad look for you
@vscode.dev
. I'm usually all for giving the benefit of the doubt but you're making it very difficult with this one
news.ycombinator.com/item?id=4798...
add a skeleton here at some point
about 1 month ago
0
1
0
This is hilarious. With AI generated music polluting Tidal feeds of existing artists I could see myself join this movement.
fuckoffaimusic.com
loading . . .
fuckoffaimusic
fuck off ai music
https://fuckoffaimusic.com/
about 1 month ago
0
0
0
JetBrains Rider has a very clever way to handle cases were there are multiple function calls on the same line when debugging, you use the arrows to select which one you want to step into. It's the first time I see this and now I wish all debuggers supported it.
loading . . .
about 1 month ago
1
4
1
Bitwarden cli compromised in supply chain attack
socket.dev/blog/bitward...
loading . . .
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
https://socket.dev/blog/bitwarden-cli-compromised
about 1 month ago
0
0
0
www.theguardian.com/world/2026/a...
loading . . .
Israeli soldiers using sexual assault to force Palestinians out of West Bank, report says
Experts say attacks, also carried out by settlers, are leading girls to quit school and enter early marriages
https://www.theguardian.com/world/2026/apr/21/israeli-soldiers-using-sexual-assault-to-force-palestinians-out-of-west-bank-report-says?CMP=Share_AndroidApp_Other
about 2 months ago
0
0
0
reposted by
Sébastien Duquette
Socket
2 months ago
🚨 Active supply chain attack on
[email protected]
. The latest version pulls in
[email protected]
-- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile.
socket.dev/blog/axios-n...
loading . . .
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency,
[email protected]
, published minutes earlier and absent from the project’s GitHu...
https://socket.dev/blog/axios-npm-package-compromised
3
99
83
reposted by
Sébastien Duquette
James
3 months ago
new post on my personal blog. i think these three areas often go unexplained, so hopefully this explains why some of these packages exist. these are fine to exist but the majority of developers shouldn't have to pay the cost for them.
loading . . .
The Three Pillars of JavaScript Bloat
A brief look at the three main causes of bloat in our JavaScript dependency trees, and how we can start to address them.
https://43081j.com/2026/03/three-pillars-of-javascript-bloat
13
151
47
reposted by
Sébastien Duquette
Matthew Sanabria
3 months ago
A tale in two images.
1
23
3
reposted by
Sébastien Duquette
Senator Bernie Sanders
3 months ago
The U.S. Senate must be clear: no war with Iran.
1295
22477
6712
reposted by
Sébastien Duquette
Filippo Valsorda
4 months ago
Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulns. That hurts security! Just turn it off and set up a pair of scheduled GitHub Actions, one running govulncheck and the other running CI with the latest version of your deps. Less work, less risk, better results!
loading . . .
Turn Dependabot Off
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
https://words.filippo.io/dependabot/
4
91
21
Yet another episode of infected npm packages
www.aikido.dev/blog/shai-hu...
loading . . .
Shai Hulud 2.0 Strikes Again: Malware Supply-Chain Attack Hits Zapier & ENS Domains
The threat actor behind “Shai Hulud 2.0” launched a new malware campaign compromising the supply chain of Zapier, ENS Domains and more — exposing secrets, injecting malicious code, and enabling widesp...
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
6 months ago
0
0
0
Trying Ubuntu in Hyper-V once again and the experience is not great. The clipboard randomly stops working, I have to close and reopen the session.
7 months ago
0
0
0
reposted by
Sébastien Duquette
Marc-André Moreau
7 months ago
So it turns out GitHub Copilot in VSCode is much better at doing code search on a very large code base because it could benefit from automatic remote indexing from GitHub, where Claude Code is basically just grepping files locally with no auto indexing:
code.visualstudio.com/docs/copilot...
add a skeleton here at some point
1
0
1
reposted by
Sébastien Duquette
Marc-André Moreau
10 months ago
New blog post! 📰 I tried "vibe coding" in VSCode using GitHub Copilot (Claude Sonnet) to build an MCP proxy tool in Rust — I didn't touch a line of code, just pure agent mode magic 🧙♂️ 🚀👇
awakecoding.com/posts/vibe-c...
loading . . .
Vibe coding a Rust MCP proxy in VSCode with GitHub Copilot
A hands-off experiment building a Rust-based Model Context Protocol (MCP) proxy tool using only GitHub Copilot agent mode. Covers setup, multi-transport support, and lessons learned from letting Copil...
https://awakecoding.com/posts/vibe-coding-a-rust-mcp-proxy-in-vscode-with-github-copilot/
0
1
2
reposted by
Sébastien Duquette
Thorsten Butz
11 months ago
Check out the
#PSCONFEU
2025 playlist. We finished the summit yesterday, we published the 1st video on the finaly day (aka yesterday) and 2nd one TODAY. Guess what will be next! Better subscribe to the channel. Playlist for 2025 below.
youtube.com/playlist?lis...
loading . . .
PSCONFEU 2025 - YouTube
https://youtube.com/playlist?list=PLDCEho7foSoo6tc8iNDSrxp27dG_gtm6g&si=nfcPxGU5RPSntR0u
0
15
10
reposted by
Sébastien Duquette
Avalonia UI
12 months ago
🎉 Big news! We've secured a $3M, three-year sponsorship from
@devolutions.net
This sponsorship will allow us to speed up development, improve docs & tooling for all the community's benefit! 🚀 Read about it here:
github.com/AvaloniaUI/...
6
53
15
reposted by
Sébastien Duquette
Chris Short
12 months ago
Arguing point-by-point considered harmful #SuggestedRead #devopsish
www.seangoedecke.com...
loading . . .
Arguing point-by-point considered harmful | sean goedecke
Engineers love to have technical discussions point-by-point: replying to every idea in turn, treating each as its own mini-discussion. It just makes sense! A…
https://www.seangoedecke.com/point-by-point-considered-harmful/?&aid=recfvviyi4vvR9OKc&_bhlid=4d82eb144effc78e2a27e58709b1fe037c27fb07
0
0
1
reposted by
Sébastien Duquette
Eric Geller
12 months ago
NEW: Trump today signed an executive order to rescind parts of Obama and Biden cyber EOs and modify others. Text is TBD, but here's a fact sheet:
www.whitehouse.gov/fact-sheets/...
Still in: secure software development, BGP, PQC Out: Some AI safety, digital ID, and cyber-related sanctions stuff
4
83
44
reposted by
Sébastien Duquette
Jeff (Gutenberg Parenthesis) Jarvis
about 1 year ago
"I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped"
www.theguardian.com/us-news/2025...
loading . . .
I’m the Canadian who was detained by Ice for two weeks. It felt like I had been kidnapped
I was stuck in a freezing cell without explanation despite eventually having lawyers and media attention. Yet, compared with others, I was lucky
https://www.theguardian.com/us-news/2025/mar/19/canadian-detained-us-immigration-jasmine-mooney
135
2475
1317
Lots of interesting insights in this thread
add a skeleton here at some point
over 1 year ago
0
1
0
Cancelled Youtube Music (switched to Tidal), Netflix, Disney+ and Microsoft Game Pass. My money will go anywhere but the US whenever I can until this nonsense ends. I have nothing against Americans but Trump can go fuck himself.
over 1 year ago
0
2
0
This is completely insane. What the 6 minutes video to get a sense of the scale of the work involved to get this running. Huge props to
@michigantypescript.com
.
add a skeleton here at some point
over 1 year ago
0
1
0
reposted by
Sébastien Duquette
Marc-André Moreau
over 1 year ago
🚀 Join my webinar: Decrypting RDP Traffic in Wireshark! 🔍 📅 Date: February 11th ⏰ Time: 09:00 AM – 10:00 AM EST Learn how to analyze and decrypt RDP traffic like a pro. Can't make it live? No worries—register now, and you'll get the slides & recording afterward! 🔗 Register now 👇
loading . . .
Decrypting RDP Traffic in Wireshark
Get tickets to Decrypting RDP Traffic in Wireshark, taking place 11/02/2025. RingCentral Events is your source for engaging events and experiences.
https://events.ringcentral.com/events/decrypting-rdp-traffic-in-wireshark-e9e4e309-e90b-4c99-a742-325c00669fde/registration
0
23
19
reposted by
Sébastien Duquette
Zeke Hausfather
over 1 year ago
I have a new paper in Dialogues on Climate Change exploring climate outcomes under current policies. I find that we are likely headed toward 2.7C by 2100 (with uncertainties from 1.9C to 3.7C), and that high end emissions scenarios have become much less likely.
journals.sagepub.com...
14
360
166
reposted by
Sébastien Duquette
Raphael Satter
over 1 year ago
New: “Major incident” at U.S. Treasury after alleged Chinese hackers steal a cryptographic key used by vendor BeyondTrust. Government workstations breached.
www.reuters.com/technology/c...
loading . . .
US Treasury says Chinese hackers stole documents in 'major incident'
Chinese state-sponsored hackers broke into the U.S. Treasury Department earlier this month and stole documents from its workstations, according to a letter to lawmakers that was provided to Reuters on Monday.
https://www.reuters.com/technology/cybersecurity/us-treasurys-workstations-hacked-cyberattack-by-china-afp-reports-2024-12-30/
5
145
99
reposted by
Sébastien Duquette
Charity Majors
over 1 year ago
I (finally) wrote up my thoughts on "Founder Mode" and the Brian Chesky morality tale about how he turned around Airbnb company culture. This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out.
charity.wtf/2024/12/17/f...
loading . . .
“Founder Mode” and the Art of Mythmaking
I’ve never been good at “hot takes”. Anyone who knows anything about marketing can tell you that the best time to share your opinion about something is when everyone is all worked up about it. Hot …
https://charity.wtf/2024/12/17/founder-mode-and-the-art-of-mythmaking/
26
294
130
hey
@semgrep.bsky.social
, big fan of your tool here. Being cold emailed 5 times in a week by one of your sales rep, not so much.
over 1 year ago
1
0
0
reposted by
Sébastien Duquette
David Kean
over 1 year ago
Good read of
@ericlaw.bsky.social
's mistakes building Fiddler as a side-project while working at Microsoft. Super tempted to deep dive into that Thread Pool problem he hints at towards the start, something Visual Studio itself thinks about a lot!
textslashplain.com/2024/11/24/f...
loading . . .
Fiddler – My Mistakes
On a flight back from Redmond last week, I finally read Linus Torvalds’ 2002 memoir “Just For Fun.” I really enjoyed its picture of Linux (and Torvalds) early in its success, with…
https://textslashplain.com/2024/11/24/fiddler-my-mistakes/
0
14
5
reposted by
Sébastien Duquette
ocx64
over 1 year ago
Just wrote my first blog post, its about Rust and Slack, check it out!
ocx64.dev/blog/rust-sl...
loading . . .
Using Rust inside a Slack Workflow app with WASM
Slack workflows are pretty cool, they use deno and I'm going to show you how you can use Rust!
https://ocx64.dev/blog/rust-slack-workflow-wasm/
0
3
2
reposted by
Sébastien Duquette
Barry Dorrans
over 1 year ago
Omg
www.infosecurity-magazine.com/news/new-cit...
add a skeleton here at some point
4
21
4
reposted by
Sébastien Duquette
Mattias Karlsson
over 1 year ago
.NET 9 Released 🎉 Announcing .NET 9
devblogs.microsoft.com/dotnet/annou...
Visual Studio 2022 v17.12 with .NET 9
devblogs.microsoft.com/visualstudio...
.NET 6 end of life
devblogs.microsoft.com/dotnet/dotne...
#dotnet
loading . . .
Announcing .NET 9 - .NET Blog
Announcing the release of .NET 9, the most productive, modern, secure, intelligent, and performant release of .NET yet. With updates across ASP.NET Core, C#, .NET MAUI, .NET Aspire, and so much more.
https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/
1
109
19
reposted by
Sébastien Duquette
Sonia Cuff
over 1 year ago
Hypervisor isolation is great for security, but not known for fast cold starts. Meet Hyperlight - an open source Rust library that can create new VMs in one to two milliseconds.
opensource.microsoft.com/blog/2024/11...
loading . . .
Introducing Hyperlight: Virtual machine-based security for functions at scale - Microsoft Open Source Blog
The Microsoft Azure Core Upstream team is excited to announce the Hyperlight project, an open-source Rust library you can use to create very small VMs for embedded functions. Learn more.
https://opensource.microsoft.com/blog/2024/11/07/introducing-hyperlight-virtual-machine-based-security-for-functions-at-scale/
0
11
7
Note mostly for future me; if
github.dev
displays "Unable to resolve resource vscode-vfs" when opening a repo, disable Enhanced Tracking Protection in Firefox.
over 1 year ago
0
2
0
you reached the end!!
feeds!
log in