@pvaneynd.hachyderm.io.ap.brid.gy
📤 2
📥 3
📝 15
reposted by
✧✦Catherine✦✧
4 days ago
comparisons of AGC program memory size to USB PD controller program memory size are at least _kind of_ apples to apples in terms of the task performed, but it's still not a fair comparison because the Apollo computer did not have to deal with thousands of other vendors connecting their […]
loading . . .
Original post on mastodon.social
https://mastodon.social/@whitequark/115630266183402483
2
0
3
reposted by
curious ordinary
about 2 months ago
Fushimi Inari Taisha in Kyoto.
#ToriiTuesday
#Shinto
#kitsune
#Japan
1
166
34
reposted by
abadidea
13 days ago
user with 537 tabs and documents open on three 4k monitors: why do computers these days use so much ram? this never happened when I had one single Internet Explorer window open on a 800x600 monitor
5
65
71
reposted by
historic drystone sheep dyke
15 days ago
I saw a new exhibit of some of hiroshige’s 100 famous views of edo today and this one stopped me in my tracks
0
9
49
reposted by
Ada Palmer
17 days ago
Doctors in China have used lab-grown insulin-producing cells to treat a woman with type 1 diabetes. The cells were made from her own tissue, reprogrammed into stem cells, and then grown into tiny clusters that release insulin. A year after the transplant, her blood sugar remains normal without […]
loading . . .
Original post on wandering.shop
https://wandering.shop/@adapalmer/115555023066596740
3
10
169
reposted by
abadidea
19 days ago
Mozilla: we are developing our AI features for Firefox with user input and emphasis on user choice users: please stop. no-one who specifically uses alternative browser Firefox wants this. our choice is no Mozilla:
1
10
37
reposted by
Anna Anthro
21 days ago
#aurora
ribbons from cockpit of a flight heading to Fort MacMurray
#alberta
as major solar storm hits earth.
0
122
33
reposted by
Lesley Carhart :unverified:
21 days ago
Tbh It would be really embarrassing to have a whole infamous spy agency and then be defeated in military operations by a reporter. Zero offense or Bellingcat.
2
2
0
reposted by
Matt Blaze
22 days ago
Delivery person rang the bell to drop off a package earlier, and for a brief moment I was expecting to open the door to find two neatly dressed, smiling strangers asking me if I’ve heard the good news about content warnings and hashtags.
2
3
12
reposted by
Matt Blaze
23 days ago
Unrelatedly, I just encountered this surprisingly deep and nerdy dive into the history of the NATO (IACO) phonetic (spelling) alphabet. Interesting lessons for usability and internationalization here. Testing matters!
https://www.youtube.com/watch?v=UAT-eOzeY4M
1
4
6
Just back from
#hanabie
at the
#ancientbelgique
and of course it was great. Going by train was also a good choice: easy and fast.
23 days ago
0
0
0
reposted by
BrianKrebs
23 days ago
Enjoyed this Techcrunch piece about the new show Pluribus from the creator of Breaking Bad. Fun fact, the star of the new show Rhea Seehorn and I used to study for a statistics class together at GMU. I had such a secret crush back then (okay maybe still a little). "If you watched all the way to […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@briankrebs/115520465812256238
4
9
50
reposted by
Bruce Lawson ✅ ♫ ♿ ✌️♂️✊
24 days ago
Someone put this "blue plaque" on a London Tesla showroom to mark his becoming the world's first trillionaire. “World’s first trillionaire Elon Musk. Could have solved world hunger but funded fascists instead. Bellend.” […]
[Original post on social.vivaldi.net]
9
80
212
reposted by
Rob Ricci
26 days ago
While cleaning a storage room, our staff found this tape containing
#unix
v4 from Bell Labs, circa 1973 Apparently no other complete copies are known to exist: https://gunkies.org/wiki/UNIX_Fourth_Edition We have arranged to deliver it to the Computer History Museum
#retrocomputing
21
102
385
reposted by
Maartje
27 days ago
Starting from today our on board crew on the European Sleeper will be using my new app to improve your experience 😍 In the next weeks more features will be rolled out 🥳
1
6
6
reposted by
Jess👾
about 1 month ago
5
15
96
Problems of multilingual people, part 🤷♂️: Every time I hear the name and title of the current pope something takes a wrong turn in my head,I take the most popular meaning, and 'papa Leone' becomes 'pope lion' 😬
about 1 month ago
0
0
0
reposted by
Maartje
about 1 month ago
Hear me out… Restaurants and fresh food stores should be required by law to publish their menu online! For complete neurotypical reasons of course
1
2
3
reposted by
BrianKrebs
about 1 month ago
Was searching my Signal contacts for something something "N" and found a contact I'd not noticed before: Note to Self. One of these days I will just RTFM. "Who is Note to Self? This contact entry is a chat to send messages to yourself. Use this feature to […]
[Original post on infosec.exchange]
12
9
27
reposted by
abadidea
about 1 month ago
ah, apparently today is Amsterdam’s 750th birthday precisely. *looks out window at October rain* yeah, I see why they had the birthday party in the summer.
#amsterdam
2
5
5
reposted by
Sven222
about 1 month ago
Ich bin gerade begeistert von
#doveadm
als Tool für dovecot-Server. Ich habe jetzt endlich meinen uralt legacy-Mailserver umgezogen. Benutzer, Passworthashes und Aliase aus der Datenbank des alten Mailservers in die neue Datenbank kopiert, dann einfach alle Benutzer nochmal separat aus der […]
loading . . .
Original post on soc.hardwarepunk.de
https://soc.hardwarepunk.de/display/da93ad12-1068-fa11-bdcf-4fa341068614
0
0
1
PSA: This morning I noticed that `needrestart` was not telling me to reload my server, which, given the latest Debian security updates I did not expect. A bit of searching revealed that a long time ago I had set `APT::Default-Release`, which will prevent apt from upgrading to security packages! […]
loading . . .
Original post on hachyderm.io
https://hachyderm.io/@pvaneynd/115422101531505880
about 1 month ago
0
0
0
reposted by
abadidea
about 2 months ago
The wife of a married couple approached us and asked a lot of very specific questions about Odin’s care needs, life expectancy and puppy woes. I can imagine that the inside of the husband’s head was an ever-increasing-in-font-size “uh-oh”
#dog
#dogs
#dogsofmastodon
0
11
9
reposted by
BrianKrebs
about 2 months ago
Everyone knows the weekends are the best time to push important updates, right? From Jeep Wrangler forum: Did anyone else have a loss of drive power after today's OTA Uconnect update? On my drive home I abruptly had absolutely no acceleration, the gear […]
[Original post on infosec.exchange]
6
13
39
reposted by
Lesley Carhart :unverified:
about 2 months ago
6
79
96
reposted by
Julius Jääskeläinen
2 months ago
Monkton House, West Dean, West Sussex is an English country house designed in 1902 by Edwin Lutyens for William Dodge James. It was extensively remodelled for his son, Edward James, in the 1930s. Working with Christopher Nicholson and Hugh Casson, and […]
[Original post on mastodon.social]
0
0
3
reposted by
abadidea
2 months ago
https://neal.fun/not-a-robot/
(accessibility note: to pass this site's captcha you will need good color vision, sound, motion tolerance, keyboard and mouse dexterity, and a webcam. also, contains a toy LLM.)
loading . . .
I'm Not a Robot
Comments
https://neal.fun/not-a-robot/
1
0
4
reposted by
Dan Piponi
2 months ago
Technician comes to repair dishwasher. Brings wrong parts. Says AI orders parts. Between Republicans and AI I've never before felt so completely surrounded by ignorance and stupidity.
1
1
4
reposted by
BrianKrebs
3 months ago
Breaking, new, by me: Self-replicating "Shai-Hulud" worm hits 180+ Software Packages At least 187 code packages made available through the JavaScript repository NPM have been infected with a self-replicating worm that steals credentials from developers and […]
[Original post on infosec.exchange]
6
18
70
reposted by
abadidea
3 months ago
no joke I think the single most effective effort-to-result change that The Tech Internet could make for usability is to move the github readme above the github file list
6
6
28
reposted by
abadidea
3 months ago
Today on New Living Internet Translations: Do not post in anger, do not get mired in a flamewar because you’re mad online. If a comment is in your cause’s favor, then post it; if it’s not then for FFS stop. Anger can be replaced by cat pics, the maddest […]
[Original post on infosec.exchange]
0
7
7
reposted by
Lesley Carhart :unverified:
3 months ago
[long US politics rant tldr tldr tldr] Man, I got in this huge, flashy debate with people on the left and the right on Bluesky last night... Look, here's the deal. I wish they had voted. Nothing in life is simple. We want there to be easy, straightforward, singular reasons for the awful mess […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@hacks4pancakes/115166553196325238
5
1
31
reposted by
abadidea
3 months ago
This is local Amsterdam news (in Dutch) about the library putting on a display of books banned from American schools and libraries, in little stars-and-stripes coffins. They say it’s because whatever nonsense America gets up to, the Dutch need to be ready to guard against it being pushed here a […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@0xabad1dea/115162935154285597
1
3
42
reposted by
Lesley Carhart :unverified:
3 months ago
This is one of the craziest trial headlines that has turned into a cybersecurity story, in a minute.
https://global.chinadaily.com.cn/a/202508/20/WS68a549d8a310b236346f2980.html
A lot of scammers are unscrupulous bastards. Some of the low level people are victims though, too. This is a dismal […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@hacks4pancakes/115082045255017402
2
0
10
reposted by
Julia Evans
4 months ago
how your terminal handles mouse clicks
https://wizardzines.com/comics/the-mouse
(from "The Secret Rules of the Terminal", which is out now!
https://wizardzines.com/zines/terminal
)
4
2
8
reposted by
Edwin
5 months ago
German dishwasher 1959
loading . . .
1
10
23
reposted by
BrianKrebs
5 months ago
And from WTAF dept, quite a bombshell from Pro Publica today: "Microsoft is using engineers in China to help maintain the Defense Department’s computer systems — with minimal supervision by U.S. personnel — leaving some of the nation’s most sensitive data vulnerable to hacking from its leading […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@briankrebs/114857817701408852
1
15
12
reposted by
daniel:// stenberg://
5 months ago
Death by a thousand slops https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/
#curl
#ai
#bugbounty
loading . . .
Death by a thousand slops
I have previously blogged about the relatively new trend of AI slop in vulnerability reports submitted to curl and how it hurts and exhausts us. This trend does not seem to slow down. On the contrary, it seems that we have recently not only received more AI slop but also more _human slop_. The latter differs only in the way that we cannot immediately tell that an AI made it, even though we many times still suspect it. The net effect is the same. The general trend so far in 2025 has been _way more_ AI slop than ever before (about 20% of all submissions) as we have averaged in about two security report submissions per week. In early July, about 5% of the submissions in 2025 had turned out to be genuine vulnerabilities. The valid-rate has decreased _significantly_ compared to previous years. We have run the curl Bug Bounty since 2019 and I have previously considered it a success based on the amount of genuine and real security problems we have gotten reported and thus fixed through this program. 81 of them to be exact, with over 90,000 USD paid in awards. ## End of the road? While we are not going to do anything rushed or in panic immediately, there are reasons for us to consider changing the setup. Maybe we need to drop the monetary reward? I want us to use the rest of the year 2025 to evaluate and think. The curl bounty program continues to run and we deal with everything as before while we ponder about what we can and should do to improve the situation. For the sanity of the curl security team members. We need to reduce the amount of sand in the machine. We must do something to drastically reduce the temptation for users to submit low quality reports. Be it with AI or without AI. The curl security team consists of seven team members. I encourage the others to also chime in to back me up (so that we act right in each case). Every report thus engages 3-4 persons. Perhaps for 30 minutes, sometimes up to an hour or three. Each. I personally spend an insane amount of time on curl already, wasting three hours still leaves time for other things. My fellows however are not full time on curl. They might only have three hours per week for curl. Not to mention the _emotional toll_ it takes to deal with these mind-numbing stupidities. Times _eight_ the last week alone. ## Reputation doesn’t help On HackerOne the users get their _reputation_ lowered when we close reports as _not applicable_. That is only really a mild “threat” to experienced HackerOne participants. For new users on the platform that is mostly a pointless exercise as they can just create a new account next week. Banning those users is similarly a rather toothless threat. Besides, there seem to be so many so even if one goes away, there are a thousand more. ## HackerOne It is not super obvious to me exactly _how_ HackerOne should change to help us combat this. It is however clear that we need them to do something. Offer us more tools and knobs to tweak, to save us from drowning. If we are to keep the program with them. I have yet again reached out. We will just have to see where that takes us. ## Possible routes forward People mention charging a fee for the right to submit a security vulnerability (that could be paid back if a proper report). That would probably slow them down significantly sure, but it seems like a rather hostile way for an Open Source project that aims to be as open and available as possible. Not to mention that we don’t have any current infrastructure setup for this – and neither does HackerOne. And managing money is painful. Dropping the monetary reward part would make it much less interesting for _the general populace_ to do random AI queries in desperate attempts to report something that could generate income. It of course also removes the traction for some professional and highly skilled security researchers, but maybe that is a hit we can/must take? As a lot of these reporters seem to _genuinely_ think they help out, apparently blatantly tricked by the marketing of the AI hype-machines, it is not certain that removing the money from the table is going to completely stop the flood. We need to be prepared for that as well. Let’s burn that bridge if we get to it. ## The AI slop list If you are still innocently unaware of what AI slop means in the context of security reports, I have collected a list of a number of reports submitted to curl that help showcase. Here’s a snapshot of the list from today: 1. [Critical] Curl CVE-2023-38545 vulnerability code changes are disclosed on the internet. #2199174 2. Buffer Overflow Vulnerability in WebSocket Handling #2298307 3. Exploitable Format String Vulnerability in curl_mfprintf Function #2819666 4. Buffer overflow in strcpy #2823554 5. Buffer Overflow Vulnerability in strcpy() Leading to Remote Code Execution #2871792 6. Buffer Overflow Risk in Curl_inet_ntop and inet_ntop4 #2887487 7. bypass of this Fixed #2437131 [ Inadequate Protocol Restriction Enforcement in curl ] #2905552 8. Hackers Attack Curl Vulnerability Accessing Sensitive Information #2912277 9. (“possible”) UAF #2981245 10. Path Traversal Vulnerability in curl via Unsanitized IPFS_PATH Environment Variable #3100073 11. Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet #3101127 12. Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl #3116935 13. Double Free Vulnerability in `libcurl` Cookie Management (`cookie.c`) #3117697 14. HTTP/2 CONTINUATION Flood Vulnerability #3125820 15. HTTP/3 Stream Dependency Cycle Exploit #3125832 16. Memory Leak #3137657 17. Memory Leak in libcurl via Location Header Handling (CWE-770) #3158093 18. Stack-based Buffer Overflow in TELNET NEW_ENV Option Handling #3230082 19. HTTP Proxy Bypass via `CURLOPT_CUSTOMREQUEST` Verb Tunneling #3231321 20. Use-After-Free in OpenSSL Keylog Callback via SSL_get_ex_data() in libcurl #3242005 21. HTTP Request Smuggling Vulnerability Analysis – cURL Security Report #3249936
https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/
4
43
57
reposted by
daniel:// stenberg://
5 months ago
The
#curl
security ream consists of seven team members. I encourage the others to also chime in to back me up (so that we do right). Every report thus engages 3-4 persons. Perhaps for 30 minutes, sometimes up to an hour or three. Each. I personally spend an insane amount of time on curl already […]
loading . . .
Original post on mastodon.social
https://mastodon.social/@bagder/114850496955105528
0
4
1
reposted by
David Ho
5 months ago
Holy cow, as an American, I wasn't aware of the Horizon IT scandal. ~1,000 postal workers were wrongfully prosecuted for theft and other crimes, imprisoned, and forced to repay tens of thousands of pounds. 13 of them committed suicide! But it was an IT error! AI will make this worse […]
loading . . .
Original post on mastodon.world
https://mastodon.world/@davidho/114835624903804555
10
3
25
reposted by
abadidea
5 months ago
"geometry glitch in the map data, or just the Dutch again?"
6
18
71
reposted by
Itamar Turner-Trauring
5 months ago
Tesla's so-called "autopilot" turns off automatically a fraction of a second before a crash, so the driver can be blamed even though the driver has no time to respond […]
loading . . .
Original post on hachyderm.io
https://hachyderm.io/@itamarst/114800927755957738
0
3
1
reposted by
Maartje
5 months ago
Good morning! Except you NMBS who canceles all trains till 7AM without replacement traffic… as if people aren’t trying to get to work…
1
2
1
Load more
feeds!
log in