Lobster Roll

All Programming (General) 796 Systems / Low-Level / OS 583 AI / Machine Learning 541 Programming Languages / CS Theory 428 Data / Databases / Infrastructure 377 Web Development 276 Security / Privacy 233 Culture / Philosophy / History / Reading 210 Productivity / Career / Business 162 Gaming / Retro Computing 129 Design / UX / Visualization 112 Maker / DIY / Hardware 112 Science / Math / Physics 72 Apple / macOS / iOS 67 Internet / Digital Culture 48 Health / Fitness / Lifestyle 5

Security / Privacy

New Attack Against Wi-Fi (schneier.com)
syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems (github.com)
Dependency Tracking is Hard (daniel.haxx.se)
First (?) hacked Emacs package (old.reddit.com)
Catching malicious contributions in open source repos (datadoghq.com)
Reversing Russian spyware I installed on my iPhone (youtube.com)
seccomp — Unsafe at any speed (2022) (blog.habets.se)
Post-Quantum Cryptography Beyond TLS: Remain Quantum Safe (akamai.com)
WebPKI and You (blog.brycekerley.net)
Perfect types with `setHTML()` (frederikbraun.de)
My Favorite 39C3 Talks (asindu.xyz)
The first AI agent worm is months away, if that (dustycloud.org)
NetBird - Open Source Zero Trust Networking (netbird.io)
Fortify your app: Essential strategies to strengthen security (youtube.com)
Hardening Firefox with Anthropic’s Red Team (blog.mozilla.org)
Clinejection — Compromising Cline’s Production Releases just by Prompting an Issue Triager (simonwillison.net)
On the Effectiveness of Mutational Grammar Fuzzing (projectzero.google)
A GitHub Issue Title Compromised 4,000 Developer Machines (grith.ai)
telemetry helps. you still get to turn it off (ritter.vg)
The Illustrated TLS 1.2 Connection (tls12.xargs.org)
You Bought Zuck’s Ray-Bans. Now Someone in Nairobi Is Watching You Poop (blog.adafruit.com)
Who Writes the Bugs? A Deeper Look at 125,000 Kernel Vulnerabilities (pebblebed.com)
Accepting user-supplied code is mostly fine (dimden.dev)
Encrypted Client Hello: Closing the SNI Metadata Gap (cdt.org)
Pocket ID: Easy Passkey Authentication (runtimeterror.dev)
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit (cloud.google.com)
California's Digital Age Assurance Act, and FOSS (runxiyu.org)
yj_nearbyglasses: attempting to detect smart glasses nearby and warn you (github.com)
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets (blog.calif.io)
Deprecate confusing APIs like “os.path.commonprefix()” (sethmlarson.dev)