Lobster Roll

All Programming (General) 1994 Systems / Low-Level / OS 1556 Programming Languages / CS Theory 1094 Data / Databases / Infrastructure 927 AI / Machine Learning 923 Web Development 679 Security / Privacy 535 Culture / Philosophy / History / Reading 500 Productivity / Career / Business 377 Gaming / Retro Computing 280 Maker / DIY / Hardware 274 Design / UX / Visualization 247 Science / Math / Physics 225 Apple / macOS / iOS 176 Internet / Digital Culture 94 Health / Fitness / Lifestyle 12 Crypto / Blockchain 2

Security / Privacy

New Attack Against Wi-Fi (schneier.com)
syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems (github.com)
Dependency Tracking is Hard (daniel.haxx.se)
First (?) hacked Emacs package (old.reddit.com)
Catching malicious contributions in open source repos (datadoghq.com)
Reversing Russian spyware I installed on my iPhone (youtube.com)
seccomp — Unsafe at any speed (2022) (blog.habets.se)
Post-Quantum Cryptography Beyond TLS: Remain Quantum Safe (akamai.com)
WebPKI and You (blog.brycekerley.net)
Perfect types with `setHTML()` (frederikbraun.de)
My Favorite 39C3 Talks (asindu.xyz)
The first AI agent worm is months away, if that (dustycloud.org)
NetBird - Open Source Zero Trust Networking (netbird.io)
Fortify your app: Essential strategies to strengthen security (youtube.com)
Hardening Firefox with Anthropic’s Red Team (blog.mozilla.org)
Clinejection — Compromising Cline’s Production Releases just by Prompting an Issue Triager (simonwillison.net)
On the Effectiveness of Mutational Grammar Fuzzing (projectzero.google)
A GitHub Issue Title Compromised 4,000 Developer Machines (grith.ai)
telemetry helps. you still get to turn it off (ritter.vg)
The Illustrated TLS 1.2 Connection (tls12.xargs.org)
You Bought Zuck’s Ray-Bans. Now Someone in Nairobi Is Watching You Poop (blog.adafruit.com)
Who Writes the Bugs? A Deeper Look at 125,000 Kernel Vulnerabilities (pebblebed.com)
Accepting user-supplied code is mostly fine (dimden.dev)
Encrypted Client Hello: Closing the SNI Metadata Gap (cdt.org)
Pocket ID: Easy Passkey Authentication (runtimeterror.dev)
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit (cloud.google.com)
California's Digital Age Assurance Act, and FOSS (runxiyu.org)
yj_nearbyglasses: attempting to detect smart glasses nearby and warn you (github.com)
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets (blog.calif.io)
Deprecate confusing APIs like “os.path.commonprefix()” (sethmlarson.dev)