Lobster Roll

All Programming (General) 33880 Systems / Low-Level / OS 24467 Programming Languages / CS Theory 17538 Data / Databases / Infrastructure 13902 Web Development 11469 Culture / Philosophy / History / Reading 10287 Security / Privacy 9989 Productivity / Career / Business 7299 Maker / DIY / Hardware 5817 AI / Machine Learning 4812 Science / Math / Physics 3792 Design / UX / Visualization 3595 Gaming / Retro Computing 3345 Apple / macOS / iOS 2618 Internet / Digital Culture 1313 Crypto / Blockchain 337 Health / Fitness / Lifestyle 89

Security / Privacy

Using AI Coding Agents for finding vulnerabilities: strengths, weaknesses, and serious consistency problems (semgrep.dev)
C++ Memory Safety in WebKit (m.youtube.com)
zfsbackrest: pgbackrest style encrypted backups for ZFS filesystems (github.com)
What Every Argument About Sideloading Gets Wrong (hugotunius.se)
Passkeys are incompatible with open-source software (smokingonabike.com)
'We are currently clean on OPSEC': The Signalgate Saga (youtube.com)
Client-side RCE via CSS Injection in Google Web Designer for Windows (balintmagyar.com)
How a VPN kill-switch caused sudo to hang (anagogistis.com)
Is it possible to allow sideloading *and* keep users safe? (shkspr.mobi)
Some minor bugs in Proton's new Authenticator app (shkspr.mobi)
I'm concerned (excerpt) (studium.dev)
A16-FuseBypass: Debug Logic Enabled on Production Apple Silicon (github.com)
KernelSnitch: Side-Channel Attacks on Kernel Data Structures (lukasmaar.github.io)
Default search engine: Wikipedia (paste.sr.ht)
Unpacking Passkeys Pwned: Possibly the most specious research in decades (arstechnica.com)
Capability-based Financial Instruments (erights.org)
Block ads and trackers (lichess.org)
I'll only buy devices with GrapheneOS (jonashietala.se)
The vulnerability might be in the proof-of-concept (sethmlarson.dev)
Malicious versions of Nx and some supporting plugins were published (github.com)
Inspecting OpenPGP certificates (openpgp.foo)
postMessaged and Compromised (msrc.microsoft.com)
Apple vs. Facebook is Kayfabe (infrequently.org)
Google wants to make sideloading Android apps safer by verifying developers’ identities (androidauthority.com)
ghrc.io Appears to be Malicious (bmitch.net)
Marshal madness: A brief history of Ruby deserialization exploits (blog.trailofbits.com)
I Hacked Monster Energy and Uncovered Their Employee Training Material (bobdahacker.com)
Rethinking the Linux cloud stack for confidential VMs (lwn.net)
Bitnami Deprecation (raesene.github.io)
AUR Chaos malware: an analysis (mh4ckt3mh4ckt1c4s.xyz)