Lobster Roll

All Programming (General) 42991 Systems / Low-Level / OS 28690 Programming Languages / CS Theory 22243 Data / Databases / Infrastructure 16895 Web Development 14819 Security / Privacy 13097 Culture / Philosophy / History / Reading 13000 Productivity / Career / Business 9831 Maker / DIY / Hardware 7093 Science / Math / Physics 5308 AI / Machine Learning 5067 Design / UX / Visualization 4698 Gaming / Retro Computing 4156 Apple / macOS / iOS 3336 Internet / Digital Culture 1734 Crypto / Blockchain 488 Health / Fitness / Lifestyle 122

Security / Privacy

The Month of AI Bugs 2025 (monthofaibugs.com)
NOPE: Strengthening Domain Authentication (RWC 2025) (youtube.com)
Slice: SAST + LLM Interprocedural Context Extractor (noperator.dev)
Why are anime catgirls blocking my access to the Linux kernel? (lock.cmpxchg8b.com)
Privacy-Preserving Age Verification—and Its Limitations (cs.columbia.edu)
maybenot: a framework for traffic analysis defenses (github.com)
CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox (hacks.mozilla.org)
Desync the Planet – Rsync Remote Code Execution (phrack.org)
Intel Outside: Hacking every Intel employee and various internal websites (eaton-works.com)
Preventing Domain Resurrection Attacks (on the Python Package Index) (blog.pypi.org)
Phrack 72 (phrack.org)
How Indirect Prompt Injections Exploit Context, Format, and Salience (fogel.dev)
Preventing NAPTR Spam (shkspr.mobi)
SystemD Service Hardening (roguesecurity.dev)
Ambient age verification (jwz.org)
libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable Burden (socket.dev)
Maintainers of Last Resort (words.filippo.io)
In-depth analysis on Valorant's Guarded Regions (2023) (reversing.info)
Single Sign On for Furries (cendyne.dev)
Vaultwarden now supports SSO with OIDC (news.ycombinator.com)
Is Germany on the Brink of Banning Ad Blockers? User Freedom, Privacy, and Security Is At Risk (blog.mozilla.org)
How to rig elections (media.ccc.de)
Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities (openreview.net)
Cross-Site Request Forgery (words.filippo.io)
MadeYouReset: Turning HTTP/2 Server Against Itself (imperva.com)
That 16 Billion Password Story (AKA "Data Troll") (troyhunt.com)
Answering the BfDI's questions on personal data in LLMs (desfontain.es)
pure: A static analysis file format checker for Zip files (github.com)
Lessons learned building an AI hacker (theori.io)
Researchers determine old vulnerabilities pose real-world threat to sensitive data in public clouds (cyberscoop.com)