Lobster Roll

All Programming (General) 799 Systems / Low-Level / OS 583 AI / Machine Learning 542 Programming Languages / CS Theory 430 Data / Databases / Infrastructure 377 Web Development 276 Security / Privacy 233 Culture / Philosophy / History / Reading 211 Productivity / Career / Business 162 Gaming / Retro Computing 129 Design / UX / Visualization 112 Maker / DIY / Hardware 112 Science / Math / Physics 72 Apple / macOS / iOS 67 Internet / Digital Culture 48 Health / Fitness / Lifestyle 5

Security / Privacy

Exploring Maturity Models For Security (cloudsecuritypartners.com)
I'm struggling to think of any online services for which I'd be willing to verify my identity or age (neilzone.co.uk)
To update blobs or not to update blobs (codon.org.uk)
You can't always fix it (ntietz.com)
How to Use an iPad as a Secure Calling and Messaging Device (yawnbox.eu)
Farewell, Felix (blog.recurity-labs.com)
mcp-firewall: A better policy-engine for CLI agents (github.com)
Fooling Go's X.509 Certificate Verification (danielmangum.com)
Agents attacking agents: AI-powered bot exploiting GitHub Actions (stepsecurity.io)
Stop Putting Secrets in .env Files (jonmagic.com)
Cultivating a robust and efficient quantum-safe HTTPS (security.googleblog.com)
Please stop using passkeys for encrypting user data (blog.timcappalli.me)
Bill Text - AB-1043 Age verification signals: software applications and online services (leginfo.legislature.ca.gov)
JavaScript DRMs are Stupid and Useless (the-ranty-dev.vercel.app)
Linux ID: Linux explores new way of authenticating developers and their code (zdnet.com)
Protecting code compiled just in time (2024) (developer.apple.com)
How my side project got banned from the internet (trysound.io)
Poisoning AI Training Data (schneier.com)
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks (ndss-symposium.org)
Data Confidentiality via Storage Encryption on Embedded Linux Devices (sigma-star.at)
96.5% of confusables.txt from Unicode is not high-risk (paultendo.github.io)
Google API Keys Weren't Secrets. But then Gemini Changed the Rules (trufflesecurity.com)
An Open Letter to Google regarding Mandatory Developer Registration for Android (keepandroidopen.org)
Firefox pwn2own 2025 documentary part 2 (m.youtube.com)
Developer-targeting campaign using malicious Next.js repositories (microsoft.com)
security and blobs (blog.lx.oliva.nom.br)
How Predator Spyware Defeats iOS Camera/Microphone Recording Indicators (jamf.com)
Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials (2024) (ias.cs.tu-bs.de)
1Password Getting More Expensive Starting in March (macrumors.com)
Getting Global Age Assurance Right: What We Got Wrong and What's Changing (discord.com)