Lobster Roll

All Programming (General) 1589 Systems / Low-Level / OS 1248 Programming Languages / CS Theory 879 AI / Machine Learning 808 Data / Databases / Infrastructure 747 Web Development 565 Security / Privacy 425 Culture / Philosophy / History / Reading 386 Productivity / Career / Business 292 Maker / DIY / Hardware 224 Gaming / Retro Computing 220 Design / UX / Visualization 203 Science / Math / Physics 173 Apple / macOS / iOS 136 Internet / Digital Culture 81 Health / Fitness / Lifestyle 9 Crypto / Blockchain 2

Security / Privacy

FedCM + IdP Registration — Call to action (liquid.surf)
4 blog posts by Brantley Coile (of PIX firewall and ATA-over-Ethernet fame) on going flying with Niklaus Wirth (coraid.com)
framedeck: A Framework mainboard based Cyberdeck (2022) (github.com)
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 (hacks.mozilla.org)
Huntarr - Your passwords and your entire arr stack's API keys are exposed to anyone on your network, or worse, the internet (reddit.com)
Signed, Sealed, Stolen: How We Patched Critical Vulnerabilities Under Fire (youtube.com)
Official specification and reference code for Fast Lightweight Online Encryption (FLOE) (github.com)
Documentary about Mozilla Firefox at pwn2own (part 1) (youtube.com)
We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them (quesma.com)
UTS #39: Unicode Security Mechanisms (unicode.org)
Process Isolation on NetBSD with chroot (overeducated-redneck.net)
How to review an AUR package (bertptrs.nl)
I found a Vulnerability. They found a Lawyer (dixken.de)
Turn Dependabot Off (words.filippo.io)
Making frontier cybersecurity capabilities available to defenders (anthropic.com)
Last Year in Container Security (nanovms.com)
finding credentials in .msi files with msiexec (ljb.fyi)
How I built a minimal-knowledge sync for WorkLedger (bastiangruber.ca)
New TLS allocators for glibc (youtu.be)
Looking for vulnerabilities is the last thing I do (neilmadden.blog)
Keep Android Open (keepandroidopen.org)
Rails Security at Scale (2019) (youtube.com)
Linux CVE assignment process (kroah.com)
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager (adnanthekhan.com)
Paged Out! #8 (pagedout.institute)
Full Disclosure of Security Vulnerabilities a 'Damned Good Idea' (2007) (schneier.com)
how openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds (vmfunc.re)
Ditching Discord (wiki.alopex.li)
What Your Bluetooth Devices Reveal About You (blog.dmcc.io)
DNS-PERSIST-01: A New Model for DNS-based Challenge Validation (letsencrypt.org)