Lobster Roll

All Programming (General) 3776 Systems / Low-Level / OS 2953 Programming Languages / CS Theory 2127 Data / Databases / Infrastructure 1762 AI / Machine Learning 1525 Web Development 1308 Security / Privacy 1010 Culture / Philosophy / History / Reading 962 Productivity / Career / Business 732 Gaming / Retro Computing 538 Maker / DIY / Hardware 516 Design / UX / Visualization 491 Science / Math / Physics 428 Apple / macOS / iOS 355 Internet / Digital Culture 162 Health / Fitness / Lifestyle 14 Crypto / Blockchain 4

Security / Privacy

A Deep Dive into A Vulnerability Apple Deemed Unexploitable (jhftss.github.io)
dumbphone journey -- eight month update (blog.frog.equipment)
Task Injection – Exploiting agency of autonomous AI agents (bughunters.google.com)
I got hacked, my server started mining Monero this morning (blog.jakesaunders.dev)
Hardware-Attested Nix Builds (garnix.io)
Remote code execution via ND6 Router Advertisements (freebsd.org)
Strengthening your Software Supply Chain (javaadvent.com)
secure local configuration in kakoune (ficd.sh)
A short update on my Raspberry Pi security alarm project (blog.cavelab.dev)
Linux Kernel Rust Code Sees Its First CVE Vulnerability (phoronix.com)
A Safer Container Ecosystem with Docker: Free Docker Hardened Images (docker.com)
Yep, Passkeys Still Have Problems (fy.blackhats.net.au)
Keeping secrets, or (less than two weeks ago) (kellett.im)
Pwning Santa before the bad guys do (dangerzone.rocks)
IP.THC.ORG - Reverse-DNS, Subdomain and CNAME Lookups (ip.thc.org)
gh-actions-lockfile: generate and verify lockfiles for GitHub Actions (gh-actions-lockfile.net)
Optimization Countermeasures (mcyoung.xyz)
Torvalds On Linux Security Modules (phoronix.com)
System Design (rye.wentcloud.com)
"Super secure" MAGA-themed messaging app leaks everyone's phone number (ericdaigle.ca)
Hacking Endpoint to Identity: "ConsentFix" (youtube.com)
"Careless Whisper" side-channel attack affects WhatsApp and Signal (cybernews.com)
Identity-aware VPN and proxy for remote access (github.com)
Spectre/Meltdown Family Tree (2019) (transient.fail)
Shai-Hulud: A complete post-mortem (trigger.dev)
Tier list of Linux security mechanisms (2024) (blog.ce9e.org)
ACME Device Attestation Extension (datatracker.ietf.org)
BpfJailer: eBPF Mandatory Access Control (lpc.events)
A very unscientific guide to the security of various PQC algorithms (keymaterial.net)
Crypto, FIDO and Security Tokens (docs.google.com)