/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Yan

@bcrypt
27 posts
2024-11-03
reminder that the bcrypt hash function ignores input above a certain length! so if you do bcrypt(username || password) for some reason, a sufficiently long username will make it accept any password. to fix this you can sha256 the input first.
2024-11-03 View on X
The Verge

Okta fixes a flaw present since July 23, 2024, that let users log in under specific circumstances with any password if the account's username had 52+ characters

The vulnerability is fixed now, but Okta said that for three months it could've been used to access accounts with usernames stretching at least 52 characters long.

2024-03-30
fyi homebrew had the backdoored version of xz utils; updating now will downgrade it https://duo.com/... [image]
2024-03-30 View on X
Ars Technica

Researchers find malicious code in versions of the compression tool XZ Utils that were incorporated into Linux distributions from Red Hat, Debian, and others

Malicious code planted in xz Utils has been circulating for more than a month.  —  Researchers have found a malicious backdoor …

2022-06-29
history repeats itself 😂 https://twitter.com/...
2022-06-29 View on X
Bloomberg

After freezing withdrawals, crypto exchange CoinFlex plans to issue up to 47M Recovery Value USD tokens, offering a 20% annual return, to repay a $47M debt

history repeats itself 😂 https://twitter.com/...
2022-06-29 View on X
CoinDesk

CoinFlex CEO Mark Lamb says crypto investor Roger Ver owes the exchange $47M in USDC, after Ver denied “some rumors” he defaulted on a debt to a counterparty

The crypto exchange is launching a recovery token because of debt owed by a high-net-worth customer.

2022-03-30
“We are working directly with various government agencies to ensure the criminals get brought to justice.” code is law, except when it's not 😆 https://twitter.com/...
2022-03-30 View on X
CoinDesk

The Ronin Network, which supports Sky Mavis' Axie Infinity game, says it was hacked, and 173,600 ETH and 25.5M USDC was stolen, worth $600M+; RON is down ~20%

It may be the largest exploit in DeFi history.  —  The latest crypto hack may be the largest yet.

2022-02-12
Apple: free as in use-after https://twitter.com/...
2022-02-12 View on X
BleepingComputer

Apple releases iOS 15.3.1, iPadOS 15.3.1, and macOS Monterey 12.2.1 to fix a WebKit flaw that may have been actively exploited, its third zero-day patch in 2022

Friday, February 11, 2022 // (IG): BB //Weekly Sponsor: BLKTRIANGLE Mitchell Clark / The Verge : Apple's latest update should fix MacBooks' battery drain issue Tyler Lee / Ubergizm...

2022-02-11
Apple: free as in use-after https://twitter.com/...
2022-02-11 View on X
BleepingComputer

Apple releases iOS 15.3.1, iPadOS 15.3.1, and macOS Monterey 12.2.1 to fix a WebKit flaw that may have been actively exploited, its third zero-day patch in 2022

Friday, February 11, 2022 // (IG): BB //Weekly Sponsor: BLKTRIANGLE Pieter Arntz / Malwarebytes Labs : Update now! Apple fixes actively exploited zero-day Ravie Lakshmanan / The Ha...

2021-08-07
given that CSAM scanning is only enabled for users who opt into icloud photo backups, i'm guessing apple would have built it into icloud if they could. they can't because of end-to-end encryption. https://twitter.com/...
2021-08-07 View on X
MacRumors

In response to CSAM detection misuse concerns, Apple says protections will roll out in the US first, then on a country-by-country basis after legal evaluation

Apple this week announced that, starting later this year with iOS 15 and iPadOS 15, the company will be able …

sorry this should say “because of eventual plans to do e2e encryption for icloud photos, or at least i hope” :)
2021-08-07 View on X
MacRumors

In response to CSAM detection misuse concerns, Apple says protections will roll out in the US first, then on a country-by-country basis after legal evaluation

Apple this week announced that, starting later this year with iOS 15 and iPadOS 15, the company will be able …

there's lots of reasons to object to apple's CSAM proposal but “they shouldn't build software to scan your device” doesn't resonate with me. given a choice between plaintext backups scanned in the cloud and end-to-end-encrypted backups scanned on-device, i'd pick the latter.
2021-08-07 View on X
@wcathcart

[Thread] WhatsApp says Apple's approach to CSAM is a setback to user privacy, will be more fraught outside the US; WhatsApp flagged 400K+ cases to NCMEC in 2020

even photos you haven't shared with anyone. That's not privacy. Will Cathcart / @wcathcart : We've worked hard to ban and report people who traffic in it based on appropriate measu...

not saying this is the choice we are facing, but i hope this makes it clear that on-device vs in-cloud is not the issue here so much as the scanning itself.
2021-08-07 View on X
@wcathcart

[Thread] WhatsApp says Apple's approach to CSAM is a setback to user privacy, will be more fraught outside the US; WhatsApp flagged 400K+ cases to NCMEC in 2020

even photos you haven't shared with anyone. That's not privacy. Will Cathcart / @wcathcart : We've worked hard to ban and report people who traffic in it based on appropriate measu...

given that CSAM scanning is only enabled for users who opt into icloud photo backups, i'm guessing apple would have built it into icloud if they could. they can't because of end-to-end encryption. https://twitter.com/...
2021-08-07 View on X
@wcathcart

[Thread] WhatsApp says Apple's approach to CSAM is a setback to user privacy, will be more fraught outside the US; WhatsApp flagged 400K+ cases to NCMEC in 2020

even photos you haven't shared with anyone. That's not privacy. Will Cathcart / @wcathcart : We've worked hard to ban and report people who traffic in it based on appropriate measu...

sorry this should say “because of eventual plans to do e2e encryption for icloud photos, or at least i hope” :)
2021-08-07 View on X
@wcathcart

[Thread] WhatsApp says Apple's approach to CSAM is a setback to user privacy, will be more fraught outside the US; WhatsApp flagged 400K+ cases to NCMEC in 2020

even photos you haven't shared with anyone. That's not privacy. Will Cathcart / @wcathcart : We've worked hard to ban and report people who traffic in it based on appropriate measu...

not saying this is the choice we are facing, but i hope this makes it clear that on-device vs in-cloud is not the issue here so much as the scanning itself.
2021-08-07 View on X
MacRumors

In response to CSAM detection misuse concerns, Apple says protections will roll out in the US first, then on a country-by-country basis after legal evaluation

Apple this week announced that, starting later this year with iOS 15 and iPadOS 15, the company will be able …

there's lots of reasons to object to apple's CSAM proposal but “they shouldn't build software to scan your device” doesn't resonate with me. given a choice between plaintext backups scanned in the cloud and end-to-end-encrypted backups scanned on-device, i'd pick the latter.
2021-08-07 View on X
MacRumors

In response to CSAM detection misuse concerns, Apple says protections will roll out in the US first, then on a country-by-country basis after legal evaluation

Apple this week announced that, starting later this year with iOS 15 and iPadOS 15, the company will be able …

2021-08-06
if i'm reading this right, it seems you can opt out of this scanning by disabling icloud backup for photos, even though all the CSAM matching happens locally https://twitter.com/...
2021-08-06 View on X
Financial Times

Security experts voice privacy concerns over Apple's new plan to scan users' devices for child abuse images, saying governments will likely increase its scope

Security researchers raise alarm over potential surveillance of personal devices  —  Apple intends to install software …

if i'm reading this right, it seems you can opt out of this scanning by disabling icloud backup for photos, even though all the CSAM matching happens locally https://twitter.com/...
2021-08-06 View on X
TechCrunch

In addition to scanning for known child abuse photos, Apple will also begin using on-device ML to warn parents and kids of sexually explicit photos in Messages

Apple later this year will roll out new tools that will warn children and parents if the child sends or receives sexually explicit photos through the Messages app.

2021-07-31
this is an excellent and well-researched post about the current state of browser competition: https://httptoolkit.tech/...
2021-07-31 View on X
HTTP Toolkit

Safari's extremely slow pace in adopting popular features and fixing showstopping bugs, and refusal to engage with contentious API proposals, is harming the web

Features not implemented are not dangerous —'Safari is the next IE' is well supported by many bugs —Ignoring Chrome proposals without engaging or alternative offers, makes the prob...

2021-06-23
the new search engine we've been working on at @brave is now in public beta! https://search.brave.com/ * we don't track clicks or queries * we don't profile you * for localized results, we only use IP and don't store it * we show you what % of results are served from our own index
2021-06-23 View on X
TechCrunch

Privacy browser Brave launches a non-tracking search engine in beta, at search.brave.com, to offer an “all in one” alternative to Google Search and Chrome

Natasha Lomas / TechCrunch :

2021-06-08
update: the 2nd hop is run by a different entity. anyone want to take bets on who? :) https://www.reuters.com/...
2021-06-08 View on X
Reuters

Apple: iCloud Private Relay will not work in China, Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda, and the Philippines

Apple Inc (AAPL.O) on Monday said a new “private relay” feature designed to obscure a user's web browsing behavior …