The only feature of 1Password that matters is their business dies overnight if they get hacked so they’ve thought harder about security than anyone you know.
You can’t vibe code that in two evenings no matter how much you ask Claude to “make it secure”
Today in InfoSec Job Security News:
I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.
So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.
https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc
As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.
Reluctantly crouched at the command line
Desperately typing to keep it online
A green light flashes, the systems come up
Churning and burning for the latest markup
Deftly inserting some Python or C
While guzzling down a coffee or three
Reckless and wild, he pours through the code
His prowess is potent, an effortless flow
As he speeds through the lines, the servers go down
As 404 errors are suddenly found
The department is empty except for one man
Still loading and coding as fast as he can
The sun has gone down and the moon has come up
His coffee gone cold long ago in his cup
But he's typing and striving, debugging the terms
And thinking of someone for whom he still burns
He's going the distance
He's coding in C
He's all alone (all alone)
All alone in his time of need
Because he's typing and writing and viewing the source
Programming and scanning and switching the ports
He's going the distance.
No trophy, no flowers, no flashbulbs, no wine
He's haunted by variables he cannot define
Undeclared functions of doubt and remorse
Compile him, defile him with processing force
In his mind, he's still twelve, just hacking his grade
And he's hoping in time that those memories will fade
'Cause he's racing and pacing and switching the ports
He's typing and writing and viewing the source
The sun has gone down and the moon has come up
And his coffee's gone cold long ago in his cup
But he's typing and striving, debugging the terms
And thinking of someone for whom he still burns
He's going the distance
He's coding in C
He's all alone (all alone)
All alone in his time of need
Cause he's racing and pacing the processing ports
He's typing and writing and viewing the source
Cause he's racing and pacing and switching the ports
He's loading and coding and viewing the source
He's going the distance
He's coding in C
He's going the distance...
PSA: Did you know that it’s **unsafe** to put code diffs into your commit messages?
Like https://github.com/i3/i3/pull/6564 for example
Such diffs will be applied by patch(1) (also git-am(1)) as part of the code change!
This is how a sleep(1) made it into i3 4.25-2 in Debian unstable.
lol https://seclists.org/oss-sec/2026/q1/89
telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.
If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes
In telnetd for a decade 💀
Daughter just came home to tell me the teachers at school tried to confiscate her vape but they couldn't because it's actually a kazoo.
"I made a kazoo noise at them and I could see them dying on the inside so I made a sad kazoo noise instead. I don't think it helped."
The grin on her face.
This seems appropriate for today. Not my OC.
wild fact I just learned (mostly) from reddit:
The person who modeled as the policeman for this Norman Rockwell drawing (Policeman with Boys) was a real policeman, and he's Officer Obie from Arlo Guthrie's Alice's Restaurant.
Huh.