4 Followers
94 Following
657 Posts
Anthropic having Fable be export controlled is a self-inflicted wound. If you spend a bunch of time telling people how dangerous your technology is, don't be surprised when some of them agree with you.

We're private previewing a feature in GitHub Actions: a network firewall.

At the end of your workflow run, we'll upload an Actions workflow artifact with the IPs and URLs from the run. It uses TLS interception to record the URLs, but the cert is per-run and thrown away after the run to preserve privacy.

If you're interested, send me a private message with the GitHub org(s) and username(s) to add to the feature flag, as well as our early access repository where you can give feedback.

Inspector general finds NIST mistakes have made vulnerability database ineffective https://therecord.media/nist-mistakes-vulnerability-database-inspector-general
Inspector general finds NIST mistakes have made vulnerability database ineffective

NIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025, “undermining the NVD’s utility and public trust," according to an inspector general report.

I've worn a Garmin for 10+ years and logged thousands of runs, rides, hikes...you name it. That data can also tell you where I live, where I've traveled, and when I've been under stress.

After reading @zackwhittaker 's recent story on Oura ring's lack of transparency reporting, I was curious about the current state of other wearables.

I looked at 12 major wearable brands to see who publishes transparency reports (aka the documents that tell you how often a company hands your data to the government).

2 out of 12 do: Apple and Google/Fitbit.

https://whyli.me/blog/wearable-transparency/

https://emilyaustin.github.io/wearable-tracker/

#infosec #privacy #running

All my attempts to communicate a vulnerability in #Signalapp have failed - I have not received any response to my multiple messages to them. Good people have tried to forward my concern to them (and I am thankful for your efforts and help), yet this has been to no avail.

I am disappointed in the lack of communication from Signal. I will be disclosing the full details of the issue later today (with end-user mitigations), after the six-month anniversary of the initial report.

"If Linux can be maintained by sending patches to an email mailing list, 'doesn’t work at scale' arguments are skill issues."
https://dbushell.com/2026/04/29/github-is-sinking/
GitHub is sinking

The one where I suggest finding the nearest lifeboat

dbushell.com
Could everyone just calm the fuck down for a week or two?
https://fedi.lwn.net/@lwn/116535169774717465
LWN.net (@[email protected])

Dirty Frag: a zero-day universal Linux LPE https://lwn.net/Articles/1071719/ #LWN #Linux #security

LWN.net's Mastodon server
GitHub - 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo

Copy Fail 2: Electric Boogaloo. Contribute to 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo development by creating an account on GitHub.

GitHub

Setting up age verification for my BBS

It's simple: if you know what a BBS is and manage to connect to it, you're clearly over 18.