@KewlCat

86 Followers
38 Following
9.3K Posts
Move fast and fix things
Sitehttps://www.kewlcat.fr

I found that crafted #MeshCore node names could compromise #HomeAssistant instances running meshcore-card, with an XSS leading to remote root access on the HA host. An attacker could then access anything controlled or visible through Home Assistant. The attacker doesn't need to be near the target, as MeshCore advertisements are repeated over the mesh, which is dense in NL.

This also affects around 20 public MeshCore analyzer websites. Some of those run CoreScope, where it looks like a vibecoding bot broke the XSS filter while hallucinating a bugfix. The analyzers are mostly public data though. In addition, the less popular MeshCore-Home-Assistant-Panel-v2 is likely also affected, but I was unable to make contact with the maintainer.

MeshCore node names are only 32 bytes, and each rendered in a different place in the page, so I had to be creative to run a more substantial payload. I found a way with three node names using an iframe feature I never heard of before.

https://mxsasha.eu/posts/meshcore-xss-home-assistant/

Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name

A crafted MeshCore node name could compromise any Home Assistant instance running meshcore-card as soon as someone viewed a dashboard with that card. MeshCore …

il est bon lui 😄
« L’IA c’est l’avenir ». Mon cul oui…

Researchers found that writers using biased AI agents to auto-complete suggestions had their sociopolitical values shifted without their knowledge it was happening.

https://www.science.org/doi/10.1126/sciadv.adw5578

We worry about cognitive capture, what the LLMs of big tech are doing to our ability to identify and think through problems. We should be equally worried about them making a grab for our ethos, what we care about, and at population scales.

#ai #bigtech #ethics

À partir de combien est-on trop riche ? La chercheuse belgo-néerlandaise Ingrid Robeyns pose la question dans son essai Limitarianism: The Case Against Extreme Wealth (Allen Lane, 2024). La philosophe et économiste y forge un concept inédit : le limitarisme. Son principe ? Limiter les fortunes individuelles à 10 millions d’euros pour bâtir un monde sans super-riches et combattre les inégalités extrêmes politiquement et moralement insoutenables.

https://usbeketrica.com/fr/article/et-si-on-limitait-la-fortune-des-riches-a-10-millions-d-euros

Et si on limitait la fortune des riches à 10 millions d'euros ?

À partir de combien est-on trop riche ? La chercheuse belgo-néerlandaise Ingrid Robeyns pose la question dans son essai Limitarianism: The Case Against Extreme Wealth (Allen Lane, 2024). La philosophe et économiste y forge un concept inédit : le limitarisme. Son principe ? Limiter les fortunes individuelles à 10 millions d’euros pour bâtir un monde sans super-riches et combattre les inégalités extrêmes politiquement et moralement insoutenables. Entretien extrait du numéro d'hiver 2026 de FUTUR, le magazine d'Usbek & Rica.

Un petit coup de vieux ?

@tomstafford

I've been waiting for the opportunity to use this!

#alttext #chatgpt #aimemes

"Je peux aussi lier cette étude intéressante qui a demandé à divers LLM de prouver des résultats subtilement faux, et qui a noté combien ils prétendaient y arriver : c'est assez mauvais (le meilleur modèle accepte encore de « prouver » des choses fausses dans 61% des cas)."
http://www.madore.org/~david/weblog/d.2026-05-22.2853.ai-and-math.html#d.2026-05-22.2853

https://matharena.ai/brokenarxiv/

David Madore's WebLog: Les LLM vont-ils tuer les mathématiques ?

David Alexander Madore's WebLog / Diary