283 Followers
148 Following
892 Posts

FR/EN

Account dedicated to #Offsec/#Infosec/digital stuff

Involved in
#UnifiedPush #MollyIm

Githubhttps://github.com/p1gp1g
Codeberghttps://codeberg.org/s1m/
Liberapayhttps://liberapay.com/S1m/
Bloghttps://s1m.fr

In March, Google got a lot of attention for claiming to have a quantum algorithm breaking elliptic curves w/ fewer than previously known resources but only released a (initially broken) zero-knowledge proof of it.

Now André Schrottenloher from Univ Rennes publishes an algorithm that requires similar ressources, even slightly reducing the amount of Toffoli gates, compared to the Google claim.
Congrats to André for advancing open science 💪🔬

🛠️: https://gitlab.inria.fr/capsule/qarton-projects/ec-point-addition
📃: https://arxiv.org/abs/2606.02235

CAPSULE / Qarton Projects / ec-point-addition · GitLab

Gitlab at Inria

GitLab

Spring time Raptor Lake update: a colleague wrote a workaround for the most common Firefox crash we were encountering in the zlib-rs library and it seems to be working. This confirms both my theory (and ryg's too) about the origin of the bug effectively being triggered by a MUX somewhere in the load/store unit malfunctioning because of the degraded clock. So let's dig in and see how you might possibly mitigate this on your system if it's affected.

https://bugzilla.mozilla.org/show_bug.cgi?id=1950764

🧵 1/10

1950764 - Crash in [@ zlib_rs::deflate::State::d_code] on Raptor Lake CPUs

RESOLVED (mh+mozilla) in Core - General. Last updated 2026-05-28.

Hi there. I'm alive and connected.

I hope I can work on NeoComment again before they cut the lines again.

Today I noticed the effect of adding DAV push from https://apps.nextcloud.com/apps/dav_push on the #Nextcloud server hosting my calendar.
I deleted a calendar entry in my desktop calendar while also having the calendar open on my phone and within two seconds it also was deleted there. 🤯
I guess for people in the walled garden ecosystem this is nothing worth mentioning but getting this working so easily while #selfhosting is awesome.

Anyway, huge thanks to @davx5app and @verdigado :)

DAV Push - Apps - App Store - Nextcloud

The Nextcloud App Store - Upload your apps and install new apps onto your Nextcloud

The pressure

for us in the #curl project right now

https://daniel.haxx.se/blog/2026/05/26/the-pressure/

The pressure

I'm doing Open Source primarily because I love it. The social aspects, the for-the-good angle and for the challenge of engineering this to work for everyone. I also do it because it is my full-time job and getting food on the table and provide for my family is not unimportant. It may come as a … Continue reading The pressure →

daniel.haxx.se

Oh, right! If you use Firefox on Android, the AI kill switch is available.

If you've set it on Sync, it should carry over, but it's still a good idea to check and flip it on any version that isn't connected to your sync profile.

https://blog.mozilla.org/en/firefox/ai-controls-firefox-mobile/

Still somewhat amazed that people don't know that Firefox has an AI kill switch. One of the first things I flipped when it became available.

AI controls are here for Firefox mobile | The Mozilla Blog

Mobile browsing is personal. It’s the link you open from a group chat because someone said, “Wait, is this real?” It’s the article you read in the

OK #Firefox users, this is a special request. I'm looking for someone with a high-end Raptor Lake machine that is experiencing instability in Firefox (or anything else for the matter). The best candidate is a CPU from the 13900* SKUs. K or not doesn't matter as long as it's one with the 8P+16E cores.

We have a potential workaround for one of the most common bugs of this CPU, but we need a broken machine to test it.

Passwords suck for Authentication. Can Passkeys replace them? - An Introduction to WebAuthn and Passkeys by Sylvain Kerkour #Infosec https://kerkour.com/passkeys
Passwords suck. Can passkeys replace them?

Did you know that most, if not the majority of data breaches originate from hacked credentials? Yep, that's right, if all you private information (and your family's too) got stolen and leaked 20 times a year, it's because employees at companies and governmental agencies can't manage to keep their passwords

Sylvain Kerkour

Working in that environment, seeing as Google rolled out the idea of "cloud computing" meaning "you have no involvement or agency in your computing because we do it for you" radicalized me for much of the work of my career.

It was one thing to run a datacenter to index the world's public web information. I understood that, it made sense.

But watching as Google and Apple co-developed the idea that computers, which I cared about, got abstracted into toys and jewelry that had all your key computing done in a way you had no agency over... where I saw firsthand the kinds of churn of resources necessary to keep these things going, it made me want to fight for a different computing future.