Wladimir Palant

3.4K Followers
8 Following
6K Posts

Software developer and security researcher, browser extensions expert. / searchable

#infosec #cybersecurty #cryptography #privacy

Websitehttps://palant.info/
PronounsHe/him
Sooooo helpful of Linux to spend half an hour trying to copy a file to a flash drive only to abort with a cryptic error eventually. I was suspecting a drive error but the problem turned out far more mundane: FAT32 simply cannot store files larger than 4 GiB. Surely this could have been reported immediately?

“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.”

Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now…

#CommandInjection

The AI Bubble — No One's Happy

The AI buildout is the largest capital expenditure in the history of the technology industry. The financial structure holding it together has a name.

No One's Happy
PSA Brave is run by a religious zealot homophobe who has a history of wanting to take away civil rights from people and is fueled by money from Peter Thiel.
Not getting any reactions to this post initially, I was worried that this kind of experience was impossible for normal people to relate to. But now that three other freaks found my post I am very much relieved. 😁
Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…
Has been a while since I’ve been releasing software. So it’s interesting to watch the news after Gnome Commander 2.0 release. I mean, there are the obvious LLM-generated articles flooding the zone with shit. And then there is the seemingly well-written article featuring a Windows screenshot of a Linux application, crediting Midjourney for it. At which point the realization dawns that the content is merely an approximate translation of a proper human-written article.

RE: https://mstdn.social/@jschauma/116610268796045193

Any site that implements Google's QR reCAPTCHA goes on my PERMANENT block list.

Don't care what site it is...

RE: https://mstdn.social/@jschauma/116610268796045193

So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

progress