brk, a.k.a. @evanrichter

@brk@infosec.exchange
115 Followers
267 Following
1.7K Posts
Security, Rust, Reverse Engineering, CTF with PwnFirstSearch
githubhttps://github.com/evanrichter
bird@evanrichter
CTFbigrick

new post about how you can choose not to use #Nix to manage some parts of your configuration, how to do it, and the benefits you get from doing that

instant changes, no rebuilds, and you can still get pinning for dependencies
https://jade.fyi/blog/use-nix-less/

You don't have to use Nix to manage your dotfiles

computers i guess

watt-hours per memory corruption bug

I wrote a post on the rust blog about functions that have no clothes:

https://blog.rust-lang.org/2025/07/03/stabilizing-naked-functions/

#rustlang

Stabilizing naked functions | Rust Blog

Empowering everyone to build reliable and efficient software.

title text: It's important for devices to have internet connectivity so the manufacturer can patch remote exploits.

(https://xkcd.com/3109)
(https://www.explainxkcd.com/wiki/index.php/3109)

Lately, I've been getting a lot of questions about travel and border security. Here are some resources I've compiled, in no specific order.

Is it safe to travel with your phone right now?

https://www.theverge.com/policy/634264/customs-border-protection-search-phone-airport-rights

Is it safe to travel with your phone right now?

Customs and Border Protection searches of phones and laptops at airports are on the rise, sometimes leading to deportations. What are your rights? The answer: it depends.

The Verge

Let's do more ranked choice voting, please.

#nyc

When you take a software dependency, that is Your risk, not the author’s
LOL. lmao, at this google-brained take. What part of WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND don’t these companies understand? There is absolutely no “supply chain” here. The authors did not “supply” anything not claimed in the license. Not even uptime or stability guarantees 🙄
https://abyssdomain.expert/@filippo/114723318068853623
Filippo Valsorda :go: (@filippo@abyssdomain.expert)

Amongst other things, there's an open source software supply chain story here. This Android library with 174 stars and one maintainer has taken down Monday.com, Eventbrite (!!!), UPS, Kraken, Lowe's, YBS, IKEA, Agibank, iFood, PagBank, pago.ro, and Udemy. Again, this is the same failure mode that caused outages in 2023. https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993753426

Mastodon
Hey Germans, please come up with a word that means "the fear of typing `return` vs `shift-return` because you don't know which inserts newline and which sends the message"

Who in their FUCKING mind would use YAML, like ever?

If someone suggests to you to just use YAML, you have instant proof that this person is not your friend, does not want the best for you and actually tries to sabotage you and your efforts.

What a fucking clusterfuck.