brk, a.k.a. @evanrichter

124 Followers
286 Following
1.9K Posts
Security, Rust, Reverse Engineering, CTF with PwnFirstSearch
githubhttps://github.com/evanrichter
bird@evanrichter
CTFbigrick

One of my favorite features of the Baochip-1x is the BIO. It's an I/O coprocessor that is based on the PicoRV32, with custom register extensions to allow direct access to GPIOs from the ISA.

Read more about the BIO at this blog post: https://www.bunniestudios.com/blog/2026/bio-the-bao-i-o-coprocessor/ I go in-depth into the architecture and its trade-offs relative to the PIO, and conclude by working through a couple of coding examples.

It's been a monumental effort, but we are finally OpenSSL free in the whole Kanidm stack - compact_jwt, hsm/tpm, webauthn-rs, kerberos/libkrimes and today Kanidm itself.

I've released difftastic 0.68! A smaller update, but still worth upgrading:

* Improved Bash, C, Go, Lua, Nix, Perl, Python, Rust, Scala, Swift and YAML parsing.
* Minor display and git compatibility fixes.

https://github.com/Wilfred/difftastic/releases/tag/0.68.0

raven-uxn now has an x86-64 assembly backend (yay!)

and it's about 2x faster (yay!!)

and the first draft was written by Claude (booo!)

and then I rewrote most of it, which made it even faster (yay!)

and introduced a memory corruption bug (booo?)

which Claude is better at debugging than I am (.......?)

--------

if you too have complicated feelings about our robot buddies, you may enjoy my writeup:

https://www.mattkeeter.com/blog/2026-03-15-uxn/

An x86-64 backend for raven-uxn

Porting 2000 lines of ARM64 assembly to x86-64, with the help of a robot buddy

This is quite awesome - successful Xbox One ROM glitching, by Markus "doom" Gaasedelen: https://www.youtube.com/watch?v=FTFn4UZsA5U

Congratulations!

RE//verse 2026: Hacking the Xbox One

YouTube

~6 months ago I posted about how a LiveCTF competitor won a few challenges with a an AI bot in the background.

Since then, I've been seeing versions of the "LLMs have ruined CTFs" discussion occur in bits and pieces, but haven't found anything consolidated... are there any good writeups or discussions out there?

Particularly interested in the area of "what LLMs are not good at" or even anti-LLM techniques beyond attempting prompt injection.

mom take me home, there are people who use nano on here

Ivan Fratric shares some tips and tricks for grammar fuzzing

https://projectzero.google/2026/03/mutational-grammar-fuzzing.html

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar t...

RE: https://functional.cafe/@manpacket/116178060408287449

array_windows() babyyyyy this is not a drill 🚨🚨

Dabao has launched!!!

Open hardware, firmware, software from @bunnie !

https://www.crowdsupply.com/baochip/dabao/updates/our-campaign-has-launched

Our Campaign Has Launched!

Today marks the start of the Dabao campaign. If you're interested in open source hardware, security, or trust, I'm offering you a chance to order some of the first evaluation boards for a mostly-open, security-oriented microcontroller. Dabao is an evaluation board for the Baochip-1x SoC, a microcontroller that raises the bar on inspectable hardware, bringing you a system-on-chip (SoC) that you can check from the silicon all the way to the software.

Crowd Supply