David Dorward

@dorward
15 Followers
312 Following
981 Posts
UK software engineer, tabletop gamer, painter of miniatures, LARPer, and hacker of things. he/him. 🔸
Homepagehttps://dorward.uk/
Bloghttps://thecoreworlds.xyz/
Githubhttps://github.com/dorward
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platforms via @pushcx https://lobste.rs/s/tsrast #privacy #security
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platforms | Lobsters

I probably should have done it a while ago, but that’s all my site-previously-known-a-Twitter accounts deactivated. One of them had been around for aproaching 20 years.

The "security" tool by Bambu has been "hacked" in minutes. Well, you cannot call hacking to just checking the poorly obfuscated JavaScript code inside a crappy Electron app.

https://hackaday.com/2025/01/19/bambu-connects-authentication-x-509-certificate-and-private-key-extracted/

Bambu Connect’s Authentication X.509 Certificate And Private Key Extracted

Hot on the heels of Bambu Lab’s announcement that it would be locking down all network access to its X1-series 3D printers with new firmware, the X.509 certificate and private key from the Ba…

Hackaday
The big lesson here is that centralization and very large platform power is the problem, as can be seen in the US right now with Elon’s takeover of Twitter, TikTok’s shutdown and Zuckerberg’s lurch to the right.

I idly looked up how to disable an internal laptop keyboard on windows 10, and the solution people have come up with is very silly:

you go into device manager, find the keyboard, and switch it to a driver that doesn't work with your keyboard

Oh dear. What a pity. Someone had their “not road legal in this country” Deplorian taken away from them.

https://www.bbc.co.uk/news/articles/cz0lldd30xlo.amp

Driver stopped in Tesla Cybertruck banned in UK - BBC News

The eye-catching vehicle, which carries a price tag of about ÂŁ48,000, is not yet legal on UK roads.

BBC News

I couldn't find any good games for my password manager. So I made one.

1Crossword connects to your 1Password vault and generates a crossword entirely out of your passwords!

The crosswords are fun, simple, and great for sharing on social media when you finish. Enjoy!

@jonty it blows my mind that someone sells a device that sticks onto the windscreen, and people plug it into their car's CANbus and let it drive them around.

10,000 users on the roads, and a disclaimer that says "THIS IS ALPHA QUALITY SOFTWARE FOR RESEARCH PURPOSES ONLY. THIS IS NOT A PRODUCT. YOU ARE RESPONSIBLE FOR COMPLYING WITH LOCAL LAWS AND REGULATIONS. NO WARRANTY EXPRESSED OR IMPLIED."

I'm beginning to think humans were a mistake, let alone computers.

Did you know that #XScreenSaver (yes, the collection of screensavers for X11) is available on Android?

And that #Google requires it to have a privacy policy in order to be available in the Play Store?

And that the maintainer chose to crowd-source a privacy policy where every item starts with "Unlike Google"?

It's become a great list of all the privacy violations Google did and still does. And I thought that it's gonna be long, but it's even longer than I imagined.

https://www.jwz.org/xscreensaver/google.html

2. Just today, I made a comment on an official Instagram post on Threads. I immediately had two clear low quality accounts quote my reply, separately, and tell me to DM them on Telegram with my Cash App or PayPal for a "new year blessing." I reported both. Almost immediately, both reports were closed, and I was told the posts don't go against their standards.