
OMG. Apparently tons of people have been generating secrets on an old server-side key generation website that had incredibly weak entropy. Like, 10 bits or something.
The website was allkeysgenerator[.]com. Here is a dump of 1000 keys generated on it. Searching for the URL finds hundreds of people recommending it for key generation.
Some of these snippets have hundreds of GitHub results.
The exact algorithm is unknown but (see below) It generates extremely predictable strings, you can visually see how the delta from character to character is almost constant. Thanks @dramforever for doing some analysis here. Their script here can generate the vast majority of sequences from this website.
Update: This script generates the entire list from a single seed, and large chunks of another.
I'm certain you can break into production websites using these keys for cookie signing etc.
Project I'd love to see:
A cross-distro collab to track ensloppified upstreams, last-trusted versions of them, and sets of backported security & general important bugfix patches.
Divided this might seem untractable, but working together, I think it's very practical to render the compromised upstreams irrelevant.
2/3
Libraries are more than buildings filled with books. They are an interconnected public network built on preservation and sharing.
“If we don’t have the one you want, we can get it for you,” is a promise shaped generations of readers through interlibrary loan, public access, and librarians committed to making knowledge available to everyone.
"LLMs impress writers who don’t want to write, coders who don’t want to code, researchers who don’t want to research, and lawyers who don’t want to actually understand case law. Those who desperately tell you how powerful AI is and that you simply must use it are looking for you to validate their own laziness or aversion to effort, and those who are impressed by LLMs’ outputs tend to be people with low standards"
"Revenge of The Business Idiot"
Ed Zitron
https://www.wheresyoured.at/the-revenge-of-the-business-idiot/
*pues eso!

If you liked this piece, you should subscribe to my premium newsletter. It’s $70 a year, or $7 a month, and in return you get a weekly newsletter that’s usually anywhere from 5,000 to 18,000 words, including vast, detailed analyses of NVIDIA, Anthropic and OpenAI’s
We demand action, loudly.
Half a million marched in Montreal with Greta for real, effective, climate action. Largest demonstration in history in Canada.
RE: https://wandering.shop/@clacksee/116639351820042391
😂 exactly this