105 Followers
109 Following
1.3K Posts
Geeky software developer, wannabe noise maker and c-base crewmember living in Berlin.
...

Today in InfoSec Job Security News:

I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

Build software better, together

GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

GitHub
TIL: “ai;dr”
Do you ever feel like you missed your calling, and were meant to be touring the countryside in a motorcycle & sidecar with your well dressed badger best friend, solving minor mysteries and enjoying tea & adventure?

THOUGHT FOR THE DAY:

The singularity has been cancelled.

What we're getting is wall to wall spam generators, optimized for passing the (modified) Turing test and convincing gullible humans that they are "intelligent".

Instead of the singularity, we are getting the spamularity.

Because a LOT of people are missing the point:

No, Elon Musk is NOT serious about putting a million data centres into orbit. It can't work: laws of physics say "nope".

But SpaceX is expected to go public this year.

Elon is talking up his company's future prospects in front of gullible investors because he needs a growth narrative beyond Starlink, which is already priced in. Something to justify the Starship proram beyond NASA's lunar ambitions.

So it's salesman's bullshit, lies for fools.

The internet was not a mistake
Social media was not a mistake

Allowing Corporations to dictate and control both of these things was the mistake.

Are you YES AI or NO AI? Vote now.

Big Tech doesn't care if you want AI or not. They should.

Package managers keep using git as a database, it never works out.

https://nesbitt.io/2025/12/24/package-managers-keep-using-git-as-a-database.html

Package managers keep using git as a database, it never works out

Git repositories seem like an elegant solution for package registry data. Pull requests for governance, version history for free, distributed by design. But as registries grow, the cracks appear.

Andrew Nesbitt

I don't think I'll stop using Firefox anytime soon.
Yes, their management are fucking idiots and it's annoying that I'll have to disable new AI features whenever they release them..

But the alternative is to use something Chromium-based, which would make Google's domination of web technology absolute - and Google is 100x more evil than Mozilla ever could be.

I hope this fucking bubble pops before Mozilla fucks up Firefox so badly that it becomes completely unusable