Gareth Bowker 

100 Followers
476 Following
462 Posts
Pilot, runner, skiier, traveller, once described as a “stealth geek”. Security and privacy research are my thing work-wise
LocationCardiff, Wales
Workhttps://paysec.uk
Gravatarhttps://gravatar.com/garethbowker

A plaque in Iceland
#climate change

A letter to the future
"Ok" is the first Icelandic glacier to lose its status as a glacier.
In the next 200 years, all our glaciers are expected to follow the same path.
This monument is to acknowledge that we know what is happening and what needs to be done.
Only you know if we did it.

August 2019
415ppm CO2

This explains a lot about what I’ve been experiencing with combatting scrapers. https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy - Include Security Research Blog

In this post we look under the hood of BrightData's SDK and how it turns ordinary consumer TVs into exit nodes of an enormous commercial, residential proxy network leveraged by the AI industry to scrape web data and train language learning models.

Include Security Research Blog

So I’ve just had a quick play with this and yes, it works. Essentially BitLocker has a backdoor. https://github.com/Nightmare-Eclipse/YellowKey

Mitigation = BitLocker PIN and BIOS password lock.

GitHub - Nightmare-Eclipse/YellowKey: YellowKey Bitlocker Bypass Vulnerability

YellowKey Bitlocker Bypass Vulnerability. Contribute to Nightmare-Eclipse/YellowKey development by creating an account on GitHub.

GitHub

Holy shit this is detailed. Can you believe the hubris to silently collect all this information on users?

#privacy

https://browsergate.eu/how-it-works/

The Attack: How it works

Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy. This page documents exactly how the system works, with line references and code excerpts from LinkedIn’s production JavaScript bundle.

BrowserGate

WOW! This is insanity!

Who’s responsible for rising RAM prices? One culprit: OpenAI.

They locked up 40% of all DRAM supply—without any obligation to buy any of it! Now that they scrapped plans to expand their data centre in Texas, prices are falling fast!

As a result, suppliers like Micron are in free fall!

https://thedeepdive.ca/openai-locked-up-40-of-global-ram-with-no-obligation-to-buy-any-of-it/

OpenAI Locked Up 40% of Global RAM With No Obligation to Buy Any of It | the deep dive

In October 2025, OpenAI CEO Sam Altman flew to Seoul and signed letters of intent with Samsung Electronics and SK Hynix — the world’s two largest memory chipmakers — targeting 900,000 DRAM wafer starts per month. Analysts estimated that volume at roughly 40% of global supply. South Korean President Lee Jae-myung stood alongside the chipmakers […]

the deep dive
Wow: Meta has been working on plans to add facial recognition technology to its AI smart glasses. nyti.ms/3Os1oxf And this was the company’s cynical view on when, and how, to do it:

Astrophotographer snaps 'absolutely preposterous' photo of skydiver 'falling' past the sun's surface | Live Science

This photo is breaking my brain. 🤯

https://www.livescience.com/space/the-sun/astrophotographer-snaps-absolutely-preposterous-photo-of-skydiver-falling-past-the-suns-surface

Astrophotographer snaps 'absolutely preposterous' photo of skydiver 'falling' past the sun's surface

Astrophotographer Andrew McCarthy has snapped a striking shot of a skydiving YouTuber perfectly aligned with the fiery surface of the sun. The unlikely image, dubbed "The Fall of Icarus," required meticulous planning to pull off.

Live Science

My webinar on making printed and digital content #accessibility is now available as a standalone video with descriptions and captions in: English, Ukrainian, Malay, Arabic, Czech, German, French, Hindi, Italian, Japanese, Portuguese, Serbian, Spanish.
https://youtu.be/AO9XXkrACtU?si=tANmv5xDWgwZ10Ay
Inclusive content is better content for all, not only people with rare or even common conditions.

Thank you #RareDiseaseDay #Eurodis

Accessibility for Printed & Digital Content

YouTube

📣THREAD: It’s surprising to me that so many people were surprised to learn that Signal runs partly on AWS (something we can do because we use encryption to make sure no one but you–not AWS, not Signal, not anyone–can access your comms).

It’s also concerning. 1/

Roo reaction

[description: kangaroo checking out a Halloween display is scared by the cackling skeleton -- you can see the roo running away far down the street]

#kangaroo #roo #animal #halloween #humor #humour