212 Followers
92 Following
1.4K Posts
26 yo 🇫🇷 💻👨‍💼, I do lots of Game Boy dev in my spare time—FLOSS is where it's at. I enjoy infosec a lot too!
(Interested in Game Boy dev? Start here: https://eldred.fr/gb-asm-tutorial)
#NoBot
Websitehttps://eldred.fr
Codeberghttps://codeberg.org/ISSOtm
Duck🦆

A/B testing, or as I prefer calling it: what if we purposefully messed with our users’ memory to see which option “gives more engagement”

i wish everyone who does that a very Please Fucking Stop

So, I recently saw some quiet discussion about a paper where researchers reverse-engineered and disclosed some attacks against PhotoDNA, the very-super-duper-secret algorithm used by tech megacorps to scan for illegal images.

They didn't make any code public, and so... I did: https://github.com/ArcaneNibble/open-alleged-photodna

A _complete_ reverse-engineering and commented Python reimplementation of the algorithm from publicly-leaked binaries.

This means that studying the algorithm and any potential flaws is now much more accessible.

This took only about two days (once I knew that there even _was_ a leaked binary to compare against), which just goes to again show that security through obscurity never works.

🔁 encouraged

GitHub - ArcaneNibble/open-alleged-photodna: because research belongs to _everybody_

because research belongs to _everybody_. Contribute to ArcaneNibble/open-alleged-photodna development by creating an account on GitHub.

GitHub
@Laz_uli Salut alors une amie a boost un de tes toot et j'ai vu la pfp et j'ai rigolé. Belle réf. 🦧 Voilà bsx bonne journya~
judging online information quality based on site where it appeared: a comprehensive guide

- "How To (...)" in the title, cookie banners, lots of side-information written in a way that wastes your time: SEO slop, don't bother. You might as well make a wild guess, same likelyhood it'll be correct

- official docs for $x, autogenerated by a rube-goldberg machine and automagically pushed into whatever-pages by a fully-skidoodled, post-quantum CI pipeline: describes everything, except the exact fact you're looking for.

- no HTTPS, tilde in the name, DNS with 4+ dots, likely hosted on some dusty uni server, white background with absolutely no CSS: one of the best resources on the subject. you question how it's even still online

- site titled "Garry's blog", default wordpress favicon, last update either previous month or 12 years ago: golden. crystal-clear exposition, good examples and screenshots framed so well you don't even need arrows pointing places. likely used as a cheat-sheet daily by everyone in the community

GIANT BAPPERS APPRECIATION POST

Canada Lynxes have such enormous paws, I love them!!!

Hi #fediverse. We need to talk about something.

While talking to a colleague about how I recently learned most people have never sat on a cow it came up that she has never sat on a horse. Like, not even once during childhood.

Another colleague admitted they also have never sat on a horse.

My hypothesis is that most people have at one point in their life sat on a horse.

🏇 🐎 🐴

Have you sat on a horse?

Please boost for scientific accuracy.

Yes
77.7%
No
22.3%
Poll ended at .

"Healthy people cost less.
Educated people contribute more.
Housed people are more stable.

...in a healthy society there are no "undeserving".
There are just people."

Brendan Eich and his consequences have been disastrous for the human race #javascript #AlsoBigotryIGuessButItsMostlyJSReally
A few years ago I designed a way to detect bit-flips in Firefox crash reports and last year we deployed an actual memory tester that runs on user machines after the browser crashes. Today I was looking at the data that comes out of these tests and now I'm 100% positive that the heuristic is sound and a lot of the crashes we see are from users with bad memory or similarly flaky hardware. Here's a few numbers to give you an idea of how large the problem is. 🧵 1/5
@K4_713 Exactly!

The only thing really stopping my coop idea, aren't tech problems:

A) Trust
B) Getting enough people on the same page ( aka Management )

I can't do either. I'm too close to the silicon.