Matthew Garrett

16.1K Followers
168 Following
6.6K Posts
Former biologist. Actual PhD in genetics. Security at Nvidia, OS security teaching at https://www.ischool.berkeley.edu. Blog: https://codon.org.uk/~mjg59/blog . He/him.
Bloghttps://codon.org.uk/~mjg59/blog
Signal@mjg.59
Oh wow https://support.apple.com/guide/deployment/app-management-updates-depd567c9ffa/1/web/1.0 looks like it enables some extremely interesting things in managed environments
WWDC26 app management updates

The following are app management updates from WWDC26.

Apple Support
@baloo @cadey Eh it depends heavily on how it's implemented, but if you're willing to change the registered callback for whatever ends up passing the token back to the VPN (assuming it's not just hitting localhost) then yes
@cadey I may have committed some crimes with auth dialogs to be able to pop a browser in the user context due to impedence mismatches, but the apparent complete lack of documentation of what external-user-interface means is just bewildering
(Sorry, for internal tooling, I can release the writeup but the plugin would not be useful to anyone)
Been writing a Network Manager VPN plugin lately and woo boy is it hard to figure out how all of this works so I guess I should write that up
@jwz as a few others have said, the Broadlink stuff with RF support is basically bulletproof - I REd their local protocol about a decade ago and thankfully they haven't decided to break it since, although if you go through setup with their app it may enable cloud mode (you can just disable it again). The main alternative that doesn't involve hacking stuff together yourself is the Bond Bridge, but I have no personal experience of it.
I’ve always wondered if ESR’s real objections to the cathedral model was that no one wanted him in the cathedral
Rewatched https://en.wikipedia.org/wiki/Killer_Net and was astonished to discover that the music was composd by Simon Boswell, better known for his work on Hackers (cc: @jonty)
Killer Net - Wikipedia

@woo sigh yes all of these numbers are meaningless but how do I translate one number into another given the assumptions made in the original number, which are theoretically consistent given all vendors use the same system
@dysfun No, you explicitly referenced a characteristic that was irrelevant to the scenario in question