269 Followers
798 Following
2K Posts
random clueless person from the internet
occasional accidental poet
fool with a keyboard
goes by kyrievo in some places
#noarchive #nobot #nobridge #noindex #noml
Accept-Languagede, en
Accept-Pronounshe/him
LocationLeipzig, Germany
Keyoxidehttps://keyoxide.org/7287c01a721c8432e525865a12b4df8abcf3f024
Websitehttps://mkhl.codeberg.page
Header-Byhttps://cohost.org/forSyn/post/5386177-was-requested-i-post
FOUND IT
Warum ist das nicht in den Schlagzeilen: In Offenbach a.M. hat die AfD ihr Ergebnis HALBIERT. Wenn sofort "AfD stärkste Kraft!" kommt, wenn sie in einem Wahlkreis knapp mit 25 % auf Platz 1 liegt, warum werden ihre Niederlagen verschwiegen? Warum sind es nur News, wenn die AfD gewinnt? https://www.volksverpetzer.de/analyse/kommunalwahl-ergebnis-ioffenbach-halbiert/?utm_source=mstdn

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

heard "be the elephant you want to see in the room" earlier and gosh if that hasn't stuck with me

Ein Bundestagsabgeordneter.

Der AfD.

Verschickt.

Rechtsextreme Comics.

An GRUNDSCHULEN.

WAS? DENN? NOCH?

AfD-Verbot JETZT!

https://www.ndr.de/nachrichten/mecklenburg-vorpommern/afd-abgeordneter-grimm-schickt-rechtsextreme-comics-an-grundschulen,afd-1050.html

[EDIT: now sorted thank you SO MUCH!]

Heads up my dudes, my son needs to do work experience this summer and he's a programmer. Nearly 15, can do 3 decent languages, main in Java, been programming since 4. All he wants to do is be a developer. Anyone offer work experience these days? Two weeks in July. London or Dartford way or anywhere in between. Ta! Retoots appreciated!

#workexperience #help

zomg I *just* realized:

LLMings 🤣

It was there the whole time!

(apologies if y'all figured out that joke already long ago…it literally just occurred to me!)

Endlich!
Die deutsche Alternative von Claude Code ist live!

TÜV geprüft
BSI zertifiziert
Fax ready

klausprogrammieren.com/
Klaus Programmieren™

Digitale Kodierungslösung der Bundesrepublik Deutschland. TÜV-geprüft, BSI-zertifiziert, FAX-ready.

for whoever needs to hear this: you're not alone. i'm not vibecoding any of the software i write. i'm writing it by hand, but i've leveled up my emacs with eglot/lsp. i'm modernizing my stacks and use languages with excellent compilers. i think about how to do more with less. i'm trying to combine the best human-written libraries and modules and assemble them with minimal boilerplate. i enjoy reading your manuals and references. i believe in robust, secure, human-written software.
stolen for alt text