Nicolás Alvarez

522 Followers
194 Following
2.9K Posts
Currently hacking and documenting Apple stuff for fun and no profit.
Twitterhttps://twitter.com/nicolas09F9
LocationBuenos Aires, Argentina
Liberapayhttps://liberapay.com/nicolas17

This is peak malicious compliance and I love it

https://sightlessscribbles.com/posts/the-paperwork-flood/

Edit : the blog author is on the fediverse if you want to follow him here, and he maintains a follow page on his site with many options!

The 'Paperwork Flood': How I Drowned a Bureaucrat before dinner., Sightless Scribbles

A fabulously gay blind author.

Dad bought a FIDO2 key. He goes to bank website, clicks "add security key", website says "to verify your identity you need an authorization code, call [phone number] to get it".

Calling that number gets you a voice bot that doesn't even remotely understand what you need and offers you unrelated options.

– I want to add a security key.
– you want to see if your check has cleared, please answer yes or no.
– no.
– [old IVR-style menu with unrelated options]

Since the bank's AI support is making his life harder, my dad is approaching the problem by throwing more AI at it and asking chatbots for help. It's not going well either.

The `left-pad` incident was 10 years ago today.

https://en.wikipedia.org/wiki/Npm_left-pad_incident

Thankfully, we've completely solved software supply chains in the years since.
npm left-pad incident - Wikipedia

Sunday is the 10-year anniversary of the npm left-pad incident.
npm left-pad incident - Wikipedia

Or maybe I should just get an LSP plugin for Vim 🤔

I accidentally updated VS Code when I updated the rest of my distro and now it has an AI Chat panel by default, the plugins panel has a whole section for MCP servers, etc etc.

How far back do I need to downgrade to?

GitHub - nevesnunes/z80-sans: OpenType font that disassembles Z80 instructions

OpenType font that disassembles Z80 instructions. Contribute to nevesnunes/z80-sans development by creating an account on GitHub.

GitHub
@jcreed Jason I have wanted to give a !!Con-style talk on how insanely small GNSS signals are because I just cannot even begin to fathom it.

-107dBm is pretty good for a radio protocol carrying data -- I think Bluetooth LE tends to bottom out around -105 dBm, with most receivers being sensitive more to like -90 or -95 dBm. but once you only have to correlate *known* data, holy shit, you can get to the truly bonkers stuff.

if you have no idea where you are or what time it is, Sony's receivers can get a lock down to -149 dBm [1]. if you already have an almanac and vaguely know what time it is, you can get a lock down to -163 dBm. and once you already have a lock on some satellites and you're just tracking them, you can keep tracking them down to -167 dBm.

-167 dBm! what the FUCK! and they can do this while consuming just 6 mW of power!

IMO this is one of the most magical things we have ever built.

[1] https://www.sony-semicon.com/en/products/lsi-ic/gps.html
GPS/GNSS Receiver | Products & Solutions | Sony Semiconductor Solutions Group

Sony Semiconductor Solutions Group develops device business which includes Micro display, LSIs, and Semiconductor Laser, in focusing on Image Sensor.

Sony Semiconductor Solutions Group

@bagder IANA just published a new field for the security.txt (RFC 9116) format: "Bug-Bounty: True/False".

The @RIOT_OS team is receiving an increased amount of presumably LLM generated bogus vuln reports (though nowhere near curl levels). And since we deployed a security.txt, scrapers started sending emails inquiring about our bug bounty programs.

I was hoping that if that field gets some visibility, scrapers might filter for that before spamming the security inboxes.

https://www.iana.org/assignments/security-txt-fields/security-txt-fields.xhtml

security.txt Fields

Ageless Linux — Software for Humans of Indeterminate Age