‼️ zei

@zei
56 Followers
47 Following
383 Posts
I write some code, and get paid both to break and fix things.
THAT'S RIGHT, MOTHERFUCKERS, I WON A WEBBY AWARD. Here's my 5-word speech. #webbys
The folks at iTerm2 figured out a way to get arbitrary code execution as the result of cat <file>, which is... impressive?
@viticci but… is using anything by OpenAI even remotely moral at this point? Even if you look past all the theft, there is still the pentagon deal, the ties to trump..

Another wild fear tactic being pressed on tech workers right now is the “permanent underclass.”

Idk anyone who’s is worried about this myself.

But to those who are worried about this:

Class struggles will not be fixed by getting “in” on AI. It’ll be fixed by collective action and labor rights.

So let me see if I have this right:

Not only did BlueSky accept $100 million in funding from a Bain Capital Crypto - an obviously crypto associated investment firm - but a few weeks ago the notably transphobic CEO stepped down, not to leave the company, but to allow an AI-boosting, investment fund asshole figurehead take over the CEO position while she continues to pollute the C-suite elsewhere?

Yeah.

Yeah, that sounds like it's going to turn out GREAT.

I am POSITIVE this is going to be the bastion of safety and community that people keep telling me it is. I'm sure NOTHING will go sideways.

https://bsky.social/about/blog/03-19-2026-series-b

https://bsky.social/about/blog/03-09-2026-a-new-chapter-for-bluesky

Bluesky's 2025 $100M Series B Lays Foundation for Open Social Web - Bluesky

In April 2025, Bluesky raised $100 million in Series B funding led by Bain Capital Crypto. Since our Series A, we've grown from 13 million to over 43 million global users.

Bluesky

> The leak, which Meta confirmed, happened when an employee asked for guidance on an engineering problem on an internal forum. An AI agent responded with a solution, which the employee implemented – causing a large amount of sensitive user and company data to be exposed to its engineers for two hours.

lol and - furthermore - lmao

https://www.theguardian.com/technology/2026/mar/20/meta-ai-agents-instruction-causes-large-sensitive-data-leak-to-employees

Meta AI agent’s instruction causes large sensitive data leak to employees

Artificial intelligence agent instructed engineer to take actions that exposed user and company data internally

The Guardian

The "Bluetooth Headphone Jacking" talk at #39c3 was awesome, too. They reversed a popular SOC that powers Bluetooth earbuds and headphones.

They found that (even without being paired to the headphone), they could dump flash and RAM from the device. Then they dumped a bunch of info from the device - e.g. the #Bluetooth address and "master" encryption keys used for the communication with paired devices (e.g. a #phone).

Then they impersonated the headphone from their laptop and connected to the phone (pretending to be the headphone).
The headphone (or the laptop impersonating the phone) has permissions to do some things on the phone, e.g. accept calls, increase/decrease volume, etc.

Then they started recovering access a #WhatsApp account via some account recovery mechanisms. That required some one-time security key which would normally be delivered via SMS, but that could be delivered via phone call as a fallback option, too. Since the phone thought it was connected to the Bluetooth headphone, phone call audio would go to the laptop via Bluetooth.

As the cherry on top, they escalated into the victim's #Amazon account.

Scary shit. #YouCannotBeParanoidEnough #security

Do you use Spotify Premium? Cancel your subscription until Spotify stops running ICE ads. There are other streaming options that don’t profit from exploiting artists while recruiting for ICE: https://indivisible.org/cancel-spotify?source=mastodon #CancelSpotify
This mastodon client came to me in a fever dream.
I had to waste the whole day, but now you too can bunnyhop through your fedi feed.
https://files.burning.homes/experimental/hall-of-toots/index.html

* webgl required
* mobile somewhat supported
* yes this html file is a whole client and the entire source
* it would run smoother and look better if you launch it locally so it don't have to bypass CORS, but oauth won't work and you'll have to use access token
* you can click urls and images
* you don't really have to login, and can just hop around the public timelines (i.e. Instance = https://mastodon.social , empty token, Federated timeline, Use Access Token)
* but I'm too tired to support CW and sensitive, so it'll kinda be full of porn
* admins will hate you
* 429 error means you won
* I am in dire need of salvation