<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-29T21:39:13Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Royce Williams</title>
  <author>
    <name>Royce Williams</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z.rss" />
  <link href="https://nostr.ae/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z" />
  <id>https://nostr.ae/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/108/195/621/247/550/549/original/d96204cc09c9dbfe.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/108/195/621/247/550/549/original/d96204cc09c9dbfe.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs0fda5tx7w0htr628hmf2nd4ypkgglzt7mew8pujq6mth257xtdqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kqkmnr</id>
    
      <title type="html">There&amp;#39;s also at least one service that provides legal-level ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0fda5tx7w0htr628hmf2nd4ypkgglzt7mew8pujq6mth257xtdqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kqkmnr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxtncag0dcnnxkkvun2034c4z252e455j3uwaeg32fuya6m7q0lpqsqrfn2&#39;&gt;nevent1q…rfn2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;There&amp;#39;s also at least one service that provides legal-level monitoring as a service -- basically they put a very specific kind of lien on the property that triggers them being notified if there&amp;#39;s a change to it
    </content>
    <updated>2026-06-16T19:06:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstve885eaced5gaydhdmlkeraf44gkpw3xsvfn6rqc7ylsqzymq7czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qukyz4</id>
    
      <title type="html">Uh, this was *always* true, Dark Reading. Phishing training was ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstve885eaced5gaydhdmlkeraf44gkpw3xsvfn6rqc7ylsqzymq7czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qukyz4" />
    <content type="html">
      Uh, this was *always* true, Dark Reading. Phishing training was *always* disproportionately punishing the victim by ineffectively treating the symptom instead of tackling the root cause.&lt;br/&gt;&lt;br/&gt;The goal was always to make the controls render natural user behavior less harmful.&lt;br/&gt;&lt;br/&gt;AI only speeds up the impact of not having been fixing the problem at the right level all along.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.darkreading.com/cyberattacks-data-breaches/beginning-end-social-engineering&#34;&gt;https://www.darkreading.com/cyberattacks-data-breaches/beginning-end-social-engineering&lt;/a&gt;
    </content>
    <updated>2026-06-16T05:27:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd5nqxxkcn58s258jhvl7zf05s4g3s6jx9xxj5cxh45emvw08z3qgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rsk3c0</id>
    
      <title type="html">RE: https://social.coop/@shauna/116737114240403155 This is a post ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd5nqxxkcn58s258jhvl7zf05s4g3s6jx9xxj5cxh45emvw08z3qgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rsk3c0" />
    <content type="html">
      RE: &lt;a href=&#34;https://social.coop/@shauna/116737114240403155&#34;&gt;https://social.coop/@shauna/116737114240403155&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is a post about cyber security.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note16xptmhcvyuhms38vnmxj0a09v6t6f5matscwwjumyaawwcjfq58qdy38ug&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note16xp…38ug&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; there&#39;s a confidence that comes from thinking you&#39;re always right, and a confidence that comes from being okay with being wrong &lt;/blockquote&gt;
    </content>
    <updated>2026-06-12T15:50:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0rg4guch5jvryp2kfpd5epnuu6wthl5yqapprd9w2ewj50mqj97szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceq2zg</id>
    
      <title type="html">Did you know that in many cultures, it&amp;#39;s considered good luck ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0rg4guch5jvryp2kfpd5epnuu6wthl5yqapprd9w2ewj50mqj97szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceq2zg" />
    <content type="html">
      Did you know that in many cultures, it&amp;#39;s considered good luck to share your food with a dog?&lt;br/&gt;-- the dog
    </content>
    <updated>2026-06-11T02:17:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstvrjn6dnfdnnjvwqu2elpsg05jfr29ydhahlahsn5k59cf0cpqngzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4ffsz</id>
    
      <title type="html">if it helps, I find you offensive. i could even make you a PDF ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstvrjn6dnfdnnjvwqu2elpsg05jfr29ydhahlahsn5k59cf0cpqngzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4ffsz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswv74yak48pdz2eh729ya8lsdxrpld4ucekuclrqhq05ndlfx3v7cujj38m&#39;&gt;nevent1q…j38m&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;if it helps, I find you offensive. i could even make you a PDF certificate. 😉
    </content>
    <updated>2026-06-09T20:18:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdar0aunzh5z45mjhq8j7jspcfdpk4exll3gc65a4xx7r6pe6echczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t97evd</id>
    
      <title type="html">A different kind of war war of attrition -- a slow death by a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdar0aunzh5z45mjhq8j7jspcfdpk4exll3gc65a4xx7r6pe6echczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t97evd" />
    <content type="html">
      A different kind of war war of attrition -- a slow death by a thousand paper-cut reductions in service, unavailability of resources, escalations, inconveniences, and distractions. Multi-front, purposefully at a crawl.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s boiling frogs all the way down.
    </content>
    <updated>2026-06-05T20:53:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz4y0ahnglmdr7mqypekt5fplcz9nyhnaarf8396jp0m29m8dss8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68w4kgu</id>
    
      <title type="html">The Quantum status page has been updated: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz4y0ahnglmdr7mqypekt5fplcz9nyhnaarf8396jp0m29m8dss8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68w4kgu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx57j69gnkn2flndlf0q8tq5364w37rvmtyyy7fcgf7kedkmf36nqwpl6ca&#39;&gt;nevent1q…l6ca&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The Quantum status page has been updated:&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/698/319/770/991/443/original/b9a72ae8d7a37609.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-06-05T15:58:02Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszsdum6msjczeehp34vvdccwnpy0a6lu7w9mklk78tf4f4dzusjhgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63yjlst</id>
    
      <title type="html">Signal beta on Android is now notifying &amp;#34;You may have new ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszsdum6msjczeehp34vvdccwnpy0a6lu7w9mklk78tf4f4dzusjhgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63yjlst" />
    <content type="html">
      Signal beta on Android is now notifying &amp;#34;You may have new messages&amp;#34; ... when there aren&amp;#39;t.
    </content>
    <updated>2026-05-23T03:35:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9npls20zf7le7uexve0alrtkhtpl705rsee5rdlxj06wmd6w2nxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67t0pre</id>
    
      <title type="html">I mean, the &amp;#34;KE&amp;#34; in KEV stands for &amp;#34;*known* ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9npls20zf7le7uexve0alrtkhtpl705rsee5rdlxj06wmd6w2nxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67t0pre" />
    <content type="html">
      I mean, the &amp;#34;KE&amp;#34; in KEV stands for &amp;#34;*known* exploited&amp;#34;. How were organizations reporting *before* to CISA that they were being exploited? Did some poor staffer there have to transcribe your email? I&amp;#39;m not seeing how making it easier to tell CISA that you were exploited (with the new form) is a bad thing?
    </content>
    <updated>2026-05-21T22:40:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2uydqgr2u3dawcag578yzdced99c4nagdpnwzctqq6xr6kv7necszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rnna0c</id>
    
      <title type="html">These are keys that I registered before the rise of WebAuthn. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2uydqgr2u3dawcag578yzdced99c4nagdpnwzctqq6xr6kv7necszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rnna0c" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyhjzs2774dt9g53mdp7l5yedwfqzwq9g6ds32ktk5kh22t7szrsqneysjl&#39;&gt;nevent1q…ysjl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;These are keys that I registered before the rise of WebAuthn. (The only way to register a new key that way is to disable everything but U2F on the key, then register it. Or at least, that used to work)
    </content>
    <updated>2026-05-20T14:01:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr862pc7m9e3vr7rzmmffa0ul2qpq0zgm5tqvn4yzx5rpkk8svragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68p7758</id>
    
      <title type="html">You say that like it&amp;#39;s a bad thing, Google. YubiKeys as ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr862pc7m9e3vr7rzmmffa0ul2qpq0zgm5tqvn4yzx5rpkk8svragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68p7758" />
    <content type="html">
      You say that like it&amp;#39;s a bad thing, Google.&lt;br/&gt;&lt;br/&gt;YubiKeys as *second* factor 4 lyfe!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/605/636/468/140/926/original/7c5566e453501a95.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-20T07:07:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgx57d5pppyxpksqka0ufhn8qzjpxpxq2lzrm730xvz5kfagpgauczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jsw6w0</id>
    
      <title type="html">inb4 all of the fun vulnerability brand names are used up and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgx57d5pppyxpksqka0ufhn8qzjpxpxq2lzrm730xvz5kfagpgauczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jsw6w0" />
    <content type="html">
      inb4 all of the fun vulnerability brand names are used up and researchers start randomizing phoneme groups, like those Amazon &amp;#34;brands&amp;#34;.
    </content>
    <updated>2026-05-18T15:30:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstwxy8s8mgrxdmgrwrhdtj9ym7n3lckpqfgrzade7rzfsrqa0pa3qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6wzrx0d</id>
    
      <title type="html">brb asking the people running the garage sale what the Wi-Fi ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstwxy8s8mgrxdmgrwrhdtj9ym7n3lckpqfgrzade7rzfsrqa0pa3qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6wzrx0d" />
    <content type="html">
      brb asking the people running the garage sale what the Wi-Fi password is
    </content>
    <updated>2026-05-17T07:48:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvnjjmllly0ashz0ms3sm2zcxfuqvazj44ztua955h2elxtl4d0kgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p4ka52</id>
    
      <title type="html">(Yes, this is a sub-post about the YellowKey BitLocker ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvnjjmllly0ashz0ms3sm2zcxfuqvazj44ztua955h2elxtl4d0kgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p4ka52" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw5afa49ucadndqvhr7rhg2h8lvzyj2hw8h5ug0wgjmgwqgsa5scq9ffq7d&#39;&gt;nevent1q…fq7d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;(Yes, this is a sub-post about the YellowKey BitLocker &amp;#34;vulnerability&amp;#34;)
    </content>
    <updated>2026-05-13T15:47:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw5afa49ucadndqvhr7rhg2h8lvzyj2hw8h5ug0wgjmgwqgsa5scqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6guxvn8</id>
    
      <title type="html">Every org that has been relying on obscurity hiding *their* ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw5afa49ucadndqvhr7rhg2h8lvzyj2hw8h5ug0wgjmgwqgsa5scqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6guxvn8" />
    <content type="html">
      Every org that has been relying on obscurity hiding *their* backdoor.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/567/654/120/471/832/original/6c9aa31095283197.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-13T14:07:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgwpff82vwe94xe0w8y89hham2lzsq08r5z5eh47wnupfszc2zwmqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6x3u8z3</id>
    
      <title type="html">I can neither confirm nor deny that it already exists. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgwpff82vwe94xe0w8y89hham2lzsq08r5z5eh47wnupfszc2zwmqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6x3u8z3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswm5v3kn7mjmfe44mq2vw6t070w0ngvv77gvan6kky3grwr56475g77qx5l&#39;&gt;nevent1q…qx5l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I can neither confirm nor deny that it already exists.&lt;br/&gt;&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1d26nzf8n5mjzavjfv07gdppw67gw4gmpzhlynrleymy58j9k8f6sk272uz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;FreddyB Aviation Photography&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1d26…72uz&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2026-05-13T05:04:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv3e6xdgd73nxh5g20wxx2u75fx5wevecuf8jlaw373vj0zn80wgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69fzl0y</id>
    
      <title type="html">ME: Hey, I totally forgot my 1994 undergrad CS &amp;#34;solve the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv3e6xdgd73nxh5g20wxx2u75fx5wevecuf8jlaw373vj0zn80wgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69fzl0y" />
    <content type="html">
      ME: Hey, I totally forgot my 1994 undergrad CS &amp;#34;solve the Eight Queens Problem with backtracking&amp;#34; exercise i I did in my Pascal class! I really got into it, did way more than the assignment required, taught it to log its work, ran it on the Sears salesfloor computers (Pentium II just came out!) a lot. Wonder if I could rewrite it in something else, it multithread it, etc.&lt;br/&gt;&lt;br/&gt;[tinkering]&lt;br/&gt;&lt;br/&gt;ME: Wow, that&amp;#39;s much faster! Now chewing on a 46x46 board, been a couple of hours. Hmm, I wonder if I can add a flag to teach it other strategies besides backtracking.&lt;br/&gt;&lt;br/&gt;[Googling]&lt;br/&gt;&lt;br/&gt;HOFFMAN ET AL, 1969: Hey, we can do a million-sided board in seconds with this one weird trick!&lt;br/&gt;&lt;br/&gt;ME: Hey, man ... I know this was a textbook lesson in recursion, but you *really* could have mentioned Hoffman after the assignment was over.&lt;br/&gt;&lt;br/&gt;PASCAL PROFESSOR: My bad.
    </content>
    <updated>2026-05-11T16:13:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspurn2dp269r6a7l8eussvn8c39ugzpejr0qx2y8jja08u4lzr04gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6dk530a</id>
    
      <title type="html">Maybe curl has been scrutinized so heavily and maintained so ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspurn2dp269r6a7l8eussvn8c39ugzpejr0qx2y8jja08u4lzr04gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6dk530a" />
    <content type="html">
      Maybe curl has been scrutinized so heavily and maintained so thoroughly that the kind of stuff Mythos (or other models) can find isn&amp;#39;t there.
    </content>
    <updated>2026-05-11T14:53:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvfl0fltygtls0wcwkfa4slm6f7x2lkk8ypvf20ug5ehs9k9g0lvgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64j58hc</id>
    
      <title type="html">RE: https://chaos.social/@icing/116526903529846107 &amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvfl0fltygtls0wcwkfa4slm6f7x2lkk8ypvf20ug5ehs9k9g0lvgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64j58hc" />
    <content type="html">
      RE: &lt;a href=&#34;https://chaos.social/@icing/116526903529846107&#34;&gt;https://chaos.social/@icing/116526903529846107&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; Aftermath: people, running Debian httpd 2.4.66, started complaining when they’ll get the 2.4.67 update to fix this RCE vulnerability. Which they already were protected from, but did not know. &amp;gt; *Because the CVE was not public at the time the fix was shipped.*&lt;br/&gt;&lt;br/&gt;[...]&lt;br/&gt;&lt;br/&gt;&amp;gt; Two security researchers found the vulnerability independently. Just scanning the 2.4.66 source code. This means &amp;gt; *the bad guys*&amp;gt;  can no longer be &amp;gt; *kept in the dark*&amp;gt; . &amp;gt; **Coordinated disclosure no longer works.**&lt;br/&gt;&lt;br/&gt;#CVE_2026_23918&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note12yxgvrmfx2p58avknefytajlgs5e250fpy28gw3jrh6tg0aqw66sgpnusj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note12yx…nusj&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; &#34;That &#39;responsibble disclosure&#39; Thing&#34;&lt;br/&gt;&lt;br/&gt;A post with the details of CVE-2026-23918, the double free vulnerability fixed in Apache httpd 2.4.67.&lt;br/&gt;&lt;br/&gt;#apache &lt;br/&gt;&lt;a href=&#34;https://eissing.org/icing/posts/responsible-disclosure/&#34;&gt;https://eissing.org/icing/posts/responsible-disclosure/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://assets.chaos.social/media_attachments/files/116/526/893/252/284/471/original/356df0201944962e.jpg&#34;&gt; &lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-05-06T12:08:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvd59lr9pl84lyypu5vathw6trwp3uxk7ud2stdzsqjvd0vh3y5dgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ax7feq</id>
    
      <title type="html">DigitalOcean: Hey that Apache thing needs upgrade on your ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvd59lr9pl84lyypu5vathw6trwp3uxk7ud2stdzsqjvd0vh3y5dgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ax7feq" />
    <content type="html">
      DigitalOcean: Hey that Apache thing needs upgrade on your droplet.&lt;br/&gt;&lt;br/&gt;Me: Thanks! Are your distro repos updated to contain the patched version?&lt;br/&gt;&lt;br/&gt;DO: lol no
    </content>
    <updated>2026-05-06T01:02:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrw8gagj4zrwvj53lzwladvjplz0skzskru43cljuzfdw9nvdqqcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p66lg74f</id>
    
      <title type="html">RE: https://infosec.exchange/@tychotithonus/116512575091069174 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrw8gagj4zrwvj53lzwladvjplz0skzskru43cljuzfdw9nvdqqcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p66lg74f" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@tychotithonus/116512575091069174&#34;&gt;https://infosec.exchange/@tychotithonus/116512575091069174&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Figured out what my beef is here. Named vulnerabilities are usually (at least implicitly) *for the benefit of defenders*. At launch, CopyFail emphasis was on impact, but support for defenders was extremely thin -- and a failure of empathy. The motivation appears to have been soley as an advertisement for &amp;#34;if you want to attack good, buy us / buy our thing&amp;#34;. I consider that asymmetry irresponsible, and the lack of empathy especially untrustworthy. I want vendors who have my back.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1mqzhug9z80wfz495jka69n3g8xr9v32t3t5q95ap6jw36s0kmvzsjwsj3q&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1mqz…sj3q&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Also, *they themselves* claim that it is no ordinary vulnerability, and should have stood out - making their failure (to initially leverage their position as even a basic clearinghouse for the rush of people who wouldn&#39;t find out about it until later) even more questionable.&lt;br/&gt;&lt;br/&gt;Again, it&#39;s a weird hybrid of &#34;this is really important&#34; with no understanding of how defenders actually operate.&lt;br/&gt;&lt;br/&gt;And for all of their claimed AI acumen, they didn&#39;t even bother to prompt for what defenders would need to know (until well after the announcement, where it&#39;s clear that they scrambled to fill in some gaps). &lt;br/&gt;&lt;br/&gt;#CopyFail&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/512/565/752/461/439/original/3e20b5b362209a80.png&#34;&gt; &lt;br/&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-05-03T21:09:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdspt7yz3rhhy32j6ftwazec5rnpjkg49c46qz6wsaf8gag8mdkpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p652l9e8</id>
    
      <title type="html">Also, *they themselves* claim that it is no ordinary ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdspt7yz3rhhy32j6ftwazec5rnpjkg49c46qz6wsaf8gag8mdkpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p652l9e8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsykf2jczjzkh2g7rd0qx427d4t8f74m3vv078awvz90584llqqcxcpaau3a&#39;&gt;nevent1q…au3a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also, *they themselves* claim that it is no ordinary vulnerability, and should have stood out - making their failure (to initially leverage their position as even a basic clearinghouse for the rush of people who wouldn&amp;#39;t find out about it until later) even more questionable.&lt;br/&gt;&lt;br/&gt;Again, it&amp;#39;s a weird hybrid of &amp;#34;this is really important&amp;#34; with no understanding of how defenders actually operate.&lt;br/&gt;&lt;br/&gt;And for all of their claimed AI acumen, they didn&amp;#39;t even bother to prompt for what defenders would need to know (until well after the announcement, where it&amp;#39;s clear that they scrambled to fill in some gaps). &lt;br/&gt;&lt;br/&gt;#CopyFail&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/512/565/752/461/439/original/3e20b5b362209a80.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-03T20:40:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsykf2jczjzkh2g7rd0qx427d4t8f74m3vv078awvz90584llqqcxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fwup73</id>
    
      <title type="html">I&amp;#39;m following this for the most part, but what I don&amp;#39;t ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsykf2jczjzkh2g7rd0qx427d4t8f74m3vv078awvz90584llqqcxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fwup73" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspr7650k9v5nr7d6ea5hqrpt6q5cnjd8zuukqywykc0gczmywyhmgccwqa6&#39;&gt;nevent1q…wqa6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;m following this for the most part, but what I don&amp;#39;t understand is why they thought they needed to stand up an entire domain name and website and coordination point, and then ... do almost nothing with it [initially, and for a couple days after].&lt;br/&gt;&lt;br/&gt;Either they thought it was important enough to do that, and they therefore have a corresponding obligation to at least minimally coordinate and inform defenders (which is what many named vulnerabilities have done in the past), or ... it wasn&amp;#39;t. They&amp;#39;ve chosen some weird middle ground, and even if it was only for marketing reasons, it sure doesn&amp;#39;t make me want to buy their product, because I don&amp;#39;t trust them to have the judgment or good taste to understand the implications of what they&amp;#39;re choosing to do.
    </content>
    <updated>2026-05-03T20:33:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdlj3uvshvfs46u0dyrwuh3gfcmqjkxuxq2x9kdpshe2r69rrn7tqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p688gfev</id>
    
      <title type="html">I suspect this is in preparation for selling the domain to an AI ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdlj3uvshvfs46u0dyrwuh3gfcmqjkxuxq2x9kdpshe2r69rrn7tqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p688gfev" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswegu0qf2f6d6uz2lqtv399msxtxy95wnqajcqd8verf8tpjg9fygy7632d&#39;&gt;nevent1q…632d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I suspect this is in preparation for selling the domain to an AI platform.
    </content>
    <updated>2026-05-03T15:21:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf7gh3xutuvpn776c44azny8q77ffvfmllddttuem224r94hgxknszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6c4avpr</id>
    
      <title>Nostr event nevent1qqsf7gh3xutuvpn776c44azny8q77ffvfmllddttuem224r94hgxknszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6c4avpr</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf7gh3xutuvpn776c44azny8q77ffvfmllddttuem224r94hgxknszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6c4avpr" />
    <content type="html">
       &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/502/036/547/068/077/original/4a8afdad3bdd0374.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-02T00:01:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvemwdfqxfe9wz3aznudxksahharpv08ekzmy984l9suvkdn7yr5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p664s2z3</id>
    
      <title type="html">/me *escapes to the woods* ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvemwdfqxfe9wz3aznudxksahharpv08ekzmy984l9suvkdn7yr5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p664s2z3" />
    <content type="html">
      /me *escapes to the woods*&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/501/578/106/898/663/original/1508f1a920e38bb0.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-01T22:04:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsykqkul2klxy2zhx328mtu8n79ppmeeujutg8gc3kwzyg72ehtp0gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pc7ddr</id>
    
      <title type="html">RE: https://mastodon.social/@Viss/116490543256385246 From my ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsykqkul2klxy2zhx328mtu8n79ppmeeujutg8gc3kwzyg72ehtp0gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pc7ddr" />
    <content type="html">
      RE: &lt;a href=&#34;https://mastodon.social/@Viss/116490543256385246&#34;&gt;https://mastodon.social/@Viss/116490543256385246&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;From my reading, this is my understanding as well. You don&amp;#39;t have to have root, and you can modify anything in the page cache. Like ... sshd, or libpam, or anything called by a cron job that&amp;#39;s running as root.&lt;br/&gt;&lt;br/&gt;How can we definitively confirm this?&lt;br/&gt;&lt;br/&gt;#CopyFail #CVE_2026_31431&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note14ruptk2zg5dxay4x8qtmvwsztynqlvafj7npcuntm2khglaez6gsn8z93m&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note14ru…z93m&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; right now, every single remote code vuln that will lead to command injection or rce will make this #copyfail thing a very very big deal.&lt;br/&gt;&lt;br/&gt;so all those qa servers and staging servers and test boxes you think nobody gives a shit about that are just flapping out there in the public, not being logged, not in the siem, not getting alerted on, not getting patched?&lt;br/&gt;&lt;br/&gt;all those are gonna catch the &#34;oops attackers overwrote sshd to steal creds&#34; disease. &lt;br/&gt;&lt;br/&gt;or cryptominers. or proxies. &lt;/blockquote&gt;
    </content>
    <updated>2026-04-30T15:13:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf55ulakkjkr099wglcengu88tfz95k26g9f9473ujchenmfvnkcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vmcqwt</id>
    
      <title type="html">The CopyFail announcement and handling is one of the least ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf55ulakkjkr099wglcengu88tfz95k26g9f9473ujchenmfvnkcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vmcqwt" />
    <content type="html">
      The CopyFail announcement and handling is one of the least defender-supporting I think I&amp;#39;ve ever seen. &lt;br/&gt;&lt;br/&gt;Mitigations were extremely thin at launch, and haven&amp;#39;t improved much, and are even brittle and misleading:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@tychotithonus/116490466168316767&#34;&gt;https://infosec.exchange/@tychotithonus/116490466168316767&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;They&amp;#39;ve also largely neglected most of the value of the feedback they&amp;#39;re getting from defenders clamoring for useful intel. The GitHub repo is full of feedback about which distros are affected or unaffected ... and a day later, none of it has been used to update the list of affected versions in the main README (except for the RHEL made-up version fix)&lt;br/&gt;&lt;br/&gt;And this exchange is painful: &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/12&#34;&gt;https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/12&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;#34;None of us are RH people so it wasn&amp;#39;t caught&amp;#34; 😐 You had *weeks* do basic vetting, or find someone who would help you.&lt;br/&gt;&lt;br/&gt;Theori seems to have to have intended this to be a showcase for their product. Instead, it has convinced me that I will *never* buy anything from them.&lt;br/&gt;&lt;br/&gt;#CopyFail #cve_2026_31431
    </content>
    <updated>2026-04-30T13:38:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf</id>
    
      <title>Nostr event nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf" />
    <content type="html">
      I keep reading &amp;#34;AiTM&amp;#34; as &amp;#34;Am I The Monster&amp;#34;
    </content>
    <updated>2026-04-22T22:47:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdr4pmd9y8z20x44safahj3xvpy9v70rka4knv9arvv7ke0fade9qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jk4g6x</id>
    
      <title type="html">https://www. ietf.org/archive/id/draft-meow -mrrp-00.html</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdr4pmd9y8z20x44safahj3xvpy9v70rka4knv9arvv7ke0fade9qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jk4g6x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszk35wp7g9e40hukg3st4s0ws0qzt87cr924m29kj8em0m9kjywwsrpzlh7&#39;&gt;nevent1q…zlh7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www&#34;&gt;https://www&lt;/a&gt;.&lt;br/&gt;ietf.org/archive/id/draft-meow&lt;br/&gt;-mrrp-00.html
    </content>
    <updated>2026-04-17T14:54:02Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0</id>
    
      <title>Nostr event nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0" />
    <content type="html">
      Lies, damned lies, and &amp;#34;LIFT TAB TO OPEN&amp;#34;
    </content>
    <updated>2026-04-16T15:12:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvgne4yylu9y3wpv22cq0fy9t9t3c7rzla6t8n2deq34k7s3qy7gqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fjnj0u</id>
    
      <title type="html">I don&amp;#39;t understand why the recovery of deleted Signal ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvgne4yylu9y3wpv22cq0fy9t9t3c7rzla6t8n2deq34k7s3qy7gqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fjnj0u" />
    <content type="html">
      I don&amp;#39;t understand why the recovery of deleted Signal messages is news.&lt;br/&gt;&lt;br/&gt;If an attacker has full access to the endpoiint, Signal has never claimed to protect messages -- and IIRC, has expressly stated that they do not.&lt;br/&gt;&lt;br/&gt;Edit: But hey, at least it is getting the word out that deleting the app doesn&amp;#39;t delete the messages!
    </content>
    <updated>2026-04-09T15:49:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd83gwxs3rcwkxpry07exxae2tru3krrgwtrkg7tu8ywyd36gnc9gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t9zyyt</id>
    
      <title type="html">RE: https://techpolicy.social/@joebeone/116194325589609756 New AI ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd83gwxs3rcwkxpry07exxae2tru3krrgwtrkg7tu8ywyd36gnc9gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t9zyyt" />
    <content type="html">
      RE: &lt;a href=&#34;https://techpolicy.social/@joebeone/116194325589609756&#34;&gt;https://techpolicy.social/@joebeone/116194325589609756&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;New AI term just dropped: vibekilling&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1679ex0ww9sjqnykfsq5vd999ez3k9w80h3drluglutwp655ept2sx7q3j4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1679…q3j4&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; great to hear &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1wa2kkh0f0knmdllhsylf4z8m60d6xg3w8sguzchqrz3nvpvldsxqaldqnj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Siva Vaidhyanathan&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1wa2…dqnj&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; talking to Brooke Gladstone on On the Media about AI and weapons of war. They talk real-time targeting and what accountability means today. &lt;a href=&#34;https://www.wnycstudios.org/podcasts/otm/articles/the-aipowered-war-machines-are-here&#34;&gt;https://www.wnycstudios.org/podcasts/otm/articles/the-aipowered-war-machines-are-here&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-03-08T15:45:58Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg6ls54fgt0l9h7pwwk7xefa8ep830g2zsadsgxlptayg24j28gjgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6cxeda7</id>
    
      <title type="html">&amp;#34;Wow, I got a TOTP code of 000000! What are the odds of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg6ls54fgt0l9h7pwwk7xefa8ep830g2zsadsgxlptayg24j28gjgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6cxeda7" />
    <content type="html">
      &amp;#34;Wow, I got a TOTP code of 000000! What are the odds of that?!&amp;#34;&lt;br/&gt;&lt;br/&gt;&amp;#34;Uh ... one in a million?&amp;#34;&lt;br/&gt;&lt;br/&gt;&amp;#34;I know, right?&amp;#34;&lt;br/&gt;&lt;br/&gt;🤣
    </content>
    <updated>2026-01-24T20:27:16Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdz5ypd2y8r7vlpkzhtu6vnzlnnsf2c32agdmkwsymhdck0r2wv6gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q7wdyl</id>
    
      <title type="html">The nice thing about EICAR is that, when properly implemented, it ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdz5ypd2y8r7vlpkzhtu6vnzlnnsf2c32agdmkwsymhdck0r2wv6gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q7wdyl" />
    <content type="html">
      The nice thing about EICAR is that, when properly implemented, it should only produce a hit if it is at the *beginning* of the file (per the EICAR spec itself). Inclusions of EICAR elsewhere are amusing, but should absolutely be false positives that should be fixed.&lt;br/&gt;&lt;br/&gt;The Anthropic magic string, by contrast, can appear *anywhere*. The chaos this enables is commensurately greater.
    </content>
    <updated>2026-01-22T22:35:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgwa5z7g4nrxaeptxngrjjcrz9p6rg83c67hzdsrs2lajddmyt3pszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q5kqat</id>
    
      <title type="html">I&amp;#39;m having a Mandela Effect / Berenstain Bears moment where I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgwa5z7g4nrxaeptxngrjjcrz9p6rg83c67hzdsrs2lajddmyt3pszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q5kqat" />
    <content type="html">
      I&amp;#39;m having a Mandela Effect / Berenstain Bears moment where I *swear* people say &amp;#34;pled&amp;#34; as the past tense of &amp;#34;plead&amp;#34; ... but half of the spellcheckers don&amp;#39;t like it?
    </content>
    <updated>2026-01-06T21:10:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspzsq8qn2cqyfjdslddsrsp64h8xwwfugfttrvckxau8qx4eyv92czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j5n79q</id>
    
      <title type="html">Ah, indeed. Though when working as designed, the ATA Secure Erase ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspzsq8qn2cqyfjdslddsrsp64h8xwwfugfttrvckxau8qx4eyv92czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j5n79q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqdu8qzdp487jpr7ks3zt0faqquvv0kuw44khn98cwgkakn3ruysgdqq2np&#39;&gt;nevent1q…q2np&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, indeed. Though when working as designed, the ATA Secure Erase *should* reach all storage. Except when it doesn&amp;#39;t. Hmm.&lt;br/&gt;&lt;br/&gt;In your experience, what are the ATA Secure Erase failure modes? If we (pessimistically) assume that it can fail silently, it is probably often working as intended (unless it throws an error).&lt;br/&gt;&lt;br/&gt;So if I had to write an internal standard at $dayjob, the wiping workflow would *always* attempt an ATA Secure Erase first, and then *always* follow with a single overwrite (with zeroes or NULL; the reasons for overlapping / random / multipass are from ancient HDD days).
    </content>
    <updated>2025-12-30T03:19:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg77pt5vqztw6mx9md2d26wd9q8qz9tarscunqn9sg80s68ytcvdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rcr6kx</id>
    
      <title type="html">I&amp;#39;d argue that verification is itself limited. Part of the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg77pt5vqztw6mx9md2d26wd9q8qz9tarscunqn9sg80s68ytcvdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rcr6kx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvnynp93xdf8n8c4dpvl9uxrcpt2v27ah5rrr5gex2hxemnue7tjgskyxe2&#39;&gt;nevent1q…yxe2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;d argue that verification is itself limited. Part of the OS-level verification gap/problem is that the storage has regions that the OS can&amp;#39;t reach. So an OS-level verification process is inherently incomplete.
    </content>
    <updated>2025-12-30T03:03:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst4k2n74w4d07ld2supzu2p3wwksj0cv73353jed60hcejd6vdgfczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pvaasf</id>
    
      <title type="html">Hmm .. since each approach covers angles that the other does not, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst4k2n74w4d07ld2supzu2p3wwksj0cv73353jed60hcejd6vdgfczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pvaasf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszgsc8s56kjhq0ucvuv6kf5msdc3gx8ka5hhk7rwemwhvu0u20jdqlrp7cr&#39;&gt;nevent1q…p7cr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hmm .. since each approach covers angles that the other does not, then, the most robust approach is probably to first trigger an ATA Secure Erase, and then do an overwrite.
    </content>
    <updated>2025-12-30T03:00:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2q6lpysu5vda0wpfqkjxrgejg35pdsqgt7at2h8l28m394wkst3szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p9hw99</id>
    
      <title type="html">SSDs also support ATA Secure Erase (controller-level ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2q6lpysu5vda0wpfqkjxrgejg35pdsqgt7at2h8l28m394wkst3szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p9hw99" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs09ydtj7t3ganmflghayjcacrg92e93g8kld4czuhqgux3v6cswhg03s0ut&#39;&gt;nevent1q…s0ut&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;SSDs also support ATA Secure Erase (controller-level encrypt-then-discard-key) -- which should, in theory, be significantly more thorough than OS-level overwrite.&lt;br/&gt;&lt;br/&gt;This is also the NIST-approved method.
    </content>
    <updated>2025-12-30T02:51:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvf6hutq3yc2k7jlre8frrnq7ng4jdm84y3wuesmyd7je696eevxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lrf3re</id>
    
      <title type="html">RE: https://infosec.exchange/@zak/115793005915790340 This is a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvf6hutq3yc2k7jlre8frrnq7ng4jdm84y3wuesmyd7je696eevxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lrf3re" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@zak/115793005915790340&#34;&gt;https://infosec.exchange/@zak/115793005915790340&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is a metaphor about cybersecurity products.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note156ng4d0q305y4mcqlc8exn0u0eyxj2fe9x663n2femh8ul66uw2qw5mum6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note156n…mum6&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Eyelashes: stop things from falling into your eyes.&lt;br/&gt;&lt;br/&gt;Also eyelashes: fall directly into your eyes.&lt;br/&gt;&lt;br/&gt;What horseshit. &lt;/blockquote&gt;
    </content>
    <updated>2025-12-27T18:49:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs986mwja8pe82mps6xar26xrerpwzjca2jdtyljk9wkc4w4cv23mqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6624wz9</id>
    
      <title type="html">Also how did we manage to land the &amp;#34;switch to passkeys&amp;#34; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs986mwja8pe82mps6xar26xrerpwzjca2jdtyljk9wkc4w4cv23mqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6624wz9" />
    <content type="html">
      Also how did we manage to land the &amp;#34;switch to passkeys&amp;#34; messaging ... but somehow miss the &amp;#34;and you absolutely must let users add more than one, with clear UX&amp;#34; bit?
    </content>
    <updated>2025-12-15T15:59:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2tmtjqg4l5s34hxh5krmggerunhngg2qhujkymeqyr0wxkp00gzgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6l4jnlq</id>
    
      <title type="html">&amp;#34;Let us be the repository of your passkeys&amp;#34; and &amp;#34;We ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2tmtjqg4l5s34hxh5krmggerunhngg2qhujkymeqyr0wxkp00gzgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6l4jnlq" />
    <content type="html">
      &amp;#34;Let us be the repository of your passkeys&amp;#34; and &amp;#34;We may terminate your account at any time and permanently refuse to communicate with you&amp;#34; ... seems like a bad combination?
    </content>
    <updated>2025-12-15T15:54:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst9c9yhs8mjr06uv6aa85qf4mgklu69g6k7wkvft9a7gfqgwrvnmczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mnnepa</id>
    
      <title type="html">Welp, Google is killing off the Dark Web Report feature, which ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst9c9yhs8mjr06uv6aa85qf4mgklu69g6k7wkvft9a7gfqgwrvnmczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mnnepa" />
    <content type="html">
      Welp, Google is killing off the Dark Web Report feature, which was useful (to me, anyway), as of Feb 16, 2026.
    </content>
    <updated>2025-12-15T15:38:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r</id>
    
      <title>Nostr event nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r" />
    <content type="html">
      I kinda hate the mashed-to-a-single word &amp;#34;protip&amp;#34;.
    </content>
    <updated>2025-12-05T15:53:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs28x3grajxxcspyp5uk7aqwchv6sqkqta0j5fymwkaey8jnqcm8zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gvsygk</id>
    
      <title type="html">I know of seven org-branded standard YubiKey bubble packs (note: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs28x3grajxxcspyp5uk7aqwchv6sqkqta0j5fymwkaey8jnqcm8zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gvsygk" />
    <content type="html">
      I know of seven org-branded standard YubiKey bubble packs (note: the *packaging* is branded, not necessarily the *key*). Are there any more?&lt;br/&gt;&lt;br/&gt;First four:&lt;br/&gt;&lt;br/&gt;1/2&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/397/825/441/original/f6c889fc2f3c6a94.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/411/125/957/original/de3305906c9a1734.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/412/202/164/original/2069f3377ec222f4.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/413/197/977/original/2b50d486de30ee16.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-11-26T00:23:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvh6pfjnff72mrqf46ygqt4gszvsuefwnwj8ferahtxje4zvurchqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ay3s8l</id>
    
      <title type="html">I don&amp;#39;t know why this is how I found out. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvh6pfjnff72mrqf46ygqt4gszvsuefwnwj8ferahtxje4zvurchqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ay3s8l" />
    <content type="html">
      I don&amp;#39;t know why this is how I found out.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html&#34;&gt;https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Anchorage is going to try voting by phone.&lt;br/&gt;&lt;br/&gt;No one who understands the problem space thinks this is a good idea.
    </content>
    <updated>2025-11-15T20:15:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9a3cs6ws28dc4ta7auj8zzuukd80y0pyyjangjpuz5vprm4nyjcgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mr2s60</id>
    
      <title type="html">OH: &amp;#34;You&amp;#39;re in his DMs. I&amp;#39;m in his VMs. We&amp;#39;re not ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9a3cs6ws28dc4ta7auj8zzuukd80y0pyyjangjpuz5vprm4nyjcgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mr2s60" />
    <content type="html">
      OH: &amp;#34;You&amp;#39;re in his DMs. I&amp;#39;m in his VMs. We&amp;#39;re not the same.&amp;#34;
    </content>
    <updated>2025-11-07T06:55:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd5c8h9rte2r44rs6ctss65463fj4fffh0xe4tr7hf34pn4c63e4qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdgpqy</id>
    
      <title type="html">The kids can&amp;#39;t eat without something to scroll. It terrifies ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd5c8h9rte2r44rs6ctss65463fj4fffh0xe4tr7hf34pn4c63e4qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdgpqy" />
    <content type="html">
      The kids can&amp;#39;t eat without something to scroll. It terrifies me. When can we rest? When can we have ideas? When can we connect?
    </content>
    <updated>2025-11-07T00:35:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqwc9sr2cquucy23z3hscpf86rhkldhmk2u5rdd2rdnsf85kqul2gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ff50rz</id>
    
      <title type="html">Indeed! This thread is what triggered the support in JtR (and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqwc9sr2cquucy23z3hscpf86rhkldhmk2u5rdd2rdnsf85kqul2gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ff50rz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx3yue00amyjqpfvn97zy7wxkccjdsa0xuep5uza2p7aqddelcq3smw06mw&#39;&gt;nevent1q…06mw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Indeed! This thread is what triggered the support in JtR (and eventually hashcat):&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://unix.stackexchange.com/questions/31549/is-it-possible-to-find-out-the-hosts-in-the-known-hosts-file&#34;&gt;https://unix.stackexchange.com/questions/31549/is-it-possible-to-find-out-the-hosts-in-the-known-hosts-file&lt;/a&gt;
    </content>
    <updated>2025-11-05T21:11:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2h2ugxewshfzxgwflwsh8wewra5mmevhzgm0kl7jh6ghmhp9wepqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64r7grx</id>
    
      <title type="html">Happy to try to crack them if you&amp;#39;d like!</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2h2ugxewshfzxgwflwsh8wewra5mmevhzgm0kl7jh6ghmhp9wepqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64r7grx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdtvl4wwwqr9ye48hd5nnxmnuyjpj23j3hpxsm6gwuh5lwfmhsmyshhj37n&#39;&gt;nevent1q…j37n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Happy to try to crack them if you&amp;#39;d like!
    </content>
    <updated>2025-11-05T21:08:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf69d57l4umjyj6gt7rjvcjzhu4cp355nqasrt9qe4muefvg76vpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d7ep5j</id>
    
      <title type="html">Whoa, how did I miss that you&amp;#39;ll be able to buy YubiKeys at ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf69d57l4umjyj6gt7rjvcjzhu4cp355nqasrt9qe4muefvg76vpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d7ep5j" />
    <content type="html">
      Whoa, how did I miss that you&amp;#39;ll be able to buy YubiKeys at Best Buy?!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/press-releases/secure-your-digital-accounts-yubikeys-available-now-in-stores-at-best-buy/&#34;&gt;https://www.yubico.com/press-releases/secure-your-digital-accounts-yubikeys-available-now-in-stores-at-best-buy/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;[Edit: *right now* -- or at least, available to pick up within the hour at my local store!]&lt;br/&gt;&lt;br/&gt;#YubiKey
    </content>
    <updated>2025-11-05T04:01:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszjcp66sewztq2eka4ay0zhqdghtd4x6j9jelzd9f3hzfxenxcu8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p669fylu</id>
    
      <title type="html">😐</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszjcp66sewztq2eka4ay0zhqdghtd4x6j9jelzd9f3hzfxenxcu8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p669fylu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ywj4n2khr80tuud5lw92d53w99mxnhuakq823nxpv0yldxlksmqcmrjjy&#39;&gt;nevent1q…rjjy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;😐
    </content>
    <updated>2025-11-04T21:21:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8rvd85hel3ncfy9se2w07cmxcmn6sfrc0jwn6dn3l25vutqecufgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceufcj</id>
    
      <title type="html">Oof. Does the mechanism provide a way for the defederating server ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8rvd85hel3ncfy9se2w07cmxcmn6sfrc0jwn6dn3l25vutqecufgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceufcj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8pkrryd2u8vvtgpppmjx263su848yn8hj9wrguz05lgd8vg9u7zq2uc87z&#39;&gt;nevent1q…c87z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oof. Does the mechanism provide a way for the defederating server to say why it happened? Or is it just totally opaque?
    </content>
    <updated>2025-11-04T21:20:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqmu52zqqrgcpwqu8zkaxyeut9ph6djcavyvg9893v4gsl8cgauzszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4cn2s</id>
    
      <title type="html">inb4 everyone realizes that several Someones are taking notes ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqmu52zqqrgcpwqu8zkaxyeut9ph6djcavyvg9893v4gsl8cgauzszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4cn2s" />
    <content type="html">
      inb4 everyone realizes that several Someones are taking notes during ransomware attacks, outages, etc. -- mapping our attack surface / dependencies / response capabilities.&lt;br/&gt;&lt;br/&gt;What percentage are active vs passive measurement are left as an exercise.
    </content>
    <updated>2025-10-29T18:45:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9mfjl5n6708uyqzc87nujqql32yx7990zq8p7dzctscay5r5vmmszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6au6t9e</id>
    
      <title type="html">https://infosec.exchange/@tychotithonus/115418342699692840</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9mfjl5n6708uyqzc87nujqql32yx7990zq8p7dzctscay5r5vmmszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6au6t9e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdwft8qrge2xvqvtaxvqc4hwwcftxmux3858yh6wd0cru0v3j2tcsncnj8d&#39;&gt;nevent1q…nj8d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@tychotithonus/115418342699692840&#34;&gt;https://infosec.exchange/@tychotithonus/115418342699692840&lt;/a&gt;
    </content>
    <updated>2025-10-22T14:45:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrltqhye2davjghpf0m50etwp2g2yqql9tqrnh9rkd479xdnhn8zszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63ywn0z</id>
    
      <title type="html">Hot take: we are boiling the illiteracy frog. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrltqhye2davjghpf0m50etwp2g2yqql9tqrnh9rkd479xdnhn8zszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63ywn0z" />
    <content type="html">
      Hot take: we are boiling the illiteracy frog.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/416/384/796/349/671/original/e3a7745fab7bb9a8.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-22T06:26:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswg6md6q580twmng3a7azgwufv9w7dnvw97g65zg56c05vuqfddxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk03kl</id>
    
      <title type="html">I feel like a lot of the &amp;#34;it was DNS&amp;#34; is conceptually ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswg6md6q580twmng3a7azgwufv9w7dnvw97g65zg56c05vuqfddxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk03kl" />
    <content type="html">
      I feel like a lot of the &amp;#34;it was DNS&amp;#34; is conceptually oversimplifying, and masking true root cause(s).&lt;br/&gt;&lt;br/&gt;It makes sense to centralize naming, It makes sense to abstract naming away from IP addresses. Many of these outages are &amp;#34;this other thing broke, and it made DNS break&amp;#34;. Most folks would never say &amp;#34;it was DNS&amp;#34; when it was a network problem that was preventing reaching the DNS servers. But a lot of the time, this isn&amp;#39;t much different from that.&lt;br/&gt;&lt;br/&gt;Don&amp;#39;t get me wrong, every outage is an opportunity to learn and improve, both locally and centrally. I just want to shift the conversation to &amp;#34;it was DNS, *because* ...&amp;#34;, and help people make informed risk trade-offs.&lt;br/&gt;&lt;br/&gt;Approach it like the NTSB would: keep going until you know, and have recommendations for, *all* of the failure modes.
    </content>
    <updated>2025-10-20T13:47:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswg7g2kn70pcd0rxpasqkddrpnna4g8q724juuvz4uwzx58ld4ktszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63y8v8e</id>
    
      <title type="html">And the opposites are also very true: Local doesn&amp;#39;t mean ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswg7g2kn70pcd0rxpasqkddrpnna4g8q724juuvz4uwzx58ld4ktszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63y8v8e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9hfu6856plyfav2j2x64fdfuxmnmu6umg58s0vh37nwxkewzdjzq39j6yd&#39;&gt;nevent1q…j6yd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And the opposites are also very true:&lt;br/&gt;&lt;br/&gt;Local doesn&amp;#39;t mean insecure. Cloud doesn&amp;#39;t mean secure.
    </content>
    <updated>2025-10-09T16:00:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqsnx3fwc5rfn8wysqf23s0qhcfcphqr8plkmrlf8yyklh73q06zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ykaglt</id>
    
      <title type="html">Good question! A core property of FIDO2 is authenticating the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqsnx3fwc5rfn8wysqf23s0qhcfcphqr8plkmrlf8yyklh73q06zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ykaglt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp6qp4xt52kf8rv6dujcs8a4zjc00hrnlkju37fvfynl059mrzpls892lq2&#39;&gt;nevent1q…2lq2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Good question!&lt;br/&gt;&lt;br/&gt;A core property of FIDO2 is authenticating the *origin* (are you connected to the right site, or a copycat). The daily benefit of this protection is intended to be worth the trade-off of requiring diligence in retaining possession of the key.&lt;br/&gt;&lt;br/&gt;Also, the idea is that loss of the key would be noticed quickly enough that the key could be revoked.&lt;br/&gt;&lt;br/&gt;Finally, putting a PIN on a &amp;#34;leave-in&amp;#34;  / installed key (which is a PIN for the *key*, not for individual sites), is a reasonable way to mitigate the risk of the window of time between the loss/theft of key and when it can be revoked.&lt;br/&gt;&lt;br/&gt;#YubiKey
    </content>
    <updated>2025-10-04T14:21:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgfz2ww08a5c74yhrgtldmly4uhd6qazctd8rgn6a42qc8vpk58rszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xll7z9</id>
    
      <title type="html">This saga feels like an ad for ZFS 😉 I&amp;#39;ve been burned by ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgfz2ww08a5c74yhrgtldmly4uhd6qazctd8rgn6a42qc8vpk58rszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xll7z9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs85hnz9wcf85zs233zrfc2tyhuxcrj3xvv6cc9atm6s6zkd8vss9qacetwy&#39;&gt;nevent1q…etwy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This saga feels like an ad for ZFS 😉&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve been burned by both hard and soft RAID too many times to ever go back.
    </content>
    <updated>2025-09-29T16:51:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspseymjmrnjjsy7wzztj3d6vgu667zh2zrqea8k5p0gmt02mj6vrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6st9dvj</id>
    
      <title type="html">Updated to include: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspseymjmrnjjsy7wzztj3d6vgu667zh2zrqea8k5p0gmt02mj6vrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6st9dvj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstg96sfj2ww3pn0rkke469edgxd5cfzq8cdz8h7ux0s88ljjj2s5cx6u9pc&#39;&gt;nevent1q…u9pc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Updated to include:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/press-releases/yubico-and-t-mobile-deployment-of-200000-phishing-resistant-yubikeys-enhances-un-carriers-work-systems-security/&#34;&gt;https://www.yubico.com/press-releases/yubico-and-t-mobile-deployment-of-200000-phishing-resistant-yubikeys-enhances-un-carriers-work-systems-security/&lt;/a&gt;
    </content>
    <updated>2025-09-23T20:22:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz503vegvksn9jvdcljul44dxppleawrurzrkukvaa3mqagl5nsqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m2qwps</id>
    
      <title type="html">I should have been collecting the receipts on a rolling basis; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz503vegvksn9jvdcljul44dxppleawrurzrkukvaa3mqagl5nsqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m2qwps" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsppt67l4p34r9d7z8n5ztls6yyqlq9sk82ceu2d8r2cgu4a5zj9nczqxwsm&#39;&gt;nevent1q…xwsm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I should have been collecting the receipts on a rolling basis; chatter at the time for multiple of these was &amp;#34;deploying fast now for highest risk, doing the rest in a more controlled fashion after&amp;#34;.&lt;br/&gt;&lt;br/&gt;Thinking of:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;npm (&amp;#34;encouraging FIDO2&amp;#34;, anyway)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;T-Mobile - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation&amp;#34&#34;&gt;https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;t-mobile.com/news/network/addi&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;tional-information-regarding-2021-cyberattack-investigation&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Twitter - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://blog.x.com/engineering/en_us/topics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;#34&#34;&gt;https://blog.x.com/engineering/en_us/topics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;blog.x.com/engineering/en_us/t&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;opics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;And probably:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Uber (&amp;#34;further strengthening our MFA&amp;#34;, reading between the lines for 2022 breach and 2023 deployment) - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.uber.com/newsroom/security-update/&amp;#34&#34;&gt;https://www.uber.com/newsroom/security-update/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;uber.com/newsroom/security-upd&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;ate/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Discord (again, reading between the lines - 2023 breach, 2025 deployment)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;eBay (public evidence is thinner here, but I got a couple of confidential reports)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;And a couple &amp;#34;we could see the writing on the wall&amp;#34; (they get points for that):&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Google (2017) - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&amp;#34&#34;&gt;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;krebsonsecurity.com/2018/07/go&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;ogle-security-keys-neutralized-employee-phishing/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Cloudflare - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://blog.cloudflare.com/how-cloudflare-implemented-fido2-and-zero-trust/&amp;#34&#34;&gt;https://blog.cloudflare.com/how-cloudflare-implemented-fido2-and-zero-trust/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;blog.cloudflare.com/how-cloudf&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;lare-implemented-fido2-and-zero-trust/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;
    </content>
    <updated>2025-09-23T20:17:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstd58zhjeqr5n93qez50fqch0yyq9e4m2xjmejc9yljgasy9kjvgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p60g5mt6</id>
    
      <title type="html">How many stories of &amp;#34;get popped, *then* do an emergency FIDO2 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstd58zhjeqr5n93qez50fqch0yyq9e4m2xjmejc9yljgasy9kjvgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p60g5mt6" />
    <content type="html">
      How many stories of &amp;#34;get popped, *then* do an emergency FIDO2 deployment&amp;#34; does your leadership need to read before you decide to deploy FIDO2 proactively?
    </content>
    <updated>2025-09-23T19:56:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswultpnqf5x7d20exj4jk0pdlqxg3cfzx6mcm5e00mf23dnef3jyszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qltmd</id>
    
      <title type="html">Like conference social preference badges, except &amp;#34;yes I will ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswultpnqf5x7d20exj4jk0pdlqxg3cfzx6mcm5e00mf23dnef3jyszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qltmd" />
    <content type="html">
      Like conference social preference badges, except &amp;#34;yes I will always say hi to your dog&amp;#34;
    </content>
    <updated>2025-09-20T01:57:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspkjwk9rqtl2tl7ke5u5p4wvvwtj5yc44ljw7d6ny5h6k4spsp4vczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64pmkan</id>
    
      <title type="html">&amp;#34;Using ChatGPT to complete assignments is like bringing a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspkjwk9rqtl2tl7ke5u5p4wvvwtj5yc44ljw7d6ny5h6k4spsp4vczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64pmkan" />
    <content type="html">
      &amp;#34;Using ChatGPT to complete assignments is like bringing a forklift into the weight room; you will never improve your cognitive fitness that way.&amp;#34;&lt;br/&gt;-- Ted Chiang&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://www.newyorker.com/culture/the-weekend-essay/why-ai-isnt-going-to-make-art&#34;&gt;https://www.newyorker.com/culture/the-weekend-essay/why-ai-isnt-going-to-make-art&lt;/a&gt;
    </content>
    <updated>2025-09-18T17:28:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfl9uysv8e35gsljmr00027dx2x7sx7wpnx0jkdh60qgfasw6759gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69zmevk</id>
    
      <title type="html">Dudes will install Debian on a 13yo MacBook Air instead of going ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfl9uysv8e35gsljmr00027dx2x7sx7wpnx0jkdh60qgfasw6759gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69zmevk" />
    <content type="html">
      Dudes will install Debian on a 13yo MacBook Air instead of going to therapy.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s me. I&amp;#39;m dudes.&lt;br/&gt;&lt;br/&gt;(XFCE is pretty snappy!)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/216/825/708/391/708/original/f7da14f14df09a72.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-17T00:37:54Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9d5a4h4sl8j7hepzm3794f5tmhpqurzp8ux2ca8fh7dfm7nc6q3gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6awwwn6</id>
    
      <title type="html">And to your solid point about the 70%, I forgot to math that out ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9d5a4h4sl8j7hepzm3794f5tmhpqurzp8ux2ca8fh7dfm7nc6q3gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6awwwn6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5shmqmj2&#39;&gt;nevent1q…qmj2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And to your solid point about the 70%, I forgot to math that out to illustrate the importance of protecting the remaining people who *aren&amp;#39;t* reusing passwords. (And I know you know this, mostly posting for those following along).&lt;br/&gt;&lt;br/&gt;In the 16 million bcrypt cost 12 case, if 70% of them can be &amp;#34;pre-cracked&amp;#34; with correlation, then the amount of time for the attack above to run for the remaining 30% drops from 300 days to 90 days. Which is an okay amount of time to buy between compromise and discovery, until we remember that you can have a lot more than two 4090s 😅, and of course, bcrypt parallelizes relatively well, such that a different hash like Argon2 or yescrypt is a better choice. But if bcrypt is the only option for some reason, bumping the work factor higher, if feasible, would be recommended.
    </content>
    <updated>2025-09-09T12:56:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg5hqsy5csx30n8pjhjfd03xy3lcg9ty7r0c3e3ftc9ktfntynerczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68c68h9</id>
    
      <title type="html">Wow, that is substantially more terrible than I was expecting. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg5hqsy5csx30n8pjhjfd03xy3lcg9ty7r0c3e3ftc9ktfntynerczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68c68h9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx5ql3f2w7wtg75gc7krmll3n4f0ngu9a3s9q098xalqucwh3qqrsnl4yx9&#39;&gt;nevent1q…4yx9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Wow, that is substantially more terrible than I was expecting. Yow.
    </content>
    <updated>2025-09-09T05:23:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v3jkxq</id>
    
      <title type="html">Well, there&amp;#39;s a spectrum there. A lot of the Hashmob bcrypt ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v3jkxq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspe4e34w56lqmncrfvpqslzxq8tamgtq7fqg6xt0msn70xwxrxscqe5p4tw&#39;&gt;nevent1q…p4tw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Well, there&amp;#39;s a spectrum there. A lot of the Hashmob bcrypt lists have been thoroughly correlated, and I think the percentage trends lower than 70% there, but I&amp;#39;d have to look.&lt;br/&gt;&lt;br/&gt;If full correlation is in play (a leak with known passwords), then the cost doesn&amp;#39;t make a ton of difference, because each hash can be targeted with john&amp;#39;s --single mode or hashcat&amp;#39;s -a 9.&lt;br/&gt;&lt;br/&gt;And for hashes that cannot be correlated, targeting a single hash  slows the attacker down only so much (because single-hash performance has to be tolerable for user experience). When the bcrypt cost gets to 12, and a million candidate passwords, that&amp;#39;s only about 30 seconds with hashcat on 2 4090s.&lt;br/&gt;&lt;br/&gt;And then that cost is magnified when it&amp;#39;s a broad attack (many hashes targeted simultaneously), Even just trying the first N thousand most common passwords, attempting to crack a million bcrypt cost 12s is correspondingly harder, so there&amp;#39;s still a &amp;#34;herd health&amp;#34; benefit to the hashes being stronger.&lt;br/&gt;&lt;br/&gt;For example, with 16 million cost 12 bcrypts, and a very short list of very common passwords (6144 words, the minimum for certain hashcat efficiencies), 2x 4090s will take 300 days to fully exhaust. The equivalent attack - all other variables constant, but dropping the bcrypt cost from 12 to five -- will complete *in 2.5 days*.&lt;br/&gt;&lt;br/&gt;And that&amp;#39;s for a *very* short wordlist. Running through longer wordlists would be correspondingly longer.&lt;br/&gt;&lt;br/&gt;So I think that the work factors should be tuned to protect folks who aren&amp;#39;t reusing their own passwords across multiple accounts, but might be sharing semi-common passwords *with other users*.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/172/505/744/839/580/original/a7a022bed207857c.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/172/529/106/047/154/original/a6e724cba6bef39c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-09T04:49:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg8lhxzds0dy5sm2ape94tw4fkmd9uufz0f3cul7qm5ayr9fh079qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6axhpml</id>
    
      <title type="html">*Nice* find! We&amp;#39;re going to have get the word out that just ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg8lhxzds0dy5sm2ape94tw4fkmd9uufz0f3cul7qm5ayr9fh079qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6axhpml" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr5t0ztj8jndxtedruwy4kp8ng7lxmglp6qu5rclkmwyttsdvuu9qz8tf76&#39;&gt;nevent1q…tf76&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;*Nice* find! &lt;br/&gt;&lt;br/&gt;We&amp;#39;re going to have get the word out that just &amp;#39;bcrypt&amp;#39; isn&amp;#39;t enough -- bcrypt cost 12 is 128 times harder than cost 5, etc. We need to know the default costs.
    </content>
    <updated>2025-09-09T03:54:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvslfc2ql75lztyqnpmlyk3jwaput3p6ulmp503z3xqgs2yhzunrczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d4fz70</id>
    
      <title type="html">Anyone seeing disclosure of what password hashing algorithm Plex ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvslfc2ql75lztyqnpmlyk3jwaput3p6ulmp503z3xqgs2yhzunrczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d4fz70" />
    <content type="html">
      Anyone seeing disclosure of what password hashing algorithm Plex uses on their back end?&lt;br/&gt;&lt;br/&gt;[Edit: &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1t9cz9v7zph5jvadd8rjfp25msrx6r0hdxnsyfmx88k8qp3pvv04szt8529&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Aaron Toponce ⚛️:debian:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1t9c…8529&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discovered a thread showing bcrypt:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://fosstodon.org/@atoponce/115172271450263878&#34;&gt;https://fosstodon.org/@atoponce/115172271450263878&lt;/a&gt; ]&lt;br/&gt;&lt;br/&gt;There are three kinds of org postures relative to disclosure of password-hashing algorithm:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs confident enough in their selection of algorithm that they &amp;lt;em&amp;gt;know&amp;lt;/em&amp;gt; that there is no harm in disclosing it&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs who know they&amp;#39;re doing it badly and want to keep it a secret&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs who won&amp;#39;t disclose their algorithm because the PR team has no idea how the passwords are hashed, and internal comms are spotty enough that the information can&amp;#39;t reach the public&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Note that a mix of 1 and 3, or 2 and 3, are also possible.&lt;br/&gt;&lt;br/&gt;1 alone is a sign of security maturity. If 2 and 3 are in play, there&amp;#39;s room for improvement ... for different reasons, but both indicators of security immaturity.&lt;br/&gt;&lt;br/&gt;Practitioners: Which type is your org?&lt;br/&gt;&lt;br/&gt;Reporters: Are you probing orgs to find out which type they are?&lt;br/&gt;&lt;br/&gt;Normalize hash-type disclosure.
    </content>
    <updated>2025-09-09T02:03:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdp9jd6adwv540pc4rs9tqtdgcwuve8dr4ccev3s5u3gczp9fpntqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hfj7k7</id>
    
      <title type="html">Clonezilla is such a hidden gem. An impressive combination of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdp9jd6adwv540pc4rs9tqtdgcwuve8dr4ccev3s5u3gczp9fpntqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hfj7k7" />
    <content type="html">
      Clonezilla is such a hidden gem. An  impressive combination of &amp;#34;make the core things easy and the tricky things possible&amp;#34; and &amp;#34;do what I probably need&amp;#34;.
    </content>
    <updated>2025-09-07T23:52:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw3r262h8mzgn9ycfrgezl2wttspgzavtwk470xrdh7aaaymcfxtgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qxp4y3</id>
    
      <title type="html">I totally forgot about this. Thank you, random synapse from ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw3r262h8mzgn9ycfrgezl2wttspgzavtwk470xrdh7aaaymcfxtgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qxp4y3" />
    <content type="html">
      I totally forgot about this. Thank you, random synapse from literally the year 2000.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://goodreads.com/book/show/331807.How_to_Good_Bye_Depression_If_You_Constrict_Anus_100_Times_Everyday__Malarkey__or_Effective_Way_&#34;&gt;https://goodreads.com/book/show/331807.How_to_Good_Bye_Depression_If_You_Constrict_Anus_100_Times_Everyday__Malarkey__or_Effective_Way_&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/143/801/695/221/087/original/141db13eb6097762.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-04T03:04:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9tlg5m2cafuvpve2qpjqknanzaxqguk63y7may98l495xl27eq8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fevdc6</id>
    
      <title type="html">That is hilarious and insightful. You win the Internet today, and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9tlg5m2cafuvpve2qpjqknanzaxqguk63y7may98l495xl27eq8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fevdc6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq25hlccwk4lgdtmtctr65eetdms0qq4yahgxhcgsyqq6eklwlntq3kvl3q&#39;&gt;nevent1q…vl3q&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That is hilarious and insightful. You win the Internet today, and it&amp;#39;s only 5:42 a.m. here. 😁
    </content>
    <updated>2025-08-28T13:42:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfgxjnqlk3qmrspx80tdwha6a90dcazcduqvtu2776q29w7np738qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qyjtph</id>
    
      <title type="html">Turns out &amp;#34;despite patches&amp;#34; means &amp;#34;despite patches ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfgxjnqlk3qmrspx80tdwha6a90dcazcduqvtu2776q29w7np738qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qyjtph" />
    <content type="html">
      Turns out &amp;#34;despite patches&amp;#34; means &amp;#34;despite patches being available, because a bunch of people aren&amp;#39;t applying them&amp;#34; rather than &amp;#34;despite patching it, but it&amp;#39;s still vulnerable anyway and there&amp;#39;s something wrong with the patches&amp;#34; 🙄&lt;br/&gt;&lt;br/&gt;Words mean things.&lt;br/&gt;&lt;br/&gt;#SavedYouAClick&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/106/641/147/402/157/original/b4557659364e2480.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-28T13:35:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq8xalt3k4cvu8f9n5a98hmrqhz6vh6fymphppy0hswym9806mmpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gh6y8p</id>
    
      <title type="html">MDXfind 1.133 released: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq8xalt3k4cvu8f9n5a98hmrqhz6vh6fymphppy0hswym9806mmpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gh6y8p" />
    <content type="html">
      MDXfind 1.133 released:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.techsolvency.com/pub/bin/mdxfind/&#34;&gt;https://www.techsolvency.com/pub/bin/mdxfind/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Highlights:&amp;lt;li&amp;gt;Now shows hash and candidate rates/sec in comfort messages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Significant (10x) improvement in solution output speed for hashes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Previously undocumented features, including &amp;lt;code&amp;gt;-m&amp;lt;/code&amp;gt; flag to specify hashtypes in hashcat mode syntax&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Metadata showing mapping of MDXfind hashtype IDs (by position in -h) to hashcat modes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Now with gzip support for hashes (&amp;lt;code&amp;gt;-f&amp;lt;/code&amp;gt; or stdin), and for candidate lists&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Too many to fully list, but lots of interesting stuff in the full changelog:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.techsolvency.com/pub/bin/mdxfind/CHANGES.txt&#34;&gt;https://www.techsolvency.com/pub/bin/mdxfind/CHANGES.txt&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Always be cracking!&lt;br/&gt;&lt;br/&gt;#MDXfind
    </content>
    <updated>2025-08-26T04:50:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0vceznfns9ph5fjy3lywuce0d2nn79zgy7azd88na0jhdktn55jczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6de5t4d</id>
    
      <title type="html">Good morning to everyone except GitHub, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0vceznfns9ph5fjy3lywuce0d2nn79zgy7azd88na0jhdktn55jczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6de5t4d" />
    <content type="html">
      Good morning to everyone except GitHub, which:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;allows (but strongly discourages) fine-grained access tokens with no expiration date, but&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;won&amp;#39;t let you create one with an expiration date more than one year out.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;So my choices are &amp;#34;never expire&amp;#34; or expire in a year or less&amp;#34;.&lt;br/&gt;&lt;br/&gt;Our Threat Models May Vary!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/084/577/063/180/916/original/104e991dda12e654.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-24T16:00:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe</id>
    
      <title>Nostr event nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe" />
    <content type="html">
       &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/076/073/281/692/964/original/7d6dfe18520f454f.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-23T04:00:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdsxs8cynqr9a2uzndvycjxadwrhcuey5wgtqx2pjrymvu3pxcfrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64w69za</id>
    
      <title type="html">These can both be true: &amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Passkey deployment has ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdsxs8cynqr9a2uzndvycjxadwrhcuey5wgtqx2pjrymvu3pxcfrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64w69za" />
    <content type="html">
      These can both be true: &amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Passkey deployment has been fraught with UX challenges, failures to advise users about threat model trade-offs, and vendor lock-in concerns &amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;The ecosystem couldn&amp;#39;t go much longer without the benefits of passkeys (reducing password reuse risk, mitigating infostealer harm, and deploying FIDO2 phishing resistance at scale)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;#Passkeys
    </content>
    <updated>2025-08-18T14:56:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstj75fw48eqx6uvp2hj0pgyk3gevj8xvyx58j3gjzzxsjns9s7zugzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyl8v9</id>
    
      <title type="html">Ah, another &amp;#34;strong MFA bypassed&amp;#34; story. /me opens ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstj75fw48eqx6uvp2hj0pgyk3gevj8xvyx58j3gjzzxsjns9s7zugzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyl8v9" />
    <content type="html">
      Ah, another &amp;#34;strong MFA bypassed&amp;#34; story.&lt;br/&gt;&lt;br/&gt;/me opens article, starts scanning for buried lede&lt;br/&gt;&lt;br/&gt;Ah, here it is ... paragraph 8:&lt;br/&gt;&lt;br/&gt;&amp;#34;First you have to compromise the endpoint&amp;#34;&lt;br/&gt;&lt;br/&gt;🙄 &lt;br/&gt;&lt;br/&gt;Surprise! This is *not something passkeys -- or any other authentication system -- are designed to mitigate*.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/passkey-login-bypassed-via-webauthn-process-manipulation/&#34;&gt;https://www.securityweek.com/passkey-login-bypassed-via-webauthn-process-manipulation/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I say again: the word &amp;#34;bypass&amp;#34; only leaves the layperson with the impression of &amp;#34;nya nya strong MFA isn&amp;#39;t as strong as they said lol&amp;#34; ... and the CIO with the impression &amp;#34;you told me I had to move to strong MFA why do they keep finding problems with it&amp;#34;&lt;br/&gt;&lt;br/&gt;Cut it out.
    </content>
    <updated>2025-08-17T22:23:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9qkeqps2e6pwk4kpuqa97eklpk5xc0u79jyqxra8jsd5kau7physzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m6kxle</id>
    
      <title type="html">So ... is the new Sandia time-independent MFA thing: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9qkeqps2e6pwk4kpuqa97eklpk5xc0u79jyqxra8jsd5kau7physzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m6kxle" />
    <content type="html">
      So ... is the new Sandia time-independent MFA thing:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&#34;&gt;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;... just ... renegotiating a new per-client code every time there&amp;#39;s a new connection?&lt;br/&gt;&lt;br/&gt;Like ... how garage door openers have worked ... since the mid-90s?
    </content>
    <updated>2025-08-17T15:39:19Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxz6xdjxy9s4754r2pwr3cwtlwxm2l2vg75hqs5z4mmk5psczvjdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdexnz</id>
    
      <title type="html">Huh -- did I miss it, or does even the upstream Sandia not ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxz6xdjxy9s4754r2pwr3cwtlwxm2l2vg75hqs5z4mmk5psczvjdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdexnz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspmhh83445ue4qt5l36fcnhrpr2xf0m6nknlq7dsmmg8uwkwlrf8qpdh8hc&#39;&gt;nevent1q…h8hc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Huh -- did I miss it, or does even the upstream Sandia not actually say what the approach *is*?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&#34;&gt;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;All I can extract from the coverage is &amp;#34;easier&amp;#34; and &amp;#34;time-independent&amp;#34;.&lt;br/&gt;&lt;br/&gt;Still digging ...&lt;br/&gt;&lt;br/&gt;Edit: is it... just ... renegotiating a new per-client code every time there&amp;#39;s a new connection?&lt;br/&gt;&lt;br/&gt;Like ... how garage door openers have worked ... since the mid-90s?
    </content>
    <updated>2025-08-17T15:33:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrt88fmw5sflgxgahhchhnl7qnd7kwtuen9y6hkxvud4qxpn74ejszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6szzg3k</id>
    
      <title type="html">Kiddo: why do you put the full year with &amp;#34;20&amp;#34; at the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrt88fmw5sflgxgahhchhnl7qnd7kwtuen9y6hkxvud4qxpn74ejszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6szzg3k" />
    <content type="html">
      Kiddo: why do you put the full year with &amp;#34;20&amp;#34; at the front when you sign the school forms?&lt;br/&gt;&lt;br/&gt;Me: *thousand-yard Y2K stare*
    </content>
    <updated>2025-08-16T22:00:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszvkx6jwxvz85dvefutayzs9sxf060dvd7uchfdet8utu54ahdfpszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65ep8th</id>
    
      <title type="html">Since it&amp;#39;s just the tree, if someone could snapshot it ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszvkx6jwxvz85dvefutayzs9sxf060dvd7uchfdet8utu54ahdfpszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65ep8th" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxy7r43qchgkzmszrq4x3eltpmj7e823vc05a5cdsyu6n77hu4zgq9m7j9d&#39;&gt;nevent1q…7j9d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Since it&amp;#39;s just the tree, if someone could snapshot it safetly and put a text-only version of it somewhere (like a GitHub gist), folks would probably appreciate that
    </content>
    <updated>2025-08-15T17:56:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqul3npk8ctuav9h754s2wwml35jnqhwzk03utdmvdmufeq0rgzsqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rvxe67</id>
    
      <title type="html">Does &amp;#34;runtime&amp;#34; here always imply &amp;#34;source code is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqul3npk8ctuav9h754s2wwml35jnqhwzk03utdmvdmufeq0rgzsqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rvxe67" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswzfqnhspg50nwn89ck3kx5jwsx75naet6705r5c5qpgqtdr5xh0cz96t3h&#39;&gt;nevent1q…6t3h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Does &amp;#34;runtime&amp;#34; here always imply &amp;#34;source code is available&amp;#34;?
    </content>
    <updated>2025-08-13T15:59:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqg9cucvm6sgd2v59dvlku94znvdv8yraf6q98zud08sy6t87e3uqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6z39mkg</id>
    
      <title type="html">On mobile, desktop, or both? I hadn&amp;#39;t seen this yet, can you ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqg9cucvm6sgd2v59dvlku94znvdv8yraf6q98zud08sy6t87e3uqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6z39mkg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf04js3g6unpz2gr27s9yv2qw0mnsvdcsyr78upqc2flr0yyk2fhg7glved&#39;&gt;nevent1q…lved&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;On mobile, desktop, or both? I hadn&amp;#39;t seen this yet, can you point me to some coverage or a summary?
    </content>
    <updated>2025-08-03T01:15:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswzcvqp775832t3feqqtpsrtc492uszc4z4up7g3n49xuknpsxqrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mmx33z</id>
    
      <title type="html">Things platforms want you to do less of:&amp;lt;li&amp;gt;untrackably ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswzcvqp775832t3feqqtpsrtc492uszc4z4up7g3n49xuknpsxqrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mmx33z" />
    <content type="html">
      Things platforms want you to do less of:&amp;lt;li&amp;gt;untrackably copy a link to something&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;save an image&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;copy arbitrary text&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;decide what to look at next&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;return to where you were a minute ago&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;find options you can change&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;know how many search results there are / length of scroll&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;decide what part of a video you want to see&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;prioritize and deprioritize content based on your own preferences&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;manage your own attention&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Mobile apps make this agenda easier. Apps are for companies.&lt;br/&gt;&lt;br/&gt;The web makes this agenda harder. The web is for people.
    </content>
    <updated>2025-08-02T16:22:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdu54xkt3t44lkyvgnjxz8fxqhl28ra4tp8a5qc3m0jk8f23e69hszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65rldxm</id>
    
      <title type="html">RIP the Corporation for Public Broadcasting. It genuinely made ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdu54xkt3t44lkyvgnjxz8fxqhl28ra4tp8a5qc3m0jk8f23e69hszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65rldxm" />
    <content type="html">
      RIP the Corporation for Public Broadcasting.&lt;br/&gt;&lt;br/&gt;It genuinely made generations of kids both smarter and more empathetic.&lt;br/&gt;&lt;br/&gt;The only winners in this outcome are the enemies of the United States.&lt;br/&gt;&lt;br/&gt;And I didn&amp;#39;t realize it was going to hit me this hard.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://cpb.org/pressroom/Corporation-Public-Broadcasting-Addresses-Operations-Following-Loss-Federal-Funding&#34;&gt;https://cpb.org/pressroom/Corporation-Public-Broadcasting-Addresses-Operations-Following-Loss-Federal-Funding&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/955/006/431/239/715/original/c0c606310dafb247.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-01T18:52:33Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0dxg2mn5thayky4d77rnq9dkn05x7q8gnkg8a5a8gz2juw79xq4gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pz9w6l</id>
    
      <title type="html">Oh look, another &amp;#34;door locks are bad because someone can ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0dxg2mn5thayky4d77rnq9dkn05x7q8gnkg8a5a8gz2juw79xq4gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pz9w6l" />
    <content type="html">
      Oh look, another &amp;#34;door locks are bad because someone can crawl through the window&amp;#34; scare article (this time a sponsored one). Not responsible journalism, Bleeping.&lt;br/&gt;&lt;br/&gt;I especially &amp;#34;appreciate&amp;#34; the scare quotes around &amp;#34;phishing-resistant&amp;#34; 🤬&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/940/426/507/441/860/original/661dc84d7ed44ed9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-30T05:03:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsptk9cdnzqu5s3wvtf8ls6sfzem5v0rgtzm26y77538pj6d5ll9nszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g5jd7q</id>
    
      <title type="html">Never tell a call with 300 people that they can just drop ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsptk9cdnzqu5s3wvtf8ls6sfzem5v0rgtzm26y77538pj6d5ll9nszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g5jd7q" />
    <content type="html">
      Never tell a call with 300 people that they can just drop questions into chat whenever they want for a 3 hour presentation. Only takes 5‰ of them taking you up on it -- who somehow don&amp;#39;t realize most of their questions are about to be answered -- to derail velocity.
    </content>
    <updated>2025-07-22T17:32:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstv822eqlgx2prdr66wl5h87wnng2m4sj4ad9t7jqk5jyu33utvjczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jxyytu</id>
    
      <title type="html">Man, this feels like *some* data-hoarding person would have ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstv822eqlgx2prdr66wl5h87wnng2m4sj4ad9t7jqk5jyu33utvjczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jxyytu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszdkrvl2ts6f3vxjul0ypfchw2h3uyr2crqw58yr3khrws0ncvdvqys55p4&#39;&gt;nevent1q…55p4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Man, this feels like *some* data-hoarding person would have retained it -- or was it never actually downloadable?
    </content>
    <updated>2025-07-16T22:16:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs898ufwxpap39yr4dpu032yrqatr6d0qtucnc04l68y22t2en5wxqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hgylky</id>
    
      <title type="html">I mean, I just liked the quote. Wasn&amp;#39;t really trying to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs898ufwxpap39yr4dpu032yrqatr6d0qtucnc04l68y22t2en5wxqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hgylky" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy00uhgh467n80u524qds4h87q0z74sf04upypp9h3fvct2qnxreq9muych&#39;&gt;nevent1q…uych&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I mean, I just liked the quote. Wasn&amp;#39;t really trying to invoke the overall article either way.&lt;br/&gt;&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qu3…rukd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-07-11T05:11:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr8a2mgmtzfklsjarkk9skp3wawdyyrutaakkvhgqf9amfqar4hgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67wxr0z</id>
    
      <title type="html">&amp;#34;Engineering should eat security.&amp;#34; -- Caleb Sima Source: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr8a2mgmtzfklsjarkk9skp3wawdyyrutaakkvhgqf9amfqar4hgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67wxr0z" />
    <content type="html">
      &amp;#34;Engineering should eat security.&amp;#34;&lt;br/&gt;-- Caleb Sima&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://danielmiessler.com/blog/ai-creative-destruction-wave&#34;&gt;https://danielmiessler.com/blog/ai-creative-destruction-wave&lt;/a&gt;&lt;br/&gt;(via &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qu3…rukd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;)
    </content>
    <updated>2025-07-11T03:03:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqm4zmsu4jzz8d3s95csrr7h0nkx5qvwuku752nne044tw0s8xhgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67pz95d</id>
    
      <title type="html">Couldn&amp;#39;t find this anywhere and my scanner is borked, but at ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqm4zmsu4jzz8d3s95csrr7h0nkx5qvwuku752nne044tw0s8xhgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67pz95d" />
    <content type="html">
      Couldn&amp;#39;t find this anywhere and my scanner is borked, but at least here&amp;#39;s a photo, with alt text.&lt;br/&gt;&lt;br/&gt;Love Rich Tennant -- quite insightful. Not affiliated, just a fan:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://the5thwave.com/&#34;&gt;https://the5thwave.com/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;1/2&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/818/490/234/977/264/original/aed1a73424353b18.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-08T16:13:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxl8hdhnfxhsqm547xv5al4evktp3v9euph06c59jvzz3v4zkraxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63s9snf</id>
    
      <title type="html">Mention of &amp;#34;several mitigations&amp;#34; without details ... ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxl8hdhnfxhsqm547xv5al4evktp3v9euph06c59jvzz3v4zkraxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63s9snf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfdygx8w7vrr5tyhwc3tc2qeyc7zpl3p3jumgxmny07fcwztnxlpqh5m7gs&#39;&gt;nevent1q…m7gs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Mention of &amp;#34;several mitigations&amp;#34; without details ... sheesh
    </content>
    <updated>2025-07-08T13:55:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspa7kjur8p2vulyxxfe656eevht6a0ue88whp6j20gcqpkcelw9zgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xmcpfy</id>
    
      <title type="html">That sounds quite satisfying -- nice work! Need before and after ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspa7kjur8p2vulyxxfe656eevht6a0ue88whp6j20gcqpkcelw9zgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xmcpfy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyfljrlwrrcz9dfrtmkgacj79pkdzdqgpm4xyq4f9ccw84gghusggtmaky5&#39;&gt;nevent1q…aky5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That sounds quite satisfying -- nice work! Need before and after photos 😉
    </content>
    <updated>2025-06-28T23:47:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgv45gl9j9kdhpx3tj2242ckyswj5y5hw2e4hpnxe6grqvxkzgrcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6a06hyz</id>
    
      <title type="html">Ooh, really?! That&amp;#39;s so great. Legit impressed</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgv45gl9j9kdhpx3tj2242ckyswj5y5hw2e4hpnxe6grqvxkzgrcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6a06hyz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp7akev2hsjlqcem7re5c82mp557cnzlphd50dpljwv3hs3pyftlqhcpnwf&#39;&gt;nevent1q…pnwf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ooh, really?! That&amp;#39;s so great. Legit impressed
    </content>
    <updated>2025-06-27T03:24:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8a792ylakyasuh9ued80rusfk43r6rsa6u58zj8ehjny9cqls48qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g0rskq</id>
    
      <title type="html">Collab / call platforms: Just add a &amp;#34;When someone shares ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8a792ylakyasuh9ued80rusfk43r6rsa6u58zj8ehjny9cqls48qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g0rskq" />
    <content type="html">
      Collab / call platforms: &lt;br/&gt;&lt;br/&gt;Just add a &lt;br/&gt;&lt;br/&gt;&amp;#34;When someone shares their screen, give all other attendees a &amp;#39;Can you see what is being shared? Yes / No&amp;#39; button&lt;br/&gt;&lt;br/&gt;already.
    </content>
    <updated>2025-06-26T16:03:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfk2460h6xaj6w8g8jhdcqhn7svnmgxtjs70xk45ftk8kexyjeahszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v5zxlm</id>
    
      <title type="html">Assuming you have **no plans to leave the house** that day ... at ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfk2460h6xaj6w8g8jhdcqhn7svnmgxtjs70xk45ftk8kexyjeahszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v5zxlm" />
    <content type="html">
      Assuming you have **no plans to leave the house** that day ... at what percentage of battery level on your primary mobile device do you *start* to get uncomfortable, and think you should charge it?&lt;br/&gt;&lt;br/&gt;Assume you will not have access to a charger or external power pack while away (If you do end up having to leave).&lt;br/&gt;&lt;br/&gt;(If your number is somewhere in between, choose the next lower number) &lt;br/&gt;&lt;br/&gt;(Please RT to improve sample size.)
    </content>
    <updated>2025-06-24T14:12:36Z</updated>
  </entry>

</feed>