Has anyone scraped git repos with embedded graphics files to verify whether any of them have undisplayed embedded data of suspicious complexity?
Notices by Matthew Garrett (mjg59@nondeterministic.computer)
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Monday, 16-Sep-2024 17:14:36 JST Matthew Garrett -
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Thursday, 15-Aug-2024 07:16:51 JST Matthew Garrett -
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Wednesday, 14-Aug-2024 11:43:34 JST Matthew Garrett Cursed PSU that's fixed 12V but has a USB-C connector
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Wednesday, 14-Aug-2024 11:43:28 JST Matthew Garrett Look at this shit. Just horrifying.
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Thursday, 01-Aug-2024 15:26:15 JST Matthew Garrett I think the thing that most people do not realise is that correctly implemented privacy preserving apps are very much the exception, not the norm
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Thursday, 01-Aug-2024 15:26:14 JST Matthew Garrett So many social norms are entirely based around nobody ever hitting F12 and looking at the network traffic
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Thursday, 01-Aug-2024 15:26:13 JST Matthew Garrett App security is frequently based on the idea that nobody can just hit F12 there, and, sadly, things like mitmproxy
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Monday, 29-Jul-2024 14:42:59 JST Matthew Garrett @qdot hey uh for reasons I'm wondering whether you have a list of devices with protocols that haven't been reimplemented yet
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Monday, 20-May-2024 10:16:15 JST Matthew Garrett Why does my IdP have two entirely different flows for MFA auth depending on how you're hitting it
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Monday, 20-May-2024 10:16:10 JST Matthew Garrett User freedom is obviously the most important aspect of free software but the economic cost of staring at wire dumps to figure out a transaction flow instead of just being able to read the implementation should not be understated
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Wednesday, 10-Apr-2024 17:37:59 JST Matthew Garrett Twitter just doing a "redirect links in tweets that go to x.com to twitter.com instead but accidentally do so for all domains that end x.com like eg spacex.com going to spacetwitter.com" is not absolutely the funniest thing I could imagine but it's high up there
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Monday, 11-Mar-2024 11:34:46 JST Matthew Garrett Sometimes I think maybe San Francisco isn't as weird as people think and then I remember I've dated multiple people who've had Tommy Wiseau as a landlord
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Sunday, 31-Dec-2023 11:42:12 JST Matthew Garrett I /could/ figure out what this function is doing with bignums by staring at decompilation for long enough, or I could just fake up a declaration for it and call it directly, and the latter sounds more fun
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Sunday, 31-Dec-2023 11:42:04 JST Matthew Garrett First rule of RE: if you already have the function, consider just calling the function
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Saturday, 30-Dec-2023 07:10:15 JST Matthew Garrett @lain your attendees should know whether someone is allowed to be at the event or not. They should not be left with a statement that implies one while actually the other is true.
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Saturday, 30-Dec-2023 07:04:30 JST Matthew Garrett You're running a conference and you receive reports of an attendee having sexually assaulted people. You have 3 choices:
(1) you behave as if you believe the accusation. You make it clear that the alleged assailant is permanently banned.
(2) you behave as if you don't believe the accusation. You make it clear that the alleged assailant is still welcome.
(3) you choose neither, and imply that the alleged assailant is not welcome but do nothing to enforce that(3) is the worst choice here
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Saturday, 30-Dec-2023 07:04:29 JST Matthew Garrett Your attendees should be able to make an informed decision about how safe they'll be at your event. If you imply one outcome while allowing another you aren't giving them the information required to make that decision.
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Sunday, 24-Dec-2023 11:18:51 JST Matthew Garrett How has the Salesforce Tower never shown Bad Apple surely that should have been the canonical test event
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Sunday, 10-Dec-2023 06:38:43 JST Matthew Garrett Bother I have somehow ended up with 12mm-wide 3 pin LED strips despite the vendor stating that they were 1cm, and now these connectors won't fit so I'm going to have to solder a bunch of shit
-
Matthew Garrett (mjg59@nondeterministic.computer)'s status on Saturday, 09-Dec-2023 09:10:24 JST Matthew Garrett Just bought a USB foot pedal, now I can finally learn vi