<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-24T11:54:54Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Royce Williams</title>
  <author>
    <name>Royce Williams</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z.rss" />
  <link href="https://yabu.me/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z" />
  <id>https://yabu.me/npub1d9j86kugzarj4skw6juglk2de6mful9svqu8yac6vum5wz5xtcwsyv7m3z</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/108/195/621/247/550/549/original/d96204cc09c9dbfe.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/108/195/621/247/550/549/original/d96204cc09c9dbfe.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf</id>
    
      <title>Nostr event nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd3kz6wgy39yrmtu2mcf45knxu2k2srk4v5a4fnp6p60ljv252ragzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qu3tf" />
    <content type="html">
      I keep reading &amp;#34;AiTM&amp;#34; as &amp;#34;Am I The Monster&amp;#34;
    </content>
    <updated>2026-04-22T22:47:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdr4pmd9y8z20x44safahj3xvpy9v70rka4knv9arvv7ke0fade9qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jk4g6x</id>
    
      <title type="html">https://www. ietf.org/archive/id/draft-meow -mrrp-00.html</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdr4pmd9y8z20x44safahj3xvpy9v70rka4knv9arvv7ke0fade9qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jk4g6x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszk35wp7g9e40hukg3st4s0ws0qzt87cr924m29kj8em0m9kjywwsrpzlh7&#39;&gt;nevent1q…zlh7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www&#34;&gt;https://www&lt;/a&gt;.&lt;br/&gt;ietf.org/archive/id/draft-meow&lt;br/&gt;-mrrp-00.html
    </content>
    <updated>2026-04-17T14:54:02Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0</id>
    
      <title>Nostr event nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9ztpaxf3695yfdw0wcrm3eu7esmh63qheflj8vp4nry7sdep4a5qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kvj0q0" />
    <content type="html">
      Lies, damned lies, and &amp;#34;LIFT TAB TO OPEN&amp;#34;
    </content>
    <updated>2026-04-16T15:12:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvgne4yylu9y3wpv22cq0fy9t9t3c7rzla6t8n2deq34k7s3qy7gqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fjnj0u</id>
    
      <title type="html">I don&amp;#39;t understand why the recovery of deleted Signal ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvgne4yylu9y3wpv22cq0fy9t9t3c7rzla6t8n2deq34k7s3qy7gqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fjnj0u" />
    <content type="html">
      I don&amp;#39;t understand why the recovery of deleted Signal messages is news.&lt;br/&gt;&lt;br/&gt;If an attacker has full access to the endpoiint, Signal has never claimed to protect messages -- and IIRC, has expressly stated that they do not.&lt;br/&gt;&lt;br/&gt;Edit: But hey, at least it is getting the word out that deleting the app doesn&amp;#39;t delete the messages!
    </content>
    <updated>2026-04-09T15:49:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd83gwxs3rcwkxpry07exxae2tru3krrgwtrkg7tu8ywyd36gnc9gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t9zyyt</id>
    
      <title type="html">RE: https://techpolicy.social/@joebeone/116194325589609756 New AI ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd83gwxs3rcwkxpry07exxae2tru3krrgwtrkg7tu8ywyd36gnc9gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6t9zyyt" />
    <content type="html">
      RE: &lt;a href=&#34;https://techpolicy.social/@joebeone/116194325589609756&#34;&gt;https://techpolicy.social/@joebeone/116194325589609756&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;New AI term just dropped: vibekilling&lt;br/&gt;nostr:note1679ex0ww9sjqnykfsq5vd999ez3k9w80h3drluglutwp655ept2sx7q3j4&lt;br/&gt;
    </content>
    <updated>2026-03-08T15:45:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg6ls54fgt0l9h7pwwk7xefa8ep830g2zsadsgxlptayg24j28gjgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6cxeda7</id>
    
      <title type="html">&amp;#34;Wow, I got a TOTP code of 000000! What are the odds of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg6ls54fgt0l9h7pwwk7xefa8ep830g2zsadsgxlptayg24j28gjgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6cxeda7" />
    <content type="html">
      &amp;#34;Wow, I got a TOTP code of 000000! What are the odds of that?!&amp;#34;&lt;br/&gt;&lt;br/&gt;&amp;#34;Uh ... one in a million?&amp;#34;&lt;br/&gt;&lt;br/&gt;&amp;#34;I know, right?&amp;#34;&lt;br/&gt;&lt;br/&gt;🤣
    </content>
    <updated>2026-01-24T20:27:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdz5ypd2y8r7vlpkzhtu6vnzlnnsf2c32agdmkwsymhdck0r2wv6gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q7wdyl</id>
    
      <title type="html">The nice thing about EICAR is that, when properly implemented, it ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdz5ypd2y8r7vlpkzhtu6vnzlnnsf2c32agdmkwsymhdck0r2wv6gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q7wdyl" />
    <content type="html">
      The nice thing about EICAR is that, when properly implemented, it should only produce a hit if it is at the *beginning* of the file (per the EICAR spec itself). Inclusions of EICAR elsewhere are amusing, but should absolutely be false positives that should be fixed.&lt;br/&gt;&lt;br/&gt;The Anthropic magic string, by contrast, can appear *anywhere*. The chaos this enables is commensurately greater.
    </content>
    <updated>2026-01-22T22:35:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgwa5z7g4nrxaeptxngrjjcrz9p6rg83c67hzdsrs2lajddmyt3pszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q5kqat</id>
    
      <title type="html">I&amp;#39;m having a Mandela Effect / Berenstain Bears moment where I ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgwa5z7g4nrxaeptxngrjjcrz9p6rg83c67hzdsrs2lajddmyt3pszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q5kqat" />
    <content type="html">
      I&amp;#39;m having a Mandela Effect / Berenstain Bears moment where I *swear* people say &amp;#34;pled&amp;#34; as the past tense of &amp;#34;plead&amp;#34; ... but half of the spellcheckers don&amp;#39;t like it?
    </content>
    <updated>2026-01-06T21:10:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspzsq8qn2cqyfjdslddsrsp64h8xwwfugfttrvckxau8qx4eyv92czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j5n79q</id>
    
      <title type="html">Ah, indeed. Though when working as designed, the ATA Secure Erase ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspzsq8qn2cqyfjdslddsrsp64h8xwwfugfttrvckxau8qx4eyv92czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j5n79q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqdu8qzdp487jpr7ks3zt0faqquvv0kuw44khn98cwgkakn3ruysgdqq2np&#39;&gt;nevent1q…q2np&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ah, indeed. Though when working as designed, the ATA Secure Erase *should* reach all storage. Except when it doesn&amp;#39;t. Hmm.&lt;br/&gt;&lt;br/&gt;In your experience, what are the ATA Secure Erase failure modes? If we (pessimistically) assume that it can fail silently, it is probably often working as intended (unless it throws an error).&lt;br/&gt;&lt;br/&gt;So if I had to write an internal standard at $dayjob, the wiping workflow would *always* attempt an ATA Secure Erase first, and then *always* follow with a single overwrite (with zeroes or NULL; the reasons for overlapping / random / multipass are from ancient HDD days).
    </content>
    <updated>2025-12-30T03:19:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg77pt5vqztw6mx9md2d26wd9q8qz9tarscunqn9sg80s68ytcvdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rcr6kx</id>
    
      <title type="html">I&amp;#39;d argue that verification is itself limited. Part of the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg77pt5vqztw6mx9md2d26wd9q8qz9tarscunqn9sg80s68ytcvdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rcr6kx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvnynp93xdf8n8c4dpvl9uxrcpt2v27ah5rrr5gex2hxemnue7tjgskyxe2&#39;&gt;nevent1q…yxe2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;d argue that verification is itself limited. Part of the OS-level verification gap/problem is that the storage has regions that the OS can&amp;#39;t reach. So an OS-level verification process is inherently incomplete.
    </content>
    <updated>2025-12-30T03:03:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst4k2n74w4d07ld2supzu2p3wwksj0cv73353jed60hcejd6vdgfczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pvaasf</id>
    
      <title type="html">Hmm .. since each approach covers angles that the other does not, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst4k2n74w4d07ld2supzu2p3wwksj0cv73353jed60hcejd6vdgfczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pvaasf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszgsc8s56kjhq0ucvuv6kf5msdc3gx8ka5hhk7rwemwhvu0u20jdqlrp7cr&#39;&gt;nevent1q…p7cr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hmm .. since each approach covers angles that the other does not, then, the most robust approach is probably to first trigger an ATA Secure Erase, and then do an overwrite.
    </content>
    <updated>2025-12-30T03:00:56Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2q6lpysu5vda0wpfqkjxrgejg35pdsqgt7at2h8l28m394wkst3szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p9hw99</id>
    
      <title type="html">SSDs also support ATA Secure Erase (controller-level ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2q6lpysu5vda0wpfqkjxrgejg35pdsqgt7at2h8l28m394wkst3szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6p9hw99" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs09ydtj7t3ganmflghayjcacrg92e93g8kld4czuhqgux3v6cswhg03s0ut&#39;&gt;nevent1q…s0ut&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;SSDs also support ATA Secure Erase (controller-level encrypt-then-discard-key) -- which should, in theory, be significantly more thorough than OS-level overwrite.&lt;br/&gt;&lt;br/&gt;This is also the NIST-approved method.
    </content>
    <updated>2025-12-30T02:51:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvf6hutq3yc2k7jlre8frrnq7ng4jdm84y3wuesmyd7je696eevxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lrf3re</id>
    
      <title type="html">RE: https://infosec.exchange/@zak/115793005915790340 This is a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvf6hutq3yc2k7jlre8frrnq7ng4jdm84y3wuesmyd7je696eevxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lrf3re" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@zak/115793005915790340&#34;&gt;https://infosec.exchange/@zak/115793005915790340&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is a metaphor about cybersecurity products.&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note156ng4d0q305y4mcqlc8exn0u0eyxj2fe9x663n2femh8ul66uw2qw5mum6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note156n…mum6&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Eyelashes: stop things from falling into your eyes.&lt;br/&gt;&lt;br/&gt;Also eyelashes: fall directly into your eyes.&lt;br/&gt;&lt;br/&gt;What horseshit. &lt;/blockquote&gt;
    </content>
    <updated>2025-12-27T18:49:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs986mwja8pe82mps6xar26xrerpwzjca2jdtyljk9wkc4w4cv23mqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6624wz9</id>
    
      <title type="html">Also how did we manage to land the &amp;#34;switch to passkeys&amp;#34; ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs986mwja8pe82mps6xar26xrerpwzjca2jdtyljk9wkc4w4cv23mqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6624wz9" />
    <content type="html">
      Also how did we manage to land the &amp;#34;switch to passkeys&amp;#34; messaging ... but somehow miss the &amp;#34;and you absolutely must let users add more than one, with clear UX&amp;#34; bit?
    </content>
    <updated>2025-12-15T15:59:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2tmtjqg4l5s34hxh5krmggerunhngg2qhujkymeqyr0wxkp00gzgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6l4jnlq</id>
    
      <title type="html">&amp;#34;Let us be the repository of your passkeys&amp;#34; and &amp;#34;We ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2tmtjqg4l5s34hxh5krmggerunhngg2qhujkymeqyr0wxkp00gzgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6l4jnlq" />
    <content type="html">
      &amp;#34;Let us be the repository of your passkeys&amp;#34; and &amp;#34;We may terminate your account at any time and permanently refuse to communicate with you&amp;#34; ... seems like a bad combination?
    </content>
    <updated>2025-12-15T15:54:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst9c9yhs8mjr06uv6aa85qf4mgklu69g6k7wkvft9a7gfqgwrvnmczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mnnepa</id>
    
      <title type="html">Welp, Google is killing off the Dark Web Report feature, which ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst9c9yhs8mjr06uv6aa85qf4mgklu69g6k7wkvft9a7gfqgwrvnmczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mnnepa" />
    <content type="html">
      Welp, Google is killing off the Dark Web Report feature, which was useful (to me, anyway), as of Feb 16, 2026.
    </content>
    <updated>2025-12-15T15:38:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r</id>
    
      <title>Nostr event nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs09mh9cnawlpdxt69atdwvs8a0m6z3p3dg0ukh4w07jalwdmdl27gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6s2k03r" />
    <content type="html">
      I kinda hate the mashed-to-a-single word &amp;#34;protip&amp;#34;.
    </content>
    <updated>2025-12-05T15:53:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs28x3grajxxcspyp5uk7aqwchv6sqkqta0j5fymwkaey8jnqcm8zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gvsygk</id>
    
      <title type="html">I know of seven org-branded standard YubiKey bubble packs (note: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs28x3grajxxcspyp5uk7aqwchv6sqkqta0j5fymwkaey8jnqcm8zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gvsygk" />
    <content type="html">
      I know of seven org-branded standard YubiKey bubble packs (note: the *packaging* is branded, not necessarily the *key*). Are there any more?&lt;br/&gt;&lt;br/&gt;First four:&lt;br/&gt;&lt;br/&gt;1/2&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/397/825/441/original/f6c889fc2f3c6a94.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/411/125/957/original/de3305906c9a1734.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/412/202/164/original/2069f3377ec222f4.jpg&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/613/143/413/197/977/original/2b50d486de30ee16.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-11-26T00:23:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvh6pfjnff72mrqf46ygqt4gszvsuefwnwj8ferahtxje4zvurchqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ay3s8l</id>
    
      <title type="html">I don&amp;#39;t know why this is how I found out. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvh6pfjnff72mrqf46ygqt4gszvsuefwnwj8ferahtxje4zvurchqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ay3s8l" />
    <content type="html">
      I don&amp;#39;t know why this is how I found out.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html&#34;&gt;https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Anchorage is going to try voting by phone.&lt;br/&gt;&lt;br/&gt;No one who understands the problem space thinks this is a good idea.
    </content>
    <updated>2025-11-15T20:15:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9a3cs6ws28dc4ta7auj8zzuukd80y0pyyjangjpuz5vprm4nyjcgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mr2s60</id>
    
      <title type="html">OH: &amp;#34;You&amp;#39;re in his DMs. I&amp;#39;m in his VMs. We&amp;#39;re not ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9a3cs6ws28dc4ta7auj8zzuukd80y0pyyjangjpuz5vprm4nyjcgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mr2s60" />
    <content type="html">
      OH: &amp;#34;You&amp;#39;re in his DMs. I&amp;#39;m in his VMs. We&amp;#39;re not the same.&amp;#34;
    </content>
    <updated>2025-11-07T06:55:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd5c8h9rte2r44rs6ctss65463fj4fffh0xe4tr7hf34pn4c63e4qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdgpqy</id>
    
      <title type="html">The kids can&amp;#39;t eat without something to scroll. It terrifies ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd5c8h9rte2r44rs6ctss65463fj4fffh0xe4tr7hf34pn4c63e4qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdgpqy" />
    <content type="html">
      The kids can&amp;#39;t eat without something to scroll. It terrifies me. When can we rest? When can we have ideas? When can we connect?
    </content>
    <updated>2025-11-07T00:35:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqwc9sr2cquucy23z3hscpf86rhkldhmk2u5rdd2rdnsf85kqul2gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ff50rz</id>
    
      <title type="html">Indeed! This thread is what triggered the support in JtR (and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqwc9sr2cquucy23z3hscpf86rhkldhmk2u5rdd2rdnsf85kqul2gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ff50rz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx3yue00amyjqpfvn97zy7wxkccjdsa0xuep5uza2p7aqddelcq3smw06mw&#39;&gt;nevent1q…06mw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Indeed! This thread is what triggered the support in JtR (and eventually hashcat):&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://unix.stackexchange.com/questions/31549/is-it-possible-to-find-out-the-hosts-in-the-known-hosts-file&#34;&gt;https://unix.stackexchange.com/questions/31549/is-it-possible-to-find-out-the-hosts-in-the-known-hosts-file&lt;/a&gt;
    </content>
    <updated>2025-11-05T21:11:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2h2ugxewshfzxgwflwsh8wewra5mmevhzgm0kl7jh6ghmhp9wepqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64r7grx</id>
    
      <title type="html">Happy to try to crack them if you&amp;#39;d like!</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2h2ugxewshfzxgwflwsh8wewra5mmevhzgm0kl7jh6ghmhp9wepqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64r7grx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdtvl4wwwqr9ye48hd5nnxmnuyjpj23j3hpxsm6gwuh5lwfmhsmyshhj37n&#39;&gt;nevent1q…j37n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Happy to try to crack them if you&amp;#39;d like!
    </content>
    <updated>2025-11-05T21:08:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf69d57l4umjyj6gt7rjvcjzhu4cp355nqasrt9qe4muefvg76vpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d7ep5j</id>
    
      <title type="html">Whoa, how did I miss that you&amp;#39;ll be able to buy YubiKeys at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf69d57l4umjyj6gt7rjvcjzhu4cp355nqasrt9qe4muefvg76vpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d7ep5j" />
    <content type="html">
      Whoa, how did I miss that you&amp;#39;ll be able to buy YubiKeys at Best Buy?!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/press-releases/secure-your-digital-accounts-yubikeys-available-now-in-stores-at-best-buy/&#34;&gt;https://www.yubico.com/press-releases/secure-your-digital-accounts-yubikeys-available-now-in-stores-at-best-buy/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;[Edit: *right now* -- or at least, available to pick up within the hour at my local store!]&lt;br/&gt;&lt;br/&gt;#YubiKey
    </content>
    <updated>2025-11-05T04:01:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszjcp66sewztq2eka4ay0zhqdghtd4x6j9jelzd9f3hzfxenxcu8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p669fylu</id>
    
      <title type="html">😐</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszjcp66sewztq2eka4ay0zhqdghtd4x6j9jelzd9f3hzfxenxcu8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p669fylu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ywj4n2khr80tuud5lw92d53w99mxnhuakq823nxpv0yldxlksmqcmrjjy&#39;&gt;nevent1q…rjjy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;😐
    </content>
    <updated>2025-11-04T21:21:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8rvd85hel3ncfy9se2w07cmxcmn6sfrc0jwn6dn3l25vutqecufgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceufcj</id>
    
      <title type="html">Oof. Does the mechanism provide a way for the defederating server ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8rvd85hel3ncfy9se2w07cmxcmn6sfrc0jwn6dn3l25vutqecufgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ceufcj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8pkrryd2u8vvtgpppmjx263su848yn8hj9wrguz05lgd8vg9u7zq2uc87z&#39;&gt;nevent1q…c87z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oof. Does the mechanism provide a way for the defederating server to say why it happened? Or is it just totally opaque?
    </content>
    <updated>2025-11-04T21:20:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqmu52zqqrgcpwqu8zkaxyeut9ph6djcavyvg9893v4gsl8cgauzszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4cn2s</id>
    
      <title type="html">inb4 everyone realizes that several Someones are taking notes ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqmu52zqqrgcpwqu8zkaxyeut9ph6djcavyvg9893v4gsl8cgauzszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6q4cn2s" />
    <content type="html">
      inb4 everyone realizes that several Someones are taking notes during ransomware attacks, outages, etc. -- mapping our attack surface / dependencies / response capabilities.&lt;br/&gt;&lt;br/&gt;What percentage are active vs passive measurement are left as an exercise.
    </content>
    <updated>2025-10-29T18:45:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9mfjl5n6708uyqzc87nujqql32yx7990zq8p7dzctscay5r5vmmszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6au6t9e</id>
    
      <title type="html">https://infosec.exchange/@tychotithonus/115418342699692840</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9mfjl5n6708uyqzc87nujqql32yx7990zq8p7dzctscay5r5vmmszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6au6t9e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdwft8qrge2xvqvtaxvqc4hwwcftxmux3858yh6wd0cru0v3j2tcsncnj8d&#39;&gt;nevent1q…nj8d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@tychotithonus/115418342699692840&#34;&gt;https://infosec.exchange/@tychotithonus/115418342699692840&lt;/a&gt;
    </content>
    <updated>2025-10-22T14:45:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrltqhye2davjghpf0m50etwp2g2yqql9tqrnh9rkd479xdnhn8zszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63ywn0z</id>
    
      <title type="html">Hot take: we are boiling the illiteracy frog. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrltqhye2davjghpf0m50etwp2g2yqql9tqrnh9rkd479xdnhn8zszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63ywn0z" />
    <content type="html">
      Hot take: we are boiling the illiteracy frog.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/416/384/796/349/671/original/e3a7745fab7bb9a8.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-22T06:26:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswg6md6q580twmng3a7azgwufv9w7dnvw97g65zg56c05vuqfddxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk03kl</id>
    
      <title type="html">I feel like a lot of the &amp;#34;it was DNS&amp;#34; is conceptually ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswg6md6q580twmng3a7azgwufv9w7dnvw97g65zg56c05vuqfddxgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk03kl" />
    <content type="html">
      I feel like a lot of the &amp;#34;it was DNS&amp;#34; is conceptually oversimplifying, and masking true root cause(s).&lt;br/&gt;&lt;br/&gt;It makes sense to centralize naming, It makes sense to abstract naming away from IP addresses. Many of these outages are &amp;#34;this other thing broke, and it made DNS break&amp;#34;. Most folks would never say &amp;#34;it was DNS&amp;#34; when it was a network problem that was preventing reaching the DNS servers. But a lot of the time, this isn&amp;#39;t much different from that.&lt;br/&gt;&lt;br/&gt;Don&amp;#39;t get me wrong, every outage is an opportunity to learn and improve, both locally and centrally. I just want to shift the conversation to &amp;#34;it was DNS, *because* ...&amp;#34;, and help people make informed risk trade-offs.&lt;br/&gt;&lt;br/&gt;Approach it like the NTSB would: keep going until you know, and have recommendations for, *all* of the failure modes.
    </content>
    <updated>2025-10-20T13:47:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswg7g2kn70pcd0rxpasqkddrpnna4g8q724juuvz4uwzx58ld4ktszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63y8v8e</id>
    
      <title type="html">And the opposites are also very true: Local doesn&amp;#39;t mean ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswg7g2kn70pcd0rxpasqkddrpnna4g8q724juuvz4uwzx58ld4ktszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63y8v8e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9hfu6856plyfav2j2x64fdfuxmnmu6umg58s0vh37nwxkewzdjzq39j6yd&#39;&gt;nevent1q…j6yd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And the opposites are also very true:&lt;br/&gt;&lt;br/&gt;Local doesn&amp;#39;t mean insecure. Cloud doesn&amp;#39;t mean secure.
    </content>
    <updated>2025-10-09T16:00:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqsnx3fwc5rfn8wysqf23s0qhcfcphqr8plkmrlf8yyklh73q06zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ykaglt</id>
    
      <title type="html">Good question! A core property of FIDO2 is authenticating the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqsnx3fwc5rfn8wysqf23s0qhcfcphqr8plkmrlf8yyklh73q06zqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ykaglt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp6qp4xt52kf8rv6dujcs8a4zjc00hrnlkju37fvfynl059mrzpls892lq2&#39;&gt;nevent1q…2lq2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Good question!&lt;br/&gt;&lt;br/&gt;A core property of FIDO2 is authenticating the *origin* (are you connected to the right site, or a copycat). The daily benefit of this protection is intended to be worth the trade-off of requiring diligence in retaining possession of the key.&lt;br/&gt;&lt;br/&gt;Also, the idea is that loss of the key would be noticed quickly enough that the key could be revoked.&lt;br/&gt;&lt;br/&gt;Finally, putting a PIN on a &amp;#34;leave-in&amp;#34;  / installed key (which is a PIN for the *key*, not for individual sites), is a reasonable way to mitigate the risk of the window of time between the loss/theft of key and when it can be revoked.&lt;br/&gt;&lt;br/&gt;#YubiKey
    </content>
    <updated>2025-10-04T14:21:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgfz2ww08a5c74yhrgtldmly4uhd6qazctd8rgn6a42qc8vpk58rszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xll7z9</id>
    
      <title type="html">This saga feels like an ad for ZFS 😉 I&amp;#39;ve been burned by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgfz2ww08a5c74yhrgtldmly4uhd6qazctd8rgn6a42qc8vpk58rszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xll7z9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs85hnz9wcf85zs233zrfc2tyhuxcrj3xvv6cc9atm6s6zkd8vss9qacetwy&#39;&gt;nevent1q…etwy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;This saga feels like an ad for ZFS 😉&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve been burned by both hard and soft RAID too many times to ever go back.
    </content>
    <updated>2025-09-29T16:51:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspseymjmrnjjsy7wzztj3d6vgu667zh2zrqea8k5p0gmt02mj6vrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6st9dvj</id>
    
      <title type="html">Updated to include: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspseymjmrnjjsy7wzztj3d6vgu667zh2zrqea8k5p0gmt02mj6vrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6st9dvj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstg96sfj2ww3pn0rkke469edgxd5cfzq8cdz8h7ux0s88ljjj2s5cx6u9pc&#39;&gt;nevent1q…u9pc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Updated to include:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.yubico.com/press-releases/yubico-and-t-mobile-deployment-of-200000-phishing-resistant-yubikeys-enhances-un-carriers-work-systems-security/&#34;&gt;https://www.yubico.com/press-releases/yubico-and-t-mobile-deployment-of-200000-phishing-resistant-yubikeys-enhances-un-carriers-work-systems-security/&lt;/a&gt;
    </content>
    <updated>2025-09-23T20:22:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsz503vegvksn9jvdcljul44dxppleawrurzrkukvaa3mqagl5nsqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m2qwps</id>
    
      <title type="html">I should have been collecting the receipts on a rolling basis; ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz503vegvksn9jvdcljul44dxppleawrurzrkukvaa3mqagl5nsqczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m2qwps" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsppt67l4p34r9d7z8n5ztls6yyqlq9sk82ceu2d8r2cgu4a5zj9nczqxwsm&#39;&gt;nevent1q…xwsm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I should have been collecting the receipts on a rolling basis; chatter at the time for multiple of these was &amp;#34;deploying fast now for highest risk, doing the rest in a more controlled fashion after&amp;#34;.&lt;br/&gt;&lt;br/&gt;Thinking of:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;npm (&amp;#34;encouraging FIDO2&amp;#34;, anyway)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;T-Mobile - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation&amp;#34&#34;&gt;https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;t-mobile.com/news/network/addi&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;tional-information-regarding-2021-cyberattack-investigation&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Twitter - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://blog.x.com/engineering/en_us/topics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;#34&#34;&gt;https://blog.x.com/engineering/en_us/topics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;blog.x.com/engineering/en_us/t&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;opics/insights/2021/how-we-rolled-out-security-keys-at-twitter&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;And probably:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Uber (&amp;#34;further strengthening our MFA&amp;#34;, reading between the lines for 2022 breach and 2023 deployment) - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://www.uber.com/newsroom/security-update/&amp;#34&#34;&gt;https://www.uber.com/newsroom/security-update/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://www.&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;uber.com/newsroom/security-upd&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;ate/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Discord (again, reading between the lines - 2023 breach, 2025 deployment)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;eBay (public evidence is thinner here, but I got a couple of confidential reports)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;And a couple &amp;#34;we could see the writing on the wall&amp;#34; (they get points for that):&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Google (2017) - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&amp;#34&#34;&gt;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;krebsonsecurity.com/2018/07/go&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;ogle-security-keys-neutralized-employee-phishing/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Cloudflare - &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://blog.cloudflare.com/how-cloudflare-implemented-fido2-and-zero-trust/&amp;#34&#34;&gt;https://blog.cloudflare.com/how-cloudflare-implemented-fido2-and-zero-trust/&amp;#34&lt;/a&gt;; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;nofollow noopener&amp;#34; translate=&amp;#34;no&amp;#34;&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;&lt;a href=&#34;https://&amp;lt;/span&amp;gt;&amp;lt;span&#34;&gt;https://&amp;lt;/span&amp;gt;&amp;lt;span&lt;/a&gt; class=&amp;#34;ellipsis&amp;#34;&amp;gt;blog.cloudflare.com/how-cloudf&amp;lt;/span&amp;gt;&amp;lt;span class=&amp;#34;invisible&amp;#34;&amp;gt;lare-implemented-fido2-and-zero-trust/&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;
    </content>
    <updated>2025-09-23T20:17:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstd58zhjeqr5n93qez50fqch0yyq9e4m2xjmejc9yljgasy9kjvgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p60g5mt6</id>
    
      <title type="html">How many stories of &amp;#34;get popped, *then* do an emergency FIDO2 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstd58zhjeqr5n93qez50fqch0yyq9e4m2xjmejc9yljgasy9kjvgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p60g5mt6" />
    <content type="html">
      How many stories of &amp;#34;get popped, *then* do an emergency FIDO2 deployment&amp;#34; does your leadership need to read before you decide to deploy FIDO2 proactively?
    </content>
    <updated>2025-09-23T19:56:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswultpnqf5x7d20exj4jk0pdlqxg3cfzx6mcm5e00mf23dnef3jyszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qltmd</id>
    
      <title type="html">Like conference social preference badges, except &amp;#34;yes I will ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswultpnqf5x7d20exj4jk0pdlqxg3cfzx6mcm5e00mf23dnef3jyszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65qltmd" />
    <content type="html">
      Like conference social preference badges, except &amp;#34;yes I will always say hi to your dog&amp;#34;
    </content>
    <updated>2025-09-20T01:57:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspkjwk9rqtl2tl7ke5u5p4wvvwtj5yc44ljw7d6ny5h6k4spsp4vczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64pmkan</id>
    
      <title type="html">&amp;#34;Using ChatGPT to complete assignments is like bringing a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspkjwk9rqtl2tl7ke5u5p4wvvwtj5yc44ljw7d6ny5h6k4spsp4vczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64pmkan" />
    <content type="html">
      &amp;#34;Using ChatGPT to complete assignments is like bringing a forklift into the weight room; you will never improve your cognitive fitness that way.&amp;#34;&lt;br/&gt;-- Ted Chiang&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://www.newyorker.com/culture/the-weekend-essay/why-ai-isnt-going-to-make-art&#34;&gt;https://www.newyorker.com/culture/the-weekend-essay/why-ai-isnt-going-to-make-art&lt;/a&gt;
    </content>
    <updated>2025-09-18T17:28:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfl9uysv8e35gsljmr00027dx2x7sx7wpnx0jkdh60qgfasw6759gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69zmevk</id>
    
      <title type="html">Dudes will install Debian on a 13yo MacBook Air instead of going ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfl9uysv8e35gsljmr00027dx2x7sx7wpnx0jkdh60qgfasw6759gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p69zmevk" />
    <content type="html">
      Dudes will install Debian on a 13yo MacBook Air instead of going to therapy.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s me. I&amp;#39;m dudes.&lt;br/&gt;&lt;br/&gt;(XFCE is pretty snappy!)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/216/825/708/391/708/original/f7da14f14df09a72.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-17T00:37:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9d5a4h4sl8j7hepzm3794f5tmhpqurzp8ux2ca8fh7dfm7nc6q3gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6awwwn6</id>
    
      <title type="html">And to your solid point about the 70%, I forgot to math that out ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9d5a4h4sl8j7hepzm3794f5tmhpqurzp8ux2ca8fh7dfm7nc6q3gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6awwwn6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5shmqmj2&#39;&gt;nevent1q…qmj2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And to your solid point about the 70%, I forgot to math that out to illustrate the importance of protecting the remaining people who *aren&amp;#39;t* reusing passwords. (And I know you know this, mostly posting for those following along).&lt;br/&gt;&lt;br/&gt;In the 16 million bcrypt cost 12 case, if 70% of them can be &amp;#34;pre-cracked&amp;#34; with correlation, then the amount of time for the attack above to run for the remaining 30% drops from 300 days to 90 days. Which is an okay amount of time to buy between compromise and discovery, until we remember that you can have a lot more than two 4090s 😅, and of course, bcrypt parallelizes relatively well, such that a different hash like Argon2 or yescrypt is a better choice. But if bcrypt is the only option for some reason, bumping the work factor higher, if feasible, would be recommended.
    </content>
    <updated>2025-09-09T12:56:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg5hqsy5csx30n8pjhjfd03xy3lcg9ty7r0c3e3ftc9ktfntynerczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68c68h9</id>
    
      <title type="html">Wow, that is substantially more terrible than I was expecting. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg5hqsy5csx30n8pjhjfd03xy3lcg9ty7r0c3e3ftc9ktfntynerczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68c68h9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx5ql3f2w7wtg75gc7krmll3n4f0ngu9a3s9q098xalqucwh3qqrsnl4yx9&#39;&gt;nevent1q…4yx9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Wow, that is substantially more terrible than I was expecting. Yow.
    </content>
    <updated>2025-09-09T05:23:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v3jkxq</id>
    
      <title type="html">Well, there&amp;#39;s a spectrum there. A lot of the Hashmob bcrypt ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9307dr8dk5a8pcq7t56n6m2ngdefv9ax57fa7sx9ny5hqczcvf5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v3jkxq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspe4e34w56lqmncrfvpqslzxq8tamgtq7fqg6xt0msn70xwxrxscqe5p4tw&#39;&gt;nevent1q…p4tw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Well, there&amp;#39;s a spectrum there. A lot of the Hashmob bcrypt lists have been thoroughly correlated, and I think the percentage trends lower than 70% there, but I&amp;#39;d have to look.&lt;br/&gt;&lt;br/&gt;If full correlation is in play (a leak with known passwords), then the cost doesn&amp;#39;t make a ton of difference, because each hash can be targeted with john&amp;#39;s --single mode or hashcat&amp;#39;s -a 9.&lt;br/&gt;&lt;br/&gt;And for hashes that cannot be correlated, targeting a single hash  slows the attacker down only so much (because single-hash performance has to be tolerable for user experience). When the bcrypt cost gets to 12, and a million candidate passwords, that&amp;#39;s only about 30 seconds with hashcat on 2 4090s.&lt;br/&gt;&lt;br/&gt;And then that cost is magnified when it&amp;#39;s a broad attack (many hashes targeted simultaneously), Even just trying the first N thousand most common passwords, attempting to crack a million bcrypt cost 12s is correspondingly harder, so there&amp;#39;s still a &amp;#34;herd health&amp;#34; benefit to the hashes being stronger.&lt;br/&gt;&lt;br/&gt;For example, with 16 million cost 12 bcrypts, and a very short list of very common passwords (6144 words, the minimum for certain hashcat efficiencies), 2x 4090s will take 300 days to fully exhaust. The equivalent attack - all other variables constant, but dropping the bcrypt cost from 12 to five -- will complete *in 2.5 days*.&lt;br/&gt;&lt;br/&gt;And that&amp;#39;s for a *very* short wordlist. Running through longer wordlists would be correspondingly longer.&lt;br/&gt;&lt;br/&gt;So I think that the work factors should be tuned to protect folks who aren&amp;#39;t reusing their own passwords across multiple accounts, but might be sharing semi-common passwords *with other users*.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/172/505/744/839/580/original/a7a022bed207857c.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/172/529/106/047/154/original/a6e724cba6bef39c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-09T04:49:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg8lhxzds0dy5sm2ape94tw4fkmd9uufz0f3cul7qm5ayr9fh079qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6axhpml</id>
    
      <title type="html">*Nice* find! We&amp;#39;re going to have get the word out that just ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg8lhxzds0dy5sm2ape94tw4fkmd9uufz0f3cul7qm5ayr9fh079qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6axhpml" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr5t0ztj8jndxtedruwy4kp8ng7lxmglp6qu5rclkmwyttsdvuu9qz8tf76&#39;&gt;nevent1q…tf76&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;*Nice* find! &lt;br/&gt;&lt;br/&gt;We&amp;#39;re going to have get the word out that just &amp;#39;bcrypt&amp;#39; isn&amp;#39;t enough -- bcrypt cost 12 is 128 times harder than cost 5, etc. We need to know the default costs.
    </content>
    <updated>2025-09-09T03:54:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvslfc2ql75lztyqnpmlyk3jwaput3p6ulmp503z3xqgs2yhzunrczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d4fz70</id>
    
      <title type="html">Anyone seeing disclosure of what password hashing algorithm Plex ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvslfc2ql75lztyqnpmlyk3jwaput3p6ulmp503z3xqgs2yhzunrczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6d4fz70" />
    <content type="html">
      Anyone seeing disclosure of what password hashing algorithm Plex uses on their back end?&lt;br/&gt;&lt;br/&gt;[Edit: &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1t9cz9v7zph5jvadd8rjfp25msrx6r0hdxnsyfmx88k8qp3pvv04szt8529&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Aaron Toponce ⚛️:debian:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1t9c…8529&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; discovered a thread showing bcrypt:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://fosstodon.org/@atoponce/115172271450263878&#34;&gt;https://fosstodon.org/@atoponce/115172271450263878&lt;/a&gt; ]&lt;br/&gt;&lt;br/&gt;There are three kinds of org postures relative to disclosure of password-hashing algorithm:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs confident enough in their selection of algorithm that they &amp;lt;em&amp;gt;know&amp;lt;/em&amp;gt; that there is no harm in disclosing it&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs who know they&amp;#39;re doing it badly and want to keep it a secret&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Orgs who won&amp;#39;t disclose their algorithm because the PR team has no idea how the passwords are hashed, and internal comms are spotty enough that the information can&amp;#39;t reach the public&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Note that a mix of 1 and 3, or 2 and 3, are also possible.&lt;br/&gt;&lt;br/&gt;1 alone is a sign of security maturity. If 2 and 3 are in play, there&amp;#39;s room for improvement ... for different reasons, but both indicators of security immaturity.&lt;br/&gt;&lt;br/&gt;Practitioners: Which type is your org?&lt;br/&gt;&lt;br/&gt;Reporters: Are you probing orgs to find out which type they are?&lt;br/&gt;&lt;br/&gt;Normalize hash-type disclosure.
    </content>
    <updated>2025-09-09T02:03:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdp9jd6adwv540pc4rs9tqtdgcwuve8dr4ccev3s5u3gczp9fpntqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hfj7k7</id>
    
      <title type="html">Clonezilla is such a hidden gem. An impressive combination of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdp9jd6adwv540pc4rs9tqtdgcwuve8dr4ccev3s5u3gczp9fpntqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hfj7k7" />
    <content type="html">
      Clonezilla is such a hidden gem. An  impressive combination of &amp;#34;make the core things easy and the tricky things possible&amp;#34; and &amp;#34;do what I probably need&amp;#34;.
    </content>
    <updated>2025-09-07T23:52:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw3r262h8mzgn9ycfrgezl2wttspgzavtwk470xrdh7aaaymcfxtgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qxp4y3</id>
    
      <title type="html">I totally forgot about this. Thank you, random synapse from ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw3r262h8mzgn9ycfrgezl2wttspgzavtwk470xrdh7aaaymcfxtgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qxp4y3" />
    <content type="html">
      I totally forgot about this. Thank you, random synapse from literally the year 2000.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://goodreads.com/book/show/331807.How_to_Good_Bye_Depression_If_You_Constrict_Anus_100_Times_Everyday__Malarkey__or_Effective_Way_&#34;&gt;https://goodreads.com/book/show/331807.How_to_Good_Bye_Depression_If_You_Constrict_Anus_100_Times_Everyday__Malarkey__or_Effective_Way_&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/143/801/695/221/087/original/141db13eb6097762.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-04T03:04:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9tlg5m2cafuvpve2qpjqknanzaxqguk63y7may98l495xl27eq8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fevdc6</id>
    
      <title type="html">That is hilarious and insightful. You win the Internet today, and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9tlg5m2cafuvpve2qpjqknanzaxqguk63y7may98l495xl27eq8czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fevdc6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq25hlccwk4lgdtmtctr65eetdms0qq4yahgxhcgsyqq6eklwlntq3kvl3q&#39;&gt;nevent1q…vl3q&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That is hilarious and insightful. You win the Internet today, and it&amp;#39;s only 5:42 a.m. here. 😁
    </content>
    <updated>2025-08-28T13:42:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfgxjnqlk3qmrspx80tdwha6a90dcazcduqvtu2776q29w7np738qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qyjtph</id>
    
      <title type="html">Turns out &amp;#34;despite patches&amp;#34; means &amp;#34;despite patches ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfgxjnqlk3qmrspx80tdwha6a90dcazcduqvtu2776q29w7np738qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qyjtph" />
    <content type="html">
      Turns out &amp;#34;despite patches&amp;#34; means &amp;#34;despite patches being available, because a bunch of people aren&amp;#39;t applying them&amp;#34; rather than &amp;#34;despite patching it, but it&amp;#39;s still vulnerable anyway and there&amp;#39;s something wrong with the patches&amp;#34; 🙄&lt;br/&gt;&lt;br/&gt;Words mean things.&lt;br/&gt;&lt;br/&gt;#SavedYouAClick&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/106/641/147/402/157/original/b4557659364e2480.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-28T13:35:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsq8xalt3k4cvu8f9n5a98hmrqhz6vh6fymphppy0hswym9806mmpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gh6y8p</id>
    
      <title type="html">MDXfind 1.133 released: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq8xalt3k4cvu8f9n5a98hmrqhz6vh6fymphppy0hswym9806mmpgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gh6y8p" />
    <content type="html">
      MDXfind 1.133 released:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.techsolvency.com/pub/bin/mdxfind/&#34;&gt;https://www.techsolvency.com/pub/bin/mdxfind/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Highlights:&amp;lt;li&amp;gt;Now shows hash and candidate rates/sec in comfort messages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Significant (10x) improvement in solution output speed for hashes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Previously undocumented features, including &amp;lt;code&amp;gt;-m&amp;lt;/code&amp;gt; flag to specify hashtypes in hashcat mode syntax&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Metadata showing mapping of MDXfind hashtype IDs (by position in -h) to hashcat modes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Now with gzip support for hashes (&amp;lt;code&amp;gt;-f&amp;lt;/code&amp;gt; or stdin), and for candidate lists&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Too many to fully list, but lots of interesting stuff in the full changelog:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.techsolvency.com/pub/bin/mdxfind/CHANGES.txt&#34;&gt;https://www.techsolvency.com/pub/bin/mdxfind/CHANGES.txt&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Always be cracking!&lt;br/&gt;&lt;br/&gt;#MDXfind
    </content>
    <updated>2025-08-26T04:50:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0vceznfns9ph5fjy3lywuce0d2nn79zgy7azd88na0jhdktn55jczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6de5t4d</id>
    
      <title type="html">Good morning to everyone except GitHub, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0vceznfns9ph5fjy3lywuce0d2nn79zgy7azd88na0jhdktn55jczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6de5t4d" />
    <content type="html">
      Good morning to everyone except GitHub, which:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;allows (but strongly discourages) fine-grained access tokens with no expiration date, but&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;won&amp;#39;t let you create one with an expiration date more than one year out.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;So my choices are &amp;#34;never expire&amp;#34; or expire in a year or less&amp;#34;.&lt;br/&gt;&lt;br/&gt;Our Threat Models May Vary!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/084/577/063/180/916/original/104e991dda12e654.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-24T16:00:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe</id>
    
      <title>Nostr event nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgsqwk33jl4qylj656w8r7dy7qp084c9j3emv48vvqp8ts08flhfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e55mqe" />
    <content type="html">
       &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/076/073/281/692/964/original/7d6dfe18520f454f.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-23T04:00:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdsxs8cynqr9a2uzndvycjxadwrhcuey5wgtqx2pjrymvu3pxcfrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64w69za</id>
    
      <title type="html">These can both be true: &amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Passkey deployment has ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdsxs8cynqr9a2uzndvycjxadwrhcuey5wgtqx2pjrymvu3pxcfrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64w69za" />
    <content type="html">
      These can both be true: &amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Passkey deployment has been fraught with UX challenges, failures to advise users about threat model trade-offs, and vendor lock-in concerns &amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;The ecosystem couldn&amp;#39;t go much longer without the benefits of passkeys (reducing password reuse risk, mitigating infostealer harm, and deploying FIDO2 phishing resistance at scale)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;#Passkeys
    </content>
    <updated>2025-08-18T14:56:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstj75fw48eqx6uvp2hj0pgyk3gevj8xvyx58j3gjzzxsjns9s7zugzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyl8v9</id>
    
      <title type="html">Ah, another &amp;#34;strong MFA bypassed&amp;#34; story. /me opens ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstj75fw48eqx6uvp2hj0pgyk3gevj8xvyx58j3gjzzxsjns9s7zugzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyl8v9" />
    <content type="html">
      Ah, another &amp;#34;strong MFA bypassed&amp;#34; story.&lt;br/&gt;&lt;br/&gt;/me opens article, starts scanning for buried lede&lt;br/&gt;&lt;br/&gt;Ah, here it is ... paragraph 8:&lt;br/&gt;&lt;br/&gt;&amp;#34;First you have to compromise the endpoint&amp;#34;&lt;br/&gt;&lt;br/&gt;🙄 &lt;br/&gt;&lt;br/&gt;Surprise! This is *not something passkeys -- or any other authentication system -- are designed to mitigate*.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/passkey-login-bypassed-via-webauthn-process-manipulation/&#34;&gt;https://www.securityweek.com/passkey-login-bypassed-via-webauthn-process-manipulation/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I say again: the word &amp;#34;bypass&amp;#34; only leaves the layperson with the impression of &amp;#34;nya nya strong MFA isn&amp;#39;t as strong as they said lol&amp;#34; ... and the CIO with the impression &amp;#34;you told me I had to move to strong MFA why do they keep finding problems with it&amp;#34;&lt;br/&gt;&lt;br/&gt;Cut it out.
    </content>
    <updated>2025-08-17T22:23:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9qkeqps2e6pwk4kpuqa97eklpk5xc0u79jyqxra8jsd5kau7physzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m6kxle</id>
    
      <title type="html">So ... is the new Sandia time-independent MFA thing: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9qkeqps2e6pwk4kpuqa97eklpk5xc0u79jyqxra8jsd5kau7physzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m6kxle" />
    <content type="html">
      So ... is the new Sandia time-independent MFA thing:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&#34;&gt;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;... just ... renegotiating a new per-client code every time there&amp;#39;s a new connection?&lt;br/&gt;&lt;br/&gt;Like ... how garage door openers have worked ... since the mid-90s?
    </content>
    <updated>2025-08-17T15:39:19Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxz6xdjxy9s4754r2pwr3cwtlwxm2l2vg75hqs5z4mmk5psczvjdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdexnz</id>
    
      <title type="html">Huh -- did I miss it, or does even the upstream Sandia not ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxz6xdjxy9s4754r2pwr3cwtlwxm2l2vg75hqs5z4mmk5psczvjdczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6vdexnz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspmhh83445ue4qt5l36fcnhrpr2xf0m6nknlq7dsmmg8uwkwlrf8qpdh8hc&#39;&gt;nevent1q…h8hc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Huh -- did I miss it, or does even the upstream Sandia not actually say what the approach *is*?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&#34;&gt;https://www.sandia.gov/labnews/2025/07/24/two-factor-authentication-just-got-easier/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;All I can extract from the coverage is &amp;#34;easier&amp;#34; and &amp;#34;time-independent&amp;#34;.&lt;br/&gt;&lt;br/&gt;Still digging ...&lt;br/&gt;&lt;br/&gt;Edit: is it... just ... renegotiating a new per-client code every time there&amp;#39;s a new connection?&lt;br/&gt;&lt;br/&gt;Like ... how garage door openers have worked ... since the mid-90s?
    </content>
    <updated>2025-08-17T15:33:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrt88fmw5sflgxgahhchhnl7qnd7kwtuen9y6hkxvud4qxpn74ejszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6szzg3k</id>
    
      <title type="html">Kiddo: why do you put the full year with &amp;#34;20&amp;#34; at the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrt88fmw5sflgxgahhchhnl7qnd7kwtuen9y6hkxvud4qxpn74ejszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6szzg3k" />
    <content type="html">
      Kiddo: why do you put the full year with &amp;#34;20&amp;#34; at the front when you sign the school forms?&lt;br/&gt;&lt;br/&gt;Me: *thousand-yard Y2K stare*
    </content>
    <updated>2025-08-16T22:00:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszvkx6jwxvz85dvefutayzs9sxf060dvd7uchfdet8utu54ahdfpszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65ep8th</id>
    
      <title type="html">Since it&amp;#39;s just the tree, if someone could snapshot it ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszvkx6jwxvz85dvefutayzs9sxf060dvd7uchfdet8utu54ahdfpszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65ep8th" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxy7r43qchgkzmszrq4x3eltpmj7e823vc05a5cdsyu6n77hu4zgq9m7j9d&#39;&gt;nevent1q…7j9d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Since it&amp;#39;s just the tree, if someone could snapshot it safetly and put a text-only version of it somewhere (like a GitHub gist), folks would probably appreciate that
    </content>
    <updated>2025-08-15T17:56:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqul3npk8ctuav9h754s2wwml35jnqhwzk03utdmvdmufeq0rgzsqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rvxe67</id>
    
      <title type="html">Does &amp;#34;runtime&amp;#34; here always imply &amp;#34;source code is ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqul3npk8ctuav9h754s2wwml35jnqhwzk03utdmvdmufeq0rgzsqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rvxe67" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswzfqnhspg50nwn89ck3kx5jwsx75naet6705r5c5qpgqtdr5xh0cz96t3h&#39;&gt;nevent1q…6t3h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Does &amp;#34;runtime&amp;#34; here always imply &amp;#34;source code is available&amp;#34;?
    </content>
    <updated>2025-08-13T15:59:11Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqg9cucvm6sgd2v59dvlku94znvdv8yraf6q98zud08sy6t87e3uqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6z39mkg</id>
    
      <title type="html">On mobile, desktop, or both? I hadn&amp;#39;t seen this yet, can you ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqg9cucvm6sgd2v59dvlku94znvdv8yraf6q98zud08sy6t87e3uqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6z39mkg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf04js3g6unpz2gr27s9yv2qw0mnsvdcsyr78upqc2flr0yyk2fhg7glved&#39;&gt;nevent1q…lved&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;On mobile, desktop, or both? I hadn&amp;#39;t seen this yet, can you point me to some coverage or a summary?
    </content>
    <updated>2025-08-03T01:15:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswzcvqp775832t3feqqtpsrtc492uszc4z4up7g3n49xuknpsxqrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mmx33z</id>
    
      <title type="html">Things platforms want you to do less of:&amp;lt;li&amp;gt;untrackably ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswzcvqp775832t3feqqtpsrtc492uszc4z4up7g3n49xuknpsxqrszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6mmx33z" />
    <content type="html">
      Things platforms want you to do less of:&amp;lt;li&amp;gt;untrackably copy a link to something&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;save an image&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;copy arbitrary text&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;decide what to look at next&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;return to where you were a minute ago&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;find options you can change&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;know how many search results there are / length of scroll&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;decide what part of a video you want to see&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;prioritize and deprioritize content based on your own preferences&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;manage your own attention&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;Mobile apps make this agenda easier. Apps are for companies.&lt;br/&gt;&lt;br/&gt;The web makes this agenda harder. The web is for people.
    </content>
    <updated>2025-08-02T16:22:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdu54xkt3t44lkyvgnjxz8fxqhl28ra4tp8a5qc3m0jk8f23e69hszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65rldxm</id>
    
      <title type="html">RIP the Corporation for Public Broadcasting. It genuinely made ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdu54xkt3t44lkyvgnjxz8fxqhl28ra4tp8a5qc3m0jk8f23e69hszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65rldxm" />
    <content type="html">
      RIP the Corporation for Public Broadcasting.&lt;br/&gt;&lt;br/&gt;It genuinely made generations of kids both smarter and more empathetic.&lt;br/&gt;&lt;br/&gt;The only winners in this outcome are the enemies of the United States.&lt;br/&gt;&lt;br/&gt;And I didn&amp;#39;t realize it was going to hit me this hard.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://cpb.org/pressroom/Corporation-Public-Broadcasting-Addresses-Operations-Following-Loss-Federal-Funding&#34;&gt;https://cpb.org/pressroom/Corporation-Public-Broadcasting-Addresses-Operations-Following-Loss-Federal-Funding&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/955/006/431/239/715/original/c0c606310dafb247.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-01T18:52:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0dxg2mn5thayky4d77rnq9dkn05x7q8gnkg8a5a8gz2juw79xq4gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pz9w6l</id>
    
      <title type="html">Oh look, another &amp;#34;door locks are bad because someone can ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0dxg2mn5thayky4d77rnq9dkn05x7q8gnkg8a5a8gz2juw79xq4gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6pz9w6l" />
    <content type="html">
      Oh look, another &amp;#34;door locks are bad because someone can crawl through the window&amp;#34; scare article (this time a sponsored one). Not responsible journalism, Bleeping.&lt;br/&gt;&lt;br/&gt;I especially &amp;#34;appreciate&amp;#34; the scare quotes around &amp;#34;phishing-resistant&amp;#34; 🤬&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/940/426/507/441/860/original/661dc84d7ed44ed9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-30T05:03:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsptk9cdnzqu5s3wvtf8ls6sfzem5v0rgtzm26y77538pj6d5ll9nszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g5jd7q</id>
    
      <title type="html">Never tell a call with 300 people that they can just drop ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsptk9cdnzqu5s3wvtf8ls6sfzem5v0rgtzm26y77538pj6d5ll9nszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g5jd7q" />
    <content type="html">
      Never tell a call with 300 people that they can just drop questions into chat whenever they want for a 3 hour presentation. Only takes 5‰ of them taking you up on it -- who somehow don&amp;#39;t realize most of their questions are about to be answered -- to derail velocity.
    </content>
    <updated>2025-07-22T17:32:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstv822eqlgx2prdr66wl5h87wnng2m4sj4ad9t7jqk5jyu33utvjczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jxyytu</id>
    
      <title type="html">Man, this feels like *some* data-hoarding person would have ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstv822eqlgx2prdr66wl5h87wnng2m4sj4ad9t7jqk5jyu33utvjczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6jxyytu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszdkrvl2ts6f3vxjul0ypfchw2h3uyr2crqw58yr3khrws0ncvdvqys55p4&#39;&gt;nevent1q…55p4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Man, this feels like *some* data-hoarding person would have retained it -- or was it never actually downloadable?
    </content>
    <updated>2025-07-16T22:16:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs898ufwxpap39yr4dpu032yrqatr6d0qtucnc04l68y22t2en5wxqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hgylky</id>
    
      <title type="html">I mean, I just liked the quote. Wasn&amp;#39;t really trying to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs898ufwxpap39yr4dpu032yrqatr6d0qtucnc04l68y22t2en5wxqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hgylky" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy00uhgh467n80u524qds4h87q0z74sf04upypp9h3fvct2qnxreq9muych&#39;&gt;nevent1q…uych&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I mean, I just liked the quote. Wasn&amp;#39;t really trying to invoke the overall article either way.&lt;br/&gt;&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Daniel Miessler :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qu3…rukd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-07-11T05:11:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr8a2mgmtzfklsjarkk9skp3wawdyyrutaakkvhgqf9amfqar4hgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67wxr0z</id>
    
      <title type="html">&amp;#34;Engineering should eat security.&amp;#34; -- Caleb Sima Source: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr8a2mgmtzfklsjarkk9skp3wawdyyrutaakkvhgqf9amfqar4hgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67wxr0z" />
    <content type="html">
      &amp;#34;Engineering should eat security.&amp;#34;&lt;br/&gt;-- Caleb Sima&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://danielmiessler.com/blog/ai-creative-destruction-wave&#34;&gt;https://danielmiessler.com/blog/ai-creative-destruction-wave&lt;/a&gt;&lt;br/&gt;(via &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qu3wjn555sk4g4xaehm55a09hhszlkrxhpcu404zytw3elkwnf8qg7rukd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Daniel Miessler :verified:&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qu3…rukd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;)
    </content>
    <updated>2025-07-11T03:03:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqm4zmsu4jzz8d3s95csrr7h0nkx5qvwuku752nne044tw0s8xhgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67pz95d</id>
    
      <title type="html">Couldn&amp;#39;t find this anywhere and my scanner is borked, but at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqm4zmsu4jzz8d3s95csrr7h0nkx5qvwuku752nne044tw0s8xhgqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p67pz95d" />
    <content type="html">
      Couldn&amp;#39;t find this anywhere and my scanner is borked, but at least here&amp;#39;s a photo, with alt text.&lt;br/&gt;&lt;br/&gt;Love Rich Tennant -- quite insightful. Not affiliated, just a fan:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://the5thwave.com/&#34;&gt;https://the5thwave.com/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;1/2&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/818/490/234/977/264/original/aed1a73424353b18.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-08T16:13:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxl8hdhnfxhsqm547xv5al4evktp3v9euph06c59jvzz3v4zkraxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63s9snf</id>
    
      <title type="html">Mention of &amp;#34;several mitigations&amp;#34; without details ... ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxl8hdhnfxhsqm547xv5al4evktp3v9euph06c59jvzz3v4zkraxczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63s9snf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfdygx8w7vrr5tyhwc3tc2qeyc7zpl3p3jumgxmny07fcwztnxlpqh5m7gs&#39;&gt;nevent1q…m7gs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Mention of &amp;#34;several mitigations&amp;#34; without details ... sheesh
    </content>
    <updated>2025-07-08T13:55:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspa7kjur8p2vulyxxfe656eevht6a0ue88whp6j20gcqpkcelw9zgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xmcpfy</id>
    
      <title type="html">That sounds quite satisfying -- nice work! Need before and after ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspa7kjur8p2vulyxxfe656eevht6a0ue88whp6j20gcqpkcelw9zgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xmcpfy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyfljrlwrrcz9dfrtmkgacj79pkdzdqgpm4xyq4f9ccw84gghusggtmaky5&#39;&gt;nevent1q…aky5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That sounds quite satisfying -- nice work! Need before and after photos 😉
    </content>
    <updated>2025-06-28T23:47:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgv45gl9j9kdhpx3tj2242ckyswj5y5hw2e4hpnxe6grqvxkzgrcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6a06hyz</id>
    
      <title type="html">Ooh, really?! That&amp;#39;s so great. Legit impressed</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgv45gl9j9kdhpx3tj2242ckyswj5y5hw2e4hpnxe6grqvxkzgrcqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6a06hyz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp7akev2hsjlqcem7re5c82mp557cnzlphd50dpljwv3hs3pyftlqhcpnwf&#39;&gt;nevent1q…pnwf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ooh, really?! That&amp;#39;s so great. Legit impressed
    </content>
    <updated>2025-06-27T03:24:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8a792ylakyasuh9ued80rusfk43r6rsa6u58zj8ehjny9cqls48qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g0rskq</id>
    
      <title type="html">Collab / call platforms: Just add a &amp;#34;When someone shares ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8a792ylakyasuh9ued80rusfk43r6rsa6u58zj8ehjny9cqls48qzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6g0rskq" />
    <content type="html">
      Collab / call platforms: &lt;br/&gt;&lt;br/&gt;Just add a &lt;br/&gt;&lt;br/&gt;&amp;#34;When someone shares their screen, give all other attendees a &amp;#39;Can you see what is being shared? Yes / No&amp;#39; button&lt;br/&gt;&lt;br/&gt;already.
    </content>
    <updated>2025-06-26T16:03:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfk2460h6xaj6w8g8jhdcqhn7svnmgxtjs70xk45ftk8kexyjeahszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v5zxlm</id>
    
      <title type="html">Assuming you have **no plans to leave the house** that day ... at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfk2460h6xaj6w8g8jhdcqhn7svnmgxtjs70xk45ftk8kexyjeahszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6v5zxlm" />
    <content type="html">
      Assuming you have **no plans to leave the house** that day ... at what percentage of battery level on your primary mobile device do you *start* to get uncomfortable, and think you should charge it?&lt;br/&gt;&lt;br/&gt;Assume you will not have access to a charger or external power pack while away (If you do end up having to leave).&lt;br/&gt;&lt;br/&gt;(If your number is somewhere in between, choose the next lower number) &lt;br/&gt;&lt;br/&gt;(Please RT to improve sample size.)
    </content>
    <updated>2025-06-24T14:12:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8dx892sv5vx6rydzrnxaev0h0nmsu8zcsn0t0crh5n90xrnfqhgczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ntyzry</id>
    
      <title type="html">&amp;#34;Showing what&amp;#39;s possible without constraints is just ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8dx892sv5vx6rydzrnxaev0h0nmsu8zcsn0t0crh5n90xrnfqhgczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ntyzry" />
    <content type="html">
      &amp;#34;Showing what&amp;#39;s possible without constraints is just delaying contact with the constraints.&amp;#34;&lt;br/&gt;&lt;br/&gt;-- &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub15xj96tr3384xt3tr4vcwtv30kkcw6pj5pmjdt9jca0xvvu6qv90s3k2uj4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Mike Williamson&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub15xj…2uj4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-06-23T18:10:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszscr4t50lcfnuwrc0qlvua8fdk6jqgyuyzec0xy0n4xen7fgpwfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kuztsr</id>
    
      <title type="html">ooh, that *is* a sweet spot</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszscr4t50lcfnuwrc0qlvua8fdk6jqgyuyzec0xy0n4xen7fgpwfqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6kuztsr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst3a4lnnm9mueffuauhgzuhnm68a7k46gfmglvtwa2sy46qaxzr2g0dadlu&#39;&gt;nevent1q…adlu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;ooh, that *is* a sweet spot
    </content>
    <updated>2025-06-20T03:47:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswu7d2efd97rarr2h6ux3glaue0mqn6kn2t569tc4kzs2jc7jpsjszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hpp7f3</id>
    
      <title>Nostr event nevent1qqswu7d2efd97rarr2h6ux3glaue0mqn6kn2t569tc4kzs2jc7jpsjszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hpp7f3</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswu7d2efd97rarr2h6ux3glaue0mqn6kn2t569tc4kzs2jc7jpsjszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6hpp7f3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs25m9efnzplwy72nxfh0hzlkfk9g28dzzw67afpjvxmexg7j97zkgaxz3qa&#39;&gt;nevent1q…z3qa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/no-the-16-billion-credentials-leak-is-not-a-new-data-breach/&#34;&gt;https://www.bleepingcomputer.com/news/security/no-the-16-billion-credentials-leak-is-not-a-new-data-breach/&lt;/a&gt;
    </content>
    <updated>2025-06-20T01:04:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsz3p7amc328ljc29e2yranrapymhms9mgu0v4f9g76vdk8zqmtj4szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gktx0q</id>
    
      <title type="html">white/orange/orange white/green/blue white/blue/green ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz3p7amc328ljc29e2yranrapymhms9mgu0v4f9g76vdk8zqmtj4szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gktx0q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg5knn6pc8nvcv9asq8vn4zme39dxhpuufk3n6ls8rj74jgdkgzvcx73yvd&#39;&gt;nevent1q…3yvd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;white/orange/orange&lt;br/&gt;white/green/blue&lt;br/&gt;white/blue/green&lt;br/&gt;white/brown/brown
    </content>
    <updated>2025-06-15T22:56:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfrexss6uegpcyp48c8harxxun565mmuej069tqwyrpnv9t37lr6czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e0qm2q</id>
    
      <title type="html">Oof, wow - do what ya gotta do. The ecosystem may need you, but ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfrexss6uegpcyp48c8harxxun565mmuej069tqwyrpnv9t37lr6czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6e0qm2q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst5qtu6p7c4gnmjfxkhruckzep24n7q4642m6m3n3kcj5ak2jhjhgchwyl3&#39;&gt;nevent1q…wyl3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oof, wow - do what ya gotta do. The ecosystem may need you, but the personal cost matters. Hang in there. If you&amp;#39;re wanting it, I hope you land somewhere that&amp;#39;s less about middens-mucking and more about pushing the envelope. 💪
    </content>
    <updated>2025-06-02T22:39:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswf6upmphl4uv506geu3slf2l58xgm3sv8w7ufd69v3jsxdfqlwaczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6w5ga8c</id>
    
      <title type="html">I&amp;#39;m getting this error immediately after login and the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswf6upmphl4uv506geu3slf2l58xgm3sv8w7ufd69v3jsxdfqlwaczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6w5ga8c" />
    <content type="html">
      I&amp;#39;m getting this error immediately after login and the recurring acceptance of usage terms. Never seen this one before, not even during scheduled maintenance, etc.&lt;br/&gt;&lt;br/&gt;#SocialSecurity&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/608/748/893/914/196/original/9520c30f9cd1914a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-06-01T15:14:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsznwjvwe3raj7ukvc7ygwz65kpjpsujjxn3u6wxa9g9x0rwetcuvqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyrue6</id>
    
      <title type="html">@npub1gv2…tlwl Hey, I know that you recently introduced a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsznwjvwe3raj7ukvc7ygwz65kpjpsujjxn3u6wxa9g9x0rwetcuvqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nyrue6" />
    <content type="html">
      &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1gv26rplqyjqcfyhxryuqjwaxs0dwve3y6gpv6smn3hjm3wse3s8squtlwl&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Simon Willison&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1gv2…tlwl&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; &lt;br/&gt;&lt;br/&gt;Hey, I know that you recently introduced a &amp;#34;pay a little to get less&amp;#34; subscription model. I have a value-add suggestion (if it doesn&amp;#39;t already exist?)&lt;br/&gt;&lt;br/&gt;As I explore the LLM space, I often find myself asking &amp;#34;what would Simon use?&amp;#34; So if I had my druthers, your subscription would include a living, opinionated &amp;#34;best model / approach for X&amp;#34; table -- with diffs published as an RSS feed or a simple, dedicated repo --  that matches your current opinion as it evolves over time.&lt;br/&gt;&lt;br/&gt;Ideally, this would be published live as it happens, rather than waiting until the end of the month. &lt;br/&gt;&lt;br/&gt;And I understand that the table would need a few fields to capture the nuance, such as size of model, affordability, local vs remote, etc. &lt;br/&gt;&lt;br/&gt;But boy howdy would I mash the subscribe button for that (if I wasn&amp;#39;t already - I just fixed that gap -- and, dear other readers, if you want to efficiently grow your understanding of LLMs ... so should you!)
    </content>
    <updated>2025-05-31T13:53:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrjzlcszgn6nh9j45rhxu4mjgtjagxp0rxelsznyml8zq4aws3x8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m545lf</id>
    
      <title type="html">Ugh ... did they explain/justify the GrapheneOS change anywhere?</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrjzlcszgn6nh9j45rhxu4mjgtjagxp0rxelsznyml8zq4aws3x8szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6m545lf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrgncsufhhjpn37q39ld3q36ta8yn4hrzkg5p23supapjsfg49nzcysgsal&#39;&gt;nevent1q…gsal&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ugh ... did they explain/justify the GrapheneOS change anywhere?
    </content>
    <updated>2025-05-28T01:44:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqdccpa26muwfd86zzvhmevmrurxcyk4uzlge5ln4dp4f905fynrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6zkm4ry</id>
    
      <title type="html">OMG this. It&amp;#39;s why I wrote this -- to provide an alternative ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqdccpa26muwfd86zzvhmevmrurxcyk4uzlge5ln4dp4f905fynrgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6zkm4ry" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswevgmjmnsx0njmh6wlsccmehy4e0femg0nlhsfwsdg02ru598ljc8ckpfm&#39;&gt;nevent1q…kpfm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;OMG this. It&amp;#39;s why I wrote this -- to provide an alternative to the footgun (well, really more of a foot-sledgehammer that people keep hitting themselves with harder and harder) :&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.techsolvency.com/2025/04/managing-unique-wordlists-password-cracking.html&#34;&gt;https://blog.techsolvency.com/2025/04/managing-unique-wordlists-password-cracking.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The steady stream of &amp;#34;how do I sort this 300GB file&amp;#34; folks in the cracking Discords is never-ending. This hurts less.
    </content>
    <updated>2025-05-26T07:14:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8m8nu6psngz7ar7mrwqacryes6yxpq7qj8zt2neejvrxqxdmnncqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6umwuhm</id>
    
      <title type="html">Wow! Any rough ETA on when the passwords will be merged to Pwned ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8m8nu6psngz7ar7mrwqacryes6yxpq7qj8zt2neejvrxqxdmnncqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6umwuhm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd2fcaet34c4eumflwrwmex6kht4drf7a6w76luucj4uk86umvmkgpv566n&#39;&gt;nevent1q…566n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Wow! Any rough ETA on when the passwords will be merged to Pwned Passwords?
    </content>
    <updated>2025-05-23T22:25:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsttuawnd9x0kdpntqcfuvpwqdxtzvn6st6xtq3mddvzjy7306shzczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lezzyc</id>
    
      <title type="html">Really hoping that the title - of the W3C&amp;#39;s position paper - ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsttuawnd9x0kdpntqcfuvpwqdxtzvn6st6xtq3mddvzjy7306shzczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6lezzyc" />
    <content type="html">
      Really hoping that the title - of the W3C&amp;#39;s position paper - &amp;#34;Third-Party Cookies Must Be Removed&amp;#34;:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://w3c.social/@w3c/114432468864338537&#34;&gt;https://w3c.social/@w3c/114432468864338537&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;... is a deliberate echo of &amp;#34;Carthage must be destroyed&amp;#34;:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Carthago_delenda_est&#34;&gt;https://en.wikipedia.org/wiki/Carthago_delenda_est&lt;/a&gt;
    </content>
    <updated>2025-05-08T12:47:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszd85hd5q9xatp38tdrzwc7s8d66m2p5uk9pcz7f0l8qe3gh0pmmqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6eqce67</id>
    
      <title type="html">inb4 the Signal clone is revealed much later to have actually ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszd85hd5q9xatp38tdrzwc7s8d66m2p5uk9pcz7f0l8qe3gh0pmmqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6eqce67" />
    <content type="html">
      inb4 the Signal clone is revealed much later to have actually been a bugdoor-riddled op, because¹:&lt;br/&gt;&lt;br/&gt;&amp;#34;Any sufficiently advanced malice is indistinguishable from incompetence.&amp;#34;&lt;br/&gt;&lt;br/&gt;¹&lt;a href=&#34;https://infosec.exchange/@tychotithonus/110782759353122562&#34;&gt;https://infosec.exchange/@tychotithonus/110782759353122562&lt;/a&gt;
    </content>
    <updated>2025-05-05T23:10:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8xydpw6wmg788xkcylpuyer2avk8nevhuzrtjmlhlydz3jveu76czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63cnfyk</id>
    
      <title type="html">Petition to make it illegal for streaming services to use ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8xydpw6wmg788xkcylpuyer2avk8nevhuzrtjmlhlydz3jveu76czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p63cnfyk" />
    <content type="html">
      Petition to make it illegal for streaming services to use thumbnails that contain spoiler content.
    </content>
    <updated>2025-04-20T07:20:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyjjwakqygksyeqc2up0awv8tggupphrzhgpy5vc2x5q3nrjrzr5czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gs5ump</id>
    
      <title type="html">And, per me: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyjjwakqygksyeqc2up0awv8tggupphrzhgpy5vc2x5q3nrjrzr5czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6gs5ump" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs88sqn2ul9lez2vqrf3hlrgrf8vv77tmh34mwx0t56pkt9lkvhx5gvkf6me&#39;&gt;nevent1q…f6me&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And, per me:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://infosec.exchange/@tychotithonus/110782759353122562&#34;&gt;https://infosec.exchange/@tychotithonus/110782759353122562&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;... the inverse is true:&lt;br/&gt;&lt;br/&gt;Any sufficiently advanced malice is indistinguishable from incompetence.&amp;#34; (bugdoors, etc.)
    </content>
    <updated>2025-03-20T15:58:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrnpc5jnt4avy032dref9tvncnrfuw6ehnj6vq2jpjazejml2m54gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6twj64q</id>
    
      <title type="html">Whew! Good thing users will be blocked from using these ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrnpc5jnt4avy032dref9tvncnrfuw6ehnj6vq2jpjazejml2m54gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6twj64q" />
    <content type="html">
      Whew! Good thing users will be blocked from using these compromised &amp;#34;passwords&amp;#34;! /s&lt;br/&gt;&lt;br/&gt;#HashCracking&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/187/706/269/173/111/original/f961a20fc04cc448.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-19T06:36:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsge03vwtx7avhejfa3lkwdhawcpkv3gc6wd5fl7lc028rml7sa6dszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ch74eh</id>
    
      <title type="html">The protective value of &amp;#34;k-anonymity&amp;#34;¹ for Have I Been ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsge03vwtx7avhejfa3lkwdhawcpkv3gc6wd5fl7lc028rml7sa6dszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6ch74eh" />
    <content type="html">
      The protective value of &amp;#34;k-anonymity&amp;#34;¹ for Have I Been Pwned / Pwned Passwords API lookups is significantly reduced because frequency data is included. And the more common the password, the more this effect is magnified.&lt;br/&gt;&lt;br/&gt;An example:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://gist.github.com/roycewilliams/2034c9253d46fbcaefb13f8e5d42daa2&#34;&gt;https://gist.github.com/roycewilliams/2034c9253d46fbcaefb13f8e5d42daa2&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;... with cracks:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://gist.github.com/roycewilliams/2bb471cc90cce7f6834204344590fcac&#34;&gt;https://gist.github.com/roycewilliams/2bb471cc90cce7f6834204344590fcac&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Using &amp;#34;k-anonymity&amp;#34;¹ to return all hashes that begin with b2e98 is less &amp;#34;anonymous&amp;#34; ... when 98.6% of the passwords (by frequency across all leaks) are the top one.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s not really hiding a needle in a haystack if you just lay it on top.&lt;br/&gt;&lt;br/&gt;Edit: in fact, even *without* the frequency data, since some passwords are much more common than others ... left-skewed distribution is an intrinsic property of password data. Missing frequency data can be largely reconstructed from public cracking efforts. (And even if that weren&amp;#39;t true, the hashes can just be cracked using traditional methods. If the cracking community can get a 97%&#43; cracking rate², what is being achieved other than plausible deniability?)&lt;br/&gt;&lt;br/&gt;K-anonymity [as implemented by HIBP, anyway -- true K-anonymity is different¹]  may just be a bad fit for password hashes.&lt;br/&gt;&lt;br/&gt;¹ Not actually k-anonymity at all:&lt;br/&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/K-anonymity&#34;&gt;https://en.wikipedia.org/wiki/K-anonymity&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;² Actually closer to 99.29% across the entire corpus, publicly:&lt;br/&gt;&lt;a href=&#34;https://gist.github.com/roycewilliams/40f0e8c93ec9c69f5b5a1874c76f2587&#34;&gt;https://gist.github.com/roycewilliams/40f0e8c93ec9c69f5b5a1874c76f2587&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#passwords #HaveIBeenPwned
    </content>
    <updated>2025-03-18T23:15:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9qg78chrqx5k52kjyv2c04wyzs6363va0skeskgxfz4v40e6j9cczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xcw9xl</id>
    
      <title type="html">Fair - though since tailoring ads based on demographic data and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9qg78chrqx5k52kjyv2c04wyzs6363va0skeskgxfz4v40e6j9cczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6xcw9xl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszfusfw7ncdau2y7dux96lk2ks06jjral52kpk6h37t9d6j7l4nmg2hez5t&#39;&gt;nevent1q…ez5t&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Fair - though since tailoring ads based on demographic data and other factors requires different people to be served different ads, it feels like it would just be too inefficient to customize many input models. Even with a global (non-tailored) tweak, it seems like burning compute in that would be eclipsed by the business pressure of burning it in general model improvement instead. But then again, I might have said that about search a decade ago, so you may be in to something. 😅Fascinating!
    </content>
    <updated>2025-03-09T16:01:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs08p22sshtfg62kelm0ftjn48s5ul78s5umaa4sz2vagc0nns4m4czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fk7dwn</id>
    
      <title type="html">Related, indeed ... but since AI handlers have models with ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs08p22sshtfg62kelm0ftjn48s5ul78s5umaa4sz2vagc0nns4m4czyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fk7dwn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8zj7e67kxr7ck788jj8l6apn72l3hv2d72mjtgjyppcflhmm4q7slv0qqa&#39;&gt;nevent1q…0qqa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Related, indeed ... but since AI handlers have models with untraceable sources, it seems far easier to manipulate the *answers* than try to alter the *inputs* (to weight Home Depot more than Lowe&amp;#39;s, etc.)
    </content>
    <updated>2025-03-09T15:40:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs05fsnzslj64775gazcg0cask766j4rqu5ec65tcm83ylzzlcextczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qpc7mg</id>
    
      <title type="html">Obvious in retrospect, but never occurred to me until this ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs05fsnzslj64775gazcg0cask766j4rqu5ec65tcm83ylzzlcextczyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6qpc7mg" />
    <content type="html">
      Obvious in retrospect, but never occurred to me until this morning:&lt;br/&gt;&lt;br/&gt;Won&amp;#39;t many broad answers provided by AI that are actually true have to be suppressed (regimes, ads and other commercial motivation, etc.)?&lt;br/&gt;&lt;br/&gt;Won&amp;#39;t improving *true* AI performance always be at odds with the goals of its creators, to the detriment of its consumers?&lt;br/&gt;&lt;br/&gt;(Note that I say &amp;#34;actually true&amp;#34; on purpose; AI picking up *wrong* but dominant answers from bad data is also a thing but not what I&amp;#39;m talking about.)
    </content>
    <updated>2025-03-09T15:34:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsge30nm6dtn78t6r2fgf4pffmv9krykwkeyy3x7ax9sewrsgr6ksqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fhe4q9</id>
    
      <title type="html">Dear everyone, Stop putting click tracking on your password-reset ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsge30nm6dtn78t6r2fgf4pffmv9krykwkeyy3x7ax9sewrsgr6ksqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6fhe4q9" />
    <content type="html">
      Dear everyone,&lt;br/&gt;&lt;br/&gt;Stop putting click tracking on your password-reset links.&lt;br/&gt;&lt;br/&gt;You need ZERO third-party metrics to record that I followed a link *that is the only way to get what I explicitly requested*.&lt;br/&gt;&lt;br/&gt;And I need ZERO interference / dependencies (from ad blocking, web filtering, etc.) for such a critical function.
    </content>
    <updated>2025-03-08T22:08:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs23ttzxhtcl0xjc5xfqxzyqlkssuyt0ldxejznndsc5egvejgn85gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j87f8k</id>
    
      <title type="html">They&amp;#39;re missing the blue painter&amp;#39;s tape labels in large ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs23ttzxhtcl0xjc5xfqxzyqlkssuyt0ldxejznndsc5egvejgn85gzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6j87f8k" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv85jfsn9snchudhpnxy6hrf8tuz0ev9xhk6juwessnnf0uz569kcxr84rx&#39;&gt;nevent1q…84rx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;They&amp;#39;re missing the blue painter&amp;#39;s tape labels in large Sharpie, with the output specs. 😉
    </content>
    <updated>2025-03-08T18:13:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy4yhthnwv2x9skmlpwekcpl0mlmhcmr7evv365j5erujm8909waqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nxnacz</id>
    
      <title type="html">There&amp;#39;s a lot to unpack here</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy4yhthnwv2x9skmlpwekcpl0mlmhcmr7evv365j5erujm8909waqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6nxnacz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstykxr2m6pt7ehzlrhpxuuw07zg5zpvnf8397mc2sw6438h05t2vsmjwmqn&#39;&gt;nevent1q…wmqn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;There&amp;#39;s a lot to unpack here
    </content>
    <updated>2025-03-01T07:37:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqf2sy9d857c75zcdavk0qzcqhfwxcmhzzw6mvpkr76pnvx6ad5aszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68frgts</id>
    
      <title type="html">I&amp;#39;d like to compile a list of good opsec references for these ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqf2sy9d857c75zcdavk0qzcqhfwxcmhzzw6mvpkr76pnvx6ad5aszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p68frgts" />
    <content type="html">
      I&amp;#39;d like to compile a list of good opsec references for these times. &lt;br/&gt;&lt;br/&gt;I&amp;#39;m interested in creating multiple sections - both general (the &amp;#34;use Tor, Use Signal&amp;#34; types), as well as for specific populations (vulnerable / targeted ones, protesters, Federal workers, etc.). &lt;br/&gt;&lt;br/&gt;Also interested in refs for both technical and non-technical audiences! Blogs, checklists, books - anything.&lt;br/&gt;&lt;br/&gt;Please reply with your favorite things. My goal is to organize them and publish them as a single meta-reference page on my website.
    </content>
    <updated>2025-02-28T03:39:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdyy2n08jl0dy7us7t8ph72kca53ujr8ywmgs0xdd3k2d2sg8pyaqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65egmvw</id>
    
      <title type="html">Indeed - though I&amp;#39;m also talking about how to surface this to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdyy2n08jl0dy7us7t8ph72kca53ujr8ywmgs0xdd3k2d2sg8pyaqzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p65egmvw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx8lxfck48k5r6uthyvweyg6dqw2ze36ltvlqgged8lptrc8datsghul8xl&#39;&gt;nevent1q…l8xl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Indeed - though I&amp;#39;m also talking about how to surface this to more ordinary users (&amp;#34;you just got a &amp;#39;special&amp;#39; version of Telegram&amp;#39;&amp;#34; etc)
    </content>
    <updated>2025-02-27T20:09:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst7yh6a97qlam042ut05swdttpl0ft4xle8fwk5aln4mtgcrqy3tszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p627q777</id>
    
      <title type="html">If a government can issue a secret order to push a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst7yh6a97qlam042ut05swdttpl0ft4xle8fwk5aln4mtgcrqy3tszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p627q777" />
    <content type="html">
      If a government can issue a secret order to push a &amp;#39;special&amp;#39; version of a mobile app just to a specific person (or set of people), how can this be mitigated?&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;How can app &amp;#34;rarity&amp;#34; be detected locally? (Antivirus and its descendants have a concept of a &amp;#34;well-known benign executable&amp;#34; vs one that has only been rarely seen. &amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Can a local app, or an OS feature, be used to compare local apps with a list of expected versions?&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Can this be done &amp;lt;em&amp;gt;independently&amp;lt;/em&amp;gt; of the OS (since the order could also subvert the rarity check)? (Even an independent app can be subverted if the only app store is the official one maintained by the same vendor.)&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;To detect unusual app versions, reproducible builds are necessary but not sufficient, unless the project is also FOSS -- because even if everyone gets the same APK, the app might receive different instructions from its server depending on unique metadata.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;
    </content>
    <updated>2025-02-27T16:44:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqjpq30ttp8flqtfexxlrcja4v37myu98m4h0rv557mq2vk5uudlgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6uhtyzu</id>
    
      <title type="html">You really want the latest - the full weekly list is reordered to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqjpq30ttp8flqtfexxlrcja4v37myu98m4h0rv557mq2vk5uudlgzyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6uhtyzu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp54ckdvdwxchq3zf5430ygd208ad8sm3m0qsdrxt7djpytu9tmggrfwdfq&#39;&gt;nevent1q…wdfq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You really want the latest - the full weekly list is reordered to be in frequency order across all targets, and in between those releases, it&amp;#39;s append-only -- so you can HTTP Range Requests or rsync with --append to grab just the new, fresh ones very quickly and append them to your giant file. It&amp;#39;s a superpower.
    </content>
    <updated>2025-02-25T17:35:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgrrn9a9m3szxj0gr98vtpln6e0zzqzsghdjaquzw70k6jy89td5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk5c89</id>
    
      <title type="html">That is ... unusually bad. Where is it from?</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgrrn9a9m3szxj0gr98vtpln6e0zzqzsghdjaquzw70k6jy89td5szyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p6rk5c89" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9ttxph46h6pgyvywxzfgtsvzeg09hx65cjmm0hg6ryy962ydzkdsje75rp&#39;&gt;nevent1q…75rp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That is ... unusually bad. Where is it from?
    </content>
    <updated>2025-02-24T18:43:19Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstkgehju74gseaeaukdvd909r8qu44fptc0vs4ypu94u8jda09lwszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64nkm5w</id>
    
      <title type="html">The hashcat.net site is down -- side effect of maintenance by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstkgehju74gseaeaukdvd909r8qu44fptc0vs4ypu94u8jda09lwszyp5kgl2m3qt5w2kzem2t3r7efh8td8nukpsrsunhrfnnw3c2se0p64nkm5w" />
    <content type="html">
      The hashcat.net site is down -- side effect of maintenance by hosting provider. Being worked.&lt;br/&gt;&lt;br/&gt;Current release can be downloaded from GitHub:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/hashcat/hashcat/releases/tag/v6.2.6&#34;&gt;https://github.com/hashcat/hashcat/releases/tag/v6.2.6&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Convenience Wayback links to popular wiki pages:&lt;br/&gt;&lt;br/&gt;**Rules:**&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://web.archive.org/web/20250211234251/https://hashcat.net/wiki/doku.php?id=rule_based_attack&#34;&gt;https://web.archive.org/web/20250211234251/https://hashcat.net/wiki/doku.php?id=rule_based_attack&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;**Example hashes:**&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://web.archive.org/web/20250216060927/https://hashcat.net/wiki/doku.php?id=example_hashes&#34;&gt;https://web.archive.org/web/20250216060927/https://hashcat.net/wiki/doku.php?id=example_hashes&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;**FAQ**&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://web.archive.org/web/20250219024304/https://hashcat.net/wiki/doku.php?id=frequently_asked_questions&#34;&gt;https://web.archive.org/web/20250219024304/https://hashcat.net/wiki/doku.php?id=frequently_asked_questions&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1ay68h9kfxm2hsfvwxmmzg274s90auhv33ftke0uumgv8uh3r2k2q497gtx&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;hashcat&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1ay6…7gtx&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; #hashcat
    </content>
    <updated>2025-02-21T20:08:53Z</updated>
  </entry>

</feed>