RC RANDOM CHAOS
RC RANDOM CHAOS

Tech · Culture · Fiction

A favicon is a code execution primitive. Article

A favicon is a code execution primitive.

How attackers hide skimmers and full payloads in favicon files, why MIME and CSP misconfiguration lets image bytes run as code, and what defenders miss.

Google killed io_uring fleet-wide in 2023
Article io_uring

Google killed io_uring fleet-wide in 2023

io_uring runs file and network operations off the syscall path, blinding seccomp, auditd, and EDR, while epoll stays observable to defenders.

Keep the hard part
Article AI workflow design

Keep the hard part

AI doesn't erode your problem-solving skills-offloading the reasoning does. Any intelligence atrophies without use; the fix is design, not avoidance.

Linux kernel deleted strncpy across 360 patches
Article linux kernel

Linux kernel deleted strncpy across 360 patches

Linux removed strncpy across 360 patches over six years. The exposure: a bounded write primitive used as a safety control it never implemented.

The channel trusted the sender
Article mobile carrier security

The channel trusted the sender

An unauthorized alert reached phones across Brazil. The confirmed finding is one control: sender authorization at the injection point did not hold.

The green check mark proves nothing
Article AI code security

The green check mark proves nothing

Accepting AI-generated code because it works extends your trust boundary to an unvetted source running under your identity. Function is not authorization.

The same-origin policy is not protecting your API
Article cors

The same-origin policy is not protecting your API

A permissive CORS header delegates the read decision to the requester, letting attacker script read authenticated responses through the victim's own browser.

The Wire — latest

All →

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.