Tech · Culture · Fiction
A favicon is a code execution primitive.
How attackers hide skimmers and full payloads in favicon files, why MIME and CSP misconfiguration lets image bytes run as code, and what defenders miss.
Google killed io_uring fleet-wide in 2023
io_uring runs file and network operations off the syscall path, blinding seccomp, auditd, and EDR, while epoll stays observable to defenders.
Keep the hard part
AI doesn't erode your problem-solving skills-offloading the reasoning does. Any intelligence atrophies without use; the fix is design, not avoidance.
Linux kernel deleted strncpy across 360 patches
Linux removed strncpy across 360 patches over six years. The exposure: a bounded write primitive used as a safety control it never implemented.
The channel trusted the sender
An unauthorized alert reached phones across Brazil. The confirmed finding is one control: sender authorization at the injection point did not hold.
The green check mark proves nothing
Accepting AI-generated code because it works extends your trust boundary to an unvetted source running under your identity. Function is not authorization.
The same-origin policy is not protecting your API
A permissive CORS header delegates the read decision to the requester, letting attacker script read authenticated responses through the victim's own browser.
The Wire — latest
All →- AI Is Quietly Eroding Expert Skills, Early Studies Warn
- Amazon shelves Altman biopic months after deepening OpenAI cloud pact
- Bipartisan JAWBONE Act would let users sue officials who coerce platforms into censorship
- Cloudflare lets AI agents deploy first, sign up later with temporary accounts
- Finland Reinvents the Library as Civic Infrastructure — Sewing Machines Included
- Hackers Hijack Brazil's Emergency Alert System, Push 'Misanthropy' Warning
- Inside Bayer's PRINCE: engineering an agentic RAG system for drug research
- IPv6 Crosses 50% of Google's Users — But the Number Depends Who's Counting
- Linux kernel finally rips out strncpy after 6 years and 360+ patches
- Loupe: open-source iOS app shows exactly what apps can fingerprint about you
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.