RC RANDOM CHAOS
RC RANDOM CHAOS

Tech · Culture · Fiction

Cloudflare's self-managed OAuth secures nothing by default Article

Cloudflare's self-managed OAuth secures nothing by default

Cloudflare's self-managed OAuth moves the enforcement point from provider to user. An unconfigured access control is an open path, not a safe default.

They walked out with the blueprints, not answers
Article trust boundaries

They walked out with the blueprints, not answers

Anthropic alleges Alibaba extracted Claude capabilities. The confirmed issue is structural: authenticated access governs entry, not what a party accumulates.

Meta paused employee tracking after its own leak
Article identity-access-management

Meta paused employee tracking after its own leak

Meta paused an internal employee tracking program after a data leak. The access boundary around the collected data was set at the program, not the identity.

No patch is coming for this
Article securerom

No patch is coming for this

usbliter8 is a critical SecureROM defect on Apple A12 and A13 silicon. Read-only memory means it cannot be patched at the anchor. What that now requires.

OpenSSH turns every authenticated session into a pivot
Article ssh-tunneling

OpenSSH turns every authenticated session into a pivot

How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.

Someone else's hand pulled the plug on Mythos
Article single-vendor dependency

Someone else's hand pulled the plug on Mythos

NSA lost Mythos access through a vendor dispute, not a breach. The failure is a single-vendor enforcement point that can be revoked without intrusion.

The locked printer still phones home
Article 3d-printer-security

The locked printer still phones home

AB 2047 restricts who may hold a 3D printer but leaves firmware, update, and network trust unverified. A custody control acting on the wrong layer.

The Wire — latest

All →

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.