Damus

Recent Notes

stf profile picture


disney is one of the most evil companies, but most people cannot look past the cute. palantier is easy with their on-the-nose, but disney is much worse, and sneaky. kill the mouse!
Sundew · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqg2mkphtpskgss0m7ahv5un68pdjpu45emeyn5ce2qgytv39lqw4qnvh5cv I love copyleft licensing, but I don't think memory safety bugs are irrelevant, nor do...
stf profile picture
@nprofile1q... @nprofile1q... most of the utils in coreutils have no remote attack surface and run without suid bit, so neither local privilege escalation is an issue. so the threat model really does not include memory-safety in any important way. thus the whole rewrite coreutils in rust for security is utter bullshit.
stf profile picture
if the part before the main, is the "prequel" then why is the part after the main a "sequel" and not a "postquel"?
stf profile picture
Product Warning: do *not* buy #ebikes with #bosch motors/controllers. they are locked-down by some #evil #proprietary shit and try to #vendorlockin you into their shitty products. the motors are good, but the apps, the navigation, are horrible, and #interoperability with devices and apps of other vendors is actively hindered.

pls discuss products/vendors that are open and interoperable in comments below.
VessOnSecurity · 1w
"MAD Bugs: Even "cat readme.txt" is not safe": https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not
stf profile picture
@nprofile1q... seriously #iterm2 is notorious for this, every time someone pokes a stick at it, something like this falls out. same back a few years ago when the company i consult for occasionally, i was like, what attack surface can be there in a terminal, turns out with iterm2 it is huge! it downloads, it opens, it parses, it does all kind of things. it's horrible if you care for attack surface minimization.