Tech · Culture · Fiction
Article Cloudflare's self-managed OAuth secures nothing by default
Cloudflare's self-managed OAuth moves the enforcement point from provider to user. An unconfigured access control is an open path, not a safe default.
Governments collect populations, not threats
Mass surveillance is default-on collection plus retention. The unwatched baseline is gone. Operate as already collected and limit what the record resolves.
LuaJIT proposal exposes a guard-elision primitive
LuaJIT's proposed relaxed type checking elides JIT trace guards, creating a type-confusion primitive reachable wherever embedded Lua handles untrusted input.
Telemetry is the breach
Meta paused an employee-tracking telemetry program after a data leak. The real finding is embedded in-process instrumentation as a structural attack surface.
The device is the inventory
Smart TV apps embed residential proxy SDKs that turn devices into exit nodes. The trust failure lives in the build pipeline, not the hardware.
They walked out with the blueprints, not answers
Anthropic alleges Alibaba extracted Claude capabilities. The confirmed issue is structural: authenticated access governs entry, not what a party accumulates.
Victim types the password, attacker keeps the token
CVE-2023-4714 session fixation (CWE-384) explained: how attackers plant a session ID, bypass MFA, what fires in telemetry, and why rotation alone is not enough.
The Wire — latest
All →- A search engine for Hacker News obsessions: 18 years, 45M comments, charted
- Age Verification Laws Are Quietly Becoming Mandatory Identity Checks Online
- AI as a supporting act: building a points-of-interest pipeline that fights hallucinations
- Apple Hikes MacBook and iPad Prices as Memory Costs Surge
- IBM claims first sub-1nm chip, packing 100B transistors with 3D 'nanostack'
- Inkeep ships OpenKnowledge, a GPL'd local-first wiki built around AI agents
- Om Malik reported dead — source page carries only the announcement
- OS9Map brings live OpenStreetMap browsing to Mac OS 9 PowerPC machines
- Oxide's interactive 3D explorer walks you through its cloud computer rack
- Sealed Herculaneum scroll read end-to-end for the first time, virtually unrolled
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.