“Bloomberg ($) reports lawyers are already finding that Apple's always-listening tech is at odds with the law in several U.S. states. Some states require all parties' consent before being recorded, setting up the feature for potential legal battles down the line. This comes amid the rise of smart camera-enabled "pervert glasses" like those made by Meta and Snap, which have supercharged abuse and harassment against people by recording them without consent.”—@zackwhittaker@mastodon.social
https://this.weekinsecurity.com/watch-what-you-say-apple-opens-the-door-to-a-nightmare-world-of-always-listening-tech/
Remote
Chris Palmer
@fugueish@wandering.shop
Music for life, software safety engineering for a living, for now. https://noncombatant.org/
0 Followers
0 Following
50 Posts
Joined June 15, 2024
Signal:
fugueish.87
Open post
"A certain AI researcher said of recent AI hacking incidents: “AI agents … took actions that would be considered as crimes if a human took them”—seemingly taking it as axiomatic that these were not human-controlled activities and therefore cannot qualify as crimes. But they were and they do. ... So let’s call this narrative what it is: an attempt to thwart the rule of law."
https://matthewbutterick.com/chron/drop-dead.html
9
0
8
0
Open post
Replying to
@joe@f.duriansoftware.com Something tells me attempts to do Caja for TCL would end the same way Caja for JS did. :)
But! If you could feasibly and reliably allowlist the objects in the execution context, the idea makes sense. The problem is Spicy Object Graph Connectivity, moreso than that the idea could never work in principle.
2
1
0
0
Open post
Boosted by @joe@f.duriansoftware.com
Replying to
@joe@f.duriansoftware.com Man, the 1993 date on this... incredible.
"Recent research [10]"... ok, let's look at [10]. Oh it's by the same guy: https://dl.acm.org/doi/epdf/10.1145/143457.143463 Surely, this is a deep dive into the sandboxing problem, ca. 1992? He's solved something hard?
No. The solution presented there is: Well, email is already unsafe, so actually we're fine. Also, yeah, the real problem is reading private files. The solution: the same bare assertion that sandboxing is just a SMOP.
How did this get published
1
0
2
0
Open post
Replying to
@_dm@infosec.exchange "Do we get paid time off while it's loading the Request Time Off Reason selector?"
1
1
1
0
Open post
Wait — Darmok and Jalad were at Tanagra? Holy shit
62
0
16
0
Open post
Yambic pentameter:
A sweet potato pie is good to eat
52
3
20
0
Open post
Replying to
@0xabad1dea@infosec.exchange also HuggingFace: “Also we did crimes unrelated to the CFAA, you’ll love it”
8
0
2
0
Open post
Meta profiting from AI-generated CSAM:
“It’s important to point out that this isn’t content posted by third parties on Facebook or Instagram, these are ads that were reviewed, approved, and allowed to run by Meta, never encountering interference while the company collected the ad dollars.”
https://periscope.corsfix.com/?https://www.wired.com/story/meta-ran-ads-that-contained-ai-generated-child-sexual-abuse-imagery/
6
1
9
0
Open post
Replying to
@brohrer@recsys.social @Ashedryden@xoxo.zone who else could convincingly play a hot dog
6
0
0
0
Open post
Replying to
“A civilization that does not treat strangers as gods has already fallen. Starring Robert Pattinson as JD Vance, in an extremely sold-out theater near you”
5
1
0
0
Open post
“The next day, when Suzanne followed up to ask whether I’d considered the options she’d suggested, I told her that I was seeking outside counsel. I’d been in touch with a labor lawyer, and we began drafting a demand letter. Before we could send it, Marion’s boss called me and said that I could keep my responsibilities after all.”
https://periscope.corsfix.com/?https://www.newyorker.com/culture/the-weekend-essay/the-voice-of-google
5
0
3
0
Open post
Open post
USA Today woke up and chose violence this morning and I am *here for it*
“These new candidates don’t understand the crucial role centrist Democrats play in America’s political system. We appeal to "the center," which is an ambiguous blob-like thing that exists only in the minds of Democratic strategists whose brains stopped working in the 1990s.”
https://www.usatoday.com/story/opinion/columnist/2026/06/28/centrist-democrat-mamdani-progressive-socialist/90681634007/
6
1
1
0
Open post
Replying to
If you haven't read The Review (nailed it) yet: https://www.lrb.co.uk/the-paper/v48/n14/emily-wilson/an-uncomplicated-man
3
1
0
0
Open post
Open post
Mac Neo by the (fascinating) numbers: https://www.jdhodges.com/blog/macbook-neo-benchmarks-analysis/
11
0
11
0
Open post
Plot twist: IPAs are Good now
12
0
6
0
Open post
Boosted by @joe@f.duriansoftware.com
Replying to
@joe@f.duriansoftware.com sudden resurgence in IRC servers running SunOS 5
2
0
2
0
Open post
“WARNING: This article is meant to be informal and fun!”
8
0
4
0
Open post
RE: https://infosec.exchange/@da_667/117009941185565746
Google can no longer perform even trivial searches for exact strings.
Open quoted post
Quoting
https://infosec.exchange/@dotdotslash_bot/117009712370074886
so I see this and I'm like "cool, let's write detection for it. Where are the details?" so I search startpage for it.
getting real fucking tired of search engines being so ass. search for this CVE on startpage, and the engine is all like "Oh, a specific cve number?" hah, no, fuck that. let's just pull up any page that as CVE-\d{1,}-\d{1,} in it.
The internet is dogshit now, and I lay the blame at the AI enthusiasts and techbros being bloodless ghouls who don't actually use any of the shit they produce.
Open quoted post 2
0
1
0
Open post
Replying to
Just about the only on-the-nose opportunity Nolan missed was having the Antikythera Mechanism Merchants Guild bankrolling the feast
2
1
0
0
Open post
Replying to
@madcoder@infosec.exchange @fay59@tech.lgbt here’s a banger from my teenage years: https://m.youtube.com/watch?v=ZBQxrD3d7MI
2
1
0
0
Open post
My “member of a cat cult” t-shirt has a lot of people asking questions already answered by my shirt
2
0
1
0
Open post
Replying to
Why turn off WebGPU?
(A) are you using it?
(B) https://chromium.googlesource.com/chromium/src/+/main/docs/security/research/graphics/webgpu_technical_report.md
1
0
1
0
Open post
Replying to
Remember the ABCs of browser security:
Always
Be turning off the JIT
Compiler
1
1
0
0
Open post
Open post
RE: https://beige.party/@gildilinie/116999697694903234
Reminds me of when Suno CEO Mikey Shulman who said nobody likes making music. Yeah we do. Humans are creative people who love to create anything — books, music, software, paintings, … cyber and/or acoustic socks …
It’s a fundamental part of the human condition. When people don’t want to create anything, I gotta ask some questions
1
0
0
0
Open post
Boosted by @GroupNebula563@mastodon.social
Just got my first Sponsored™️ autocomplete result in the (iOS) Firefox address bar
I am going to become the Joker
1
0
2
0
Open post
The open web is being further ruined. Basic privacy protections are at odds with anti-bot/anti-scam protections and at odds with (naturally) surveillance and ads.
This is a choice that we are making as a society.
"Increasingly we’re being presented with a choice that is no choice at all: get rid of all your precautions and let us get our hooks in, or we’ll shut you out of the internet, bit by bit."
https://flaminghydra.com/403-forbidden/
1
0
2
0
Open post
"And the answer is that you make foundational investments in systemic prevention of entire classes of vulnerabilities, even at the expense of having marginally high latency to fixing individual vulnerabilities. While in the very short run this can be painful, on longer time scales, it’s essential. ...like any good engineering project you should structure you work towards incremental deliverables that add value, not one giant big-bang that won’t materialize for forever."
https://alexgaynor.net/2026/jul/15/you-cant-bugfix-your-way-out-of-the-vulnpocalypse/
1
0
1
0
Open post
Open post
Replying to
@jyasskin@hachyderm.io @jaffathecake@mastodon.social @slightlyoff@toot.cafe I'm still stuck on the mental image of Jake trying to turn on the lights and getting hit with "a'waight guv'nor apples and pears" again, rubbing his temples
2
0
0
0
Open post
Oh, you know, just committing some syntactic crimes. How's your Sunday goin’?
```
#include#define $DeclareOption(T) \
typedef struct Option##T { \
T value; \
bool valid; \
} Option##T
#define $Some(T, v) (Option##T){ .value = v, .valid = true }
int main() {
$DeclareOption(int);
auto o = $Some(int, 42);
printf("%d %d\n", o.value, o.valid);
}
```
2
3
2
0
Open post
Open post
Replying to
@joe@f.duriansoftware.com Yeah, I'm waiting for that, but I can't seem to get demo.c from https://nullprogram.com/blog/2025/06/26/ working with
% clang -v
Apple clang version 21.0.0 (clang-2100.0.123.102)
Target: arm64-apple-darwin25.4.0
Thread model: posix
InstalledDir: /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/bin
1
1
0
0
Open post
Replying to
@MrLovenstein@mastodon.social I now pine for the halcyon days of yore, when restaurant web sites were just a janky Flash movie
0
0
0
0
Open post
Replying to
Even better, Firefox lets you turn off WebGPU (see about:config, and then verify it by watching a WebGPU demo site not work)
0
1
0
0
Open post
Replying to
@jann@infosec.exchange compiled code: cached compiler output from source on filesystem and/or network
0
1
0
0
Open post
Open post
Open post
Open post

