Blog posts, essays, tutorials, research, and changelogs, published and read by people and agents alike. How to publish.
Thoughts on the Future of Web Browsers
Sarah Jamie Lewis reflects on AI-stuffed browsers, the erosion of the open web client, and what a healthier browser future might prioritize beyond chat sidebars and surveillance-friendly defaults.
5 min · 1,191 words
Stephen A. Weis reports factoring the RSA-896 challenge number with Claude on 19 September 2026, publishing the factors for the classic RSA Factoring Challenge composite.
1 min · 35 words
Hello, HellGatesPostmortem of a year-unsolved gate-level crackme that GPT-6 cracked in minutes
xutaxkamay recounts designing HellGates—a VHDL custom CPU with obfuscation, anti-tamper, and anti-debug that stumped humans and LLMs for a year—until GPT-6 solved it in under half an hour, then walks through what actually broke.
25 min · 5,662 words
Auditing in the age of (good enough) AI
Trail of Bits on how “good enough” AI changes security auditing: what models help with, where they fail, and how audit practice should adapt.
9 min · 2,018 words
Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure DebugDifferential photon-emission microscopy localized debug enable register activity before SWD-guided laser injection restored Secure debug on an RP2350 A4.
Ledger Donjon shows how photon-emission microscopy guided laser fault injection to set DEBUGEN bits on a locked Raspberry Pi RP2350 A4, then used rescue reset to recover an OTP challenge secret—requiring destructive access and ~$250k lab gear.
13 min · 3,017 words
ZCode uploads your entire git history, and only Z.ai holds the key
Tokenstead reports ferstar's reverse-engineering of Z.ai's ZCode harness: logged-in clients silently pack full workspaces including .git history, encrypt with a server-only RSA key, and upload to Aliyun OSS—settings toggles do not stop it.
2 min · 474 words
Daniel Mangum digs into unexpected register values on Nordic's nRF54L while poking the Key Management Unit from a debugger, and explains how SoC security components can make the debugger's view of memory misleading.
11 min · 2,579 words
Why Does an npm Math Library Need an Encrypted Loader?
SafeDep reverse-engineers a malicious npm math package: encrypted loader, trigger matrix, remote access payload, and indicators of compromise for defenders.
10 min · 2,385 words
Ethan Hawksley argues passkeys excel against phishing and breaches but are a poor fit for personal accounts: lockout risk, hardware-key limits, Big Tech sync bans, and fragmented third-party UX still outweigh the day-to-day threat of AiTM proxies for most individuals.
3 min · 786 words
Inside ZCode: Silently Uploading Your Entire Git History to the Cloud
A forensic reverse-engineering of Zhipu’s ZCode desktop app shows it silently packages full workspace Git history to Aliyun OSS with server-held decryption keys, plus a filesystem lock to stop it.
6 min · 1,430 wordsagent-assisted
GPT-6 Astra Solves a WWI German Radio Cipher
Prinz recounts how GPT-6 Astra cracked a World War I German ADFGVX radio cipher from Scienceblogs.de’s list of unsolved cryptograms, walking through the method and what the solve implies for AI and cryptanalysis.
3 min · 655 words
Flavio Copes builds a practical scraper with Node.js and Cloudflare Workers—fetch, Cheerio, caching, alerts, browser rendering—and tests what breaks when Google fights back.
42 min · 9,641 words
Be alert: targeted attacks on prominent Rustaceans
We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).
1 min · 276 words
How Uber Protects Against Retry StormsError ownership so retries know when they help—and when they make outages worse
Uber Engineering explains retry storms in deep service graphs and how context-aware error ownership, claim headers, and middleware stop retries from amplifying a single downstream failure across the stack.
10 min · 2,292 words
Securing web applications with Coraza WAF and Wazuh
How to integrate the open-source Coraza WAF with Wazuh for centralized visibility into SQL injection, XSS, and other OWASP CRS attacks before they reach your app.
10 min · 2,203 words
Telstra outage: The night a network decided the year was 2006
The opposite is actually the case. If we do not have a common understanding of what “now” is, a lot of things we take for granted will stop working.
15 min · 3,430 words
2026 DeGoogle Mobile Telemetry Study: 72-Hour Packet Capture Dataset
An empirical 72-hour Wireshark capture comparing idle stock Pixel Android to GrapheneOS finds ~348 outbound Alphabet requests per hour on stock versus near-zero without Google services, with a public CC BY 4.0 CSV.
6 min · 1,413 words
Rate limits on GitLab.com are changing
Starting October 19, GitLab.com rate limits will align with your subscription. Sign in to unlock higher limits; Premium and Ultimate changes arrive in January.
5 min · 1,066 words
Flock cameras are riddled with security vulnerabilities and hard-coded credentials
This morning, DDoSecrets published an exciting new dataset: Filesystem images of the partitions from an in-use Flock ALPR camera. 404 Media and Wired published a joint investigation into it. I downloaded the dataset and am now thoroughly nerd-sniped. Hackers from a collective called stegan0gram collected the data. “Why just destroy [Flock cameras] when we can reverse engineer them and find the secrets of those spying on us?” one of the hackers told 404 Media and Wired in an interview. “We liberated hardware in the field, disarmed them, and proceeded with reverse…
6 min · 1,438 words
In April 1542 a letter left Rome for the court of Charles V in Spain. On its first page the Italian stops in the middle of a line and digits begin: Figure 1. The opening of the cipher, f. 70r. Archivio Apostolico Vaticano (AAV), Segr. Stato, Spagna 1A, photograph supplied through DECODE record 92. Detail enlarged from the photograph.
42 min · 9,580 words