Articles
Long-form writing on tech, culture, and the edges of the internet.
Code rides the error channel
Arbitrary code execution in QubesOS through the copy-to-VM error reporting backchannel, and what it means for the trust boundary between qubes.
Google locked AuroraStore out of the Play Store
The Play Store blocking AuroraStore shows GrapheneOS users never held the app delivery path. The dependency, not the block, is the exposure.
MFA protects the login, not the session.
Fastpotify mints unbound session cookies that survive MFA. Stolen via AiTM or infostealer, they replay as full sessions. The telemetry that catches it.
Pixel 11 drops hardware MTE
Pixel 11 has no hardware memory tagging. GrapheneOS inherits the gap. What the missing per-access MTE check removes from your threat model.
Private was never private
Messaging apps protect your chat from other users, not from the operator that holds the content, the metadata, and the terms you accepted at install.
Three filled lines in the HuggingFace postmortem
A HuggingFace hack postmortem by METR and Redwood confirms only authorship, subject, and focus. Mechanism is not confirmed, so no control change is authorized.
Volume 5 lands on both desks at once
Tmp.0ut Volume 5 is dual-use tooling. Its publication proves which of your controls enforced identity and which only concealed a now-public method.
Your browser tab runs as root on Omarchy
In Omarchy, any user process reaches root. The user-to-root boundary is gone, turning initial access into full host compromise and lateral movement.
Nobody has to break into GitHub
GitHub incidents are feature abuse under valid credentials. The break is at the execution boundary, and standing scope is the real exposure.
Nobody had to hack your meetings.
Over 180,000 tl;dv meetings were left open because access to recorded content was not conditioned on validated identity. What that failure exposes.
The record is the authority
A for-sale DNS record sells naming authority itself, and every control above DNS keeps validating the name for whoever now holds the record.
Patching would not have stopped this breach
A Metabase zero-day converted an analytics application's standing data access into attacker access, leaving reach and scope as the only controls in play.