RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Code rides the error channel
qubesosvulnerability-analysis

Code rides the error channel

Arbitrary code execution in QubesOS through the copy-to-VM error reporting backchannel, and what it means for the trust boundary between qubes.

6 min read
Google locked AuroraStore out of the Play Store
grapheneosapp store dependency

Google locked AuroraStore out of the Play Store

The Play Store blocking AuroraStore shows GrapheneOS users never held the app delivery path. The dependency, not the block, is the exposure.

6 min read
MFA protects the login, not the session.
session hijackingMFA bypass

MFA protects the login, not the session.

Fastpotify mints unbound session cookies that survive MFA. Stolen via AiTM or infostealer, they replay as full sessions. The telemetry that catches it.

6 min read
Pixel 11 drops hardware MTE
GrapheneOSMTE

Pixel 11 drops hardware MTE

Pixel 11 has no hardware memory tagging. GrapheneOS inherits the gap. What the missing per-access MTE check removes from your threat model.

7 min read
Private was never private
privacymessaging security

Private was never private

Messaging apps protect your chat from other users, not from the operator that holds the content, the metadata, and the terms you accepted at install.

9 min read
Three filled lines in the HuggingFace postmortem
AI securityincident response

Three filled lines in the HuggingFace postmortem

A HuggingFace hack postmortem by METR and Redwood confirms only authorship, subject, and focus. Mechanism is not confirmed, so no control change is authorized.

6 min read
Volume 5 lands on both desks at once
dual-use toolingsecurity by obscurity

Volume 5 lands on both desks at once

Tmp.0ut Volume 5 is dual-use tooling. Its publication proves which of your controls enforced identity and which only concealed a now-public method.

8 min read
Your browser tab runs as root on Omarchy
privilege escalationlinux security

Your browser tab runs as root on Omarchy

In Omarchy, any user process reaches root. The user-to-root boundary is gone, turning initial access into full host compromise and lateral movement.

8 min read
Nobody has to break into GitHub
github securitypersonal access tokens

Nobody has to break into GitHub

GitHub incidents are feature abuse under valid credentials. The break is at the execution boundary, and standing scope is the real exposure.

8 min read
Nobody had to hack your meetings.
access-controldata-exposure

Nobody had to hack your meetings.

Over 180,000 tl;dv meetings were left open because access to recorded content was not conditioned on validated identity. What that failure exposes.

8 min read
The record is the authority
DNS securityphishing

The record is the authority

A for-sale DNS record sells naming authority itself, and every control above DNS keeps validating the name for whoever now holds the record.

7 min read
Patching would not have stopped this breach
zero-daydata breach

Patching would not have stopped this breach

A Metabase zero-day converted an analytics application's standing data access into attacker access, leaving reach and scope as the only controls in play.

8 min read