RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

They walked out with the blueprints, not answers
trust boundariesaccess control

They walked out with the blueprints, not answers

Anthropic alleges Alibaba extracted Claude capabilities. The confirmed issue is structural: authenticated access governs entry, not what a party accumulates.

7 min read
Victim types the password, attacker keeps the token
session-fixationcve-2023-4714

Victim types the password, attacker keeps the token

CVE-2023-4714 session fixation (CWE-384) explained: how attackers plant a session ID, bypass MFA, what fires in telemetry, and why rotation alone is not enough.

6 min read
Compiling a Rust crate runs the author's code.
supply-chain-securityrust

Compiling a Rust crate runs the author's code.

crates.io federates all publish identity to GitHub, turning one account takeover into build-time code execution across every downstream Cargo project.

6 min read
Meta paused employee tracking after its own leak
identity-access-managementdata-leak

Meta paused employee tracking after its own leak

Meta paused an internal employee tracking program after a data leak. The access boundary around the collected data was set at the program, not the identity.

7 min read
No patch is coming for this
secureroma12-a13

No patch is coming for this

usbliter8 is a critical SecureROM defect on Apple A12 and A13 silicon. Read-only memory means it cannot be patched at the anchor. What that now requires.

8 min read
OpenSSH turns every authenticated session into a pivot
ssh-tunnelinglateral-movement

OpenSSH turns every authenticated session into a pivot

How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.

7 min read
Ransomware spreading through trusted accounts
ransomwareidentity security

Ransomware spreading through trusted accounts

A novel ransomware variant spread through compromised accounts, exposing identity - not the perimeter - as the boundary that must be enforced at runtime.

7 min read
Seven years after checkm8, the A12 falls too
iPhone securitySecureROM

Seven years after checkm8, the A12 falls too

Usbliter8 is a SecureROM boot exploit for A12/A13 iPhones. What it can and cannot do, who it threatens, and how to reduce your exposure.

7 min read
Someone else's hand pulled the plug on Mythos
single-vendor dependencylayered defense

Someone else's hand pulled the plug on Mythos

NSA lost Mythos access through a vendor dispute, not a breach. The failure is a single-vendor enforcement point that can be revoked without intrusion.

7 min read
The locked printer still phones home
3d-printer-securityfirmware-trust

The locked printer still phones home

AB 2047 restricts who may hold a 3D printer but leaves firmware, update, and network trust unverified. A custody control acting on the wrong layer.

8 min read
The most expensive incident this year stole nothing.
operational risksystem availability

The most expensive incident this year stole nothing.

A Codex logging defect can write terabytes to local SSDs, turning a function assumed low-consequence into a board-level availability and cost exposure.

7 min read
The patch opens the attack window.
vulnerability-managementmass-exploitation

The patch opens the attack window.

The Coming Loop is the collapsing gap between vulnerability disclosure and mass exploitation of internet-facing appliances - and why edge telemetry stays blind.

6 min read