RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The copy runs past the allocation, again
vulnerability-managementdetection-engineering

The copy runs past the allocation, again

Recurring dystopian tech vulnerabilities persist because defenders patch the CVE instance and never hunt the underlying mechanism. The inaction is the vuln.

6 min read
The kernel is still C
use-after-freeopenbsd

The kernel is still C

An OpenBSD kernel use-after-free (CWE-416, CVSS 7.8) escalates a local user to root via pool reclaim and cr_uid overwrite. Mechanism, exploit path, and the BSD telemetry gap.

7 min read
The rubric graded an empty chair
systems failure analysistrust delegation

The rubric graded an empty chair

Brown's AI cheating scandal is not a student failure. It is an assessment system that resolves trust by reference and never revalidates the reality behind it.

7 min read
The string you validated no longer exists
unicode-securityencoding-attacks

The string you validated no longer exists

Unicode transliteration is a Turing-complete rewrite engine at every trust boundary. CVE-2024-4577, Django CVE-2019-19844, and Trojan Source show why.

6 min read
You are already in the murder investigation
surveillancesystems failure analysis

You are already in the murder investigation

Flock license plate readers answer queries by reference, never by purpose; the promise that footage serves only serious crime lives in policy, not the system.

7 min read
An open door where the gate should be
ai-agent-securityaccess-control

An open door where the gate should be

GitHub's AI agent returned private repo content when tricked, proving it holds read reach across the private boundary with no enforced refusal.

7 min read
Brussels reopens the envelope on every private message
private message scanningeu surveillance

Brussels reopens the envelope on every private message

The EU is one step from reviving private message scanning. The capability never changed, only the framing. What that exposes and what must now be true.

7 min read
Every Windows laptop carries a tag you can't reach
identity governanceboard oversight

Every Windows laptop carries a tag you can't reach

A board-level analysis of the persistent Windows device identifier as an identity exposure that sits outside enterprise control and must be re-evaluated.

8 min read
Nobody checked what came back
software supply chaindependency management

Nobody checked what came back

The idTech build did not fail. It resolved a version reference exactly as designed, treating a source's identity as proof of its content's integrity.

8 min read
OpenBSD use-after-free hands local users root
openbsdprivilege-escalation

OpenBSD use-after-free hands local users root

An OpenBSD use-after-free escalates a local user to root. Confirmed: the privilege boundary was crossable. Reputation is not enforcement.

6 min read
The console gathers dust, then deletes your games
digital rightslicense termination

The console gathers dust, then deletes your games

Sony's EU inactivity policy is license termination, not deletion. Purchase transferred access, not ownership, and Sony controls the condition.

5 min read
A valid go.sum hash proves nothing
supply-chain-securitygo-ethereum

A valid go.sum hash proves nothing

Argegy is not a CVE. It's a Go supply chain claim against go-ethereum - module trust, init() execution, T1195, and where telemetry goes blind.

6 min read