Jasper van Gelder

3.7K posts

Jasper van Gelder banner
Jasper van Gelder

Jasper van Gelder

@JaspervGelder

Entrepreneurship, Programming, Security

Rotterdam Katılım Aralık 2009
360 Takip Edilen247 Takipçiler
Jasper van Gelder retweetledi
SPEAK UK
SPEAK UK@speakukorg·
Remember the Discord breach exposing users’ ID photos? That is the risk when platforms are pushed towards large-scale age checks. The Online Safety Act means more sensitive data collected, stored, and in some cases: exposed.
SPEAK UK tweet media
English
5
175
440
7K
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@FrankvanBerge @_basjacobs Dat is nog steeds de rekening naar de toekomst verleggen. We zouden massaal in België moeten tanken op kosten dus van de Belgische overheid ;) ( dit laat precies het probleem zien, je kan de markt niet dwingen, de prijs moet linksom of rechtsom worden betaald )
Nederlands
1
0
0
34
FrankvanBerge
FrankvanBerge@FrankvanBerge·
@_basjacobs De overheid kan we lagere accijns op brandstoffen heffen, zoals alle landen om ons heen bewijzen. Landen met vaak een hoger begrotingstekort en een veel hogere staatsschuld dan Nederland.
Nederlands
1
0
3
165
Jasper van Gelder retweetledi
Ansel Lindner
Ansel Lindner@AnselLindner·
The Project Eleven reminds me of the Quantum simulator scam Vitalik was selling before Ethereum. "Be scared, it's a huge threat. And buy my theoretical services to mitigate the theoretical risk in a theoretical future."
Ansel Lindner tweet media
English
2
8
46
1.9K
Jasper van Gelder retweetledi
Craig Raw 🐦
Craig Raw 🐦@craigraw·
Silent payments is not just a new approach to static payment codes. It's the first serious contender to improve the address derivation system since HD wallets in 2013. HD wallets were a big win over single keys, and silent payments could be a similar leap forward.
English
8
118
487
28.8K
Jasper van Gelder retweetledi
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@jsblokland Tijd voor vrije pensioen keuze, wel verplichtingen maar zelf kunnen kiezen wie het voor je beheert in plaats van koppeling met werkgever.
Nederlands
0
0
0
30
Jasper van Gelder retweetledi
jeroen blokland
jeroen blokland@jsblokland·
Lekker bezig, APG! In 2025 realiseerden aandelen een rendement van 6,7% in euro’s en zelfs obligaties noteerden een, weliswaar klein, plusje. APG: -1,6%. In 2024 realiseerden aandelen een rendement van boven de 20% en kwam ook het obligatierendement, wederom maar net aan en zonder inflatie, boven nul uit. Zelfs met die achterhaalde 60/40-portefeuille had je tussen de 10 en 15% kunnen uitkomen. APG: 8,9%. Je zou er maar verplicht aan moeten deelnemen.
jeroen blokland tweet media
Nederlands
19
35
164
13.7K
Jasper van Gelder retweetledi
Mark Ermolov
Mark Ermolov@_markel___·
Intel SGX has fallen! Its most important key is in our hands: we extracted the Global Wrapping Key from an instance of the Intel Gemini Lake platform
Mark Ermolov tweet mediaMark Ermolov tweet media
English
33
353
2K
215.6K
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@UID_ Among devs there seems to be this consensus, communication to the others just seems lacking. There is research just not a lot and most of them agree there should be a clear upgrade path before enough qubits are a reality. Though the impact is very small (P2PK, key reuse )
English
0
0
0
16
Jasper van Gelder retweetledi
Zynx
Zynx@ZynxBTC·
The Bitcoin community must prepare for the biggest astroturfing campaign we have ever seen. It's clear that quantum will be the major attack vector against Bitcoin for the next few years until a conclusive solution is found. Most of the FUD will be completely unfounded and intended to separate you from your coins. Do not underestimate the vested interest in pushing this narrative far beyond what is necessary because they stand to benefit enormously. Think quantum VC funds and shitcoins trying to promote themselves as "quantum resistant" alternatives. And the attention seekers. Never forget about them. While it is clear that the Bitcoin network needs to become quantum resistant, please understand that some of the smartest developers in the world are working on this and have been for years. Most of the discussion does not happen in public but believe it is a priority and of upmost importance. Bitcoin will be fine.
nic carter@nic_carter

Many are wondering "what Google saw" that caused them to revise their post-quantum cryptography transition deadline to 2029 last week. It was this: research.google/blog/safeguard…

English
61
66
607
100.2K
Jasper van Gelder retweetledi
klöss
klöss@kloss_xyz·
do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
107
488
3.5K
872.4K
Jasper van Gelder retweetledi
Jonas Schnelli
Jonas Schnelli@_jonasschnelli_·
Going from ~1,000 noisy qubits to 500k fault-tolerant ones by 2029 isn’t just a "roadmap",… it’s a **physical miracle** or a massive bluff.
nic carter@nic_carter

Specifically, this paper. It's a brand new resource estimate that's wildly lower than prior estimates of what it would take to break ECC-256. Featuring the Google Quantum AI team + Justin Drake + Dan Boneh quantumai.google/static/site-as…

English
39
57
466
68.1K
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@DelcinMaria Ye or any other node relaying... If it's consensus valid there will always be someone relaying
English
1
0
0
11
Delcin #BIP-110
Delcin #BIP-110@DelcinMaria·
When nodes filter out spam, scammers are compelled to send it directly to miners. They lose their anonymity in the process. Filters up KNOTS + BIP110 + DATUM for max Bitcoin decentralisation.
English
5
20
100
1.5K
Jasper van Gelder retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 MASSIVE CYBERATTACK: The EU Commission, ENISA, and the DG for Digital Services have been compromised by threat actor ShinyHunters. Leaked data includes: ▪️ Emails & attachments ▪️ Full SSO user directory ▪️ DKIM signing keys ▪️ AWS config snapshots ▪️ NextCloud/Athena data ▪️ Internal admin URLs It's a mess!
International Cyber Digest tweet mediaInternational Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
120
845
2.6K
194.5K
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@bgroothuis Ik zie dat u ‘voor’ de eindstemming voor het voorstel heeft gestemd en dus voor verlenging van scanning van berichten. Dus hoezo spin ? U heeft inderdaad keurig netjes voor bescherming van E2EE gestemt maar weer tegen targeted scanning...
Nederlands
0
0
0
44
Bart Groothuis
Bart Groothuis@bgroothuis·
Ik heb niet ‘voor’ gestemd, dat is een spin. Heb gestemd om E2EE in stand te houden (am 30 uit mijn hoofd), alsmede server side scanning naar bestaand KP materiaal. Uiteindelijk was de vraag of bestaande praktijk van server side scanning kon worden voortgezet en daar heb ik + op gestemd
Nederlands
1
0
1
22
Jasper van Gelder retweetledi
GrapheneOS
GrapheneOS@GrapheneOS·
Brazil's authoritarian age verification law became active this month. It won't be implemented by GrapheneOS. Complying would require integrating a mandatory process for each user where a third party service checks government identification and confirms a match using the camera.
English
157
1.1K
8.5K
259.4K
Jasper van Gelder
Jasper van Gelder@JaspervGelder·
@RTLnieuws niets over chat control ? "VVD leest graag nog wat langer mee uw appjes" had een mooie kop geweest. Extension of the temporary derogation from the ePrivacy Directive to combat online child sexual abuse howtheyvote.eu/votes/189270
Nederlands
1
0
0
31