yan

20.2K posts

yan banner
yan

yan

@bcrypt

security engineering @brave / helped build Let's Encrypt, Privacy Badger, and HTTPS Everywhere @eff / physics alum @mit / rabbit enthusiast

Katılım Kasım 2012
330 Takip Edilen74.1K Takipçiler
Sabitlenmiş Tweet
yan
yan@bcrypt·
could not for the life of me figure out how to buy a bus ticket in Milan. it was literally easier to get a shell 😆
yan tweet media
English
90
620
7K
0
Carbon
Carbon@CogniCarbon·
I built a tool that ranks health influencers by how well their claims match 150,000 research papers. Here's the leaderboard. Will post more results soon!
Carbon tweet media
English
300
139
3.5K
560.2K
yan
yan@bcrypt·
@sumlac i added the marin data, lmk if you see any issues!
English
1
0
0
116
Justin Calmus
Justin Calmus@sumlac·
@bcrypt This is good stuff! I’m in Marin, may need to add coverage there 😆
English
2
0
1
318
yan
yan@bcrypt·
in light of the tragic news that a 2-year old died at a licensed SF daycare earlier this month, i made a site to show childcare license violations and complaints in the Bay Area: azuki.vip/childcare/
English
5
0
52
7.4K
yan
yan@bcrypt·
@sumlac i'll add it with my next data refresh!
English
0
0
1
225
yan
yan@bcrypt·
* the data is public at ccld.dss.ca.gov/carefacilityse… but i found that site hard to use * PRs welcome github.com/diracdeltas/ch… * i am aware this does not show small home daycares; working on that * very grateful to Claude for making this a sunday project instead of a multi-week one
English
0
0
8
1.6K
yan
yan@bcrypt·
why is Claude installing a Native Messaging host in Brave's profile directory if code.claude.com/docs/en/chrome explicitly doesn't support Brave??
That Privacy Guy@alexanderhanff

thatprivacyguy.com/blog/anthropic… @AnthropicAI secretly installs spyware when you install Claude Desktop Anthropic's Claude Desktop silently installs a Native Messaging bridge into seven... #ai #privacy #eprivacy #compliance #infosec #gdpr #law #cyber #security #anthropic #claude

English
7
12
108
23.6K
yan retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
543
4K
16.3K
12.3M
yan
yan@bcrypt·
wow it turns out that some of those AI slop reports that every bug bounty program is now flooded with are from security companies trying to get free training input @Bugcrowd please name them! bugcrowd.com/blog/bugcrowd-…
English
2
2
17
2.8K
yan retweetledi
Brave
Brave@brave·
AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks. We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.
Brave tweet media
English
94
557
3.9K
1.6M
yan retweetledi
Meredith Whittaker
Meredith Whittaker@mer__edith·
📣🚨 BAT SIGNAL: A law in France that would mandate a backdoor in end to end encrypted communications is set for a vote within the next day, after some start-stop skirmishes.  The French Narcotraffic law would require encrypted communications providers—like Signal—create a backdoor by giving the government the ability to add themselves to any group or chat they like. In the name of (checks notes) fighting drug trafficking.  While those hyping this bad law have rushed to assure French politicians that the proposal isn’t’ ‘breaking encryption’ their arguments are as tedious as they are stale as they are laughable. For those catching up, let’s review the basics: end to end encryption must only have two ‘ends’—sender and recipient(s). Otherwise, it is backdoored. Whatever method is devised to add a ‘third end’ —from a perverted PRNG in a cryptographic protocol, to vendor-provided government software grafted onto the side of secure communications that allow said government to add themselves to your chats—it rips a hole in the hull of private communications and is a backdoor.  Indeed, the ghost participant proposal was roundly rebuked (humiliated, even) when it was first proposed in 2019 in the UK. The technical community was united, and it was never implemented in law or otherwise.  We cannot accept any backdoor, however it’s dressed up. Communications don’t stay within jurisdictional boundaries. Which means a hole created in France becomes a vector for anyone wanting to undermine Signal’s robust privacy guarantees, anywhere. Instead of contending with unbreakable math, they only have to compromise a French government employee, or the vendor-provided software used to sideload government operatives into your private chats.  This is why, as always, Signal would exit the French market before it would comply with this law as written. At this moment especially, there is simply too much riding on Signal, on our being able to forge a future in which private communication persists, to allow such pernicious undermining.  We hope—WE HOPE—that this callow, dishonest attack will fail, and will be the last. We would love to get back to the work of maintaining and improving our core technologies, instead of fighting legislation which is distinguished in nothing as much as its refusal to listen to decades of expert consensus in its drive to imperil global cybersecurity and the human right of privacy.
English
105
839
2.2K
446.7K
yan
yan@bcrypt·
(this is the sort of tweet that would have absolutely slapped on infosec twitter circa 2015, RIP)
English
0
0
72
5.1K
yan
yan@bcrypt·
ecdsa private key leak due to nonce reuse strikes again, this time in the elliptic npm library github.com/advisories/GHS…
English
2
32
166
19.5K
yan
yan@bcrypt·
@AmandaAskell @bratwebb ALSO recall that i won the plank and wall sit competitions at Anya's birthday party!!
English
0
0
2
554
yan
yan@bcrypt·
@AmandaAskell @bratwebb my default protein intake is pretty low (like 1 g/kg at most) and i didn’t get much benefit from going higher! if you’re consistent you should still gain muscle. my main metric is climbing and i went from 11b’s to 12b’s in like a year of strength training with no diet changes
English
1
0
4
683
Amanda Askell
Amanda Askell@AmandaAskell·
I knew strength training would be hard because lifting heavy things is hard. But it also seems to involve eating protein like it's a part time job. If any seasoned people have tips for beginners, I'd love to know them!
English
142
6
894
119.3K
yan
yan@bcrypt·
@KumailNanji i heard this works even better: rm -rf /
English
0
0
14
1.9K
Kumail Nanji
Kumail Nanji@kumailnanji·
Mac tip of the year: Go to "~/Library/Caches" and delete everything inside I just reclaimed 500gb of storage 🤯😤
Kumail Nanji tweet media
English
154
298
5.2K
813.5K
yan
yan@bcrypt·
@thdxr october 2023
yan tweet media
Español
0
0
20
1.1K
dax
dax@thdxr·
has anyone generated an impressive logo you'd actually ship with ai? this feels like a good benchmark
English
127
10
945
184.7K
yan
yan@bcrypt·
@troyhunt haha i got this too
English
0
1
17
5.4K
Troy Hunt
Troy Hunt@troyhunt·
You absolute muppet, Ghulam 🤦‍♂️
Troy Hunt tweet media
English
177
219
7.5K
788.6K
yan
yan@bcrypt·
target.com prices delivery items based on your local store setting, not your delivery address, so if you live in SF just set your local store to Missouri or something lol
yan tweet mediayan tweet media
English
5
15
222
14.7K
cinesthetic.
cinesthetic.@TheCinesthetic·
What something that’s completely normal in movies but would be weird and even psychotic in real life?
English
5K
3.6K
118.9K
25.4M