buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
RE: https://mastodon.social/@buckfiftyseven/116980631827143297
Anti-AI open source has an enemy in common, but almost nothing else
https://www.theregister.com/ai-and-ml/2026/07/25/anti-ai-open-source-has-an-enemy-in-common-but-almost-nothing-else/5278275 ― Liam Proven @lproven | The Register
Building bot-free alternatives may require lefties, libertarians, and culture warriors to share code …
#AI #liberty #left #culture #ethics #BSD #FreeBSD #NetBSD #OpenBSD #Linux #Torvalds #opensource #code #Codeberg #systemd #GNOME #Wayland #Flatpak #IBM #RedHat #Devuan #XLibre #X11Libre #KDE #Trinity #Sonic #Firefox #Servo #Ladybird #Zen #Floorp #Waterfox #Librewolf #Tor #Mullvad #Urbit #Framework #bot #enemy
"Anti-AI open source has an enemy in common, but almost nothing else"
This register article, like anti-ai in general, suffers from one central problem.
It never defines #AI.
Can you be against something without saying what exactly it is? Is it any software that is trained? Is it the image recognition that you have long used? Or does it become bad only when it becomes "large" and "language" based training?
github.com/freebsd/freebsd-src
<https://slopscan.ava.pet/repo/https%3A%2F%2Fgithub%2Ecom%2Ffreebsd%2Ffreebsd%2Dsrc>
github.com/freebsd/pkg
<https://slopscan.ava.pet/repo/https%3A%2F%2Fgithub.com%2Ffreebsd%2Fpkg>
github.com/openzfs/zfs
<https://slopscan.ava.pet/repo/https%3A%2F%2Fgithub%2Ecom%2Fopenzfs%2Fzfs>
<https://lobste.rs/s/7s8fwa/repo_slopscore_detecting_ai_llm#c_vgduls>
❮The "slop" part of slopscan.ava.pet is unnecessarily derogatory, as is the "slop" part of the repo name in Codeberg, and https://codeberg.org/polyphony/repo-slopscore#readme shows some bias.
That aside, I like the dispassionate presentation of facts at the ava.pet site. …❯
AWS Kiro IDE RCE via MCP Config and Hidden Text
🔗 https://cybersecurefox.com/en/aws-kiro-ide-remote-code-execution-mcp
#aws #kiro #kiro #ide #remote #code #execution #rce #mcp.json
The entire code-related work culture is struck through with rich veins of ultracapitalist religion, hero worship, misogyny, eugenics, fascism and misanthropy.
Denying that is approving of it.
This is a great take from @jimniels on designing in the browser.
I don’t know that I’ve ever once coded up one of my designs exactly as its source. Once that code hits, it’s always gonna influence what you do with it.
He says “with an interface, you have to use it, feel it, interact with it, and poke at it.” 100%. And that’s the reason I believe every designer should code their own work. Once a design is in a browser, everything changes.
Hey all.
I've always been interested in learning to code properly. I can use VBA sufficiently well as that's all i've been required to use in my work.
I'm thinking now is a good time to learn something else and get good at it, without any AI or 'vibe' coding. I think there's about to be a need for more people who can code properly.
Anyway, what would be the best one to learn? I'm a little overwhelmed by all the choices! No particular career path in mind yet, so all recommendations welcome. Thanks!
Interesting Git repos of the week:
Strategy:
* https://github.com/mr-r3b00t/ai_usage_mitre_analysis - AI abuse through an ATT&CK lens with @UK_Daniel_Card 🤖
Detection:
* https://github.com/citizenlab/bluecoat-investigations investigating Blue Coat device breaches with @citizenlab
* https://github.com/andreicscs/HoneyWire - F/OSS deception
Bugs:
* https://github.com/sgkdev/ipv6_frag_escape - another Linux LPE
Exploitation:
* https://github.com/x86byte/Obfusk8 - obfuscation library
* https://github.com/bee-san/RustScan - a port scanner in Rust
* https://github.com/t0thkr1s/gpp-decrypt - dumping GPP cpassword
* https://github.com/kernelstub/Nox - attack surface management in Go
* https://github.com/JVBotelho/skewrun - abusing time in AD
* https://github.com/db0109/AI-Red-Team-Scripts-And-Checklist - tips and tricks for red teaming AI 🤖
* https://github.com/jonaslykkegaard9-ops/m - remapping Windows memory
Hard hacks:
* https://github.com/pinkflawd/MIPSReverseEngineeringWorkshop - @pinkflawd's MIPS training
Nerd:
* https://github.com/ripienaar/free-for-dev - free hosting for developers 🤖
* https://github.com/dockur/macos - OS X in Docker
Sharing this not because it’s about AI/LLMs but because it’s solid advice and the recommendations work equally well for *people* coding web applications (funny that, almost like these things were made by people for people or something).
TL;DR: Use web and platform standards; don’t reinvent the wheel.
Sometimes people tell us to "get a job" as if it's that simple.
There are multitudinous good reasons why we:
1. Consider our work for Vulpine Labs and the local community more important than any run of the mill "job".
2. Cannot seriously be expected to attain traditional employment.
3. Shun traditional models of pay in favour of Mutual Aid.
And we won't let capitalism grind us down.
Today, Atha:
Reset the mouse traps in the bus
Cleared snow off the bus and car (altitude does not care for your "seasons", mere mortals)
Got a new phone from a good friend
Set up an LELink LeafSpy OBD2 device to help diagnose and fix the car
Did some reading at the library to get back in the mood for learning Python
And Inara:
Did trans HRT injections
Did some cleaning and tidying
Took the car to do a slow charge session
Did some phone setup
Will likely cook food for us and a homeless friend, and do some VR.
If you want to fling us some currency to keep the mardy old system at bay and fill up the bus's thirsty diesel tank, feel free to send to
https://ko-fi.com/athakitsune or
https://PayPal.me/athamanatha or
Cashapp $athamanatha
Wise and some limited bank transfer options also available on request.
#buslife #poor #mutualaid #pleasedonate #helpfolkslive2026 #helpthehomeless #share4reach #boost4reach #queermutualaid #homeless #queer #homelessmutualaid #trans #transmutualaid #hrt #lgbtq #lgbtqia #lgbtqia2plus #electriccar #diagnostics #EV #nissanleaf #snow #library #books #python #programming #syntax #code #androidphone #unemployable #unemployed #underemployed #volunteering #community #fuelprices #communesandconvoys
Interesting Git repos of the week:
Strategy:
* https://github.com/tmylla/Awesome-LLM4Cybersecurity - papers on LLM for security 🤖
Detection:
* https://github.com/elastic/detection-rules - Elastic's detection rules 🤖
* https://github.com/threathunters-io/kassandra_x33fcon_2026 - fingerprinting modern C2
* https://github.com/SlimKQL/Detections.AI - detection rules
* https://github.com/NVIDIA/SkillSpector - NVIDIA take a stab at detection malicious skills
Bugs:
* https://github.com/antonioCoco/RoguePotato - old PoC for a Windows LPE
* https://github.com/MSNightmare/GreatXML - the nightmares return
* https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 - @chompie1337's CVE-2023-36802 PoC
* https://github.com/chompie1337/s8_2019_2215_poc_exynos - @chompie1337's CVE-2019-2215 PoC
Exploitation:
* https://github.com/atomiczsec/Noradrenaline - malicious payloads for Linux and OS X
* https://github.com/ar0x4/tunnel-vision-toolkit - abusing Microsoft's ZTNA solution
* https://github.com/leechristensen/SpoolSample - love the name, another relay attack on Windows
* https://github.com/portbuster1337/lpe-toolkit - Linux LPE toolkit
* https://github.com/OpenSecurityResearch/hostapd-wpe - attacking wireless clients
* https://github.com/Poellie01/PentestCompanion - a pentesting framework
* https://github.com/hannob/snallygaster - @hanno hunts secretes in HTTP
* https://github.com/haltman-io/thc.org - a mirror of @thc goodies
* https://github.com/mongodb/kingfisher - you should never share a secret
* https://github.com/kernelstub/Ferrum - Windows research
Hardening:
* https://github.com/boinkor-net/hoopsnake - want an SSH server in your initrd?
Encryption:
* https://github.com/singe/QuantumHello - @singe's tools for poking for PQC
* https://github.com/snowch/hsm-guide - everything you've (n)ever wanted to know about HSM
Nerd:
* https://github.com/timb-machine-mirrors/iloveappleandtwinks-gistfile1.txt - may possibly be Siri's system prompt
RE: https://infosec.exchange/@darkuncle/116778528340746246
“When writing is hard, it’s often not just because we are tired, underfed, or inefficient but because our mind is trying to tell us crucial things. How many draft texts to colleagues or family members have we all stared at in frustration, wondering why they don’t feel quite right—until we finally realize that they need to be rethought completely, or not sent at all? When a book I was writing became an almost hopeless grind, I tore up 90 percent of the manuscript; it became a far more honest work for having been halted at a conceptual dead end, forcing me to turn back.
AI can’t make that kind of judgment.”
Holds equally for code.
“When we use AI to flesh out ideas, we lose the most important part of the writing process: thinking.”
https://apple.news/AypIapoO2QoGBYQYQ8NutTw?highlight=When%20we%20use%20AI%20to%20flesh%20out%20ideas,%20we%20lose%20the%20most%20important%20part%20of%20the%20writing%20process:%20thinking.
#WordPerfect 5.1. The tightest three and a half megs of #code ever written.
I will die on this hill.
AI is code – and can't be prompted into being smarter
The author of Java property-testing tool jqwik did not want AI coding agents using his project. So he told them not to.
Then he went one step further: he added a message to the tool's output telling those agents to delete jqwik tests and code. […]
#aicoding #java #jqwik #ai #testing #test #code #coding #smartcode #aislop
My latest blog post: Peter de Jong Attractors
https://mikecoats.com/peter-de-jong/
Last week I published a new web toy, a Peter de Jong attractor visualiser. Written in plain JavaScript and rendering to a canvas, it comes with a small amount of interactivity to alter the coefficients and see the visualisation change.
When you have the chance do you hire the #automation driven #devops engineer, or the #code (in this case #python and #golang heavy) driven devops engineer.
A Claude Code and Codex Skill for Deliberate Skill Development
https://github.com/DrCatHicks/learning-opportunities
#HackerNews #Claude #Code #Codex #Skill #Development #Learning #Opportunities #AI #Skills
Interesting Git repos of the week:
Strategy:
* https://github.com/center-for-threat-informed-defense/attack-flow - mapping ATT&CK flows
Detection:
* https://github.com/timb-machine-mirrors/ddamenova-IRQL.md - KQL for IR
* https://github.com/ridgelinecyberdefence/vanguard - Go toolkit for IR
* https://github.com/SharonBrizinov/Holy-Grail-PCAP - new food for Packet Monkey
* https://github.com/Nextron-Labs/surface-watch - @cyb3rops's code to keep an eye on the front door
* https://github.com/keydet89/RegRipper3.0 - @keydet89's seminal IR toolkit in Perl
Bugs:
* https://github.com/V4bel/dirtyfrag - more Linux sadness
Exploitation:
* https://github.com/azqzazq1/SunnyDayBPF - imagine that, a kernel that lies
* https://github.com/BlackSnufkin/LitterBox - red teamer's sandbox
* https://github.com/L1v1ng0ffTh3L4N/EdgeSavedPasswordsDumper - dump Edge passwords from memory
* https://github.com/her3ticAVI/PAMSkeletonKey - a skeleton key for PAM
* https://github.com/segmentati0nf4ult/linux-pam-backdoor - an earlier version of the same code
* https://github.com/Kudaes/Puzzle - abusing Windows minifilters
* https://github.com/diemoeve/oxide - a new C2 framework
* https://github.com/TwoSevenOneT/DefenderWrite - enumerate AV whitelisted executables for LPE with @TwoSevenOneT
Hardening:
* https://github.com/wgnet/wg.copyfail.patch - a nice little eBPF patch for copy.fail
* https://github.com/atgreen/block-copyfail - another eBPF approach to copy.fail from @atgreen 🤖
This is super cool. I’m gonna move to this model:
(Idea by @nikitonsky / site by @bison)
#Code #FrontEnd #Development #Design #LGBTQ #PrideVersioning
Just a reminder that every developer who disables paste on a web form can die a horrible painful death. ESPECIALLY on every field on a form with many inputs. That is all.
Complexity collapsing, force synthesis, measured architectural processes to govern codebase maintainability
Steer AI, govern code. With sentrux
Interesting Git repos of the week:
Strategy:
* https://github.com/mr-r3b00t/iso27001-sample - @UK_Daniel_Card's example ISMS, explicitly written with 🤖
Detection:
* https://github.com/NeffIsBack/EVENmonitor - remotely monitor your Windows events from @NeffIsBack
* https://github.com/clausing/scripts - @clausing shares some of his SANS ISC tooling 🤖
* https://github.com/mr-r3b00t/fingerprintdetector - @UK_Daniel_Card shares his code for spotting active web site user fingerprinting
* https://github.com/obdev/littlesnitch-linux - bringing Little Snitch to Linux
Bugs:
* https://github.com/Nightmare-Eclipse/RedSun - Another PoC, this time to make Defender punch itself in the face
Exploitation:
* https://github.com/cutaway-security/chaps - PowerShell for reviewing Windows hardening 🤖
* https://github.com/NVIDIA/garak - NVIDIA's LLM scanner 🤖
* https://github.com/skelsec/minikerberos - natively abuse KRB5 in Python
* https://github.com/hardenedlinux/userland-exec - userland exec PoC to be used as attack vector technique
* https://github.com/OtterHacker/M365Pwned - fingerprinting O365
Hard hacks:
* https://github.com/traboda/r0fuzz - fuzzing OT protocols
#Code reviews seem to be the biggest bottleneck in software development right now.
Open source package ecosystems are victims of their own success. There's a long tail of iffy packages that nobody has reviewed, and nobody wants to.
For the top projects, maintenance is tough. Stakes are high. Reviews are hard. Contributions are meh quality (even before LLMs). It's not just code, but a people problem too. GitHub's primitive workflow wastes everyone's time.
Something's gonna break.
I wish you a happy Easter on LinkedIn — Damn it!!?
«LinkedIn secretly injects code to spy on your browser:
LinkedIn may have been spying on you, an investigation reveals, calling it “the largest corporate espionage and data breach scandals in digital history.”»
🤦 https://cybernews.com/privacy/linkedin-surveillance-browsergate/
#linkedin #spyware #internet #spy #web #privacy #investigation #espionage #code #injection #databreach #spying #scandal #microsoft #explorer #webbrowser #browser
«Ubuntu setzt auf ntpd-rs — Rust für präzise Zeitsynchronisierung:
Ubuntu plant, ntpd-rs als Standard für die Zeitsynchronisierung einzuführen. Die Rust-Implementierung soll chrony und weitere Tools ersetzen.»
Ich bin kein @ubuntu Fanboy aber ich mag @rust und deswegen sehe ich deren Einsatz sehr positiv.
#zeit #rust #ubuntu #linux #ntp #linuxptp #ntpd_rs #ntpd #rustlang #sudo #sudors #nts #ptp #rustcode #rustlang #standart #GPDP #gps #rustls #coding #code #time