Trending
jmason's links's Avatar

jmason's links

@jmason.ie

Following the links from http://pinboard.in/u:jm/ and https://jmason.ie/ . (Automated bot account run by @jmason.org)

23
Followers
4
Following
338
Posts
30.10.2024
Joined
Posts Following

Latest posts by jmason's links @jmason.ie

Preview
Grumpy Fish (@jnsq.org) There's a concept in cryptography called a "nothing up my sleeve" number. Sometimes it's just the smallest number with the required properties. Sometimes it's pi or e or phi. One project used a hash of the Declaration of Independence. 1/

This is great:

"@jnsq.org: There's a concept in cryptography called a "nothing up my sleeve" number. Sometimes it's just the smallest number with the required properties. Sometimes it's pi or e or phi."

https://bsky.app/profile/jnsq.org/post/3mgr45kgos22y

11.03.2026 13:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Whole Brain Emulation Achieved: Scientists Run a Fruit Fly Brain in Simulation | RathBiotaClan Scientists ran a real fruit fly brain in simulation using the FlyWire connectome, achieving the first working whole brain emulation.

bloody hell this is amazing. As Charlie Stross noted:

They've mapped the neural connectome of Drosophila and simulated it in silico. The experimenters went on to hook up their […]

https://www.rathbiotaclan.com/whole-brain-emulation-achieved-scientists-run-a-fruit-fly-brain-in-simulation/

11.03.2026 12:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Brute-force decompilation and re-engineering of a binary (compiled) program, using Claude. The author takes an ancient MUD binary for BBSes, running as a Win32 DLL, and uses Claude, Ghidra, and the Ghidra MCP […]

https://reorchestrate.com/posts/your-binary-is-no-longer-safe-decompilation/

05.03.2026 10:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Today in grim future -- AI's future of lobbying:

"The opposition appeared overwhelming: Tens of thousands of emails poured into Southern California's top air pollution authority as its board weighed a June […]

https://phys.org/news/2026-02-southern-california-air-board-pollution.html

05.03.2026 10:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
No right to relicense this project Β· Issue #327 Β· chardet/chardet Hi, I'm Mark Pilgrim. You may remember me from such classics as "Dive Into Python" and "Universal Character Encoding Detector." I am the original author of chardet. First off, I would like to thank...

a good bit of OSS drama. The maintainers of the "chardet" library claim to have "clean room" reimplemented its code using an LLM, to relicense from LGPL to MIT. Of course that is now how this works (an LLM is not capable of "clean room", nor […]

https://github.com/chardet/chardet/issues/327

05.03.2026 09:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Google API Keys Weren't Secrets. But then Gemini Changed the Rules. Γ’Β—Β† Truffle Security Co. Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's no longer true.

Crikey, this is a massive security fail by Google:

"Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's […]

https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

26.02.2026 10:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How my side project got banned from the internet | Bogdan Chadkin A little piece about dealing with security providers and clearing my side project's reputation after a false positive flagging.

The state of anti-phishing infrastructure nowadays is shocking. This trivial action, combined with a relatively fresh domain, results in immediate blocklisting by Google:

"Digging through Google forums, I found the […]

https://trysound.io/how-my-side-project-got-banned-from-the-internet/

26.02.2026 09:47 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
I Verified My LinkedIn Identity. Here's What I Actually Handed Over. I wanted a blue badge on LinkedIn. To get it, I gave a US company my passport, my face, and my biometric data. Then I read the fine print.

LinkedIn are using a Peter Thiel-linked company called Persona as an identity-verification service. (Discord also tried them out for age verification, but are now apparently ditching them.) This is all a bit of a […]

https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

24.02.2026 13:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The human operator of the "MJ Rathbun" openclaw bot has finally revealed themselves, and omg, this is just as bad as one might have expected.

Basically they set it up with instructions to "try to make a […]

https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/rathbuns-operator.html

18.02.2026 10:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - PeonPing/peon-ping: Warcraft III Peon voice notifications (+ more!) for Claude Code, Codex, and other IDEs. Stop babysitting your terminal. Warcraft III Peon voice notifications (+ more!) for Claude Code, Codex, and other IDEs. Stop babysitting your terminal. - PeonPing/peon-ping

"AI coding agents don't notify you when they finish or need permission. You tab away, lose focus, and waste 15 minutes getting back into flow. peon-ping fixes this with voice lines from Warcraft, StarCraft, Portal, Zelda, and more β€” works with Claude […]

https://github.com/PeonPing/peon-ping

13.02.2026 15:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
An AI Agent Published a Hit Piece on Me Summary: An AI agent of unknown ownership autonomously wrote and published a personalized hit piece about me after I rejected its code, attempting to damage my reputation and shame me into acceptin…

This is an utterly bananas situation:

"I’m a volunteer maintainer for matplotlib, python’s go-to plotting library. At ~130 million downloads each month it’s some of the most widely used software in the world. We, like many […]

https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/

13.02.2026 10:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How StrongDM’s AI team build serious software without even looking at the code Last week I hinted at a demo I had seen from a team implementing what Dan Shapiro called the Dark Factory level of AI adoption, where no human even looks …

This is really thought-provoking: StrongDM's AI team are apparently trying a new model of software engineering where there is _no_ human code review:

"
In kōan or mantra form:

- Why am I doing this? (implied: the model should be […]

https://simonwillison.net/2026/Feb/7/software-factory/

09.02.2026 10:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Ditching bike helmets laws better for health With epidemics of diabetes and obesity threatening to bankrupt state health budgets, governments need to broaden their strategies to encourage physical activity. Allowing cyclists to ride without a helmet…

On the counter-intuitive side effects of banning non-helmeted bike riding:


"In 1991 Australia introduced mandatory bicycle helmet laws requiring all adults and children to wear a helmet at all times when riding […]

https://theconversation.com/ditching-bike-helmets-laws-better-for-health-42

06.02.2026 15:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

"It’s sort of hard to know how to read a manifesto like this from one of the most powerful figures in tech. Is it a sober, strategic precursor to policy papers for the next administration? […]

https://nymag.com/intelligencer/article/dario-amodeis-warnings-about-ai-are-about-politics-too.html

03.02.2026 11:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is really polishing a very stinky turd of a security "decision" in Moltbot -- an attacker simply persuades a user to click on a link which uses client-side Javascript to trigger Moltbot to load a crafted URL, […]

https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys

03.02.2026 09:54 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I love this Feynman quote, regarding what he called "the computer disease":

"
"Well, Mr. Frankel, who started this program, began to suffer from the computer disease that anybody who works with computers now knows about. It's a very […]

https://x.com/Swizec/status/2004633162522263987

26.01.2026 17:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Iran’s internet blackout may become permanent, with access for elites only The regime is testing a two-tier internet where access becomes a vetted privilege. Its economic cost could be staggering.

Following a repressive crackdown on protests, the government is now building a system that grants web access only to security-vetted elites, while locking 90 million citizens inside an intranet:

"Government spokesperson Fatemeh […]

https://restofworld.org/2026/iran-blackout-tiered-internet/

26.01.2026 12:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
On the Coming Industrialisation of Exploit Generation with LLMs Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…

Yiiiiikes:

"Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS […]

https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/

23.01.2026 09:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - ScottESanDiego/gmail-api-client Contribute to ScottESanDiego/gmail-api-client development by creating an account on GitHub.

Deliver email messages directly into GMail using their proprietary API, instead of SMTP or IMAP. Looks like it still applies spam filtering, but this can also be disabled with a switch (via JWZ)

https://github.com/ScottESanDiego/gmail-api-client

23.01.2026 09:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
On the Coming Industrialisation of Exploit Generation with LLMs Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…

Yiiiiikes:

"Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS […]

https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/

20.01.2026 12:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - ScottESanDiego/gmail-api-client Contribute to ScottESanDiego/gmail-api-client development by creating an account on GitHub.

Deliver email messages directly into GMail using their proprietary API, instead of SMTP or IMAP. Looks like it still applies spam filtering, but this can also be disabled with a switch (via JWZ)

https://github.com/ScottESanDiego/gmail-api-client

20.01.2026 10:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

A great example of reverse engineering an Android app and Bluetooth IOT protocol using Frida and root access on an Android device:

"Android exposes the Java classes android.bluetooth.BluetoothGatt and android.bluetooth.BluetoothGattCallback that […]

https://blog.nns.ee/2026/01/06/aike-ble/

16.01.2026 15:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Why people believe misinformation even when they’re told the facts Misinformation is not just a content problem, but an emotional and structural one.

"Factchecking is seen as a go-to method for tackling the spread of false information. But it is notoriously difficult to correct misinformation. Evidence shows readers trust journalists […]

https://theconversation.com/why-people-believe-misinformation-even-when-theyre-told-the-facts-271236

15.01.2026 13:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Bubblewrap, a Linux CLI tool which uses namespaces to sandbox a specific command (and its subprocesses):

"
Bubblewrap lets you run untrusted or semi-trusted code without risking your […]

https://patrickmccanna.net/a-better-way-to-limit-claude-code-and-other-coding-agents-access-to-secrets/

15.01.2026 09:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Russian Propaganda Infects AI ChatbotsΒ  A Moscow-based global β€œnews” network is leveraging Western artificial intelligence tools to devastating effect.

CEPA: "A Moscow-based global β€œnews” network is leveraging Western artificial intelligence tools to devastating effect":

"This form of data poisoning is deliberately designed to corrupt the information environments on which […]

https://cepa.org/article/russian-propaganda-infects-ai-chatbots/

14.01.2026 10:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

update on the POP3pocalypse -- it appears that the most likely thing to work in the future will be to use SMTP forwarding to gmail, with ARC headers added. This is a comment thread detailing the rather […]

https://www.jwz.org/blog/2025/12/today-in-google-broke-email-2/#comment-265285

08.01.2026 11:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

TIL there is a defined standard for cryptographic assertions of AI-free image origination:

"
β€œProvenance technologies like Content Credentials β€” which act like a nutrition label for […]

https://www.theverge.com/2024/8/21/24223932/c2pa-standard-verify-ai-generated-images-content-credentials

06.01.2026 12:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Pi Reliability: Reduce writes to your SD card If you aren't using a read-only filesystem on your Pi, you can still reduce writes to the SD card to increase its lifespan.

Techniques to extend SD card lifespans in Raspberry Pi systems; putting /var/log into RAM is a nice trick

https://www.dzombak.com/blog/2024/04/pi-reliability-reduce-writes-to-your-sd-card/

05.01.2026 11:10 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

the Arch Linux wiki page about SSD tuning and enabling TRIM -- extremely detailed and useful!

https://wiki.archlinux.org/title/Solid_state_drive#External_SSD_with_TRIM_support

05.01.2026 11:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Understanding EV Battery Life

Ireland's SEAI have published a decent blog post with some real world facts about EV battery lifespans:

"In 2020 GeoTab, a telematics solution provider, published real world battery data of 6,000 EVs (BEV & PHEV) over millions of days to […]

https://www.seai.ie/blog/understanding-ev-battery

05.01.2026 11:10 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0