@gabrielesvelto @hsivonen yep this is still largely subsidized by cheap inference and essentially free training (for the consumer). I don’t bet on it staying this cheap.
freddy@social.security.plumbing
Posts
-
I’m seeing a lot of denial and logical fallacies on Mastodon about LLM capability to find security bugs. -
I’m seeing a lot of denial and logical fallacies on Mastodon about LLM capability to find security bugs.@gabrielesvelto @hsivonen not really. Some bugs are truly hard to find with fuzzing and are more easily identified by seeing codesmell and trying to trace it back to user. Reading and remembering code is limited by brain power / will power. As sad as it is: LLMs scale better here.
-
aah, the reason why the in-app kindle purchase flow in german has a button labeled "Bitte lesen" (which translates to "Please read") for opening the purchased ebook is that someone mistranslated "Read now" as if it was meant in imperative form?@jann I got into a (mild) argument multiple times with our localizers and gave up. I disagree with them but I also don’t have to live with the feedback they get elsewhere. Firefox in English it is…

-
@gaz Have you seen this?@gaz not CSS-only as I originally thought. But still pretty cool. I think doing THIS and then going CSS-only is the next frontier

-
@gaz Have you seen this?@gaz Have you seen this? You must see this
https://front-end.social/@html5test/116301798349200500 first response also contains link to how he built it -
Last year, my position was that we still had time to design PQ authentication mechanisms.@filippo I like their aggressive timeline, but I'm not sure there's any specific argument or reason that explains why it should be expedited. Am I missing something?
-
Rooting OpenWRT from the parking lot: I discovered an XSS in the OpenWRT SSID scan page, that can be chained to remote root access 👾Write-up and demo: https://mxsasha.eu/posts/openwrt-ssid-xss-to-root/CVE-2026-32721, fixed in 24.10.6 / 25.12.1 -
Firefox oder Brave?@kuketzblog Danke für die Empfehlung
