mkultra tournament edition

@amenbreakpoint.com

we're trapped in the belly of this horrible machine, and right now you can get free shipping with code "DEADFLAG" site: amenbreakpoint.com signal: abp.01

Lookin at an (old?) unsecured bucket for a "NSFW AI Character" chat app and this shit is GROSS. Generated characters from real people, way too much stable diffusion Emma Watson, etc. And why the fuck are dudes sending dick pics to a chatbot? Thousands of weird dude dicks wtf.

> ... a cinematic search for an elusive group - CLODO - that bombed computer companies in 1980s Toulouse, France. Journeying through the cybernetic nodes of military, industrial, and socialist development, the film exposes how recording devices fail to collect the ashes of history.

Machines in Flames [Full Documentary]

Machines in Flames (2022, 50min) finds a secret history of self-destruction by following the footsteps of a clandestine group of French computer workers from the 1980s. Machines in Flames presents a ...

vimeo.com

Apparently my 2009 app store 99c goldrush slop app got linked in Wired back in the day. If I remember correctly I didn't renew my dev license and it got delisted a few months later. Still, time to add "featured in wired" to my CV.

iPhone App Turns Your Smile Upside Down

If you�re a staunch pessimist like me, people who seem to always be walking on sunshine weird you out. Fortunately, a new iPhone application called Daily Downer should drag those bright-eyed Pollyanna...

web.archive.org

Reached out to (politely) ask a vibe-coded app to stop scraping my data; too aggressive, no caching, repeated expensive queries. Got back a very apologetic email that was an LLM'ed "you're absolutely right" response. I mean, I'm glad they knocked it off but an all-bot interaction is just a bummer.

A critical security issue I've been trying to report to SpankMatch/SpankChain since Dec 2023 has finally been addressed. This post details that, plus the shitshow the waning days of GCR were. Quote GCP: "The product team has currently not expressed interest in proactively reaching out to users."

SpankMatch, Secrets, and (Everyone's!) Orphaned Google Container Registry Layers

In which Google moves the headstones and leaves the bodies.

amenbreakpoint.com

Missed this when it came out, good shit. At this point I don't think it's controversial that Firebase should be "considered dangerous" in the slop era (and in the past) but it's just going to get worse and have a super long tail. I'd complain about Goog's response, but meh, Always Has Been.

Firewreck 2.0

Out of the top 1.5 Million Android apps on the Play Store, 11,126 were insecure and exposed users' PII. In total these 11 thousand apps exposed 1.43 Billion user records.

mrbruh.com

I've reported like 10 leaked PATs from packages to their owners in the last couple of weeks and it's kinda bs this issue (from 2022!) is open has been added & removed from the GitHub Public Roadmap 3 times. imo any PAT's a disaster waiting to happen, call that shit "Chekhov's Token (classic)".

Packages support for fine-grained PATs · Issue #558 · github/roadmap

Summary Personal Access Tokens, or PATs, provide users a quick way to create tokens they can use to make API calls. The tokens allow users to specify scopes to determine what the token can access. ...

github.com