Lookin at an (old?) unsecured bucket for a "NSFW AI Character" chat app and this shit is GROSS. Generated characters from real people, way too much stable diffusion Emma Watson, etc. And why the fuck are dudes sending dick pics to a chatbot? Thousands of weird dude dicks wtf.
mkultra tournament edition
@amenbreakpoint.com
we're trapped in the belly of this horrible machine, and right now you can get free shipping with code "DEADFLAG" site: amenbreakpoint.com signal: abp.01
so if I jump in it'll just kick me out the other side? neat.
> ... a cinematic search for an elusive group - CLODO - that bombed computer companies in 1980s Toulouse, France. Journeying through the cybernetic nodes of military, industrial, and socialist development, the film exposes how recording devices fail to collect the ashes of history.
Machines in Flames [Full Documentary]
Machines in Flames (2022, 50min) finds a secret history of self-destruction by following the footsteps of a clandestine group of French computer workers from the 1980s. Machines in Flames presents a ...
vimeo.com
Cool thrift store find today. I know it's Nortel, but I heard it so much f'ing with them locally bitd that "Meridian Mail. Mailbox?" is permanently etched in my brain. I also want to build an Ithaca version of Telehamster (telehamster.net) but am also scared of picking up phones.
Apparently my 2009 app store 99c goldrush slop app got linked in Wired back in the day. If I remember correctly I didn't renew my dev license and it got delisted a few months later. Still, time to add "featured in wired" to my CV.
iPhone App Turns Your Smile Upside Down
If you�re a staunch pessimist like me, people who seem to always be walking on sunshine weird you out. Fortunately, a new iPhone application called Daily Downer should drag those bright-eyed Pollyanna...
web.archive.org
Not going to DC this year (boo.) but I wanna flog the cool badge co-worker bud is bringing to @defcon.bsky.social this year for badgelife peeps to get sweaty over. www.instagram.com/reels/DZVt7t...
Elliot Pfarr on Instagram: "Cult of Cthulhu, Indie Def Con 34 Badge! After 10 years of consuming #badgelife, I’ve created my first indie badge, Cult of Cthulhu. Cult of Cthulhu is a BLE based RPG s...
49 likes, 18 comments - elliotpfarr on June 8, 2026: "Cult of Cthulhu, Indie Def Con 34 Badge! After 10 years of consuming #badgelife, I’ve created my first indie badge, Cult of Cthulhu. Cult of Ct...
instagram.com
Reached out to (politely) ask a vibe-coded app to stop scraping my data; too aggressive, no caching, repeated expensive queries. Got back a very apologetic email that was an LLM'ed "you're absolutely right" response. I mean, I'm glad they knocked it off but an all-bot interaction is just a bummer.
correction, also the parade. gotta carrot this year too.
the book sale is Ithaca's only recognized civic holiday
"My Dinner With Andre" (coworker pointed out my shirt situation halfway into the day)
the book sale is Ithaca's only recognized civic holiday
A critical security issue I've been trying to report to SpankMatch/SpankChain since Dec 2023 has finally been addressed. This post details that, plus the shitshow the waning days of GCR were. Quote GCP: "The product team has currently not expressed interest in proactively reaching out to users."
SpankMatch, Secrets, and (Everyone's!) Orphaned Google Container Registry Layers
In which Google moves the headstones and leaves the bodies.
amenbreakpoint.com
Firebase should require a written aptitude test at this point, jesus.
At least three different people notified the popular app that wants to help men stop watching porn that it was jeopardizing user data.
"Because everyone else lowered the bar, we decided to join them" is so on-brand...
I've still not heard back from anyone. It's is an issue that's survived the shutdown of SpankMatch and I've sent emails about since _Dec 2023_. Root cause is in the email & I'd be happy to answer any Qs. I'd normally do this over email but bsky is the only response I've had. @spankchain.bsky.social
Ok great we’ll take a look and get back to you!
Missed this when it came out, good shit. At this point I don't think it's controversial that Firebase should be "considered dangerous" in the slop era (and in the past) but it's just going to get worse and have a super long tail. I'd complain about Goog's response, but meh, Always Has Been.
Firewreck 2.0
Out of the top 1.5 Million Android apps on the Play Store, 11,126 were insecure and exposed users' PII. In total these 11 thousand apps exposed 1.43 Billion user records.
mrbruh.com
Pre-order arrived, finally got a chance to listen. Holy hell.
Autechre Guitar, by Shane Parish
10 track album
shaneparish.bandcamp.com
I WARNED YOU ABOUT [GitHub PATs (classic)] BRO !!!! I TOLD YOU DOG! [2025-12-17] amenbreakpoint - Reported information disclosure in a GOV.UK service [2025-12-10] amenbreakpoint - Reported information disclosure in a GOV.UK service
vdp.cabinetoffice.gov.uk
I've reported like 10 leaked PATs from packages to their owners in the last couple of weeks and it's kinda bs this issue (from 2022!) is open has been added & removed from the GitHub Public Roadmap 3 times. imo any PAT's a disaster waiting to happen, call that shit "Chekhov's Token (classic)".
Smells like GCP's "allAuthenticatedUsers" principal footgun...
The AI-chat-enabled stuffed toy Bondu invites little kids to have intimate conversations with it, like an LLM imaginary friend. It also exposed virtually all their chats on a web interface with no security. Anyone with a Gmail account could log in and read transcripts. www.wired.com/story/an-ai-...
At this point I believe I've received a copyright claim from every member of KISS except Peter Criss. Working on it.
We stand with our colleagues and fellow members in full solidarity - this unfair and illegal arrest is an affront to a free press. ✊💔
On Friday, January 9, ICE arrested a member of our union, the Minnesota Newspaper and Communications Guild, as part of Operation Metro Surge. He has been transferred to a detention facility in Texas, where he is awaiting action on his petition for habeas corpus. newsguild.org/guild-member...
Make sure to do the good shit on Signal, not here.
NLG Know Your Rights reminder: Shut the f*** up!
YouTube video by National Lawyers Guild, Detroit & MI
youtube.com
Gonna flog this dead horse since this mirrors my experience with GCR and other registries: BUILD CONTEXT LEAKS ARE EVERYWHERE (and OCI images are the absolute worst offenders). You're probably doing it _right now_.
Security firm Flare has scanned the Docker Hub portal and found secrets and tokens, including for production systems, in more than 10,000 images flare.io/learn/resour...
had a nyquil dream that was just my brain trying to workshop bootleg shirt mashups of ikiru and akira. all bart ska-mpson level disasters.
I've reported like 10 leaked PATs from packages to their owners in the last couple of weeks and it's kinda bs this issue (from 2022!) is open has been added & removed from the GitHub Public Roadmap 3 times. imo any PAT's a disaster waiting to happen, call that shit "Chekhov's Token (classic)".
Packages support for fine-grained PATs · Issue #558 · github/roadmap
Summary Personal Access Tokens, or PATs, provide users a quick way to create tokens they can use to make API calls. The tokens allow users to specify scopes to determine what the token can access. ...
github.com
"Yesterday’s flexibility has become today’s insurmountable technical debt." Put it on my tombstone.
🚨☸️🚨