kiding πŸ§‘β€πŸ’»'s Avatar

kiding πŸ§‘β€πŸ’»

@kiding.bsky.social

Dongsung "Donny" Kim make break software πŸ“£ IT-Security Expert / DEF CON Speaker 🏒 Security Office πŸŽ™ kiding 🏠 https://kidi.ng

179 Followers  |  81 Following  |  310 Posts  |  Joined: 01.05.2023
Posts Following

Posts by kiding πŸ§‘β€πŸ’» (@kiding.bsky.social)

Preview
Help us test WEBCAT alpha Web applications are only as trustworthy as the servers that serve them, and servers can get hacked. So, last year, we introduced WEBCAT (Web-Based Code Assurance and Transparency), a project designed...

Web applications are only as trustworthy as their servers, and servers can get hacked. That’s why we are introducing WEBCAT, which lets web browsers verify the origin of code before it runs.

🌞 Today, WEBCAT enters alpha testing! If you like to experiment with cutting-edge software, give it a try:

03.03.2026 18:48 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 1
Indie World 2026.3.3
YouTube video by ν•œκ΅­λ‹Œν…λ„ 곡식 채널 Indie World 2026.3.3

개발자 인터뷰 2:15

03.03.2026 15:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

ν•œκ΅­ κ²Œμž„ 개발 μŠ€νŠœλ””μ˜€ λ“œλ¦Όλͺ¨μ…˜μ΄ μ œμž‘ν•œ "마이 리틀 퍼피"κ°€ 3μ›” 3일 λ‹Œν…λ„ 인디 μ›”λ“œμ—μ„œ μ†Œκ°œλ˜μ—ˆμŠ΅λ‹ˆλ‹€.

03.03.2026 15:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

였... μ§„μ§œ λ‚˜μ°Œλ‚˜ ν•  μ†Œλ¦¬λ₯Ό

03.03.2026 13:15 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Forced to choose between "Oops, I was being evil" and "Oops, I was being stupid," Sam Altman has gone with "stupid."

03.03.2026 04:19 β€” πŸ‘ 204    πŸ” 36    πŸ’¬ 9    πŸ“Œ 0

if you’re cis and you don’t get it this is LITERAL TORTURE

it will result in dead trans people

and with their other goal of making us β€œsexually explicit” for existing

you see the pipeline right?

we exist -> we’re jailed for it -> we’re tortured and die

WE NEED YOU TO STOP THIS

02.03.2026 03:34 β€” πŸ‘ 5165    πŸ” 3287    πŸ’¬ 6    πŸ“Œ 33
Preview
Hacktivists claim to have hacked Homeland Security to release ICE contract data | TechCrunch A hacking group called Department of Peace said they hacked a specific office within Homeland Security to protest ICE’s mass deportation campaign, and the companies aiding it.

NEW: A group of hacktivists calling themselves "Department of Peace" claims to have hacked an office wihin the Department of Homeland Security.

The hacktivists leaked data on more than 6,000 contracts between DHS/ICE and private companies to the transparency website Distributed Denial of Secrets.

02.03.2026 16:17 β€” πŸ‘ 43    πŸ” 23    πŸ’¬ 1    πŸ“Œ 2

they will tell you that they need to do regime change iran to liberate the women, and while you docilely repeat their propaganda they will bomb a girls school in broad daylight and laugh at how much contempt they have for you for buying their lies

28.02.2026 14:15 β€” πŸ‘ 141    πŸ” 42    πŸ’¬ 0    πŸ“Œ 0

The first deaths announced from the US-Israeli strikes on Iran: dozens of school girls. They hit an elementary school in Hormozgan.

28.02.2026 11:35 β€” πŸ‘ 3755    πŸ” 1617    πŸ’¬ 63    πŸ“Œ 169

직μž₯인이고 λ™λ£Œκ°€ μžˆλŠ” "λŒ€λ‹€μˆ˜"μ—κ²ŒλŠ” 이미 μ›¬λ§Œν•œ κ²€μ§„κΈ°κ΄€μ—μ„œ 돈 더 λ°›κ³  λŒ€μž₯λ‚΄μ‹œκ²½ ν•˜κ³  μžˆλ‹€λŠ” 정보 μ •λ„λŠ” 기본값인데, 그런 ν™˜κ²½μ΄ μ•„λ‹Œ 삢을 μ‚¬λŠ” μ‚¬λžŒλ“€μ—κ²ŒλŠ” μ΄μƒν•˜κ²Œ 느껴질 μˆ˜λ„ μžˆκ² λ‹€λŠ” 생각이 λ“€κΈ°λŠ” ν•œλ‹€. λ†“μΉ˜λŠ” 것 없이 보편적인 μ‚¬λžŒμ—κ²Œ 꼼꼼히 정보λ₯Ό μ „λ‹¬ν•˜κ³  μ„€λͺ…ν•˜λŠ” 것이 μ–Έλ‘ μ˜ μ—­ν• μ΄κ² μœΌλ‚˜ ν•œκ΅­ 언둠은 κ·Έ μ±…μž„μ„ μ™„μ „νžˆ 놓아버린지 였래. 클릭질 μž₯μ‚¬λ§Œμ„ μœ„ν•΄ 클릭베이트 ν—€λ“œλΌμΈμ„ 뽑아내고 숏폼마λƒ₯ μŠ€μ³μ§€λ‚˜κ°€λ©° μ†ŒλΉ„λ˜λŠ” μ§€ν˜•μ—μ„œ λ―Έλ””μ–΄ λ¦¬ν„°λŸ¬μ‹œλ‹ˆ λ…μžκ°€ κ΅μ°¨κ²€μ¦ν•˜λΌ ν•΄μ„œ λ¬΄μ—‡ν•˜κ² λ‚˜. λΏŒλ¦¬λΆ€ν„° μ–Έλ‘ κ°œν˜μ΄ ν•„μš”ν•˜λ‹€.

28.02.2026 03:40 β€” πŸ‘ 6    πŸ” 19    πŸ’¬ 0    πŸ“Œ 0

μ„œμšΈκ²½μ œ ν—€λ“œλΌμΈμΈλ° ꡭ가건강검진을 ν•œλ²ˆμ΄λΌλ„ λ°›μ•„λ³Έ μ‚¬λžŒμ΄λΌλ©΄ 건강검진 ν•­λͺ© ν•˜λ‚˜ 더 μΆ”κ°€λ˜λŠ” 걸둜 μ΄ν•΄ν•˜μ§€λ§Œ, λ¬Έμž₯만 λ–Όμ„œ 읽으면 ꡉμž₯히 μ΄μƒν•˜κ²Œ 이해될 μˆ˜λ„ μžˆκ² λ‹€. λ‚΄μš©μ€ κ±΄κ°•κ²€μ§„μ‹œ κΈ°μ‘΄ 50μ„Έ 이상 λΆ„λ³€μž ν˜ˆκ²€μ‚¬ λŒ€μ‹  45μ„Έ 이상 10λ…„ μ£ΌκΈ° λŒ€μž₯λ‚΄μ‹œκ²½μœΌλ‘œ μ „ν™˜ν•œλ‹€λŠ” μ–˜κΈ°λΌ 의료(μ •ν™•νžˆλŠ” κ²€μ§„) μ‹œμŠ€ν…œμ— 뢀담될 것도 μ—†λ‹€. μ •μ±…λΈŒλ¦¬ν•‘ 곡식 μ›Œλ”©μ€ "ꢌ고"인데 μ„œμšΈκ²½μ œκ°€ 또 "κ²½μ œμ§€" ν•˜λ©΄μ„œ 무슨 λ³‘μ—­μ˜λ¬΄λ§ˆλƒ₯ κ°ˆκ²¨λ†¨κ³ . ꡭ가검진은 μ—¬λŸ¬κ°€μ§€ μ‚¬μœ λ‘œ λŒ€μƒμž μ œμ™Έμ‹ μ²­λ„ κ°€λŠ₯ν•˜λ‹ˆ 사싀 μ–΄λ–€ λ©΄μ—μ„œλ“  쒋은 변화인데 ν•œκ΅­ 언둠은 λ„λŒ€μ²΄.

28.02.2026 03:24 β€” πŸ‘ 12    πŸ” 43    πŸ’¬ 1    πŸ“Œ 0
Post image

Does any human being understand YouTube recommendation engine?

28.02.2026 03:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
This App Warns You if Someone Is Wearing Smart Glasses Nearby The creator of Nearby Glasses made the app after reading 404 Media's coverage of how people are using Meta's Ray-Bans smartglasses to film people without their knowledge or consent. β€œI consider it to ...

NEW: A hobbyist has created Nearby Glasses, an app that warns you if someone close by is wearing smart glasses. 404 Media spoke to the creator who said he was inspired by our coverage that uncovers how men are wearing Meta's Ray-Bans to covertly film massage parlor workers.

24.02.2026 15:48 β€” πŸ‘ 11740    πŸ” 5035    πŸ’¬ 148    πŸ“Œ 275
Reverse CAPTCHA: Evaluating LLM Susceptibility to Invisible Unicode Instruction Injection A systematic evaluation of five frontier models across two encoding schemes, four hint levels, and tool use ablation β€” 8,308 graded outputs with full statistical analysis

Reverse CAPTCHA: Evaluating LLM Susceptibility to Invisible Unicode Instruction Injection

26.02.2026 19:28 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Previously harmless Google API keys now expose Gemini AI data Google API keys for services like MapsΒ embedded in accessibleΒ client-side code could be used to authenticate to the Gemini AI assistant and access private data.

Google API keys for services like MapsΒ embedded in accessibleΒ client-side code could be used to authenticate to the Gemini AI assistant and access private data.

26.02.2026 15:55 β€” πŸ‘ 6    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0

We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others.

NDSS'26 paper: www.ndss-symposium.org/wp-content/u...
GitHub: github.com/vanhoefm/air...

26.02.2026 18:32 β€” πŸ‘ 15    πŸ” 8    πŸ’¬ 4    πŸ“Œ 0
Preview
LLMs killed the privacy star, we can't rewind, we've gone too far You'll find these days that there's no hiding place Add privacy to the list of potential casualties caused by the proliferation of AI, because researchers have found that large language models (LLMs) can be used to deanonymize internet users – even those who use pseudonyms – more efficiently than human sleuths.…

LLMs killed the privacy star, we can't rewind, we've gone too far

26.02.2026 00:17 β€” πŸ‘ 12    πŸ” 6    πŸ’¬ 2    πŸ“Œ 0
Preview
FBI agents visited my home about an article I wrote, and now I can't go to Mexico Mexico formally requested the FBI's help in seeking answers about one of my stories. Having federal agents on my doorstep sparked my own years-long effort to pry information out of the FBI to explain ...

In 2020, the FBI came to my house to try to ask me questions about a story I'd written. I declined.

For this.weekinsecurity.com, I wrote about the back-story of what happened that day and after, my outstanding questions, and why press freedoms have taken a major step back under Trump's second term.

25.02.2026 13:57 β€” πŸ‘ 47    πŸ” 25    πŸ’¬ 3    πŸ“Œ 2

> 고양이 μ•Œλ ˆλ₯΄κΈ° μ‹¬ν•˜λ©΄ 뭐 μ–Όλ§ˆλ‚˜ μ‹¬ν•˜λ‹€κ³ .
μ €λ₯Ό ν˜„μ‹€μ—μ„œ 보신 뢄은 μ•„μ‹œκ² μ§€λ§Œ μ‚Άμ˜ 질 좔락이 ꡉμž₯ν•˜μ£ . μœ„μ—μ„œ μ–ΈκΈ‰ν•œ κ·Έ λ™λ£ŒλŠ” 고양이 μƒ€μ›Œμ‹œμΌœ μ£Όλ‹€κ°€ μ•„λ‚˜ν•„λ½μ‹œμŠ€κ°€ λ‘λ²ˆ 정도 μ™€μ„œ μ‹€λ €κ°”μ—ˆμŠ΅λ‹ˆλ‹€. ν˜„μž¬λŠ” 비염이 μ²œμ‹μœΌλ‘œ λ°œμ „ν•΄μ„œ μŠ€ν…Œλ‘œμ΄λ“œ ν‘μž…κΈ° λ“€κ³  λ‹€λ‹ˆκ³ .

25.02.2026 10:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

본인은 고양이···λ₯Ό μ§‘μ—μ„œ ν‚€μš°λŠ” νšŒμ‚¬ λ™λ£ŒΒ·Β·Β·κ°€ μ–΄μ œΒ·Β·Β·μ•‰μ•„ 있던 μ˜μžΒ·Β·Β·μ˜† μ˜μžμ— μ•‰λŠ” μ •λ„λ‘œλ„ μ•Œλ ˆλ₯΄κΈ°κ°€ μ‹¬ν•˜κ²Œ μ˜¬λΌμ™€μ„œ 이건 반기기 μ’€ μ–΄λ €μš΄ κ²°μ •. λ°˜λ €λ™λ¬Ό λ™λ°˜ μΆœμž…μ—…μ†Œ λΆ™μ–΄μžˆλŠ” 곳은 κ·Έλƒ₯ ν”Όν•˜λ©΄ 그만일 수 μžˆμ§€λ§Œ, λ‹€λ₯Έ 이유둜 κ°€κ³  μ‹Άμ—ˆλ˜ κ³³μ΄κ±°λ‚˜ λ‹€λ₯Έ 선택지가 μ—†λŠ” 곳이라면. λ°˜λ €λ™λ¬Ό 인ꡬ가 μ¦κ°€μΆ”μ„Έμ΄λ‹ˆ μ–΄λŠ 정도 이해가 λ˜μ§€ μ•ŠλŠ” 것은 μ•„λ‹ˆμ§€λ§Œ, λˆ„κ΅°κ°€λŠ” 컀피λ₯Ό λ§ˆμ‹œλŸ¬ κ°”λ‹€κ°€ μ΄μœ λ„ λͺ¨λ₯Έμ±„ ν•˜λ£¨μ΄ν‹€ μ£½μ–΄μžˆμ–΄μ•Ό ν•˜λŠ” 것인지. μ•„, 저도 고양이 정말 μ’‹μ•„ν•˜λŠ”λ°μš”...

25.02.2026 10:56 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

@atp.fm

25.02.2026 02:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

No mention in documents, no easy workaround, just an obscure Console message. A viable workaround is to abandon IOHID all together for CGEventTap. I'm not sure what the point of this is when 1) user explicitly allowed the app to grab keyboard inputs 2) OS disallows it *only* for internal keyboards?

25.02.2026 02:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Karabiner Elements stops working on internal keyboard on MacOS 26.4 beta 1 Β· Issue #4402 Β· pqrs-org/Karabiner-Elements It shows no errors, just stops working. Probably not a karabiner issue since it was working before, but I wanted to warn.

With macOS 26.4 beta, Apple silently introduced a "protection" for internal keyboards, breaking ALL keyboard-related applications making use of IOHID: Karabiner-Elements, Katana, and my own SokIM.

25.02.2026 00:47 β€” πŸ‘ 1    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Preview
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for web developers to sanitize untrusted…

The Sanitizer API landed in Firefox 148, along with element.setHTML().

This lets you fully configure how HTML strings are cleaned as they're parsed.

hacks.mozilla.org/2026/02/good...

24.02.2026 14:18 β€” πŸ‘ 203    πŸ” 58    πŸ’¬ 1    πŸ“Œ 14
Preview
Donald Trump’s β€˜Board of Peace’ explores stablecoin for Gaza Proposal to launch cryptocurrency pegged to US dollar comes after cash supply was decimated during Israeli offensive

Officials advising Donald Trump’s β€œBoard of Peace” are exploring a US dollar-backed crypto stablecoin for Gaza.

According to the Financial Times, this crypto concept is in an exploratory phase, but it could spell the rebuilding of Gaza being tied to a crypto experiment.

www.ft.com/content/cf4f...

23.02.2026 19:49 β€” πŸ‘ 167    πŸ” 67    πŸ’¬ 21    πŸ“Œ 20
Twitter: Last Week Tonight with John Oliver (HBO)
YouTube video by LastWeekTonight Twitter: Last Week Tonight with John Oliver (HBO)
23.02.2026 13:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Hackers Expose Age-Verification Software Powering Surveillance Web Three hacktivists tried to find a workaround to Discord’s age-verification software. Instead, they found its frontend exposed to the open internet.

Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning.

www.therage.co/persona-age-...

21.02.2026 23:40 β€” πŸ‘ 1228    πŸ” 606    πŸ’¬ 25    πŸ“Œ 58

i mean like so many people outside the US are forced to learn American English + politics + culture just for survival… the sentiment is understandable in my head yet sometimes not

21.02.2026 18:57 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0