πŸ’šπŸ§‘ π˜π˜’π˜€π˜’π˜’π˜―'s Avatar

πŸ’šπŸ§‘ π˜π˜’π˜€π˜’π˜’π˜―

@hackancuba.bsky.social

Linuxero, informΓ‘tico y algo mΓ‘s... Me gustan las impresoras :) | GPG 0x35710D312FDE468B | Matrix: @hackan:http://mozilla.org | Mastodon: @hackancuba@fosstodon.org

78 Followers  |  11 Following  |  10 Posts  |  Joined: 29.08.2023  |  2.2152

Latest posts by hackancuba.bsky.social on Bluesky


old.reddit.com/r/drawsteel/...

06.01.2026 23:42 β€” πŸ‘ 181    πŸ” 6    πŸ’¬ 5    πŸ“Œ 0

Today’s a big for MCDM! Thanks to everyone who made the Crack the Sun crowdfunding campaign a success! It’s gonna be magic! As of today, I’m no longer the Lead Designer of Draw Steel products, and I’m stepping into the role of Game Director of our next RPG, Crows. I can’t wait to play it with you.

05.01.2026 14:46 β€” πŸ‘ 519    πŸ” 31    πŸ’¬ 56    πŸ“Œ 4
Preview
RSA test vector crowdsourcing instructions

Do you have an idle cluster? Can you spare a couple core-years?

Help me bruteforce some test vectors for RSA key generation edge cases!

Here are the instructions, it's just a matter of running a single self-contained cross-compilable Go binary that will report the results autonomously.

04.01.2026 15:48 β€” πŸ‘ 111    πŸ” 33    πŸ’¬ 14    πŸ“Œ 3

The vibes are off (Cloudflare CEO’s corporate MAGAism), but they are right on the specific. Piracy Shield is a dangerous erosion of net neutrality and free speech principles, all just to protect Serie A (Italy’s premier football league).

10.01.2026 09:40 β€” πŸ‘ 87    πŸ” 10    πŸ’¬ 4    πŸ“Œ 1

I just vibecoded with exe.dev and Opus 4.5 a backoffice for our FIPS 140 validation, with a separate view for the lab (where they can also upload test vectors), public links for clients, and guided scripts for testing.

I have not looked at the code once. It works great.

I am... processing this.

02.01.2026 17:16 β€” πŸ‘ 67    πŸ” 10    πŸ’¬ 4    πŸ“Œ 0

If you are a resident of California, the state now has a portal where you can demand deletion of your personal data from 500+ registered data brokers with a single request form, for free.

consumer.drop.privacy.ca.gov

02.01.2026 02:26 β€” πŸ‘ 11745    πŸ” 5200    πŸ’¬ 276    πŸ“Œ 362
Preview
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age

Really big age release coming tomorrow! πŸŽ…πŸ»

- native post-quantum keys
- built-in recipients for hw plugins
- age-inspect tool
- plugin framework
- batchpass plugin
- many improved error messages

24.12.2025 12:02 β€” πŸ‘ 118    πŸ” 23    πŸ’¬ 0    πŸ“Œ 0
Preview
Building a Transparent Keyserver We apply a transparency log to a centralized keyserver step-by-step, in less than 500 lines, with privacy protections, anti-poisoning, and witness cosigning.

Using an age keyserver as a demo, this article demonstrates how to add a transparency log to a centralized service step-by-step.

We use Tessera for the tlog, VRFs for privacy, and the Witness Network. It all takes just 500 lines to integrate!

The result of years of work making tlogs accessible.

19.12.2025 15:32 β€” πŸ‘ 62    πŸ” 17    πŸ’¬ 2    πŸ“Œ 3
Preview
GitHub - geomys/ct-archive: A directory of archived Certificate Transparency (CT) logs and tools to archive RFC 6962 and Static CT logs. A directory of archived Certificate Transparency (CT) logs and tools to archive RFC 6962 and Static CT logs. - geomys/ct-archive

If you want to help seed the Certificate Transparency archive (github.com/geomys/ct-ar...), there is now an RSS feed for your BitTorrent client! Don't forget to set unlimited seed ratio ✨

raw.githubusercontent.com/geomys/ct-ar...

17.12.2025 18:59 β€” πŸ‘ 17    πŸ” 8    πŸ’¬ 1    πŸ“Œ 0

You know what? Keep posting tremendous art, and at some point we are gonna start demanding to fight this dude!!😁

18.12.2025 15:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Save 20% on Go Slimey Go! on Steam Help Slimey, our tiny slippery protagonist, visit his friends for some well deserved teatime after some thrilling platforming challenges!

Hey hey!
Go Slimey Go! is now out!!
Muy cousin and his team worked super hard to bring this project to life.
Support Latin games πŸ˜ŽπŸ˜ƒ
store.steampowered.com/app/3215230/...
#GoSlimeyGo

12.12.2025 20:19 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
A screenshot of the tool's encounter builder section, with dropdowns for monsters, automatic calculation of challenge levels, and more.

A screenshot of the tool's encounter builder section, with dropdowns for monsters, automatic calculation of challenge levels, and more.

My Draw Steel Adventure Tools!

This spreadsheet helps you create combat encounters, montages, negotiations, and more, all following official recommendations! Available on my Patreon at patreon.com/Alphastream

www.youtube.com/watch?v=DtbB...

#DrawSteel #TTRPG

12.12.2025 21:11 β€” πŸ‘ 103    πŸ” 26    πŸ’¬ 1    πŸ“Œ 1
Preview
Save 20% on Go Slimey Go! on Steam Help Slimey, our tiny slippery protagonist, visit his friends for some well deserved teatime after some thrilling platforming challenges!

Hey hey!
Go Slimey Go! is now out!!
Muy cousin and his team worked super hard to bring this project to life.
Support Latin games πŸ˜ŽπŸ˜ƒ
store.steampowered.com/app/3215230/...
#GoSlimeyGo

12.12.2025 20:19 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Draw Steel: Crack the Sun Project Update: We did it!! We Cracked the Sun Hey folks, Matt Colville here. I am writing this to you as I am in the middle of giving feedback to to the writers of Crack the Sun: Act II (The Hound of Dalrath’s Call...
12.12.2025 07:03 β€” πŸ‘ 81    πŸ” 10    πŸ’¬ 0    πŸ“Œ 2
Preview
Good King Omund's Box of Dice A new game for a new age! Draw Steel is the breathtaking new, action-oriented, fantasy RPG from MCDM that’s both fun to play and fun to run!

We only have a few of these left from the Dicefunder earlier this year and we will be selling them on Friday.

26.11.2025 07:11 β€” πŸ‘ 24    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Post image 26.11.2025 23:36 β€” πŸ‘ 120    πŸ” 10    πŸ’¬ 4    πŸ“Œ 1
screenshot of text:

Triple-Base64 Encoding

All exfiltrated data is encoded through three layers of base64 before upload:

content β†’ base64 β†’ base64 β†’ base64
This serves multiple anti-forensic purposes:

    Evades GitHub's built-in secret scanning
    Bypasses third-party secret detection tools
    Makes casual browsing of repository contents ineffective
    Complicates forensic analysis of stolen data

screenshot of text: Triple-Base64 Encoding All exfiltrated data is encoded through three layers of base64 before upload: content β†’ base64 β†’ base64 β†’ base64 This serves multiple anti-forensic purposes: Evades GitHub's built-in secret scanning Bypasses third-party secret detection tools Makes casual browsing of repository contents ineffective Complicates forensic analysis of stolen data

movie: we can't trace their payload, it's behind two layers of base64!

computer knowers: *groan*

reality:

25.11.2025 13:17 β€” πŸ‘ 602    πŸ” 76    πŸ’¬ 40    πŸ“Œ 12
Level 4 DRAW STEEL Metal Troubadour - Riffs and a Song for the abilities!
YouTube video by BarcodeDM Level 4 DRAW STEEL Metal Troubadour - Riffs and a Song for the abilities!

This is amazing, have people seen this??

www.youtube.com/watch?v=BhOe...

19.11.2025 22:46 β€” πŸ‘ 73    πŸ” 8    πŸ’¬ 0    πŸ“Œ 0
21.11.2025 02:45 β€” πŸ‘ 224    πŸ” 29    πŸ’¬ 6    πŸ“Œ 3
Preview
28 Points Later A definitive guide to the Russian zombie diplomacy of Trump’s peace plan for Ukraine β€” aka what happens when you let the Russians eat your brains

The β€œpeace plan” for Ukraine is just a framework for Russia & the US to take assets away from Ukrainian recovery, and to ensure Russia evades accountability for war crimes

Europe can, and must, craft better with Ukraine

A point by point analysis of the shambles:

www.greatpower.us/p/28-points-...

21.11.2025 21:22 β€” πŸ‘ 666    πŸ” 232    πŸ’¬ 24    πŸ“Œ 19
Draw Steel Ancestry Guide - Part 1! #drawsteel
YouTube video by Matthew Colville Draw Steel Ancestry Guide - Part 1! #drawsteel

Draw Steel Ancestries, Part One!

youtu.be/97wxQueVXcc

22.11.2025 03:15 β€” πŸ‘ 207    πŸ” 30    πŸ’¬ 5    πŸ“Œ 3

Amazing, thanks!

16.11.2025 08:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Excellent, thanks!

16.11.2025 08:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Does draw steel backers get access as well? I don't remember

15.11.2025 23:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 3    πŸ“Œ 0

@hellomcdm.bsky.social hey guys, i have a quick question regarding discord: i was trying to join the server but it errors out; observing the request, i see a 403 response with "the user is banned from this guild", which is interesting, as I have never been in the server before :thinking:
any clues?

08.11.2025 00:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Memos to Federal Employees Were Written By People With Ties to Project 2025, Metadata Shows James Sherk and Noah Peters appear as the authors of memos sent by the Office of Personnel Management.

Some of the OPM memos ordering federal employees to return to offices and ordering hiring freezes were written by people who worked on Project 2025, according to metadata on the documents www.404media.co/opm-memos-to...

27.01.2025 23:43 β€” πŸ‘ 323    πŸ” 125    πŸ’¬ 8    πŸ“Œ 9
Preview
Accelerando - Charlie's Diary I hope that if you enjoy the ebook you'll consider buying my other books, but this is the only reminder you'll get. (I'm not into shareware with nag screens ...)

Accelerando is one of my favorite sci-fi novels. I would say it's been highly influential in tech.
Today I learned it is available for free under a CC license below.

(Yes, I am kind of slow for ebook news I prefer the physical stuff)

www.antipope.org/charlie/blog...

10.01.2025 18:59 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

But that's not it: this been there for a while, we also need to look at the past to we what has the attacker done so far! Its quite bad.
Luckily, as far as we know, it doesn't call home, right? Please tell me it doesn't.

30.03.2024 22:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.

30.03.2024 17:13 β€” πŸ‘ 688    πŸ” 275    πŸ’¬ 7    πŸ“Œ 15

@hackancuba is following 10 prominent accounts