's Avatar

@tstjern.bsky.social

31 Followers  |  173 Following  |  34 Posts  |  Joined: 27.02.2025  |  1.8835

Latest posts by tstjern.bsky.social on Bluesky

Åh nej inte en bugg i autokorrigeringen i det för lilla tangentbordet som behöver autokorrigering för att fungera.

26.10.2025 10:15 — 👍 1    🔁 0    💬 0    📌 0
Preview
GitHub - geomys/sandboxed-step: A GitHub Action that runs a command in a gVisor sandbox A GitHub Action that runs a command in a gVisor sandbox - geomys/sandboxed-step

I got frustrated with how GitHub Actions lets workflows with read-only permissions poison the cache of read/write workflows (!!??!?), so yesterday night I put together an Action that runs commands in a gVisor sandbox.

24.10.2025 12:59 — 👍 49    🔁 11    💬 2    📌 0
Abstract. Germany is currently rolling out an opt-out, nation-scale database of the medical records of the majority of its population, with low-income people being disproportionally represented among its users. While there has been considerable criticism of the system coming from civil society, independent academic analysis of the system by the cryptography and information security community has been largely absent. In this paper, we aim to raise awareness of the system’s existence and, based on the system’s public specifications, highlight several concerning cryptographic engineering decisions. Our core observations is that the system’s most sensitive long-term user keys are derived by a rudimentary, home-grown centralized key escrow mechanism. This mechanism relies on a per-use salt and only 256 bit of entropy, shared globally across millions of users. Furthermore, the system’s specification mandates only level 3 compliance with the obsolete FIPS 140-2 security standard, which requires “hard, opaque potting”, but lacks active tamper sensing. As a result, the system remains vulnerable to attacks by nation states and other well-funded adversaries.

Abstract. Germany is currently rolling out an opt-out, nation-scale database of the medical records of the majority of its population, with low-income people being disproportionally represented among its users. While there has been considerable criticism of the system coming from civil society, independent academic analysis of the system by the cryptography and information security community has been largely absent. In this paper, we aim to raise awareness of the system’s existence and, based on the system’s public specifications, highlight several concerning cryptographic engineering decisions. Our core observations is that the system’s most sensitive long-term user keys are derived by a rudimentary, home-grown centralized key escrow mechanism. This mechanism relies on a per-use salt and only 256 bit of entropy, shared globally across millions of users. Furthermore, the system’s specification mandates only level 3 compliance with the obsolete FIPS 140-2 security standard, which requires “hard, opaque potting”, but lacks active tamper sensing. As a result, the system remains vulnerable to attacks by nation states and other well-funded adversaries.

Image showing part 2 of abstract.

Image showing part 2 of abstract.

Germany Is Rolling Out Nation-Scale Key Escrow And Nobody Is Talking About It (Jan Sebastian Götte) ia.cr/2025/1963

20.10.2025 17:27 — 👍 0    🔁 1    💬 0    📌 0
Front page of NYT on September 22, 2025, with large top-of-page photo of a Charlie Kirk memorial service, and the lead page-one story on the same topic.

Front page of NYT on September 22, 2025, with large top-of-page photo of a Charlie Kirk memorial service, and the lead page-one story on the same topic.

Front page of today's NYT, Oct 19, with no story about the nationwide protests, and a "below the fold" montage of two photos, and a link to a story on page 23.

Front page of today's NYT, Oct 19, with no story about the nationwide protests, and a "below the fold" montage of two photos, and a link to a story on page 23.

Those with sharp eyes might detect a subtle difference in NYT play last month of an event in one city, w 100,000+ attendees, versus play this morning of some 2500+ events w many millions of attendees, in all 50 states.

See if you can spot it! /s

Then you can find today's story on p A23

19.10.2025 14:35 — 👍 3830    🔁 1236    💬 183    📌 149
Preview
How Fr Paul Murphy helps Irish peacekeepers prepare for danger Niall O’Connor is reporting this week from South Lebanon where he met Fr Paul Murphy who cares for the Irish soldiers.

On a visit to Camp Shamrock, we spoke to Fr Paul Murphy about his work, how he is the only unarmed non-combatant in the base, and how when he was stabbed in a terror attack at the gates of a military barracks it only reinforced his sense of duty.
http://jrnl.ie/6846276t

16.10.2025 19:09 — 👍 2    🔁 1    💬 0    📌 0
Preview
Wikipedia Volunteers Avert Tragedy by Taking Down Gunman at Conference After the man walked onto the stage at the “Wiki World’s Fair” event and threatened to kill himself, witnesses said, two members of the audience jumped in to stop him.

Two Wikipedia contributors averted a potential tragedy at a conference for the site’s editors on Friday in Manhattan when they jumped in to take down a man with a gun.

18.10.2025 00:50 — 👍 562    🔁 139    💬 25    📌 32

UXO cleanup was not something USAID did, that was a State affair. In Gaza, we kept advocating for more UXO work, but it was always tied to the ceasefire negotiations and Israel's desired "humanitarian bubbles" - the project which became GHF. As a result, no meaningful US-funded UXO work occurred.

16.10.2025 15:59 — 👍 35    🔁 13    💬 0    📌 0

Both sides of a conflict are calling each other evil and corrupt, rendering me, a humble journalist, helpless to discern the truth. Best I can do is let you know that both sides are in fact saying those things. Hope this helps

14.10.2025 17:54 — 👍 3463    🔁 501    💬 36    📌 21
Post image Post image

Reminder of what Salvini was doing 11 years ago: visiting Crimea to support Russian annexation of the region and encourage Italian businesses to invest there.

12.10.2025 17:04 — 👍 59    🔁 23    💬 4    📌 2
Preview
A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research Today we’re announcing the next major chapter for Apple Security Bounty, featuring the industry’s highest rewards — up to $2 million and a maximum payout in excess of $5 million — expanded research ca...

Apple is planning a special initiative featuring iPhone 17 with Memory Integrity Enforcement. To rapidly make this defense available to those targeted by mercenary spyware, the company will provide a thousand iPhone 17 devices to civil society organizations.

security.apple.com/blog/apple-s...

10.10.2025 15:51 — 👍 14    🔁 11    💬 0    📌 2

Den här synen på makt har ju ganska uppenbara begränsningar när den de facto inte påverkat massvält och krigsbrott inför fullt mediepådrag i två år.

12.10.2025 10:21 — 👍 0    🔁 0    💬 1    📌 0

While providing tech support for my FIL:

FIL: What's that screen?

ME: The terminal. You should never use it.

FIL: Never?

ME: So you know how I'm allowed to watch you open the electrical panel and swap out breakers, but I'm not allowed to ever open up it myself?

FIL: Ah! I understand, thank you.

11.10.2025 01:31 — 👍 1532    🔁 239    💬 19    📌 12

De ger sej ut på duktigt djupt vatten direkt med premissen att GT skulle vara makthavare i det här sammanhanget. Ekar ganska tomt med tanke på hur lite det frågas av riktiga makthavare i det här sammanhanget.

11.10.2025 16:12 — 👍 3    🔁 0    💬 1    📌 0

In my consultant phase after I left Twitter a lot of folk asked me for advice on building social networks and my advice was always: don’t. Do not.

04.10.2025 04:13 — 👍 91    🔁 14    💬 2    📌 1

tired: it's always DNS

inspired: ICANN feel it coming in the air tonight

29.09.2025 11:02 — 👍 1321    🔁 277    💬 18    📌 8

Sounded like smaller drones intended to disrupt traffic and cause headlines. Same around Oslo as well. Different from armed drones over Poland or Migs going 10 minutes inside Estonian airspace.

23.09.2025 19:34 — 👍 1    🔁 0    💬 0    📌 0

To be fair Sqlite is probably something Brendan Eich was asked to fit into the Netscape 2 betas during a few weeks in the 90's

23.09.2025 19:01 — 👍 1    🔁 0    💬 0    📌 0

filing this under the, "this is why we can't have nice things" folder...

17.09.2025 17:44 — 👍 18    🔁 7    💬 5    📌 1

Phishing email sent to NPM package maintainers:

08.09.2025 17:12 — 👍 32    🔁 19    💬 1    📌 3

Låter som termer som inte används på allvar på 20 år har bevarats av någon techlobby-bubbla och nu kommer ut ur en politikers mun :)

03.09.2025 10:27 — 👍 1    🔁 0    💬 0    📌 0
Bunny meme with text: "There are tunnels underground where bunnies are safe -- safe from undefined behaviour"

Bunny meme with text: "There are tunnels underground where bunnies are safe -- safe from undefined behaviour"

Couldn't not do this

01.09.2025 19:58 — 👍 3    🔁 10    💬 0    📌 0

Prompt engineering is knowing the correct answer and trying to get the chatbot to produce it.

19.08.2025 14:44 — 👍 453    🔁 104    💬 14    📌 8
16.08.2025 19:52 — 👍 40    🔁 7    💬 2    📌 0

Placera killarna där nere också tack.

15.08.2025 09:40 — 👍 5    🔁 0    💬 0    📌 0

I ljuset av de temperaturbaserade problemen med Stockholms vattenförsörjning vill jag påminna om att det finns killar som på allvar föreslagit "datacenter på havsbotten" som "lösning" på AI-modellernas vattenförbrukning

15.08.2025 09:27 — 👍 9    🔁 2    💬 3    📌 0

Jag får gratulera @jensliljestrand.bsky.social till fantastisk kunskap om ryska dialekter och hoppas att jag inte gav upphov till kulturartiklar när jag talade ryska med mina barn på Spaniensemestern. bsky.app/profile/jens...

12.08.2025 15:08 — 👍 29    🔁 5    💬 5    📌 0

I think it's great how the entire U.S. economy is currently being held together by like 4 tech companies, and in response we're about to put tariffs on semiconductors.

It's a brilliant plan.

05.08.2025 22:41 — 👍 1465    🔁 225    💬 33    📌 7

Occam's brödkniv

05.08.2025 09:32 — 👍 1    🔁 0    💬 0    📌 0

@tstjern is following 20 prominent accounts