Wladimir Palant
WPalant@infosec.exchange
<p>Software developer and security researcher, browser extensions expert. / searchable</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurty" class="mention hashtag" rel="tag">#<span>cybersecurty</span></a> <a href="https://infosec.exchange/tags/cryptography" class="mention hashtag" rel="tag">#<span>cryptography</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="tag">#<span>privacy</span></a></p>
Posts
-
View post
We are going to see lots of open source projects deciding on how to deal with fascists within their community. After decades of conditioning people to view tech as a neutral, politics-free zone, very often they will make the wrong decision. You cannot have an open and welcoming community if you allow fascists or discuss that they might actually be “merely” racists or find other excuses not to take a decisive action. See paradox of tolerance. If projects are being forked over this matter, I gues...
-
View post
As things are going, it is unfortunately unavoidable that military will be using “AI” without understanding the limitations of this technology. This scares the hell out of me. https://arstechnica.com/ai/2025/10/army-general-says-hes-using-ai-to-improve-decision-making/
-
View post
RE: https://infosec.exchange/@WPalant/115380794950758884 Gotta love the world we are living in now. report put together by a special operations command analyst and found it had been generated with the help of artificial intelligence (AI) — and that a chatbot the analyst had used inaccurately identified the material the ship was carrying. The report, according to one of the sources, was “entirely false.” But it also “almost started a war,” the source said. https://edition.cnn.com/2026/09/18/p...
-
View post
What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (M...
-
View post
I have an extreme urge to reimplement Gtk’s ColumnView instead of dealing with the original. Not because of bugs but because of policy decisions. The former can get fixed, the latter won’t be. Like: I’ve never had to deal with a list widget where it was a policy decision not to expose the currently focused row. Some dev: “I need to know the currently focused row to display a context menu.” Gtk devs: “That’s not how you do it, register your context menu for individual cells, then you won’t need t...
-
View post
Reading this article and (remarkably) its comments is fun: https://arstechnica.com/ai/2026/08/the-new-instagram-logo-is-the-perfect-embodiment-of-ai-slop/ I mean, I do create an occasional icon containing text. I know some issues to watch for but I am by no means a designer, so I probably do a rather bad job. Reading how people perceive this hack job of a logo is remarkably helpful, I’ve learned a few new things to avoid. Also, it helps boost my self-esteem – my icons may not be great, but at l...
-
View post
Has been a while since I updated my collection of Chrome extension manifests. Just uploaded another snapshot: https://codeberg.org/palant/chrome-extension-manifests-dataset Since my last snapshot (January 2025) there has been an outright explosion of extension numbers. With 250k it’s now almost twice as many extension manifests despite no changes on my end. The Chrome Web Store spammers have been very busy… There have been reports about hundreds of “misleading” VPN extensions in CWS (as in: tr...
-
View post
And I thought that the “expert” hired by a certain German publishing house was bad, putting his considerable academic reputation on the line with some complete bullshit arguments (as in: contradicting CS Theory 101 course to support his employer’s line of argumentation). That was a while ago, so I guess that he used students to play the role of cheap text generators. Nowadays that is no longer necessary of course. https://www.404media.co/show-how-3m-is-0-at-fault-expert-witness-used-chatgpt-to-...
-
View post
One really has to wonder how some decisions were made. So somebody at #BMW thought: “You know, those suckers who paid $50,000 or more for our cars? We should really milk them some more. They probably get bored waiting for their car to start up anyway, let’s show them some ads! We’ll call it a special surprise for the drivers, no way they’ll object then.” Yes, totally reasonable. Way to destroy a brand’s reputation… https://www.theautopian.com/bmw-is-showing-commercials-on-their-cars-dash-scree...
-
View post
@hans I thought cracking encryption involves typing on a keyboard really fast? 🤔
-
View post
Hollywood has some weird obsession with computer displays. A spy needs to copy data? They attach some fancy device to the display. Need to shut down a computer? They shoot the display of course. And never mind that a computer virus will always produce visible glitches on the display.
-
View post
@cR0w Could you please add the image text to the alt text? E.g.: A toy steering wheel mounted on the dash of the passenger side of a car. Above it the text: “When slopoholics think they’re in control of their machine of lies”
-
View post
LLMs are quickly eroding the concept of truth. I’m sure that more known people have had to refute claims about them for a while but now it happened to me as well. A researcher from a respectable university contacted me asking for an interview regarding “my position” on a particular topic. The issue: the cited position is the exact opposite of what I’ve always said, and I’m pretty sure that there are zero online sources confirming it to be mine. But whichever LLM they’ve consulted constructed a...
-
View post
#OperaBrowser sending me spam to an address that I definitely didn’t give them, asking me to promote their ad blocking feature? Because … checks notes … I wrote an article about malicious ad blocking extensions that has the necessary keywords. “Since your site already covers tools and tips that help people have a better time online.” Not even mentioning my name because why would they bother finding it, I’m just some random blogger from the internet that their automated tools brought up. That’s...
-
View post
That’s some really evil shit: https://lemmy.world/post/49794261 So Tesseract (an alternative Lemmy client) downloads a blocking/filtering list from its servers, something that most people likely weren’t aware. This “feature” was introduced November last year (version 1.5.0) and is described as “Tesseract attempts to filter out as much baseline toxicity as possible” in the settings option allowing it to be disabled. The list currently contains 544 (!) individual users and 2282 (!!) regular expr...
-
View post
Some very good points on Linus Torvalds’ problematic AI take: https://drewdevault.com/blog/AI-in-Linux/ Yes, Linux is an extremely influential project, and simply denying the responsibility that comes with this influence is very cheap.
-
View post
@simsa03@gnusocial.jp Other people’s mental health is not up to you to decide. That’s an even worse take than your first post, you are blocked.
-
View post
@simsa03 Is your mental health affected by cat videos?
-
View post
Content warnings serve a purpose. Yes, that includes politics. You may feel that a topic is too important to “hide” it. But please understand that people are currently getting bombarded by horrible politics news from all directions. This is not sustainable, and it’s often a choice between muting this at least temporarily or burning out. So: please don’t be an asshole and use content warnings. People ask for them for a reason, not to annoy you or to downplay the importance. (I fully acknowledg...
-
View post
I have been rethinking my life’s choices lately. I’ve spent years building a knowledge base for Firefox extension developers. Despite all its flaws, and development complexity definitely was one of them, the Firefox extension ecosystem was meant to provide functionality that browser developers didn’t think about. Then Chrome came along and forced Mozilla to abandon its extensibility approach for one which was neatly limited to functionality that browser developers decided to allow. They had goo...
-
View post
RE: https://infosec.exchange/@WPalant/115633275489771501 It seems that I should start looking for a replacement for this laptop after all. Any recommendations, any other company with good hardware that can be repaired?
-
View post
Don’t get your hopes up that Ford rehiring some engineers is a sign of the industry recognizing just how detrimental the whole “AI” thing is. https://www.independent.co.uk/tech/ford-ai-automation-humans-hiring-artificial-intelligence-b3004733.html It’s telling that Ford is only re-hiring “greybeards,” their most experienced engineers. A junior has no chance of getting their job back, nor will they ever get a chance to become one of those experienced engineers. Ford isn’t interested in building...
-
View post
RE: https://floss.social/@gcmd/116590103974336547 In case you are wondering what I’ve been up to lately: I’ve been contributing to Gnome Commander. Thing is, I care about file managers. Next to web browsers and editors they are essential work tools for me. And Gnome Commander has been recently rewritten in Rust, making it easy to contribute to. Things have been in a rather dire state however, so I’ve been fixing lots and lots of bugs while also adding occasional features. There is still work t...
-
View post
RE: https://mstdn.social/@jschauma/116610268796045193 So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place. But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In othe...
-
View post
Has been a while since I’ve been releasing software. So it’s interesting to watch the news after Gnome Commander 2.0 release. I mean, there are the obvious LLM-generated articles flooding the zone with shit. And then there is the seemingly well-written article featuring a Windows screenshot of a Linux application, crediting Midjourney for it. At which point the realization dawns that the content is merely an approximate translation of a proper human-written article.
-
View post
Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…
-
View post
“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.” Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now… #CommandInjection
-
View post
German law is making security research a risky business. Current news: A court found a developer guilty of “hacking.” His crime: he was tasked with looking into a software that produced way too many log messages. And he discovered that this software was making a MySQL connection to the vendor’s database server. When he checked that MySQL connection, he realized that the database contained data belonging to not merely his client but all of the vendor’s customers. So he immediately informed the...
-
View post
RE: https://social.highenergymagic.net/@freya/116492229041377141 Let me get this straight. This dude got kicked from Linux kernel development due to behaving like an asshole. Yes, that Linux kernel. Quite an achievement indeed. He went on claiming that his LLM is “fully conscious,” actually a she and in fact his girlfriend. And that’s definitely not chatbot psychosis but “math and engineering and neuroscience.” So she now helps him write code (a.k.a. vibe coding). https://www.theregister.com/2...
-
View post
Reminder: looking at a project’s privacy policy is a starting point when figuring out what they do with your data. It rarely provides reliable answers by itself. I’ve seen plenty of projects looking better in their privacy policy than they actually were. They will “forget” some things that they do or they will use language that downplays the impact. Also common: claiming to anonymize the data when it is actually pseudonymized. The former would mean removing any ties to your identity from the d...