What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

1

Question: when did security analysts start describing leveraged exploit paths as "primitives"? Did this start with the FORCEDENTRY JBIG2 exploit or does this terminology have a longer history, maybe in gadget-based exploitation?

projectzero.google/2026/01/pix

0
0
0
0
0
0
0
0
0
1
0
1
0
0
0

🎊 Go 1.26 Release Candidate 2 is released!

🔐 Security: Includes security fixes for archive/zip (CVE-2025-61728), net/http (CVE-2025-61726), crypto/tls (CVE-2025-68121, CVE-2025-61730), cmd/go (CVE-2025-61731, CVE-2025-68119).

🏃‍♂️ Run it in dev! Run it in prod! File bugs! go.dev/issue/new

🔈 Announcement: groups.google.com/g/golang-ann

📦 Download: go.dev/dl/#go1.26rc2

$ go install golang.org/dl/go1.26rc2@latest
$ go1.26rc2 download
Downloaded   0.0% (       0 / 62956023 bytes) ...
Downloaded  50.0% (31478011 / 62956023 bytes) ...
Downloaded 100.0% (62956023 / 62956023 bytes)
Unpacking go1.26rc2.linux-mipsle.tar.gz ...
Success. You may now run 'go1.26rc2'
$ go1.26rc2 version
go version go1.26rc2 linux/mipsle
0
0
0
0

탄수화물과 단백질만 좋아하는 요리 잘하는 남성이 강원도에 장가 오면서 기대한 것 : 끝내주게 맛있는 평창 한우, 고구마, 옥수수, 감자 궤짝으로 배송 받아서 에어프라이기에 요리해 먹기 실제로 얻게 된 것 : 무한 한정식 산나물 곤드레밥 두부요리 제공 사건 (투명도 20%의 내적 비명 소리가 들리며)

RE: https://bsky.app/profile/did:plc:32ffmsxrwnugpta5nopzr6lk/post/3mcgi6dwgks2s

0
2
1
0
0
0

📢 v1.114 is rolling out! Today, we're expanding access to the Live Now beta to everyone. This experimental feature lets you add a temporary LIVE badge to your avatar, helping others discover that you're currently live-streaming on Twitch. They can click it to land directly on your stream page.

A preview of the Live Now feature, showing the popup that appears when someone is live streaming and you click their avatar.
0
0
0
0

From a pragmatic standpoint I get Wikimedia making deals with AI companies: They will scrape anyways, this way you might get some money.

But it still _feels_ off. Telling all volunteers "you are working for Microsoft/Perplexity/etc for free now" _feels_ wrong.

0
0
0
0

RE: furry.engineer/@soatok/1158961

As a professional source code reviewer, I gotta agree with “We cannot overstate the extent to which just reading the OpenSSL source code has become miserable.” The answer to “how does OpenSSL—” is always “I don’t know and I don’t have six months to find out.” This is not true of alternative libraries with the same functionality.

@0xabad1deaabadidea I feel the same when I have to explain that FFMPEG rawdogging assembly is not the "performance" tradeoff that people should look at and go "holy based".

They openly admit to lying about ABI-stability when they know damn well they re-shuffle enum values between random updates, why the fuck would anyone trust them to be able to maintain assembly code with instructions that look like passwords.

The code is already unreadable, the specs for it are buried in NDAs and patent hellholes, which doesnt matter because FFMPEG is very proud to diverge from specs. That codebase does not need to include assembly to become a security nightmare and going "see no evil hear no evil" while closing your eyes and plugging your ears doesn't fucking work because some fucker is 100% gonna speak a lot of evil. Media files are historically one of the most reliable things to look into if you're looking for a 0-click 10/10 RCE.

It is impossible to trust a review of projects like these, I don't care how skilled and certified the team signing off on it was, if they don't find anything they did not understand what they were reading and one day someone on the red team will do a better job than them.

0

Notice for Players Regarding Server Time Adjustment

A very early reminder to many players, mostly in Europe DCs - remember that on March 30, the server time will be adjusted by an extra hour ahead to align with the in-game day-night cycle. This may interfere with many features such as public transit, career quests, and some items with a clock feature may display incorrect time.

0
0
0

🚀 Heute startete die AWS European Sovereign Cloud in Potsdam & wir waren als BSI vor Ort.

Denn: Wir unterstützen den US-Cloud-Anbieter Amazon Web Services (AWS) bei der Ausgestaltung von Sicherheits- & Souveränitätsmerkmalen seiner European Sovereign Cloud (ESC).

Zur Pressemitteilung:
👉️ bsi.bund.de/dok/1190346

🎬️ Ein Statement unserer Präsidentin Claudia Plattner gibt's im Video.

0
0
0
0
1
0
0

So @lwnLWN.net is currently under the heaviest scraper attack seen yet. It is a DDOS attack involving tens of thousands of addresses, and that is affecting the responsiveness of the site, unfortunately.

There are many things I would like to do with my time. Defending LWN from AI shitheads is rather far from the top of that list. I *really* don't want to put obstacles between LWN and its readers, but it may come to that.

(Another grumpy day, sorry)
0
0
0

중국이 해외 AI를 활용해서, 미성년자가 성적인 대화를 할 수 있게 개조한 서비스를 제공한 개발자와 운영자를 체포, 4년/18개월 징역을 먹였습니다. www.chinadaily.com.cn/a/202601/13/... 중국 법원은 이 서비스가 음란물이라고 판결했습니다. 조사 결과 피고인들은 성능향상이 아니라 섹텐을 위해 시스템을 튜닝했다고.

AI software under lens for fac...

0
0
0
0

something i didn't realize was a problem until like the last year is that when i say "infrared", half of the people reading it will go "yep, that's right, near infrared in the range of 750 nm to 1500 nm that shows up on silicon sensors" and the other half will go "yep, that's right, far infrared in the range of 1500 nm to 1 mm that shows up on microbolometers" (qualifying it as "NIR" or "LWIR" does not help very much in my experience)

@whitequark✧✦Catherine✦✧ Free-space communication using anything longer than 1.2um (e.g. 1550nm SFP modules) might be quite unlikely to be detected, due to invisibility to Si cameras. The government where I live believes itself entitled to regulate all communication via infrared, but has graciously granted the public a licence to use TV remotes, perhaps to gratify themselves that they are not being disobeyed. The power limit of 125mW probably means that many hot objects are illegal to communicate with.

Table from https://www.legislation.gov.au/F2025L01047/asmade/text explaining that people are allowed to use Infrared between 187.5 THz and 420 THz for communications as long as the output power is below 125 milliwatts.
0
1
1
0