0daysto.live

0daysto.live

0daystolive | @[email protected]

Opinions are those of my employer.
Computer Hacker.
Work @ https://sorcery.ie
Blog @ https://0daysto.live

3233. Make It Myself

title text: It's not as big a loss as it looks, because now I have have leftover supplies, which will help me talk myself into doing this all over again with a new project!

desktop link: https://xkcd.com/3233
mobile link: https://m.xkcd.com/3233
explainxkcd: https://www.explainxkcd.com/wiki/index.php/3233

sensitive media
Single panel comic.

No hair is talking to hat and gesturing at two boxes labeled "sale" and "$80"

No hair says "They want $80 for this? I could make one myself for $10 in parts, an hour of work, a trip to the hardware store, another $30 in parts, another few hours of work, two more trips to the store for $20 more in parts, another hour to redo the first hour of work because I messed up, and $80 to buy this when the one I made breaks."

owning the libs

maintaining the libs

reviewing pull requests on the libs

setting up ci and fuzz tests for the libs

"Days of arguing about exploitability can save minutes of fixing the bug."

-- Socrates, on vulnerability disclosure

We are very close to inventing water from first principles

Coca Cola Dose in schwarz mit goldener Schrift. 
Zero caffeine. 
Zero sugar. 
Zero calories.

the phrase "bog standard" implies the existence of Bog NIST

The "Change my mind meme" with that one dude everyone hates. I can't remember his name but it doesn't matter because he now has a catte head. And he's sitting smugly at a table with a sign that says "CTI is just an expensive story time subscription for nerds. Change my mind."

In January, behind closed doors at the Pentagon, Under Secretary of War for Policy Elbridge Colby summoned Cardinal Christophe Pierre
— Pope Leo XIV’s then-ambassador to the United States
— and delivered a lecture.

“America,” Colby and his colleagues told the cardinal, “has the military power to do whatever it wants in the world. The Catholic Church had better take its side.”

As tempers rose, one U.S. official reached for a fourteenth-century weapon and invoked the Avignon Papacy -- the period when the French Crown used military force to bend the bishop of Rome to its will.

Letters from Leo can now independently confirm that the meeting took place
— and that the Vatican was so alarmed by the Pentagon’s tactics that Pope Leo XIV shelved plans to visit the United States later this year.
https://www.thelettersfromleo.com/p/the-pentagon-threatened-pope-leo

did you know? the google forms share icon has a stray pixel in its corner

why? because the icon spritesheet has a massive black triangle overlapping the icons

what is that triangle? it's a giant out-of-bounds hat!

"How many products does Microsoft have named 'Copilot'? I mapped every one."
https://teybannerman.github.io/strategy/2026/03/31/how-many-microsoft-copilot-are-there.html

"A few weeks ago, I tried to explain to someone what Microsoft Copilot is. I couldn’t… because the name ‘Copilot’ now refers to at least 75 different things."

Circular graph from the article illustrating the interconnected ecosystem of Microsoft's Copilot products and features. It's ridiculous.

How annoyed are judges about getting filings with hallucinated citations? They are using ChatGPT to write limericks mocking the filers 🤖😵

https://flcourts-media.flcourts.gov/content/download/2486572/opinion/Opinion_2025-0843.pdf

 AI Spotted
There once was a litigant pro se,
Who let an AI lead the way.
It briefed every claim,
Cited cases—by name,
That vanished by morning’s next day.
Limerick on Pro Se Parties Using Artificial Intelligence (on file with the
Fourth District Court of Appeal) (generated by ChatGPT 5.2).

Here’s one of my more reflective poems, written while waiting for a train at a provincial railway station.

If I Could Have My Time Over
 
If I could have my time over,
I would do it all differently
and not treat each precious moment
with such disregard and flippancy.
 
I would use my time effectively,
I would think ahead and plan.
I would reserve my stores of energy,
and take charge when I can.
 
But it’s too late in the journey
for regret, too late to repent –
because there’s not a socket in sight,
and my battery’s on one per ce

WE DON'T WANT TO KNOW BANKSY'S IDENTITY

STOP INVESTIGATING BANKSY FFS

INVESTIGATE LITERALLY EVERYTHING ELSE

Outlook's "sign in with app notification" feature is such an awful security footgun - it should not exist. It allows you to login to your email without any info, just clicking approve in the app, meaning you are just one misclick away from giving away your email. It gets enabled as an option by default if you install the Outlook app and I immediately started getting login approval requests.

New FOSS funding model just dropped

GitHub releases screenshot for Strawberry showing multiple Linux releases available but "macOS and Windows release is available on Patreon"

Every accusation a confession latest

Screenshot tweet of Rubio on Fox, quote: "That entire regime is led by radical clerics who don't make geopolitical decisions. They make decisions on the basis of theology, their view of theology which is an apocalyptic one." Post from @jonathanlarsen.bsky.social "EXCLUSIVE: At more than 30 installations, U.S. commanders told troops the war on Iran is a Christian war.

The Military Religious Freedom Foundation has been “inundated” with more than 110 complaints.

One NCO said they were told the U.S. war is to bring about Armageddon and the return of Jesus…"

"There's nothing we can do"
"What do you suppose we do?"
"We are powerless"

- The democracy supposedly worth spreading through bombs

We and our 847 partners can have a CSRF vulnerability, as a treat

> The State cannot claim it lacks capacity. It has police, it has a military, it has an airport. It simply refuses to apply scrutiny to US-linked flights in the way it would to almost any other perceived security concern.

https://www.irishexaminer.com/opinion/commentanalysis/arid-41792807.html

Today we had a fire alarm in the office. A colleague wrote to a Slack channel 'Fire alarm in the office building', to start a thread if somebody knows any details. We have AI assistant Glean integrated into the Slack, and it answered privately to her: "today's siren is just a scheduled test and you do not need to leave your workplace". It was not a test or a drill, it was a real fire alarm. Someday, AI will kill us.

Image of fire brigade near our office Glean answer:

In building ... today’s siren is just a scheduled test and you do not need to leave
your workplace while it's running.

If you're unsure or something seems off (e.g. smoke, smell, people evacuating), call Munich building emergency number ... or ask at reception immediately.

in 2017 a popular twitter game was to type a partial phrase then see what your phone auto-completes it with.

this proved so popular that it is now the only business model in the US.

»