315 karma · joined June 24, 2016
Also seeing a lot of ignorance about cycling here in the comments. Would recommend some people to watch some Not Just Bikes videos. Building better cycle infrastructure is better for everyone, cars and cyclists included. Less people die, and cars don't have to deal with cyclists on the road. Ex https://www.youtube.com/watch?v=d8RRE2rDw4k
I feel he's depending on others' kindness and not even really acknowledging them. It's like he feels it's a miraculous power that's helping him (God?) rather than the actual individuals choosing to help him. Maybe that explains why he doesn't seem to feel the need to give back to them.
It reminds me of an episode of The Wire where a mediocre detective tries to use magic to solve a case. After he wakes up the next day he goes to the office and finds the case is solved. He says the magic worked! And the police chief tells him it wasn't magic, it's his colleagues who worked all night solving cases.
Later I found fizsh, which I love and still use as default shell now. It's basically a configuration around zsh adding the colors, completions, and other good stuff inspired by fish to zsh. Can really recommend it for those who are used to zsh or bash but want their CLI to be more readable. Colors especially help with big command line arguments to show where they start and end, and keeping track of complex stuff like loops and conditional logic in your commands.
Also a bit annoyed there's no date on the article, but looking at the HTML source it seems it was released today (isn't it annoying when blog software doesn't show the publish date?).
I personally work as pentester and we're still doing a lot of manual work with AI simply as a better version of Google, but seeing the BOTS presentation I feel we can do better. Do you have any idea if anyone's working on something similar to Louie in pentesting space, or if Louie could work with pentesting workflows?
[0] https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/... [1] https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/... [2] https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/...
It's a pretty cool attack chain, if there's an XSS on marketing.example.com it can be used to execute a CSRF on app.example.com! It could also be used with dangling subdomain takeover or if there's open subdomain registration.
https://scotthelme.co.uk/csrf-is-dead/
But I didn't know about the Sec-Fetch-Site header, good to know.
I guess you'd say most people in the world don't live in functioning countries then? China, Russia, much of the middle east and Africa are not democratic and sometimes the death of a dictator is the only way to move them forward. USA and many democracies in the west are also backsliding so maybe soon few people will live in a "functioning country".
Counterpoint on Kim: The death of Stalin or Mao Zedong released a death grip on their respective countries. You can't ignore that getting rid of natural death would make individual centralization of power a worse problem.
>How are these people currently oppressing you, and how would the existence of longevity treatments make that worse?
Just one example: Trump using sanctions to block the ICC from doing it's job (and thus letting people in Gaza die and blocking steps of justice against Israel). The fact is that the centralization of power in modern times into individual hands is already unprecedented. Old people are already ruling the world and they'd do everything to rule it forever.
I guess any user can just run something /api/getdatabase/dumppasswords and it will give any user the passwords?
or /webapp?html=<script>alert()</script> and run arbitrary JS?
I'm surprised nobody mentioned that security is a big reason not to do anything like this.
I can also recommend his other site, Analog Antiquarian[1] where he writes more about the larger history. His Magellan series that's going on now is really amazing, makes you feel like you're really experiencing the epic voyage through South America and South East Asia.
[0] https://www.filfre.net/2018/06/doing-windows-part-1-ms-dos-a...
Think of how much time is wasted because so much software that's been written but not maintained and can't be used because of how libraries have "evolved" since then.
"Cannot live without" is a strong wording, but software that I use a lot and that's mature/stable in my experience: shell (zsh, bash, sh), GNU utils, vim, nmap, xfce, git, ssh, mpv, Xorg, curl, and lots of little old CLI tools.
A: They will refuse to change the lightbulb, claiming it "doesn't scale" unless the "lightbulb problem" is fixed globally ;)
In seriousness, enjoyed this article and it's a wise realization. I think the world would be a better place if more people take the time to be a good person to the people around them, rather than focusing so much on big picture issues.
Hidden in some paragraph it does say
> Instead, PDF.js runs under the origin resource://pdf.js. This prevents access to local files, but it is slightly more privileged in other aspects.
Seems like it's not an XSS letting you take over the website origin, but it lets you run JS under this resource://pdf.js origin. Could be an interesting vector when combined with other weaknesses, but not an instant knock out as I expected when I read the title and saw the points :)
Was gonna write:
http://localhost:8888/..../..../..../..../..../..../etc/host...
mypc
These regex substitutions are so easy to bypass :)