Sign in

Étienne H

@eh0urdeba1gt.bsky.social
238 followers 925 following 68 posts

Organizer @nsec.io, Hacker, CTFs, Privacy, Research, Social Tech, Serial Expat 🗺️🧭

PostsRepliesMedia
Reposted by Étienne H
Martin Clavey @mart1oeil.eu · 02/10/2026
arXiv limite les soumissions à 2 par mois pour faire face à la submersion due à la genAI next.ink/259620/arxiv...
next.ink
arXiv limite les soumissions à 2 par mois pour faire face à la submersion due à la genAI
Submergée par les propositions d’articles générés par IA, la plus ancienne et populaire des plateformes de prépublication scientifique resserre encore…
1155
Reposted by Étienne H
Ā₦ǤĦŪĿĀ MĒṜ₭ĪĿĿ @cocoscorpse.bsky.social · 19/09/2026
Leave them in peace.
0499
Reposted by Étienne H
DG MEME @ecmemes.bsky.social · 15/09/2026
Canadian PM: "What we are looking for is a unique alliance with the European Union". 🇨🇦 🇪🇺?
14510
Reposted by Étienne H
Jules @juleswp.eurosky.social · 14/09/2026
La communauté de @wikipediafr.bsky.social a durci sa recommandation sur l'IA générative (IAg) : son usage pour la rédaction de l'encyclopédie, qui était jusqu'alors « vivement déconseillé », est désormais interdit. #AI #IA #LLM 👉 w.wiki/ERaF
Ce texte est considéré comme une recommandation dans Wikipédia. Il décrit des exigences dont le principe et le contenu sont acceptés par un grand nombre de wikipédiens.

Vous pouvez librement modifier cette page, mais il est conseillé d'utiliser la page de discussion pour proposer un changement majeur.

En résumé : L'intelligence artificielle générative (IAg) n'apporte aucune garantie sur la fiabilité, la libre réutilisation et la vérifiabilité du contenu. Son utilisation pour la rédaction des articles est donc interdite.

Sur Wikipédia en français, le principe est l'interdiction de l'utilisation de l'intelligence artificielle générative (IAg) fondée sur les grands modèles de langage (LLM) pour la rédaction des articles.

En effet, l'expérience montre que l'usage de cet outil conduit quasi-systématiquement à contrevenir aux principes fondateurs et règles de Wikipédia, en particulier la vérifiabilité du contenu. Le mésusage des IAg aboutit à l'introduction de plagiats, d'informations fausses, de sources détournées, inexistantes (hallucinations) ou de mauvaise qualité, etc.

Ce qui apparaît comme un gain de temps individuel pour les utilisateurs d'IAg, induits en erreur par l'apparente facilité d'usage de l'outil, génère en réalité une perte de temps collective et une dégradation du contenu de l'encyclopédie.

Il existe des exceptions à cette interdiction générale : l'usage des outils IAg à des fins de correction orthographique est autorisé ; leur usage raisonné à des fins d'aide à la rédaction par des contributeurs maîtrisant les règles de Wikipédia est possible à certaines conditions, détaillées plus bas.
8400176
Reposted by Étienne H
Catalin Cimpanu @campuscodi.risky.biz · 08/09/2026
Kudelski and Sekoia researchers look at how the Lazarus Group is now operating from six distinct sub-clusters after a major reorganization of the North Korean intel service two years ago www.sekoia.com/blog/beyond-... kudelskisecurity.com/research/bey...
2156
Reposted by Étienne H
Andrew Deck @andrewdeck.bsky.social · 20/08/2026
I took a look at Backstory, an experimental tool from Google DeepMind that automates parts of the image verification process. “Backstory takes an initial process that would take you 50 minutes, and it can shrink it down to three," @mikecaulfield.bsky.social told me. www.niemanlab.org/2026/08/goog...
niemanlab.org
Google’s new AI tool helps fact-checkers investigate AI fakes
Backstory automates provenance checks, reverse image searches, and context tracing to speed up verification work.
1115
Reposted by Étienne H
Sam Stepanyan @securestep9.bsky.social · 30/07/2026
#HuggingFace built an interactive replay of the #OpenAI agent that breached them: Anatomy of a frontier-lab agent intrusion. It includes 17,613 logged attacker actions across the 4.5-day campaign. Fascinating to watch 📽️ 👇 huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html
011
Reposted by Étienne H
daniel wraith @danielroe.dev · 25/07/2026
sorry, brb, just escaping my sandbox
149712
Reposted by Étienne H
Margaret Mitchell @mmitchell.bsky.social · 06/07/2026
If you haven't read this piece on language use in around AI, you definitely should. Great work from @emilymbender.bsky.social , @nannainie.bsky.social and Peter Zukerman, with solutions for what to call things we backoff to just anthropomorphising. firstmonday.org/ojs/index.ph...
Table 3: Suggestions for de-anthropomorphizing language.
Category, Alternative Strategies, Examples.

Cognizer & Products of cognition: Instead of language that locates thinking in an algorithm, describe the algorithm as performing calculations or other algorithmic operations and the people using it doing the thinking. Examples: 
artificial intelligence → probabilistic automation

hybrid intelligence → augmented human intelligence

image recognition → image labeling

speech recognition → automatic transcription

the model shows bias → the model reflects bias

model mistakes → model errors

chatbots are good at … → chatbots are good for ….
912644
Étienne H @eh0urdeba1gt.bsky.social · 31/03/2026
"So I think we’re living in the last fleeting moments where there’s any uncertainty that AI agents will supplant most human vulnerability research. Enjoy it, if that’s your thing, while you can. It’s not going to last." sockpuppet.org/blog/2026/03...
sockpuppet.org
Vulnerability Research Is Cooked
000
Reposted by Étienne H
TechCrunch @techcrunch.com · 17/03/2026
Apple's first-ever "background security improvement" fixes a vulnerability in its Safari browser running its latest software.
techcrunch.com
Apple rolls out first 'background security' update for iPhones, iPads, and Macs to fix Safari bug | TechCrunch
Apple's first-ever "background security improvement" fixes a vulnerability in its Safari browser running its latest software.
11812
Étienne H @eh0urdeba1gt.bsky.social · 14/03/2026
"The federal government may exclude ChatGPT and other AI chatbots from its upcoming online harms bill and instead rely on cabinet to regulate the technology at a later date. " thelogic.co/news/exclusi...
thelogic.co
Ottawa mulls workaround to pass online harms bill without tackling AI - The Logic
The government could ask cabinet to regulate ChatGPT and other AI systems at a later date without needing to pass fresh legislation, The Logic has learned
000
Étienne H @eh0urdeba1gt.bsky.social · 13/03/2026
Let's Encrypt rolls out DNS-PERSIST-01, a new domain ACME-like validation challenge, that is “particularly suited for environments where traditional challenge methods are impractical, such as IoT deployments, multi-tenant platforms" letsencrypt.org/2026/02/18/d...
letsencrypt.org
DNS-PERSIST-01: A New Model for DNS-based Challenge Validation
When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who ...
010
Reposted by Étienne H
Bearstech @bearstech.com · 04/02/2026
Une carte réalisée par Proton sur la dépendance des États européens aux technologies américaines 👉 proton.me/fr/busines...
carte des dépendances européennes
11812
Reposted by Étienne H
NorthSec @nsec.io · 26/01/2026
⏰ 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝗖𝗙𝗣 𝟮𝟬𝟮𝟲: 𝗗𝗲𝗿𝗻𝗶è𝗿𝗲 𝗰𝗵𝗮𝗻𝗰𝗲 𝗱'𝗲𝗻𝘃𝗼𝘆𝗲𝗿 𝘂𝗻𝗲 𝗽𝗿𝗼𝗽𝗼𝘀𝗶𝘁𝗶𝗼𝗻 • 𝗟𝗮𝘀𝘁 𝗖𝗵𝗮𝗻𝗰𝗲 𝘁𝗼 𝗦𝘂𝗯𝗺𝗶𝘁 𝗮 𝗣𝗿𝗼𝗽𝗼𝘀𝗮𝗹 (𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲𝘀/𝗪𝗼𝗿𝗸𝘀𝗵𝗼𝗽𝘀/𝗩𝗶𝗹𝗹𝗮𝗴𝗲𝘀) 👉 Submit your proposal at nsec.io/cfp before February 2nd, 2026! #NorthSec #cybersecurity #infosec #cfp
Reminder to submit a proposal for NorthSec's Call for Proposals (CfP)
012
Reposted by Étienne H
evacide @evacide.bsky.social · 02/01/2026
If you are a resident of California, the state now has a portal where you can demand deletion of your personal data from 500+ registered data brokers with a single request form, for free. consumer.drop.privacy.ca.gov
consumer.drop.privacy.ca.gov
274116455132
Reposted by Étienne H
Daniel Cuthbert @dcuthbert.bsky.social · 27/12/2025
Anyone who’s tried to capture FaceID and the scanning that happens on your iPhone, will resonate with this video Great to see Associated Press do this piece on capturing surveillance tech youtu.be/D1tyEUq2u-E?...
youtu.be
How AP photographers capture infrared technology used in surveillance
YouTube video by Associated Press
172
Reposted by Étienne H
Flef @flefgraph.bsky.social · 24/12/2025
Voici un atlas du Bluesky francophone. Avec plus de 300 000 comptes répertoriés, et 2000+ volontaires visibles. Tout visible, avec zoom et recherche, ici : ago-carto.fr/main.html?gr... PS: Il y aura une maj en janvier. Si vous n'êtes pas dedans, postez une réponse sur ce post pour être volontaire.
Et si Agoratlas realisait des atlas ?

*Cartographie avec les différentes communautés*

Atlas de la francophonie sur Bluesky :
Cartographie globale des follows
Contenant Zoom + Recherche !

Puis par communauté :
Statistiques globales
Comptes les plus visibles
Top posts

Notes : Pour respecter la vie privée de chacun, les comptes et posts visibles ne sont sélectionnés que parmi les volontairesVisuels du site "ago-carto.fr".

"Pour permettre cette publication, Jonathan Tardif a créé bénévolement le site “ago-carto.fr”, a but non commercial, permettant de diffuser des études publiques “social data” via un nouveau support."


"Sur celui-ci, vous pourrez voir ce qui se passe sur un réseau social à l’échelle du *réseau*, avec une vue englobant toutes les bulles de la langue étudiée.

Ici pour Bluesky, mais bientôt pour Youtube, TikTok..."
234566185
Reposted by Étienne H
DG MEME @ecmemes.bsky.social · 24/12/2025
Dura lex, sed lex. In the EU, a large platform can't: - pretend an account is authentic just because it paid for a verified badge - spread harmful content - prevent public data access for researchers
113145
Reposted by Étienne H
Alexandre Archambault @archambault-avocat.fr · 28/11/2025
BlueSky carte de presse, on te demande d'écrire sur l'indignation dans le monde numérique 🇫🇷 rapport à une juridiction 🇨🇦 ordonnant à un acteur 🇫🇷, ici #OVH, de filer des infos ? Avant de pomper le papier bien putaclic heise.de/en/news/Cana..., éléments de réponse 🧵
heise.de
Canadian Court: OVHcloud from France must hand over user data
The Ontario court has ordered OVHcloud to provide data stored in its cloud. This raises questions about digital sovereignty.
144
Reposted by Étienne H
Vas Panagiotopoulos @vaspanagiotopoulos.com · 27/11/2025
New report by 🇫🇷France's National Cyber Security Agency (@anssi-fr.bsky.social) on the threat landscape for mobile phones since 2015. 👇 www.cert.ssi.gouv.fr/uploads/CERT...
0137
Étienne H @eh0urdeba1gt.bsky.social · 25/11/2025
Flare "found that 41.47% of people in a study [on infostealers] were infected through a gaming-related file (such as fake Roblox, etc)" flare.io/learn/resour...
flare.io
41% of Infostealer Victims Infected by Gaming-Related File - Flare
Infostealers have rapidly become the star of the cybercrime show, and we found that gamers are a major target of threat actors.
010
Reposted by Étienne H
Matthew Green @matthewdgreen.bsky.social · 22/11/2025
Keys are hard. www.nytimes.com/2025/11/21/w...
nytimes.com
Cryptographers Held an Election. They Can’t Decrypt the Results.
1625159
Reposted by Étienne H
Proton @proton.me · 13/11/2025
The recent Louvre breach illustrated the critical need for strong security in the world’s cultural institutions. To support cultural institutions around the world, we’re offering them 2 yrs of Proton Pass Professional for free 👇 proton.me/blog/free-password-manage…
proton.me
Free password manager for cultural institutions | Proton
To help defend our cultural heritage, Proton Pass Professional password manager plans are free for two years to qualifying organizations. Learn more.
212015
Reposted by Étienne H
Catalin Cimpanu @campuscodi.risky.biz · 10/11/2025
While AI companies are allowed to slurp everything they want, Quad9 warns that legal fees are drowning DNS resolvers, which are now being targeted by copyright owners to enforce blocks on piracy sites quad9.net/news/blog/wh...
quad9.net
Quad9 | A public and free DNS service for a better security and privacy
A public and free DNS service for a better security and privacy
17245
Reposted by Étienne H
Suave Morbida @maitre-poulard.bsky.social · 09/11/2025
Je ne sais pas quoi faire de cette infographie donc la voici
Most to Least Common 4-Digit PIN Numbers

34m analysed from multiple data breaches
918668
Reposted by Étienne H
Lukasz Olejnik @lukaszolejnik.bsky.social · 08/11/2025
My analysis of the leaked #GDPR overhaul proposal. Some changes are great. Some risk decreasing privacy protections. The changes are very far‑reaching. Tread carefully! Also, some of the proposed amendments may in fact be ... not so legit. techletters.substack.com/p/techletter...
32612
Reposted by Étienne H
Etienne - Tek @tek.randhome.io · 04/11/2025
I have been doing trainings to journalists on digital investigations with @gijn.org since 2023, and they just published a article on several investigations that used skills journalists learned in these sessions gijn.org/stories/inve...
gijn.org
How Digital Threats Training Has Powered Innovative Cyber Investigations Around the World
Alumni of GIJN's four Digital Threats training courses have produced a number of exposés on online scams and political disinformation, from India to Kenya to the Philippines.
011
Reposted by Étienne H
VIGINUM @viginum.bsky.social · 03/11/2025
#VIGINUM et Advens lancent Cyber for Good Media, un programme dédié aux journalistes pour renforcer leurs compétences en cybersécurité et en lutte contre la menace informationnelle. 🗞️ Intéressé ? Les inscriptions sont ouvertes jusqu'au 5 décembre (15 places disponibles) ➡️ cyberforgood.org/fr/media/
cyber for good media : le premier programme pour protéger les journalistes indépendants et de la PQR face à la menace informatique et informationnelle.
02112
Reposted by Étienne H
netzpolitik.org @netzpolitik.org · 04/11/2025
Scoop: We obtained vast amounts of European mobile phone location data from data brokers. It was allegedly collected for advertising purposes only, but can be used to spy on high-ranking EU officials & NATO staff in Brussels. The Commission is 'concerned' & issued new security guidance to its staff.
netzpolitik.org
Databroker Files: Targeting the EU
Precise locations and revealing movement patterns: the mobile phone location data of millions of people in the EU is up for sale. Collected supposedly only for advertising purposes, this data can also...
9169107
Reposted by Étienne H
Sebastian Meineck @sebmeineck.bsky.social · 04/11/2025
Für den neusten Teil der #DatabrokerFiles haben @roofjoke.netzpolitik.org & ich 278 Millionen Handy-Standortdaten aus Belgien ausgewertet – erhoben nur für Werbezwecke 🤡 Wieder fanden wir Bewegungsprofile bis zur Privatadresse, u.a. von EU-Spitzenpersonal. 1/x netzpolitik.org/2025/databro...
netzpolitik.org
Databroker Files: Datenhändler verkaufen metergenaue Standortdaten von EU-Personal
Exakte Ortungen, verräterische Bewegungsmuster: Die Handy-Standortdaten von Millionen Menschen in der EU stehen zum Verkauf. Angeblich nur zu Werbezwecken erhoben, lassen sich die Daten auch für Spion...
711264
Reposted by Étienne H
COcyber @cocyber.eu · 13/10/2025
🛡️ ENISA Threat Landscape 2025 is out Based on nearly 4,900 incidents across Europe, #ENISA maps a fast-evolving #cyberenvironment: ▶️ #ransomware decentralisation ▶️ #AI-driven #phishing ▶️ state-aligned espionage ▶️ industrialised #cybercrime. Full report: www.enisa.europa.eu/publications...
044
Reposted by Étienne H
Ron Deibert @rondeibert.bsky.social · 03/11/2025
Along with numerous orgs and individuals, I have signed on to an Open Letter to the 🇨🇦 Minister of AI raising serious concerns about the government's approach to AI strategy. Details are here 👇 bccla.org/policy-submi...
bccla.org
OPEN LETTER to the Minister of Artificial Intelligence and Digital Innovation from civil society organizations and individuals opposing "National Sprint" consultation on AI strategy - BC Civil Liberti...
The Honourable Mélanie JolyMinister of IndustryHouse of CommonsOttawa, OntarioK1A 0A6 The Honourable Evan SolomonMinister of Artificial Intelligence and Digital InnovationHouse of CommonsOttawa, Ontar...
52716
Étienne H @eh0urdeba1gt.bsky.social · 03/11/2025
"OpenAI has announced the launch of an "agentic security researcher" that's powered by its GPT-5 large language model (LLM) and is programmed to emulate a human expert capable of scanning, understanding, and patching code." thehackernews.com/2025/10/open...
thehackernews.com
OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
OpenAI’s GPT-5 Aardvark scans, exploits, and patches software flaws autonomously—marking a leap in AI-driven cybersecurity.
010
Reposted by Étienne H
Ron Deibert @rondeibert.bsky.social · 29/10/2025
Everyone is talking about AI. It's obviously having a transformative impact across all sectors of society. So how should the Canadian government approach it? My interview with Yvonne Lau for the @financialpost.com financialpost.com/technology/c...
financialpost.com
Canada isn't doing its part to stop AI government surveillance, UofT director says
Ronald Deibert says the ability of governments and criminal actors to surveil and target people is growing in scope thanks to AI. Read more.
22215
Étienne H @eh0urdeba1gt.bsky.social · 30/10/2025
"A trio of novel physical attacks raises new questions about the true security offered by these TEES and the exaggerated promises and misconceptions coming from the big and small players using them." arstechnica.com/security/202...
arstechnica.com
New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel
On-chip TEEs withstand rooted OSes but fall instantly to cheap physical attacks.
010
Reposted by Étienne H
Zack Whittaker @zackwhittaker.com · 23/10/2025
In case you haven't had enough cyber for one day... I'm re-upping my deep-dive blog on why ad-blockers are critical for your online security and privacy, and what threats they can help defend against. Plus, I run through some of the best ad blockers out there, for your browser and beyond.
this.weekinsecurity.com
Why ad blockers are a top security and privacy defense for everyone
Ad blockers can help defend against some of the top hacks, scams, and surveillance today. Here are some of the best ad blockers that you can use.
24315
Reposted by Étienne H
Jeff Yates @jeffyates.bsky.social · 24/10/2025
Nvidia dit maintenant vouloir construire des centres de données pour l'IA dans l'espace, avec des panneaux solaires de 4km par 4km. J'espère que les médias ne couvriront pas ceci avec crédulité, c'est absolument une farce. Ce n'est pas sérieux!
blogs.nvidia.com
How Starcloud Is Bringing Data Centers to Outer Space
The NVIDIA Inception startup projects that space-based data centers will offer 10x lower energy costs and reduce the need for energy consumption on Earth.
2259
Reposted by Étienne H
James Kettle @jameskettle.com · 24/10/2025
Google Cloud Platform was vulnerable to a HTTP desync attack leading to "responses being misrouted between recipients for certain third-party models". Aka your LLM response goes to someone else. The Expect header strikes again! Context: http1mustdie.com cloud.google.com/support/bull...
cloud.google.com
Security Bulletins  |  Customer Care  |  Google Cloud
0145
Reposted by Étienne H
Signal Infos FR @signalappfr.bsky.social · 02/10/2025
🧵 Signal introduit une avancée majeure pour son protocole de chiffrement : le Sparse Post Quantum Ratchet (SPQR), Ce mécanisme renforce le Signal Protocol face aux futures attaques quantiques, tout en conservant ses garanties existantes de secret antérieur (FS) et sécurité post-compromission (PCS).
131
Reposted by Étienne H
John Scott-Railton @jsrailton.bsky.social · 18/10/2025
NOW: US court permanently bans Pegasus spyware maker from hacking WhatsApp. NSO Group can't help their customers hack WhatsApp etc. ether. Must delete exploits & R&D. Bad news for NSO. Huge competitive disadvantage for the notorious company. Big additional win for WhatsApp 1 /
619895
Reposted by Étienne H
Evan McBroom @evanmcbroom.bsky.social · 16/10/2025
@reconmtl.bsky.social has uploaded the majority of the 2025 talks, including my talk on LSA. You can check it out at the below link if you'd like. Thank you again to the organizers and everyone else who helps put on the conference. I look forward to coming back! youtu.be/G2CfMWXLU1U?...
youtu.be
Recon 2025 - The Finer Details of LSA Credential Recovery
YouTube video by Recon Conference
0115
Reposted by Étienne H
Étienne H @eh0urdeba1gt.bsky.social · 02/10/2025
📑 Paper: "Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities" Researchers just proved that Spectre + L1TF, long assumed "mitigated", can leak TLS keys from other VMs in real-world clouds (Google Cloud, AWS). Full preprint paper: download.vusec.net/papers/rain_...
download.vusec.net
111
Étienne H @eh0urdeba1gt.bsky.social · 02/10/2025
📑 Paper: "Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities" Researchers just proved that Spectre + L1TF, long assumed "mitigated", can leak TLS keys from other VMs in real-world clouds (Google Cloud, AWS). Full preprint paper: download.vusec.net/papers/rain_...
download.vusec.net
111
Reposted by Étienne H
John Scott-Railton @jsrailton.bsky.social · 01/10/2025
NEW: turns out the EU helped finance a bunch of spyware companies with..public money. Extremely bad look. Group of MEPs calls for action.👇 apache.be/2025/10/01/e...
19263
Reposted by Étienne H
halvarflake.bsky.social @halvarflake.bsky.social · 10/09/2025
I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: security.apple.com/blog/memory-...
security.apple.com
Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our adv...
45617
Reposted by Étienne H
Pieter Haeck @pieterhaeck.bsky.social · 09/09/2025
BREAK: Dutch chips company ASML buys an 11 percent stake in French AI company Mistral - in the biggest tech sovereignty deal in a while. www.asml.com/en/news/pres...
asml.com
ASML, Mistral AI enter strategic partnership
03612
Reposted by Étienne H
NorthSec @nsec.io · 02/09/2025
📸 𝗟𝗲𝘀 𝗽𝗵𝗼𝘁𝗼𝘀 𝗼𝗳𝗳𝗶𝗰𝗶𝗲𝗹𝗹𝗲𝘀 𝗱𝗲 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝘀𝗼𝗻𝘁 𝗱𝗶𝘀𝗽𝗼𝗻𝗶𝗯𝗹𝗲𝘀! • 𝗢𝗳𝗳𝗶𝗰𝗶𝗮𝗹 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝗣𝗵𝗼𝘁𝗼𝘀 𝗔𝗿𝗲 𝗢𝘂𝘁! Revivez les meilleurs moments de NorthSec avec notre album photo officiel! ⚓️ photos.app.goo.gl/bMCHe366jdP1...
132