Sign in

Liam 🦆

@liamosaur.ragequ.it
289 followers 237 following 194 posts

Australian hacker. Foghlaimeoir Gaeilge. Tír Bundúchasach. Mar a bhí sí i gcónaí, beidh sí go deo.

PostsRepliesMedia
Liam 🦆 @liamosaur.ragequ.it · 19/01/2026
I click the "keep me logged in" checkbox Hoping that tomorrow is the day It finally does something
240
Liam 🦆 @liamosaur.ragequ.it · 07/01/2026
I always wash brand new clothes before wearing them, so don't care about wrinkles
030
Liam 🦆 @liamosaur.ragequ.it · 06/01/2026
It says a lot that this post could be about any of several other social media networks
000
Liam 🦆 @liamosaur.ragequ.it · 31/12/2025
... learning mode where I look up in the dictionary every word that I'm not sure about, then write the word and meaning in a notebook. This is why I've been working away at An Táin Bó Cúailnge for over a year - while satisfying, it's very slow progress. I've been leaning more into the other modes
000
Liam 🦆 @liamosaur.ragequ.it · 31/12/2025
As a learner, I have 3 modes when reading - one where I just want to read for enjoyment and if I don't know a word, I just guess based on the context and keep reading (Dún an Airgid). Another mode where I look up words that seem critical/interesting (Cath Fionntrá / Conaire Mór), and a dedicated...
100
Liam 🦆 @liamosaur.ragequ.it · 31/12/2025
In 2025 I read the Irish language books Dún an Airgid, Cath Fionntrá, a few chapters of Táin Bó Cúailnge (an ongoing project), and I'm halfway through Conaire Mór (only started a week ago!). My low stakes new year's resolution is to finish more than 3 Irish books in 2026
100
Liam 🦆 @liamosaur.ragequ.it · 30/12/2025
This is what happens when editors no longer have younger staff members to run headlines past before publishing. "'Bricked up' means the same thing as 'Bricked', right?" 😏
000
Liam 🦆 @liamosaur.ragequ.it · 29/12/2025
Lisdexamfetamine is way more! AU$31.50 for 30, but that's subsidised under the Pharmaceutical Benefits Scheme. Without PBS the full price is nearly AU$100
010
Liam 🦆 @liamosaur.ragequ.it · 29/12/2025
The full retail price (i.e. not govt subsidised) of 100x5mg of dex is AU$11.99 in Australia. US drug prices are an absolute scam and in no way reflect global market prices
120
Liam 🦆 @liamosaur.ragequ.it · 26/12/2025
What sort of irony is it when the age verification system doesn't work because of your long white beard?
031
Liam 🦆 @liamosaur.ragequ.it · 26/12/2025
In Australia, boxing day is the traditional start of a cricket test match played in Melbourne. The slowest, longest form of the game, perfect for half-watching from the couch. In fact many people have been known to watch it while napping
130
Liam 🦆 @liamosaur.ragequ.it · 25/12/2025
"no worries, I can chop all the salad" - the words of a man who thinks he's getting off Xmas meal prep lightly until he remembers that he's in a holiday rental and all the knives are blunt as a hammer
100
Liam 🦆 @liamosaur.ragequ.it · 24/12/2025
I feel l flew Ryanair for the first time this year and didn't hate it, because they didn't try to pretend to be anything other the cheapest airline out there. Want to use the overhead locker? Pay more
120
Liam 🦆 @liamosaur.ragequ.it · 23/12/2025
(also I often use this story as a metaphor when trying to talk to men who don't understand or appreciate the additional baseline stress that a lot of non-men carry just existing in spaces where potentially untrustworthy men are present, and the corresponding need for safe spaces)
030
Liam 🦆 @liamosaur.ragequ.it · 23/12/2025
A Zimbabwean coworker once told me about the anxiety she didn't realise she was carrying in Zim/ZA until she moved to Australia and could feel her phone vibrate and get it out immediately without needing to check her surroundings for potential thieves. It's something I think about a lot
220
Reposted by Liam 🦆
Kawaiicon @kawaiicon.bsky.social · 23/12/2025
Wanna re-live the ✨kawaii ✨ magic? Well lucky ducks, guess what we have prepared! All of the Kawaiicon 3 talks are up on YouTube! Check em out! youtube.com/@kawaiiconnz
youtube.com
Kawaiicon NZ
New Zealand's cute infosec con (& book publishers) ✨
15223
Liam 🦆 @liamosaur.ragequ.it · 21/12/2025
"If you have a soft backpack, please place it under the seat in front of you" With respect - fuck no. I took the time to check my larger bag. I'm 6'3". The only thing going under the seat in front is my feet. I'm not going to be punished because I didn't bring the biggest allowable cabin bag
130
Liam 🦆 @liamosaur.ragequ.it · 19/12/2025
your knowledge of antipodean drinking-vessel size controversies is impressive and I apologise for ever doubting you
120
Liam 🦆 @liamosaur.ragequ.it · 18/12/2025
This was probably a pure accident but this is an absolutely devastating comeback question to ask of a South Australian
330
Liam 🦆 @liamosaur.ragequ.it · 17/12/2025
Stop trying to force AI into everything - web browser edition
000
Liam 🦆 @liamosaur.ragequ.it · 17/12/2025
120
Liam 🦆 @liamosaur.ragequ.it · 17/12/2025
Holy shit, haven't heard that one in a good while
110
Reposted by Liam 🦆
Zora O'Neill @zoraoneill.com · 17/12/2025
Don’t forget the Segway!
715532
Reposted by Liam 🦆
Courtney Milan @courtneymilan.com · 13/12/2025
The funny thing is there are absolutely traits skills and characteristics that financially super successful people have and they are: money being born into money knowing other people with money
502331484
Liam 🦆 @liamosaur.ragequ.it · 12/12/2025
Just in case I'm kicked in the head by a horse in the future and decide I want to revisit the US, this is a pre-emptive declaration that the current administration is insane, harmful and is getting worse. Chilling effects on free speech can get fucked🖕 www.theguardian.com/us-news/2025...
theguardian.com
Tourists to US would have to reveal five years of social media activity under new Trump plan
Plan would apply to countries not currently required to get visas to the US, including Britain and France
020
Reposted by Liam 🦆
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 11/12/2025
We’ve seen other orgs attempt 3rd party bug bounties, thinking it will help their ecosystem become safer. Inevitably, the safety of software depends more on the maturity of the org producing it than how many bugs are reported to it. Bug foie gras isn’t the safest path to maturity
0317
Reposted by Liam 🦆
Kat Abughazaleh @katmabu.bsky.social · 10/12/2025
Requiring foreign visitors to hand over 5 years of social media isn’t “security,” it’s unchecked government control. All-seeing surveillance systems don’t make us safer. They are in direct opposition to our civil liberties. www.nbcnews.com/politics/tru...
nbcnews.com
Foreign tourists could be required to disclose 5 years of social media histories under Trump administration plan
The Customs and Border Protection proposal would apply even to countries that don't require visas to enter.
1139126233845
Liam 🦆 @liamosaur.ragequ.it · 10/12/2025
I am sad to inform you that Calibri is now officially woke
053
Liam 🦆 @liamosaur.ragequ.it · 09/12/2025
"GenAI images look like shit hurr" isn't a great argument to make. Not because AI slop doesn't look like shit (it does), but because as soon as the tech incrementally improves and looks less like shit, your main complaint has been refuted. GenAI images are shit because they're built on theft
010
Liam 🦆 @liamosaur.ragequ.it · 08/12/2025
... that's a jpeg
000
Reposted by Liam 🦆
mcc @dryad.technology · 05/12/2025
Developer attempts to replicate "Liquid Glass" in CSS, and once finished realizes what she'd actually created is an exploit for a fundamental, previously unknown, and rather serious browser vulnerability lyra.horse/blog/2025/12... "CSS hack accidentally becomes regular hack"
lyra.horse
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
242013574
Liam 🦆 @liamosaur.ragequ.it · 01/12/2025
ASD's social media team launch an attempt to get another category added to the #hacklore "this is not a realistic threat, please stop worrying about this" list 😔 I find this advice inexplicable and hard to align with any real-world threats
242
Reposted by Liam 🦆
Mekka Okereke @mekka.mekka-tech.com · 07/11/2025
While US venture capitalists were buying monkey jpegs, and DOGE coins, and figuring out how to get Black women fired, and tweeting about white birthrates, and trying to mandate which bathroom trans kids should use, China was making progress on climate change and taking the lead in a real industry.
272531802
Liam 🦆 @liamosaur.ragequ.it · 30/11/2025
For some dumb reason "you can just add Szechuan pepper to the sauce" had never occurred to me before this conversation. Freshly pounded peppercorns, laoganma crispy chilli oil, black vinegar, soy + a pack of hoisin duck dumplings straight from the freezer. Took less than 10 minutes to cook
110
Reposted by Liam 🦆
Rob Delaney @robdelaney.bsky.social · 29/11/2025
Bong Joon Ho hit me up for the squad you legend deadline.com/2025/11/bong...
Bong Joon Ho took a characteristically radical approach when questioned on his thoughts around the rise of Al technology at the jury press conference of the Marrakech Film Festival on Saturday.
The Korean director, who is president of the jury, gave two responses, one measured, the other deeply personal.
"My official answer is, Al is good because it's the very beginning of the human race finally seriously thinking about what only humans can do. But my personal answer is, I'm going to organize a military squad, and their mission is to destroy AI," he said.
4589592545
Liam 🦆 @liamosaur.ragequ.it · 29/11/2025
I had this or v similar mid-year, it fuckin suuuuuucks. Thoughts are with you. Oxymetazoline spray helped me a lot
010
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
Putting the OWASP Top 10 together is hard work, and everyone's a critic. It's still a very useful list, and I have massive respect to everyone who contributes to OWASP 💜 Including their awesome cheatsheet on how to create secure File Upload components! cheatsheetseries.owasp.org/cheatsheets/...
cheatsheetseries.owasp.org
File Upload - OWASP Cheat Sheet Series
Website with the collection of all the cheat sheets of the project.
010
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
In fact, a developer could invest a bunch of time learning the Top10 in depth, but if asked "what are some common real-world scenarios that devs need to worry about?" would be unlikely to say "Insecure File Uploads", despite them being a common source of critical vulns. This is a problem.
110
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
...if you can upload executables that run on the webserver, it's a Broken Access Control. If I can overwrite a binary, it's a Software Integrity Failure etc. etc. While this categorisation is academically interesting, it's not helpful to a developer trying to understand what they need to worry about
100
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
So which OWASP Top10 category do Insecure File Uploads fall into? Well the answer is "it's complicated and depends...". What it depends on is often the impact - if the file upload leads to XSS, it's an Injection vuln. If it can bypass file type check controls, it's a Security Misconfiguration...
100
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
To give a concrete example - my team did some work earlier in the year analysing data from about 2.5k pentest reports. Looking at critical issues found during webapp pentesting, this mostly matched the OWASP Top10. But there was one standout difference - our #2 issue was File Upload Vulns...
100
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
...This is OWASP's own summary of the Top10. The goal is not just abstract/academic categorisation - it's to provide an *actionable resource* to devs about what they need to be concerned about. "Be concerned about this abstract category" is not as useful advice as something more concrete would be...
100
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
Hot take about the updated OWASP Top10 - it's a great resource, but I have some concerns about the trend in categorisation. If the goal was "create categories that cover the top critical security risks to web applications", the new Top 10 would nail it. But the stated goal is slightly different...
110
Liam 🦆 @liamosaur.ragequ.it · 27/11/2025
It seems the "X, but with computers" model needs to be tested with everything, including white-collar crime. As much as some people would like to believe otherwise, algorithms (inc AI), are not an accountability sink. Collusion is still collusion. Crime is still crime
000
Liam 🦆 @liamosaur.ragequ.it · 26/11/2025
"absolutely no idea who chewed that blue thing up"
110
Liam 🦆 @liamosaur.ragequ.it · 25/11/2025
Yeah, a bunch of little reasons for me. A lot of my meetings are with clients outside of my organisation, but are set up by other people in my org. This gives those people more meeting slots to choose from. I don't care when I eat, as long as I can get a break
010
Liam 🦆 @liamosaur.ragequ.it · 25/11/2025
I got sick of meetings filling up my day around lunchtime, leaving me without a time to eat, so I wrote a Power Automate flow that detects when I'm close to having no time for lunch and auto-reserves a lunch slot in my calendar
150
Liam 🦆 @liamosaur.ragequ.it · 25/11/2025
I don't disagree that this would be useful advice for those people, but if the scope of what they're going for is "what do normies with normie threat models need to hear?", this pretty much nails it for 90% of people IMO (which is in itself a sad story - we need more low-key activists in this world)
200
Liam 🦆 @liamosaur.ragequ.it · 24/11/2025
I love everything about this letter - a list of things the general public should and shouldn't worry about when it comes to security www.hacklore.org/letter
hacklore.org
The Letter — Stop Hacklore!
121
Liam 🦆 @liamosaur.ragequ.it · 23/11/2025
I've actually found a pretty good supply of high-zing peppercorns, but sometimes if I'm having a quick meal (frozen dumplings), I ain't got time for the mortar and pestle season. The oil sounds perfect
110