Sign in

Luca Hammer

@luca.social.luca.run.ap.brid.gy
73 followers 3 following 675 posts

Autism. ADHD. Queer. Curious. Tired. Flew too close to the sun doing social media analysis, got burned out. Currently recovering and working as a technical account […] 🌉 bridged from ⁂ social.luca.run/@luca, follow @ap.brid.gy to interact

PostsRepliesMedia
Luca Hammer @luca.social.luca.run.ap.brid.gy · 30/09/2026
Why isn't there a Deutsche Bahn branded USB charger? Type F plug so it doesn't lose contact all the time; with all the electronics in the plug. Edit: Already exists. Not DB branded, but from Brennstuhl. www.brennenstuhl.com/de-DE/steckdos…
brennenstuhl.com
Steckdosenadapter USB C PD 20W weiß | brennenstuhl®
Mini USB C Power Delivery 20W Adapter zum Einstecken in ein Steckdosennest - Output ✓ brennenstuhl®
101
Luca Hammer @luca.social.luca.run.ap.brid.gy · 30/09/2026
I grew up in Stubaital, a valley in Austria. It was only a few years ago that I realized Wuppertal isn't a valley but a city. Why isn't it called Wupperstadt?!
011
Luca Hammer @luca.social.luca.run.ap.brid.gy · 27/09/2026
Two new achievements unlocked. - Severed a power cable by digging - Severed a water line by digging Thankfully the cable wasn't hot and the water line only connected to the rain barrel. (We had to remove a tree to make space for the heat pump and the tree cutting company was unable to use […]
social.luca.run
Original post on social.luca.run
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 19/09/2026
I have been running CachyOS for some months on the living room computer. Starting steam after booting makes it easy to operate it only with controllers. But sometimes I want to use it for other things than gaming and install updates and stuff. I don't like using a mouse on the couch and prefer […]
social.luca.run
Original post on social.luca.run
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 18/09/2026
Ich muss mich entschuldigen. Für etwa zehn Jahre habe ich immer wieder erzählt, dass ich im wahrscheinlich kleinsten Ort mit ICE-Bahnhof wohne. Gestern war ich bei @martini (aktiver unter www.instagram.com/martincreates) und der hat einfach eine […] [Original post on social.luca.run]
Deutschlandkarte mit blauen Kreisen, wo jeweils der Ortsname und die Einwohnerzahl steht.

Klanxbüll 1014
Züssow 1255
Velgast 1476
Neu-Eichenberg 1732
Bad Kleinen 3704
Binz 5049
Büchen 6733
Wabern 7262
Bützow 7745
Landstuhl 8332
Altenbeken 9161
Oberstdorf 9279
Pasewalk 9666
Tutzing 9926
212
Luca Hammer @luca.social.luca.run.ap.brid.gy · 18/09/2026
Weil es mich gerade so irritiert: Gilt die Unschuldsvermutung trotz Selbstanzeige?
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 18/09/2026
Die letzten beiden Tage war ich vor Ort, um eine Kundenveranstaltung zu unterstützen; Zum Ausgleich habe ich heute frei. Ich möchte einen esp32 mit evcc verbinden, damit darüber in Zukunft die Leistungsreduktion durch den Netzbetreiber erfolgen kann. Das Angebot für die Wärmepumpe kann endlich […]
social.luca.run
Original post on social.luca.run
130
Luca Hammer @luca.social.luca.run.ap.brid.gy · 16/09/2026
Wicked Cushions or Soulwit? Regular or gel? #headphones
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 14/09/2026
[Rassismus, Kapitalismus, Existenz] Was passiert, wenn Schwarze gedoxt werden? Ihnen wird die Wohnung gekündigt, damit der Wert der Immobilie nicht gefährdet wird. Könnte ja sein, dass Nazis sie anzünden. vm.tiktok.com/ZGdQUJ1oV
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 12/09/2026
Nächste Woche habe ich Geburtstag. Statt einer Feier bewerfe ich Vereine mit Geld. Es würde mich freuen, wenn ihr etwas dazulegt, wenn ihr es leicht könnt oder den Accounts folgt, um deren Arbeit zu verfolgen und zu verbreiten. @Freiheitsrechte "Schutzschild […] [Original post on social.luca.run]
Screenshot von sechs Überweisungen vom 12. September 2026 an die sechs im Beitrag erwähnten Organisationen. Der Überweisungsbetrag sind jeweils 161 Euro.
000
Reposted by Luca Hammer
Hrefna (DHC) @hrefna.hachyderm.io.ap.brid.gy · 10/09/2026
I think a lot of students—and unfortunately a lot of adults—think that what you learn in a degree is the _content_ of the degree, but really what you are studying is the _process_. Knowing what's in Canterbury Tales won't come up in your day to day life. As a rule no one is going to ask you to […]
hachyderm.io
Original post on hachyderm.io
2019
Luca Hammer @luca.social.luca.run.ap.brid.gy · 26/08/2026
"Andere wollen in eine fremde Stadt, um sich frei zu fühlen. Ich möchte schreiben, wo mich niemand kennt, aber ihr mich alle lest."
000
Reposted by Luca Hammer
Tatjana Scheffler @tschfflr.fediscience.org.ap.brid.gy · 22/08/2026
RE: fediscience.org/@tschfflr/117110243… Two days 😄
002
Luca Hammer @luca.social.luca.run.ap.brid.gy · 12/08/2026
Für das Handy waren die Perseiden zu schnell. Im Zeitraffer huschen Flugzeuge und Satelliten durchs Bild.
001
Luca Hammer @luca.social.luca.run.ap.brid.gy · 12/08/2026
🎶 „Alle deine Minderwertigkeitskomplexe bekommen von mir auf die Fresse“ – Sexy von ok.danke.tschüss vm.tiktok.com/ZGdxftyCC
000
Reposted by Luca Hammer
Roasting House Coffee @roastinghouse.mastodonapp.uk.ap.brid.gy · 09/08/2026
If you're a small business introducing a #ChatBot. Don't. We stand out because our service is better, we use higher quality materials, we care about every part of the product down to the glue on the envelopes (real thing, we did this). Introducing #chatbots indicates your customer's needs can […]
mastodonapp.uk
Original post on mastodonapp.uk
2512
Luca Hammer @luca.social.luca.run.ap.brid.gy · 08/08/2026
Enbee auf dem hohen Burgstall. #Tirol #Stubaital
Gehäkelte Biene in Farben der nichtbinären Flagge fliegt über einer Wolkendecke. Rundherum kommen Berge durch die Wolkendecke.
010
Luca Hammer @luca.social.luca.run.ap.brid.gy · 05/08/2026
Möchte jemand 168 Seiten „Einführung in den Fallschirmsport“ von circa 1981? Herausgegeben im Eigendruck von P. Seifried aus Graz. Wird hier gerade aussortiert. #antiquariat #fallschirmspringen #medien #Oesterreich
Gelber Einband mit Wasserfleck auf der linken Seite. Ein Bild von einem Paragleiter, darunter der Titel „Einführung in den Fallschirmsport“.Aufgeklapptes Heft. Erste Seite.

FALLSCHIRMSPRINGEN MACHT SPASSAN DER VUGEL UND DIE DER FREIE FALL IST DIE DIMENSION DER VOGEL, UND LUFTKRÄFTE AM KÖRPER ERFÜLLEN DEN TRAUM, FLIEGEN

KÖNNEN.

KAUM EINE ANDERE SPORTART BIETET EIN SO UNMITTELBARES KAUM EINE ANDERE SPORTARTEDES LUFTRAUMES SCHAUEN DIE UND WEITE DE DER GEÖFFNETE FALLSCHIRM IST EIN BUNTES, GEHORSAMES FABELTIER.

RMSPRINGEN WILL, MUSS DEN SPORT MIT WER FALLSCHIRMSPRINGEN WILL, MUSS DEN WACHEM INTERESSE LERNEN. WISSEN BEDEUTET SICHERHEIT

DIE ZIVILE AUSBILDUNG WIRD IN ÖSTERREICH VON FALLSCHIRM- SPORTVEREINEN DURCHGEFOHRT DIE FINE AUSBILDUNGSGENEHMI- GUNG BESITZEN MÜSSEN. SPORTLICHE DACHORGANISATION IST DER ÖSTERREICHISCHE AEROCLUB, DER AUCH FÜR WETTBEWERBE, REKORDE UND DIE DI VERLEIHUNG DER LEISTUNGSABZEICHEN ZU STÄNDIG IST.

DIESES HEFT ENTHÄLT DAS ZUR ERLANGUNG DER GRUNDBERECH- TIGUNG UND DEREN ERWEITERUNG ERWEITERUNG FÜR FÜR ABSPRÜNGE MIT HAND AUSGELÖSTEN FALLSCHIRMEN NÖTIGE GRUNDWISSEN. ES IST ALS UNTERLAGE FÜR DEN UNTERRICHT DURCH FS-LEHRER ES GEDACHT.

TECHNIK, TAKTIK UND TRAINING FÜR DEN WETTBEWERBSMÄSSIGEN FALLSCHIRMSPORT SIND NICHT BESPROCHEN. ZUERST GILT ES, SICHERER LUFTFAHRER ZU WERDEN IN EINEM LUFTRAUM, DER IMMER DICHTER FREQUENTIERT WIRD.

GLÜCK AB GUT LAND

P.SEIFRIED

Herausgeber, Eigentümer, Verleger und für den Inhalt verantwortlich: Hans P. Seifried, A-8042 Graz, St. Peter Hauptstraße 29e/XI Tel.0316 45 42 42. EigendruckInhaltsverzeichnis.

2

INHALT:

1. ERSTSPRUNGVORBEREITUNG

1.1 RECHTLICHE VORAUSSETZUNGEN

1.2

SPRUNGAUSRÜSTUNG

1.3

ORIENTIERUNG IN DER SPRUNGZONE

1.4 ABSETZFLUGZEUG

1.5

EINSTEIGEN UND AUSSTEIGEN, ABSPRUNGHALTUNG KAPPENKONTROLLE, ORIENTIERUNG, STEUERUNG

1.6 LANDEN

1.7

STÖRUNGEN

1.8 HINDERNISLANDUNGEN

2. ORGANISATION EINES SPRUNGBETRIEBES

3. BESTIMMUNG DES ABGANGSPUNKTES

4. ZIELFAHREN

5. ABSPRÜNGE MIT HANDAUSGELÖSTEM FS

EINWEI SUNG

5.1 5.2 ZEIT

5.3

LAGE

5.4 GESCHWINDIGKEIT

5.5

INSTRUMENTE

5.6

FLASH

5.7

GEFAHREN

5.8

LAGEÄNDERUNGEN

5.9

KAPPENTRENNUNG CUTAWAY-VERFAHREN

ANHANG: AUTOMATISCHE AUSLÖSER

6. FALLSCHIRMKUNDE

6.1

ΕΙΝΤEILUNG DER FS

6.2

BAUTEILE

131.6.3

6.4

RUNDKAPPEN RUNDKAPPENGLEITER

6.5

FLÄCHENGLEITER

6.7

ZULASSUNG UND FS-PAPIERE

6.8 WARTUNG UND LAGERUNG

7. AERODYNAMIK DER FLÄCHENGLEITER

6.9

KONTROLLPUNKTE UND STORQUELLEN

7.1 AUFTRIEB

7.2

FLUGEIGENSCHAFTEN

7.3

WETTEREINFLÜSSE

7.4

LANDEE INTEILUNG

7.5

UMSTEIGEN AUF EINEN FLÄCHENGLEITER

8. RECHTSVORSCHRIFTEN

8.1 LUFTFAHRTGESETZ✓

8.2

ZLPV = ZIVILLUFTFAHRTPERSONALVERORDNUNG

8.3 LUFTVERKEHRSREGELN

8.4

SUCH- UND RETTUNGSDIENSTVERORDNUNG

8.5

ZIVILFLUGPLATZVERORDNUNG

8.6

ZIVILFLUGPLATZBETRIEBSORDNUNG

8.7 AIP

8.8 ANHANG

9. WETTERKUNDE

9.1 WIND

9.2 WOLKEN

9.3 TEMPERATUR

9.4 LUFTDRUCK

9.5

HÖHENMESSER

9.6 GEBIRGSSPRÜNGE

10. ANMERKUNGEN ZUR ERSTEN HILFE1.

2.

ERSTSPRUNGEINWEISUNG: PROFLISTE ÜBER ERHALTENE INFORMATIONER

1.

RECHTLICHE VORAUSSETZUNGEN

FLUGSCHÜLERAUSWEIS, SCHULE, FS-LEHRER

AUSRÜSTUNG ERSTSPRUNG-FS: HAUPTGERÄT, RESERVE TYPE, AUSLÖSUNG, FUNKTION, GURTZEUGANPASSUNG

3. ORIENTIERUNG FS-ZENTRUM (VEREINSBEREICH), PACKZONE SPRUNGZONE, VERHALTEN AM FLUGPLATZ, PLATZBEGRENZUNG, HINDERNISSE

3

ABSETZFLUGZEUG TYPE, CHARAKTERISTIKA, GEFAHRENBEREICH

SPRUNGVERLAUF 5.

CHECK

EINSTEIGEN

FLUG

KOMMANDOS

AUSSTEIGEN

HALTUNG

6.

ZÄHLEN

1.1

KAPPENKONTROLLE

ORIENTIERUNG AM FS

1.2

AUSWEICHEN VON

HINDERNISSEN

buul1.5

1.6

LANDEN

LANDEFALL, SPRUNGBESPRECHUNG


7. STÖRUNGEN:

VERHINDERUNG ERKENNUNG BEURTEILUNG

VERFAHREN KOLLISIONEN

IM FLUGZEUG ABGANG/ HÄNGENBLEIBEN

SLIP, STEUERUNG

FEHLÖFFNUNGEN: TRAGENDE / NICHT TRAGENDE

SCHLEIFEN

8. HINDERNISLANDUNGEN

WALD, LEITUNG, WASSER, GEBÄUDE, BETON

9. PACK-KENNTNISSE IN DER GRUNDSCHULUNG, LAGERORDNUNG

10. PRAKTISCHE ÜBUNGEN

FS-UMSCHNALLEN + ANPASSEN, FREIKOMMEN HÄNGEGURTZEUG: SLIP, GURTEN KREUZEN, FREIKOMMEN, BS ÖFFNEN, LANDEFALL, FS AUFNEHMEN

HINWEIS: ZUR VORBEREITUNG AUF DIE PRÜFUNG ZUR ERLANGUNG DES LUFTFAHRERSCHEINES FÜR FALLSCHIRMSPRINGER KÖNNEN DIE PUNKTE FRAGEN ZUR PRÜFUNG DES ERARBEITETEN INFORMATIONSSTANDES GELTEN DES INHALTSVERZEICHNISSES UND DIE ABSATZÜBERSCHRIFTEN ALS O = KENNZEICHNUNG VON NICHT BEI DER PRÜFUNG BENÖTIGTEN INFOS
002
Reposted by Luca Hammer
Safeguarding Research/Culture @safeguardingresearch.fedihum.org.ap.brid.gy · 04/08/2026
We got another safeguarding request, this time about #reddit data: Since 2015, Pushshift has been collecting public reddit data and made it accessible to researches via academictorrents. But in late July, they were asked to take them down and complied. The torrent-metadata was/is still […]
fedihum.org
Original post on fedihum.org
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 01/08/2026
Ruetz Katarakt in slow motion. I could watch water fall for hours. #tyrol #austria
011
Reposted by Luca Hammer
Henrik Schönemann @lavaeolus.fedihum.org.ap.brid.gy · 30/07/2026
Diese Nachricht des (antiquarisch) Bücher kaufen, für Trainingsdaten scannen und dann vernichten geht schon eine Weile durch meine Timeline: Vor ein paar Wochen auf deutsch, seit ein paar Tagen auf englisch Gibt es, vielleicht direkt aus der Bibliotheks-/Archiv-Bubble, Texte dazu? Also […]
fedihum.org
Original post on fedihum.org
031
Reposted by Luca Hammer
Henrik Schönemann @lavaeolus.fedihum.org.ap.brid.gy · 31/07/2026
Sammlung von Antworten & sonst relevanten Takes: - @Lambo openbiblio.social/@Lambo/1167977897… - @dbellingradt hcommons.social/@dbellingradt/11700… - @Lapizistik social.tchncs.de/@Lapizistik/117008… - @corinnaehlers […]
fedihum.org
Original post on fedihum.org
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 30/07/2026
„Wir fordern deshalb: Sexuelle Identität als Diskriminierungsmerkmal im Grundgesetz Artikel 3 aufnehmen!“ weact.campact.de/petitions/schutz-q…
003
Reposted by Luca Hammer
Anne Wizorek @marthadear.zirk.us.ap.brid.gy · 27/07/2026
content note: #CSDBerlin, trauer gut für euch, wenn ihr eure trauer direkt in wut und „jetzt erst recht!“ umwandeln könnt. ich persönlich kriege die traurigkeit kaum zu fassen und fühle mich verletzlich wie lange nicht mehr. deshalb an alle fellow queer people, denen es ähnlich geht: es ist […]
zirk.us
Original post on zirk.us
014
Reposted by Luca Hammer
Henrik Schönemann @lavaeolus.fedihum.org.ap.brid.gy · 26/07/2026
Filtering & muting are acts of self-protection: fedi.tips/filtering-your-timeline-t… You can set expiry dates & automatically put content behind a CW or supress it completely. This is neither neglect nor ignorance but self-protection. Everyone process […]
fedihum.org
Original post on fedihum.org
013
Luca Hammer @luca.social.luca.run.ap.brid.gy · 26/07/2026
[Tod, Gewalt] Meine Gedanken sind bei den Angehörigen und allen queeren Menschen. Ein Fahrzeug wurde gestern in den CSD Berlin gelenkt. Eine Person wurde getötet, drei schweben in Lebensgefahr, dreizehn weitere wurden verletzt.
012
Luca Hammer @luca.social.luca.run.ap.brid.gy · 25/07/2026
„Paws 🐾 ⏸️“ Thanks Jaime Gama.
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 24/07/2026
I can't decide if I prefer B or H. www.ecb.europa.eu/euro/banknotes/fu…
ecb.europa.eu
Future banknotes
Die Europäische Zentralbank (EZB) ist die Zentralbank der Mitgliedstaaten der Europäischen Union, die den Euro eingeführt haben. Unsere vorrangige Aufgabe ist es, Preisstabilität im Euroraum zu gewährleisten und so die Kaufkraft der gemeinsamen Währung zu erhalten.
001
Luca Hammer @luca.social.luca.run.ap.brid.gy · 17/07/2026
🎶 „Es geht um linke Straßenpolitik und nicht um Fame Ihr braucht Regeln für die Kommunikation Nicht nur Nazis und Konsorten, die in eurer Gegend woh'n Auch die Sicherheitsbehörden werden sich schnell interessier'n“ — Keine Angst von Danger Dan youtu.be/Gg-SCpXba64
018
Reposted by Luca Hammer
Robert W. Gehl @rwg.aoir.social.ap.brid.gy · 16/07/2026
Hey, #fedi and #mastodon folks: is there anyone out there who's written a guide to pulling out Mastodon About pages via the API? What I'm interested in doing is gathering About pages (including server rules). I can do this by hand (indeed, I've done this many times before!) but maybe it's time […]
aoir.social
Original post on aoir.social
106
Reposted by Luca Hammer
Jennifer X. Pumpkins 🎃 @jenyetagain.bsky.social · 13/07/2026
convincing people that computers are smart was a huge mistake. computers are exactly as stupid now as they were in 1975, they're just much faster at stupid.
371801480
Luca Hammer @luca.social.luca.run.ap.brid.gy · 11/07/2026
"Connection reachable again." Train goes chooooo.
000
Reposted by Luca Hammer
Bijan Moini @bijanmoini.de · 10/07/2026
Was man inzwischen übrigens auch ohne Vorbehalt sagen kann: Die AfD ist eine rechtsextreme Partei. Das „in Teilen rechtsextrem“ ist falsch und verharmlosend. Wer wegen dieser Aussage Probleme bekommen sollte, kann gern unser Gutachten vorlegen (und soll sich bei uns melden).
432033686
Luca Hammer @luca.social.luca.run.ap.brid.gy · 10/07/2026
Hello threejs. I don't know what I am doing, but I like that things appear on the screen.
010
Reposted by Luca Hammer
hoppla @hoppla.mas.to.ap.brid.gy · 03/07/2026
As a GP in Germany, I struggle with the claim that “people don’t want to work.” In daily practice, I see the opposite: many patients push themselves to keep working, even when they should rest. They worry about burdening colleagues, unfinished tasks, or upcoming deadlines. If we want to […]
mas.to
Original post on mas.to
01911
Luca Hammer @luca.social.luca.run.ap.brid.gy · 28/06/2026
Excess mortality. This time because of the heat wave.
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 27/06/2026
If you have a @mullvadnet account that is connected to a payment service (CC, PayPal, bank transfer), you can contact support to cancel and request a refund. #VPN #dontSupportAFascist
011
Luca Hammer @luca.social.luca.run.ap.brid.gy · 27/06/2026
I initially bought the thermal camera to identify insulation issues during winter, now I'm hunting for heat bridges and appliances that produce too much warmth. Fridge heats up the whole wall, AC sucks in air through the extractor hood exhaust, the […] [Original post on social.luca.run]
Black and white thermal image.  White area on the wall and the ceiling with a red indicator that the area is 33 °C. Blue indicator at the front of the fridge shows 26 °C.Area around the extractor hood exhaust says 31.6 °C, while the coldest point in the area is 27.8 °C.Front of dishwasher is 30.8 to 31.6 °C. A wet rag hanging on a cabinet is 24.7 °C.Surround receiver shows 37.6 °C through the mesh on top.
213
Luca Hammer @luca.social.luca.run.ap.brid.gy · 24/06/2026
Is Linux Mint still the best choice for people leaving Windows? Else I will have to go back and change the distro. Luckily they already used LibreOffice for some time, so their spreadsheets and browser look the same.
302
Luca Hammer @luca.social.luca.run.ap.brid.gy · 23/06/2026
I'm moving my followers from @Luca@vis.social to this account because I wasn't active there for too long and the account got frozen. I didn't even know that that was a thing. I could appeal it, but don't want to. I will keep a fond memory of that place.
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 20/06/2026
Ich suche einen Einbau-Backofen mit Heißluft, 2x Voll-/Teleskopauszug und Drehknöpfen. Ohne Touch, ohne App, ohne "Smart". Bisher habe ich ein einziges Modell gefunden: Respekta AB701-19 www.respekta.de/produkte/backoefen/…
010
Luca Hammer @luca.social.luca.run.ap.brid.gy · 19/06/2026
»Photovoltaik-Anlage macht Lärm „Kein glückliches Leben mehr“: Anwohner kritisieren Solarpark in Rödinghausen« Hahahaha. Heul. (Person beschwert sich über den Lüfter im Wechselrichter, der in der Nähe des Gartens steht. Regelt das nicht das Immissionsschutzgesetz?)
010
Luca Hammer @luca.social.luca.run.ap.brid.gy · 17/06/2026
Ich habe mich an Linoleumdruck probiert.
Vier bedruckte Karten auf einem Tisch. Die Motive sehen ein bisschen aus wie Schaltkreise in einer Unendlichkeitsschlaufe. Sie sind in pink und schwarz. Jeweils unten oder auf der Rückseite ist luca.run gedrucktDrei geschnitzte Linoleumstücke und eine bedruckte Karte.
041
Reposted by Luca Hammer
Raphael @rami.chaos.social.ap.brid.gy · 11/06/2026
Wenn ich ein:e freiberufliche Übersetzer:in suchen würde mit folgenden Parametern: - Englisch→Deutsch - Anwendungshandbuch einer Software - Gesamtumfang derzeit 40 Artikel viele <1500 Wörter, manche >3500 Wörter, wird schon ein paar Wochen Arbeitszeit brauchen - Hoher Qualitätsanspruch, bitte […]
chaos.social
Original post on chaos.social
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 07/06/2026
Someone shared the domains to block on the DNS level (eg pihole) to prevent ‚Bright Data‘ from using your home network for scraping, but I can't find it anymore.
000
Reposted by Luca Hammer
hex @hex.kolektiva.social.ap.brid.gy · 07/06/2026
But if *I* hijack *their* devices it's a "felony." blog.includesecurity.com/2026/06/th…
blog.includesecurity.com
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). We’re all aware of the community-level opposition happening against datacenters, aimed at improving AI capabilities, being built recently. What you might not be aware of are the distributed efforts to train AI that could be using the devices inside your home. In this post, we’re going to explore how the company Bright Data facilitates modern AI models scraping training data from the Internet using its residential proxy network. Bright Data is a data-collection company that sells access to what it markets as the world’s largest residential proxy network of 400M+ home IP addresses that its customers route web-scraping traffic through. The supply behind that network comes from an SDK: a piece of software embedded in consumer apps that, with the user’s consent, turns their phone or smart TV into one of those exit nodes. We’ll document what you, the average user, should know about what this company’s SDK does on your systems such as your mobile phone and your smart TV. We’re going to explore how their SDK works, which platforms have shipped it, and why your Internet-connected TV is the ultimate proxy for AI models looking to train on data scraped from the Internet. ### **Why This Matters Now** AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search. But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer. Krebs reported in October 2025 that _“a glut of proxies from Aisuru and other sources is fueling large-scale data harvesting efforts tied to various AI projects.”_ Academic measurement going back to 2019 shows these networks are overwhelmingly misused. The FBI issued a formal advisory earlier this year. Most of the existing press has focused on the **illegal** residential-proxy supply: botnets (Aisuru, Kimwolf), trojanized apps (HUMAN Security’s PROXYLIB disclosure), pre-infected IoT hardware (Google/Mandiant’s IPIDEA takedown). These are the bad actors. On the other hand, the legal supply side has received far less scrutiny. Today Bright Data is the largest residential proxy network in the world by its own marketing, advertising “150M+ IPs” sourced via a consent SDK embedded in partner apps. This research documents how that SDK works, which platforms have shipped it, and why the connected-TV is the ultimate residential proxy. ### **Why Connected TV (CTV) is the Ideal Proxy** Connected TV, a.k.a Smart TV, is a near-perfect residential proxy. Compared to a mobile phone: **Factor**| **Mobile phone**| **Smart TV / CTV** ---|---|--- Power| Battery most of the day| Always plugged in Network| WiFi + cellular| Always WiFi, high-speed Uptime| Intermittent| 24/7 in standby Bandwidth ceiling| Low (cellular caps)| Effectively unlimited User attention| Actively used| Often unattended Consent UI| Text on a phone screen| Text navigated via TV remote arrow keys Corporate/family oversight| Higher (MDM, mobile EDR)| Virtually none A TV never hits 1% battery, jumps between WiFi networks or gets locked when the user is asleep. Some partner publishers do disclose the Bright Data relationship in their privacy policies PlayWorks is one example. But privacy-policy disclosure is the wrong control surface for a TV. It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog, doesn’t convey that a paying Bright Data customer is about to route their scraping traffic through the user’s home internet. Petflix, a Roku app documented by The Verge, is a representative case. Its opt-in screen reads: _“To enjoy Petflix for free with fewer ads, you are allowing Bright Data to occasionally use your device’s free resources and IP address to download public web data from the internet. Bright Data will only use your IP address for approved business-related use cases. None of your personal information is accessed or collected except your IP address. Period.”_ The Petflix dialog says “occasionally.” The SDK’s publicly queryable config sets `max_bw_monthly_wifi: 200,000,000,000` bytes — a 200 GB default monthly WiFi budget. **Who Bright Data Names as Partners** Bright Data exposes a partner manifest endpoint. The endpoint is unauthenticated and anyone can fetch it. Names in the manifest that I was able to identify with high confidence from public sources: **Partner ID (from config)**| **Entity**| **Scale** ---|---|--- playworks_digital| **PlayWorks Digital Ltd**| 400+ CTV game titles; reach ~250M TV homes via Comcast, Sky, Cox, LG, Samsung, Vizio, Roku cloudtv| **CloudTV**| Integrated across 125+ TV brands and 15+ OEMs longvision_media_hong_kong_co_limited| **Longvision Media HK (LongTV)**| 5M OTT users across HK and Malaysia viber_media_s_r_l| **Viber Media S.à r.l. (Rakuten)**| 250M–820M monthly users of the Viber messenger supercent_inc| **Supercent** (Korea)| #1 Korean mobile publisher by downloads in 2023 moonfrog_labs_private_limited| **Moonfrog Labs** (Stillfront subsidiary)| ~10M MAU on Teen Patti Gold alone; acquired for $90M hola_networks| **Hola Networks**| Bright Data’s lineage parent; user base reported in the tens to ~100M+ range at peak per Hola’s own historical marketing Others (`desoline, free_time, ott_studio, global_microtrading, m_m_media, easystaff_lp`) are present but less identifiable from public sources. `bright_screensavers, bright_videos`, and `brightdata `are Bright Data’s own apps. A note on what the partner list proves: Being listed in Bright Data’s config means an integration might have existed at some point. It does _not_ by itself prove that a specific publisher’s currently-shipping app(s) includes the SDK in production. For any named publisher, per-app verification is required. What the partner list _does_ directly prove: 1. Bright Data ships this roster in an **unauthenticated public endpoint**. 2. At least three CTV-focused entities (PlayWorks, CloudTV, Longvision) monetized their user’s devices as residential proxy exit nodes. PlayWorks in particular reports CTV distribution across major TV platforms and ISPs, with reach figures in the hundreds of millions of households per its own marketing materials. ### **How does the Bright Data SDK turn a user’s device into a residential proxy exit node?** The Bright Data SDK is a publicly documented commercial product, offered to publishers via Bright Data’s SDK integration docs (with a JavaScript variant for web). What follows builds on that public surface with findings from reverse-engineering the shipping iOS framework and instrumenting 30 days of its runtime traffic. The SDK ships as an iOS framework (brdsdk.framework) inside partner apps. I reverse-engineered the binary and captured 30 days of traffic from a research fleet running the SDK inside a consent-installed partner app. #### **The Unauthenticated Config** On every launch the SDK calls: `GET <https://clientsdk.bright-sdk.com/sdk_config_ios.json>?appid=<bundle>&ver=<sdk-version>&uuid=sdk-ios-<32hex>` The endpoint is unauthenticated in any meaningful sense. The server gates only on two query parameters `appid `(an app bundle ID, which can be found in the App Store listing of the partner app) and `ver `(the SDK version string). Supply those and any randomly generated UUID, and the server returns the same response a real device gets: feature flags, idle-detection thresholds (battery %, CPU/memory ceilings, WiFi-vs-cellular rules), per-country bandwidth tiers, and the partner manifest I showcased above. Each of these branches is worth examining on its own: the idle rules that decide when your device is eligible to relay, a flag that routes peer traffic around your VPN, a map that stitches your installs across platforms into one identity, and the per-country bandwidth caps. #### **The Peer Tunnel** After config fetch, the SDK opens a persistent WebSocket to: `wss://proxyjs.brdtnet.com:443` This hostname resolves to AWS Global Accelerator IPs (3.33.193.183, 15.197.193.114 as of this writing). The TLS certificate is `CN=*.luminatinet.com` — the domain for Luminati Networks, Bright Data’s pre-2018 corporate name. The rebrand was publicly announced in 2018. Active SDK infrastructure still runs on the legacy cert, which is a useful detection pivot: the current customer-facing proxy service lives on brightdata.com-branded domains, so any luminatinet.com / brdtnet.com traffic on your network is specifically the peer-tunnel plane, not customer-side Bright Data usage. The server identifies itself as `uWebSockets: 20`. The peer endpoint requires no authentication to upgrade. The server accepts any TLS-valid WebSocket upgrade and immediately pushes the connecting client an application-layer frame with the client’s public IP echoed back. From there, a handshake unfolds: 1. **Server → client: tunnel_init** establishes the session, returns the client’s public IP. 2. **Server → client: cid_set** the server assigns the client a session-tracking identifier in the format `<IP>-<token>/ls<N>c<M>p443_<IP>_<counter>`. We confirmed this format matches the cid field present in the SDK’s captured telemetry traffic from real devices. 3. **Server → client: status_get** the server polls the device for its idle state, battery, network type, and available bandwidth. The device responds with a continuous telemetry feed: `idle, wifi_connected, mobile_connected, mobile_type` (LTE/5G), `roaming, battery_level, using_battery, screen_on, on_call, cpu_usage, mem_usage, raw_bw, bw, ipv6_supported, appid` (the host app), `sdk_version, platform`, and the assigned `cid`. This is a continuous feed of physical-device state to a third party, delivered via a consent dialog whose text is chosen by the host app publisher. 4. **Handshake complete.** Once the device reports favorable status, the server’s job-matching layer is free to push `cmd_tun` frames: individual scraping-job instructions that the SDK executes as HTTP requests against third-party sites, using the user’s residential IP as the source. Every frame on the WebSocket is plain JSON with a fixed envelope: `{"type": "ipc_call"|"ipc_post"|"ipc_result"|"ipc_error", "cmd": <command>, "cookie": <correlation-id>, "err_code": 0, "msg": { ...payload... }}` The full command vocabulary extracted from the binary and verified on the wire: **Direction**| **cmd**| **Purpose** ---|---|--- Server → Client| tunnel_init| Open session, echo public IP Server → Client| cid_set| Assign session identifier Server → Client| status_get| Poll device idle/battery/bandwidth Server → Client| cmd_tun / tun| Dispatch a scraping job Server → Client| dns| Request DNS resolution of a target Server → Client| consent| Request consent state Client → Server| status_send| Periodic heartbeat with device state Client → Server| tun_report / tun_ack / tun_fin| Relay-job lifecycle responses Client → Server| tunnel_init_decline| Decline a session Client → Server| logs| Ship diagnostic logs to server There’s no message signing, HMAC, client certificate or device attestation. Only the TLS layer and the server’s IP-reputation filter gating which peers actually receive jobs. For readers familiar with commercial malware protocol design: this is substantially less secure than typical C2. #### **When the SDK considers you “idle”** The config ships an explicit rulebook for when the device is eligible to relay someone else’s traffic: `"idle_metrics": { "ignore_screen_on": true, // relay even with the screen on "ignore_on_call": true, // relay while the user is on a phone call "max_bw_ratio": 1, "min_battery": 0.2, "wifi_on_battery": true, "min_battery_wifi": 0.2, "max_cpu_usage": 70, "max_mem_usage": 90, "mem_screen_off": true, "idle_timeout": 30, "not_idle_timeout": 10 }` The ignore_screen_on and ignore_on_call flags are notable: “idle” does not mean the user is away from the device. It means the device’s CPU, memory, and battery are within the SDK’s thresholds. A user on a phone call, actively reading the screen, is considered idle for relay purposes. #### **Cross-Platform Identity Linkage** The config also ships a dual_pairing map: ``**"dual_pairing":** { "ios_com.brd.earnapp": ["win_earnapp.com", "mac_com.earnapp"] }`` That’s a server-side map tying a user’s iOS, Windows, and macOS installations of the same brand into one entity. It’s cross-platform identity stitching documented inside a public config file.One more forward-looking field: http3_enabled: true. The SDK is already shipping the flag for QUIC-based peer transport. A future version may move the peer tunnel from TCP/443 to UDP/443, which would break any defender relying on TCP connection tracking to detect the WebSocket. #### **The Inspection Bypass** The SDK’s config ships a flag “use_netifs”: true. That flag triggers code in the SDK binary that constructs its NWConnection with a specific required interface: `en0 `(WiFi) or `pdp_ip0 `(cellular), rather than using the system default route. **On iOS, this bypasses any configured VPN’s tun0 interface entirely.** The peer tunnel does not cross a user-configured VPN, even when the rest of the app’s HTTPS traffic does. We observed this empirically. My research setup includes transparent TLS interception. It captured every HTTPS call the SDK made, except the peer tunnel to proxyjs.brdtnet.com:443, even though port 443 is explicitly redirected to the inspector. The bypass uses Apple’s documented NWParameters.requiredInterface API. It’s worth emphasizing that the SDK uses **two independent inspection bypasses** , one per plane: * **Control plane** (config fetch, telemetry pings): built on CFNetwork’s CFHTTPMessage primitives rather than URLSession/NSURLConnection. This defeats URLSessionlevel instrumentation (swizzling, network extensions, URLProtocol subclasses) commonly used in mobile app-sec tooling, while still respecting the system proxy and so remaining visible to TLS-intercepting researchers. * **Data plane** (peer tunnel): built on NWConnection with requiredInterface set to the physical interface. This is what defeats VPNs and ensures the scraping is executed from a residential IP. Both choices are legitimate Apple APIs. The combination is the interesting artifact: the data plane is invisible to VPN-based inspection _and_ the control plane is invisible to URLSession-based hooks. Researchers who rely on either single technique see only half the SDK’s behavior. For enterprise security teams running MDM, corporate-VPN-based traffic inspection, or home-router parental controls: the most sensitive channel this SDK operates is designed to go around your visibility layer. ### **The geography tiers** The config ships per-country bandwidth thresholds. Four countries get explicit non-default policies: **Country**| **Min battery to relay**| **Daily cap**| **Monthly cap** ---|---|---|--- **Uzbekistan**| **1%**| 1 GB| 30 GB **Oman**| **1%**| 1 GB| 30 GB Qatar| 20%| 40 MB| 250 MB UAE| 20%| 40 MB| 250 MB default (worldwide)| 20%| 50 MB| 500 MB Looking at the config, Uzbekistan and Oman devices are permitted to relay down to **1% battery** , with daily caps 20× the default and monthly caps 60× the default. Qatar and UAE devices are throttled _below_ default. We can only speculate as to why the tiers are drawn this way. One reading is deliberate market segmentation, relaxing limits where grid power is stable and throttling where mobile data is expensive. The default-worldwide allowance still permits **500 MB of someone else’s traffic per month** over the user’s home internet. ### **Testing Setup and Methodology** Three data sources: 1. **Thirty days of TLS-inspecting proxy captures** from iOS device running consent-installed partner apps (including XYO COIN, which embeds the Bright SDK). 2. **Static analysis of the SDK binary** (brdsdk.framework, version 1.532.120, iOS arm64). All specific Bright Data hostnames, cert fingerprints, and TLS infrastructure described are publicly observable by anyone making the same requests. No session-specific identifying data from either the research fleet or the research client appears in this document. ### **Timeline** * **May 11, 2026** – Email notice sent to privacy@brightdata.com notifying their team about the release of this blog post. No response to the notification has been received at the time of this article’s publishing. ### **Defense Approaches** The traffic leaves clear fingerprints at the network boundary, and the SDK leaves identifiable symbols in the app binary. The approaches below let you detect and block the peer tunnel — at the network level or on the device itself. Three approaches, ordered by ease of deployment: **Approach 1: DNS block** (trivial, effective for network-routed devices): proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com Blocking proxyjs.* kills the peer tunnel without affecting any customer who legitimately uses Bright Data’s customer-facing proxy service on a different domain. **Approach 2: TLS SNI filtering:** Drop or alert on TLS handshakes where server_name matches *.brdtnet.com, *.luminatinet.com, or *.luminati.io. Works at the network boundary without TLS inspection. **Approach 3: TLS certificate fingerprint:** * .brdtnet.com → SHA256 313ce4ec7d5a51e5… * .luminatinet.com → SHA256 5028612e625befea… Stable until Sectigo cert rotation (current certs valid through mid-2026). **The use_netifs caveat:** All three layers only work on traffic that crosses your network boundary. The SDK’s use_netifs binding means that on iOS, when the device is on cellular, peer traffic bypasses corporate WiFi entirely. For managed fleets, the complementary control is MDM-based app binary scanning: search installed apps for the Swift symbols BrdWebSocketFacade and BrdNetwork.DNSResolver, and prohibit apps containing them on corporate-issued devices. For household users concerned about a specific smart TV or mobile app: block the hostnames above at your router’s DNS settings (Pi-hole, NextDNS, Cloudflare Gateway, your ISP’s equivalent). — This blog post was written in partnership with our guest author and independent security researcher Buchodi. ### Share this: * Share on X (Opens in new window) X * Share on Facebook (Opens in new window) Facebook * ### Like this: Like Loading…
21048
Reposted by Luca Hammer
Anna @netzhexe.chaos.social.ap.brid.gy · 06/06/2026
So does anyone have experience with either Piler or Open Archiver, or how do other people handle this? If I had only a couple hundred mails or so on the server, I might even consider using email on my phone again, which would open up some interesting opportunities for actually dealing with all […]
chaos.social
Original post on chaos.social
000
Luca Hammer @luca.social.luca.run.ap.brid.gy · 06/06/2026
Ich feiere den Honigbienen-Influencer zum Wildbienenschutz-Influencer Arc. vm.tiktok.com/ZGd91VHb3
001
Luca Hammer @luca.social.luca.run.ap.brid.gy · 05/06/2026
Auch Mal die kleinen Artists unterstützen. #düsseldorf
Panoramaaufnahme der Merkurarena in Düsseldorf. Aufgenommen von einem Sitzplatz im oberen Rang. Am anderen Ende der Arena ist eine Bühne aufgebaut, mit dem Robbie Williams Logo. Die Ränge sind fast leer, Stehplätze am Boden zu etwa einem Drittel gefüllt.
010
Reposted by Luca Hammer
Space Hobo @spacehobo.teh.entar.net.ap.brid.gy · 29/05/2026
I actually worked at the same place as Andrew Tridgell, over a quarter-century ago. I got to know a few of the OzLabs folks during their immediate post-IBM years, and always had the highest respect for them in that way where you feel acute impostor syndrome when they're in the room. Tridge […]
teh.entar.net
Original post on teh.entar.net
66107