Sign in

Insecurity Princess 🌈💖🔥

@saraislet.infosec.exchange.ap.brid.gy
11 followers 0 following 120 posts

I write about power dynamics in engineering management Insecurity Princess. Previously led Clod Security for Netflix. Queer femme mathematician. Dismantling […] 🌉 bridged from ⁂ infosec.exchange/@saraislet, follow @ap.brid.gy to interact

PostsRepliesMedia
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 03/10/2026
RE: infosec.exchange/@saraislet/1151269… I deployed Cloud Glider, and it's been a Journey I stopped writing up individual steps as I did last year, but I can walk through some of the highlights in a new thread here It's a little overengineered, for reasons that I will try to […]
infosec.exchange
Original post on infosec.exchange
100
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 30/09/2026
"We’re also sharing a preview of specialist dots with their own identity for access management, IT-provisioned hardware, and support for deep integrations with a company’s systems of record to allow them to take on well-defined responsibilities inside organizations." IAM: dots IT: dots D&R […]
infosec.exchange
Original post on infosec.exchange
102
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 15/09/2026
Do I know anyone at the Lead Dev conference? #LDX #LDX3 #LeadDev
210
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 07/08/2026
RE: infosec.exchange/@saraislet/1124083… I was reminded of this list last night because I had an encounter with a prickly pear cactus pad, in which my shoulder just BARELY brushed what I thought were only long sturdy spikes I spent an hour with tweezers pulling dozens of tiny […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Insecurity Princess 🌈💖🔥
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 04/08/2026
Technician: so usually this end is supposed to be cool and that end is supposed to be warm, but in your case it's the other way around Me: so we have heatpump? Technician *laughs*: no you have a broken AC
211
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 31/07/2026
Tired: "promoted to customer Wired: "promoted to Skynet"
100
Reposted by Insecurity Princess 🌈💖🔥
Matthew Dockrey @attoparsec.clacks.link.ap.brid.gy · 28/07/2026
Sometimes you can't sleep until you've gotten a very silly idea out of your head.
A classic Super Mario Bros. warp zone, except the pipes run horizontally into the wall, and it says "WELCOME TO WEFT ZONE!"
12030
Reposted by Insecurity Princess 🌈💖🔥
Marc Abrahams @marcabrahams.mstdn.science.ap.brid.gy · 03/07/2026
The mathematics of the mega-MAGA fireworks: "There is a 40-minute wall of light and roar that no blink and no camera frame can resolve into individual fireworks.... The organizers seem to have arrived at the same conclusion by their own route. Their guidance calls for hearing protection for all […]
mstdn.science
Original post on mstdn.science
209
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 27/06/2026
HOW AM I ONLY NOW LEARNING THAT MARY PARKER FOLLETT WAS GAY!? #MPF
Picture of book paragraph in which "companion" is circled:
In 1926, Follett's companion, Isobel Briggs, died. Devastated by her loss, Follett later moved to London where she was to renew old acquaintances and make new friends. In 1933, after completing a series of lectures at the London School of Economics, Follett made a brief visit to Boston. While there, she had to go into hospital, and there she died in December 1933.

A brave, pioneering life ended; but her work, vital and insightful, lives on. Indeed, in practically every area when we begin to see the light, we find that Follett has already lit the pathway for us to follow. She remains startlingly modern and in many respects is still avant-garde. The assessment of Follett is unanimous: very much ahead of her time in the 1920s, she remains today, in Peter Drucker's telling phrase, the "prophet of management."
100
Reposted by Insecurity Princess 🌈💖🔥
Dan Fixes Coin-Ops @ifixcoinops.retro.social.ap.brid.gy · 25/06/2026
Fucking hell we're gonna have trillions of dollars just vanish overnight because of these coked-up weirdos aren't we
6312
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 25/06/2026
Because I plan org onsites around breaks to recharge social batteries I didn't realize this was a skill I should advertise but now I think I should find a way to fit this in my resume
000
Reposted by Insecurity Princess 🌈💖🔥
Katharine Hayhoe @katharinehayhoe.com · 23/06/2026
We have a new entry in the climate dictionary under “irony”
181219493
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 22/06/2026
I realized why I found Jared Harris so compelling as Hari Seldon in the Foundation TV series His acting reminds me of a dramatized version of John Conway, and I hadn't realized that my mental image of Hari Seldon had at some point merged with John Conway (whom I'd been lucky to see lecture in […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Insecurity Princess 🌈💖🔥
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 19/06/2026
If you run nginx, it's time to update. Some RCEs were just patched. And no, this isn't the same one from a week or two ago.
1113
Reposted by Insecurity Princess 🌈💖🔥
Martin Paul Eve @eve.gd · 18/06/2026
Accurate.
Screenshot of a social media post by Angus McIntyre (@angusm@mastodon.social). The post humorously claims that the UK government's plan to teach 10 million British children how to use VPNs could become one of the largest IT education projects ever. It jokes that experts support the scheme because peer education and incentives will help it succeed, and includes a mock quote saying that, with the rise of autocratic governments worldwide, VPN literacy is more important than ever and that the project comes at the right time. The humour derives from the implication that government internet restrictions would encourage widespread VPN use among young people.
131369437
Reposted by Insecurity Princess 🌈💖🔥
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 18/06/2026
I had this one sitting in my draft queue before I went on vacation, and forgot to hit publish. I hope nobody starved. So please enjoy my rant on hybrid signatures. keymaterial.net/2026/06/18/on-hybri…
2139
Reposted by Insecurity Princess 🌈💖🔥
Adrianna Tan @skinnylatte.hachyderm.io.ap.brid.gy · 16/06/2026
People went to the SF Giants Pride event and various players used that opportunity to write religious and homophobic messages instead Maybe they shouldn’t have gone Landen Roupp, JT Brubaker, and Ryan Walker, Sam Hentges […]
hachyderm.io
Original post on hachyderm.io
030
Reposted by Insecurity Princess 🌈💖🔥
MH Thaung @mhthaung.mastodon.scot.ap.brid.gy · 13/06/2026
I've been rather absent from the #microfiction tag. Here's a dozen of my oldest tiny stories, including the first one I ever posted. Can you guess which one it is? mhthaung.neocities.org/stories2026/…
mhthaung.neocities.org
First dozen
012
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 15/06/2026
My day is often brightened by reading #MicroFiction from Kit Bashir's ( @Unixbigot ) #PowerOnStoryToot I'm glad that people like her share their writing with the world 🥰
000
Reposted by Insecurity Princess 🌈💖🔥
Kit Bashir @unixbigot.aus.social.ap.brid.gy · 04/06/2026
“I-is that a guillotine? I thought this was going to be a bloodless revolution!” “It used to be a guillotine; we’ve removed the blade and added a rack and pinion drive instead of gravity” “Ooo-kay, so what does it do now?” “It implants a prosthetic empathy chip in the brainstem” “You […]
aus.social
Original post on aus.social
2119
Reposted by Insecurity Princess 🌈💖🔥
impfmilf @impfmilf.troet.cafe.ap.brid.gy · 15/06/2026
#Mohntag #Mohn #MohnLiebe #Bloomscrolling #Flowers Moin!
Vor einem Feld mit Wintergerste wachsen Gräser, und blühen Mohnblumen, Kamille und Schafgarbe. Ein paar Baumwipfel hinter dem Feld und bewölkter Himmel darüber.
123
Reposted by Insecurity Princess 🌈💖🔥
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 14/06/2026
@saraislet : Look at that girl's tattoo Me: sorry, missed it @saraislet : Look at those boots! Me: sorry, missed it @saraislet : Look at… Me: we're at a train station. Just assume that I'm distracted by trains.
133
Reposted by Insecurity Princess 🌈💖🔥
petersuber @petersuber.fediscience.org.ap.brid.gy · 08/06/2026
"Bots Now Outnumber Humans Online And The Internet Was Never Built For This." www.forbes.com/sites/josipamajic/20… "The culprit is not the old wave of scraper bots and search crawlers, but agentic AI… […]
fediscience.org
Original post on fediscience.org
015
Reposted by Insecurity Princess 🌈💖🔥
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 08/06/2026
This explains a lot about what I’ve been experiencing with combatting scrapers. blog.includesecurity.com/2026/06/th…
blog.includesecurity.com
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). We’re all aware of the community-level opposition happening against datacenters, aimed at improving AI capabilities, being built recently. What you might not be aware of are the distributed efforts to train AI that could be using the devices inside your home. In this post, we’re going to explore how the company Bright Data facilitates modern AI models scraping training data from the Internet using its residential proxy network. Bright Data is a data-collection company that sells access to what it markets as the world’s largest residential proxy network of 400M+ home IP addresses that its customers route web-scraping traffic through. The supply behind that network comes from an SDK: a piece of software embedded in consumer apps that, with the user’s consent, turns their phone or smart TV into one of those exit nodes. We’ll document what you, the average user, should know about what this company’s SDK does on your systems such as your mobile phone and your smart TV. We’re going to explore how their SDK works, which platforms have shipped it, and why your Internet-connected TV is the ultimate proxy for AI models looking to train on data scraped from the Internet. ### **Why This Matters Now** AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search. But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer. Krebs reported in October 2025 that _“a glut of proxies from Aisuru and other sources is fueling large-scale data harvesting efforts tied to various AI projects.”_ Academic measurement going back to 2019 shows these networks are overwhelmingly misused. The FBI issued a formal advisory earlier this year. Most of the existing press has focused on the **illegal** residential-proxy supply: botnets (Aisuru, Kimwolf), trojanized apps (HUMAN Security’s PROXYLIB disclosure), pre-infected IoT hardware (Google/Mandiant’s IPIDEA takedown). These are the bad actors. On the other hand, the legal supply side has received far less scrutiny. Today Bright Data is the largest residential proxy network in the world by its own marketing, advertising “150M+ IPs” sourced via a consent SDK embedded in partner apps. This research documents how that SDK works, which platforms have shipped it, and why the connected-TV is the ultimate residential proxy. ### **Why Connected TV (CTV) is the Ideal Proxy** Connected TV, a.k.a Smart TV, is a near-perfect residential proxy. Compared to a mobile phone: **Factor**| **Mobile phone**| **Smart TV / CTV** ---|---|--- Power| Battery most of the day| Always plugged in Network| WiFi + cellular| Always WiFi, high-speed Uptime| Intermittent| 24/7 in standby Bandwidth ceiling| Low (cellular caps)| Effectively unlimited User attention| Actively used| Often unattended Consent UI| Text on a phone screen| Text navigated via TV remote arrow keys Corporate/family oversight| Higher (MDM, mobile EDR)| Virtually none A TV never hits 1% battery, jumps between WiFi networks or gets locked when the user is asleep. Some partner publishers do disclose the Bright Data relationship in their privacy policies PlayWorks is one example. But privacy-policy disclosure is the wrong control surface for a TV. It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog, doesn’t convey that a paying Bright Data customer is about to route their scraping traffic through the user’s home internet. Petflix, a Roku app documented by The Verge, is a representative case. Its opt-in screen reads: _“To enjoy Petflix for free with fewer ads, you are allowing Bright Data to occasionally use your device’s free resources and IP address to download public web data from the internet. Bright Data will only use your IP address for approved business-related use cases. None of your personal information is accessed or collected except your IP address. Period.”_ The Petflix dialog says “occasionally.” The SDK’s publicly queryable config sets `max_bw_monthly_wifi: 200,000,000,000` bytes — a 200 GB default monthly WiFi budget. **Who Bright Data Names as Partners** Bright Data exposes a partner manifest endpoint. The endpoint is unauthenticated and anyone can fetch it. Names in the manifest that I was able to identify with high confidence from public sources: **Partner ID (from config)**| **Entity**| **Scale** ---|---|--- playworks_digital| **PlayWorks Digital Ltd**| 400+ CTV game titles; reach ~250M TV homes via Comcast, Sky, Cox, LG, Samsung, Vizio, Roku cloudtv| **CloudTV**| Integrated across 125+ TV brands and 15+ OEMs longvision_media_hong_kong_co_limited| **Longvision Media HK (LongTV)**| 5M OTT users across HK and Malaysia viber_media_s_r_l| **Viber Media S.à r.l. (Rakuten)**| 250M–820M monthly users of the Viber messenger supercent_inc| **Supercent** (Korea)| #1 Korean mobile publisher by downloads in 2023 moonfrog_labs_private_limited| **Moonfrog Labs** (Stillfront subsidiary)| ~10M MAU on Teen Patti Gold alone; acquired for $90M hola_networks| **Hola Networks**| Bright Data’s lineage parent; user base reported in the tens to ~100M+ range at peak per Hola’s own historical marketing Others (`desoline, free_time, ott_studio, global_microtrading, m_m_media, easystaff_lp`) are present but less identifiable from public sources. `bright_screensavers, bright_videos`, and `brightdata `are Bright Data’s own apps. A note on what the partner list proves: Being listed in Bright Data’s config means an integration might have existed at some point. It does _not_ by itself prove that a specific publisher’s currently-shipping app(s) includes the SDK in production. For any named publisher, per-app verification is required. What the partner list _does_ directly prove: 1. Bright Data ships this roster in an **unauthenticated public endpoint**. 2. At least three CTV-focused entities (PlayWorks, CloudTV, Longvision) monetized their user’s devices as residential proxy exit nodes. PlayWorks in particular reports CTV distribution across major TV platforms and ISPs, with reach figures in the hundreds of millions of households per its own marketing materials. ### **How does the Bright Data SDK turn a user’s device into a residential proxy exit node?** The Bright Data SDK is a publicly documented commercial product, offered to publishers via Bright Data’s SDK integration docs (with a JavaScript variant for web). What follows builds on that public surface with findings from reverse-engineering the shipping iOS framework and instrumenting 30 days of its runtime traffic. The SDK ships as an iOS framework (brdsdk.framework) inside partner apps. I reverse-engineered the binary and captured 30 days of traffic from a research fleet running the SDK inside a consent-installed partner app. #### **The Unauthenticated Config** On every launch the SDK calls: `GET <https://clientsdk.bright-sdk.com/sdk_config_ios.json>?appid=<bundle>&ver=<sdk-version>&uuid=sdk-ios-<32hex>` The endpoint is unauthenticated in any meaningful sense. The server gates only on two query parameters `appid `(an app bundle ID, which can be found in the App Store listing of the partner app) and `ver `(the SDK version string). Supply those and any randomly generated UUID, and the server returns the same response a real device gets: feature flags, idle-detection thresholds (battery %, CPU/memory ceilings, WiFi-vs-cellular rules), per-country bandwidth tiers, and the partner manifest I showcased above. Each of these branches is worth examining on its own: the idle rules that decide when your device is eligible to relay, a flag that routes peer traffic around your VPN, a map that stitches your installs across platforms into one identity, and the per-country bandwidth caps. #### **The Peer Tunnel** After config fetch, the SDK opens a persistent WebSocket to: `wss://proxyjs.brdtnet.com:443` This hostname resolves to AWS Global Accelerator IPs (3.33.193.183, 15.197.193.114 as of this writing). The TLS certificate is `CN=*.luminatinet.com` — the domain for Luminati Networks, Bright Data’s pre-2018 corporate name. The rebrand was publicly announced in 2018. Active SDK infrastructure still runs on the legacy cert, which is a useful detection pivot: the current customer-facing proxy service lives on brightdata.com-branded domains, so any luminatinet.com / brdtnet.com traffic on your network is specifically the peer-tunnel plane, not customer-side Bright Data usage. The server identifies itself as `uWebSockets: 20`. The peer endpoint requires no authentication to upgrade. The server accepts any TLS-valid WebSocket upgrade and immediately pushes the connecting client an application-layer frame with the client’s public IP echoed back. From there, a handshake unfolds: 1. **Server → client: tunnel_init** establishes the session, returns the client’s public IP. 2. **Server → client: cid_set** the server assigns the client a session-tracking identifier in the format `<IP>-<token>/ls<N>c<M>p443_<IP>_<counter>`. We confirmed this format matches the cid field present in the SDK’s captured telemetry traffic from real devices. 3. **Server → client: status_get** the server polls the device for its idle state, battery, network type, and available bandwidth. The device responds with a continuous telemetry feed: `idle, wifi_connected, mobile_connected, mobile_type` (LTE/5G), `roaming, battery_level, using_battery, screen_on, on_call, cpu_usage, mem_usage, raw_bw, bw, ipv6_supported, appid` (the host app), `sdk_version, platform`, and the assigned `cid`. This is a continuous feed of physical-device state to a third party, delivered via a consent dialog whose text is chosen by the host app publisher. 4. **Handshake complete.** Once the device reports favorable status, the server’s job-matching layer is free to push `cmd_tun` frames: individual scraping-job instructions that the SDK executes as HTTP requests against third-party sites, using the user’s residential IP as the source. Every frame on the WebSocket is plain JSON with a fixed envelope: `{"type": "ipc_call"|"ipc_post"|"ipc_result"|"ipc_error", "cmd": <command>, "cookie": <correlation-id>, "err_code": 0, "msg": { ...payload... }}` The full command vocabulary extracted from the binary and verified on the wire: **Direction**| **cmd**| **Purpose** ---|---|--- Server → Client| tunnel_init| Open session, echo public IP Server → Client| cid_set| Assign session identifier Server → Client| status_get| Poll device idle/battery/bandwidth Server → Client| cmd_tun / tun| Dispatch a scraping job Server → Client| dns| Request DNS resolution of a target Server → Client| consent| Request consent state Client → Server| status_send| Periodic heartbeat with device state Client → Server| tun_report / tun_ack / tun_fin| Relay-job lifecycle responses Client → Server| tunnel_init_decline| Decline a session Client → Server| logs| Ship diagnostic logs to server There’s no message signing, HMAC, client certificate or device attestation. Only the TLS layer and the server’s IP-reputation filter gating which peers actually receive jobs. For readers familiar with commercial malware protocol design: this is substantially less secure than typical C2. #### **When the SDK considers you “idle”** The config ships an explicit rulebook for when the device is eligible to relay someone else’s traffic: `"idle_metrics": { "ignore_screen_on": true, // relay even with the screen on "ignore_on_call": true, // relay while the user is on a phone call "max_bw_ratio": 1, "min_battery": 0.2, "wifi_on_battery": true, "min_battery_wifi": 0.2, "max_cpu_usage": 70, "max_mem_usage": 90, "mem_screen_off": true, "idle_timeout": 30, "not_idle_timeout": 10 }` The ignore_screen_on and ignore_on_call flags are notable: “idle” does not mean the user is away from the device. It means the device’s CPU, memory, and battery are within the SDK’s thresholds. A user on a phone call, actively reading the screen, is considered idle for relay purposes. #### **Cross-Platform Identity Linkage** The config also ships a dual_pairing map: ``**"dual_pairing":** { "ios_com.brd.earnapp": ["win_earnapp.com", "mac_com.earnapp"] }`` That’s a server-side map tying a user’s iOS, Windows, and macOS installations of the same brand into one entity. It’s cross-platform identity stitching documented inside a public config file.One more forward-looking field: http3_enabled: true. The SDK is already shipping the flag for QUIC-based peer transport. A future version may move the peer tunnel from TCP/443 to UDP/443, which would break any defender relying on TCP connection tracking to detect the WebSocket. #### **The Inspection Bypass** The SDK’s config ships a flag “use_netifs”: true. That flag triggers code in the SDK binary that constructs its NWConnection with a specific required interface: `en0 `(WiFi) or `pdp_ip0 `(cellular), rather than using the system default route. **On iOS, this bypasses any configured VPN’s tun0 interface entirely.** The peer tunnel does not cross a user-configured VPN, even when the rest of the app’s HTTPS traffic does. We observed this empirically. My research setup includes transparent TLS interception. It captured every HTTPS call the SDK made, except the peer tunnel to proxyjs.brdtnet.com:443, even though port 443 is explicitly redirected to the inspector. The bypass uses Apple’s documented NWParameters.requiredInterface API. It’s worth emphasizing that the SDK uses **two independent inspection bypasses** , one per plane: * **Control plane** (config fetch, telemetry pings): built on CFNetwork’s CFHTTPMessage primitives rather than URLSession/NSURLConnection. This defeats URLSessionlevel instrumentation (swizzling, network extensions, URLProtocol subclasses) commonly used in mobile app-sec tooling, while still respecting the system proxy and so remaining visible to TLS-intercepting researchers. * **Data plane** (peer tunnel): built on NWConnection with requiredInterface set to the physical interface. This is what defeats VPNs and ensures the scraping is executed from a residential IP. Both choices are legitimate Apple APIs. The combination is the interesting artifact: the data plane is invisible to VPN-based inspection _and_ the control plane is invisible to URLSession-based hooks. Researchers who rely on either single technique see only half the SDK’s behavior. For enterprise security teams running MDM, corporate-VPN-based traffic inspection, or home-router parental controls: the most sensitive channel this SDK operates is designed to go around your visibility layer. ### **The geography tiers** The config ships per-country bandwidth thresholds. Four countries get explicit non-default policies: **Country**| **Min battery to relay**| **Daily cap**| **Monthly cap** ---|---|---|--- **Uzbekistan**| **1%**| 1 GB| 30 GB **Oman**| **1%**| 1 GB| 30 GB Qatar| 20%| 40 MB| 250 MB UAE| 20%| 40 MB| 250 MB default (worldwide)| 20%| 50 MB| 500 MB Looking at the config, Uzbekistan and Oman devices are permitted to relay down to **1% battery** , with daily caps 20× the default and monthly caps 60× the default. Qatar and UAE devices are throttled _below_ default. We can only speculate as to why the tiers are drawn this way. One reading is deliberate market segmentation, relaxing limits where grid power is stable and throttling where mobile data is expensive. The default-worldwide allowance still permits **500 MB of someone else’s traffic per month** over the user’s home internet. ### **Testing Setup and Methodology** Three data sources: 1. **Thirty days of TLS-inspecting proxy captures** from iOS device running consent-installed partner apps (including XYO COIN, which embeds the Bright SDK). 2. **Static analysis of the SDK binary** (brdsdk.framework, version 1.532.120, iOS arm64). All specific Bright Data hostnames, cert fingerprints, and TLS infrastructure described are publicly observable by anyone making the same requests. No session-specific identifying data from either the research fleet or the research client appears in this document. ### **Timeline** * **May 11, 2026** – Email notice sent to privacy@brightdata.com notifying their team about the release of this blog post. No response to the notification has been received at the time of this article’s publishing. ### **Defense Approaches** The traffic leaves clear fingerprints at the network boundary, and the SDK leaves identifiable symbols in the app binary. The approaches below let you detect and block the peer tunnel — at the network level or on the device itself. Three approaches, ordered by ease of deployment: **Approach 1: DNS block** (trivial, effective for network-routed devices): proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com Blocking proxyjs.* kills the peer tunnel without affecting any customer who legitimately uses Bright Data’s customer-facing proxy service on a different domain. **Approach 2: TLS SNI filtering:** Drop or alert on TLS handshakes where server_name matches *.brdtnet.com, *.luminatinet.com, or *.luminati.io. Works at the network boundary without TLS inspection. **Approach 3: TLS certificate fingerprint:** * .brdtnet.com → SHA256 313ce4ec7d5a51e5… * .luminatinet.com → SHA256 5028612e625befea… Stable until Sectigo cert rotation (current certs valid through mid-2026). **The use_netifs caveat:** All three layers only work on traffic that crosses your network boundary. The SDK’s use_netifs binding means that on iOS, when the device is on cellular, peer traffic bypasses corporate WiFi entirely. For managed fleets, the complementary control is MDM-based app binary scanning: search installed apps for the Swift symbols BrdWebSocketFacade and BrdNetwork.DNSResolver, and prohibit apps containing them on corporate-issued devices. For household users concerned about a specific smart TV or mobile app: block the hostnames above at your router’s DNS settings (Pi-hole, NextDNS, Cloudflare Gateway, your ISP’s equivalent). — This blog post was written in partnership with our guest author and independent security researcher Buchodi. ### Share this: * Share on X (Opens in new window) X * Share on Facebook (Opens in new window) Facebook * ### Like this: Like Loading…
1220
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 02/06/2026
Unexpected oof. "People can do terrible things when they feel safe and powerful. Your father had probably gotten his way for so long that he thought he was untouchable, and that is a dangerous way for a person to feel." -Becky Chambers, The Long Way to a Small, Angry Planet
000
Reposted by Insecurity Princess 🌈💖🔥
Liam Proven @lproven.social.vivaldi.net.ap.brid.gy · 02/06/2026
"the solution might be cancelling my AI subscription" thoughts.hmmz.org/2026-05-31.html "[AI coding tech] is horrific for attention. It's a thermonuclear ADHD amplifier and I have seen the same effect in every single one of my adult friends."
thoughts.hmmz.org
vibecoding as adhd multiplier
Comments
12230
Reposted by Insecurity Princess 🌈💖🔥
Matthew Haughey @mathowie.xoxo.zone.ap.brid.gy · 28/05/2026
Today I wrote about Kentucky's bourbon bubble bursting a.wholelottanothing.org/kentuckys-b…
a.wholelottanothing.org
Kentucky’s Bourbon problem
Bourbon and Whiskey distilling is big in Kentucky and always has been. But it saw a huge surge in the early 2000s, so much so that customer demand outstripped how much Kentucky distilleries could even produce. There were several reasons for this, but personally I feel like everyone was getting
0219
Reposted by Insecurity Princess 🌈💖🔥
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 24/05/2026
The way that you, as an adult, react to creatures has a massive impact on young people watching you. If you scream when you see a bee, they will scream too. After all you have survived in this world much longer than they have and you are scared, so they need to be scared too. Even if you are […]
sauropods.win
Original post on sauropods.win
5825
Reposted by Insecurity Princess 🌈💖🔥
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 15/05/2026
I just had an opportunity to use the phrase "I admire your ability to reach that level of confidence without the inconvenience of competence" at work
8581
Reposted by Insecurity Princess 🌈💖🔥
Kit Bashir @unixbigot.aus.social.ap.brid.gy · 13/05/2026
“So uh, I don’t suppose I should call you ‘ship’ any more, in that body” “Not as a noun, no.” *snarf* “Call me Cass, love. You have slurpee in your hair.” #Tootfic #MicroFiction #PowerOnStoryToot
224
Reposted by Insecurity Princess 🌈💖🔥
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 12/05/2026
One students paper included footnotes for each "fact that ChatGPT got wrong" that was relevant. Interesting flex!
031
Reposted by Insecurity Princess 🌈💖🔥
Weird Socks @ohmu.social.seattle.wa.us.ap.brid.gy · 23/04/2026
Today in #NotTheOnion
Wired magazine headline
"Palantir Employees Starting to Wonder if They're the Bad Guys"
01036
Reposted by Insecurity Princess 🌈💖🔥
Hrefna (DHC) @hrefna.hachyderm.io.ap.brid.gy · 10/05/2026
RE: hachyderm.io/@rmondello/11655187247… I love my hardware security key _at work_. Why? Because all of the failure modes are things where my job has decided the tradeoffs are worth it, so if I lose my key or if it breaks I call and get another one by either the end of the day or […]
hachyderm.io
Original post on hachyderm.io
004
Reposted by Insecurity Princess 🌈💖🔥
catsynth / amanda c @catsynth.mstdn.social.ap.brid.gy · 09/05/2026
I did the best I could today. I will do the best I can again tomorrow.
012
Reposted by Insecurity Princess 🌈💖🔥
David August ❌👑 @davidaugust.mastodon.online.ap.brid.gy · 06/05/2026
#USpol #ballroom
screenshot of a post by colindmcintosh 4/27/26 

"Ballroom Republicans" is the perfect thing to brand them as. Every single Democrat should be repeating "Ballroom Republicans" over and over and over again. 

It is worse than "let them eat cake" — while you can't pay rent or get healthcare or find a job, the GOP is completely and utterly absorbed with building a fucking ballroom for their lavish DC parties. 

Ballroom Republicans
31263
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 07/05/2026
I had a dream that I invented a wearable fungus clothing line At first, I wasn't sure it would be practical or comfortable, but it's growing on me
1914
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 30/04/2026
Last night, I sauteed green beans in sesame oil with garlic, ginger, and chili paste. It was fantastic Other fun recent cooking experiments: ★ grilled cheese with "Vampire Slayer" garlic cheddar cheese and garam masala ★ curried red lentils from fresh turmeric, ginger, and garlic ★ chicken with […]
infosec.exchange
Original post on infosec.exchange
101
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 29/04/2026
Since the British crown jewels (the Koh-i-Noor diamond) are literally stolen, maybe "skeletons in the closet" is better terminology for security to describe an attacker's target
000
Reposted by Insecurity Princess 🌈💖🔥
Julia Evans @b0rk.social.jvns.ca.ap.brid.gy · 29/04/2026
really appreciated this post by Armin Ronacher about the importance of software archival and what might come after GitHub personally i’m not very enthusiastic about self hosting and this post helped me see why lucumr.pocoo.org/2026/4/28/before-g…
lucumr.pocoo.org
Before GitHub
Comments
2416
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 22/04/2026
Products no one asked for: "Down Detector" but for finding ducks
012
Reposted by Insecurity Princess 🌈💖🔥
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 19/04/2026
Researching Clawhub for a conference tal at the moment. It’s like they are speed running every package manager security flaw from the past 20 years 😅
231
Reposted by Insecurity Princess 🌈💖🔥
Tim W RESISTS @tim.union.place.ap.brid.gy · 18/04/2026
The "logic" of blocking content from being archived on the Wayback Machine to prevent it being used for AI training blows my mind. Locks only keep the honest people out. In this case, all you're doing is restricting access for quite probably the best, and possibly the only, long-term durable […]
union.place
Original post on union.place
014
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 10/04/2026
This is entirely accurate, and completely useless.
LinkedIn notification with Netflix logo: "You're a top applicant for Engineering Manager, Cloud Infrastructure Security at Netflix and 230+ other jobs"
010
Reposted by Insecurity Princess 🌈💖🔥
2 Spoopy 4 You @jcrabapple.dmv.community.ap.brid.gy · 03/04/2026
Sickle cell disease has just been cured for the first time in New York techfixated.com/sickle-cell-disease…
techfixated.com
Sickle cell disease has just been cured for the first time in New York
For 21 years, Sebastien Beauzile lived with a disease that shaped every part of his existence.
2423
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 02/04/2026
The long-term arc of how we approach software engineering operations and resilience and maintaining operations expertise is one of the most crucial open questions right now, but we're all too exhausted to put meaningful energy into engaging with that And then there's the further metacognition […]
infosec.exchange
Original post on infosec.exchange
101
Insecurity Princess 🌈💖🔥 @saraislet.infosec.exchange.ap.brid.gy · 01/04/2026
The best description of a kitten I've ever read: "you need to imagine that you have a toddler who can fly!"
Picture of book text: THE PERFECT KITTEN

Try to accept that your house may not always stay looking at its best, especially when your kitten is at the "running around the walls and up the curtains" stage. Put away any precious ornaments, even if they are fairly high up - you need to imagine that you have a toddler who can fly! Choose a litter box big enough for the kitten to scratch about in and become used to - the hooded type may be better than an open box, as this will prevent spillage. These boxes also often contain air fresheners, to help keep smells at bay.
000
Reposted by Insecurity Princess 🌈💖🔥
Bodil @bodil.lol · 01/04/2026
People keep assuring me that LLMs writing code is a revolution, that as long as we maintain sound engineering practices and tight code review they're actually extruding code fit for purpose in a fraction of the time it would take a human. And every damned time, _every damned time_ any of that […]
social.treehouse.systems
Original post on social.treehouse.systems
91277
Reposted by Insecurity Princess 🌈💖🔥
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 31/03/2026
Are we having fun yet? arxiv.org/abs/2603.28627
2139