Sign in

str4d

@str4d.xyz
17K followers 474 following 3K posts

Cryptography, privacy, zero knowledge, Rust, Zcash dev, gaming, hardware hackery, art appreciation. He/him. str4d.xyz abyssdomain.expert/@str4d age18f63qx4gk8x7p4lfuwwglqcan7snvp406q5vmk26g9fmpe9c799qqzzr3w

PostsRepliesMedia
Reposted by str4d
Ryan Boyd @ryanboyd.bsky.social · 21/09/2026
NEW BRAIN DROPPED
med.stanford.edu
Human brain is two separate organs, Stanford Medicine-led research finds
Stanford Health Care delivers the highest levels of care and compassion. SHC treats cancer, heart disease, brain disorders, primary care issues, and many more.
232602780
str4d @str4d.xyz · 06/09/2026
My life right now:
The "epic handshake" meme: two people gripping each other in opposing bicep curls.

Left arm: Middle-aged women looking at my twins.
Right arm: Developers testing GLM-5.3-Flash.
Handshake: "Oh, they're such good weights!"
0154
str4d @str4d.xyz · 29/08/2026
The main reason I'd want Polytoken to be open-source at this stage is to figure out why certain things don't work. Fortunately, it has a /feedback command and a very responsive developer, so I can just keep throwing my observations in there instead and forget about them.
140
str4d @str4d.xyz · 22/08/2026
Optimist: The cup is half full Pessimist: The cup is half empty Cryptographic engineer: Your RNG is broken, that's not a uniform distribution.
0132
Reposted by str4d
The Get Up Kevins @kevinnewburn.bsky.social · 10/08/2026
Happy Zero Cool Day y'all
A screenshot from the movie Hackers.  Zero Cool says that on August 10th he crashed 1507 systems in one day.
31903187
Reposted by str4d
TASBot @tas.bot · 07/08/2026
Are you at DEF CON? Do you have a spare TV or monitor? Please let @dwangoac.tas.bot know. He needs one for the Game Hacking Village.
041
str4d @str4d.xyz · 06/08/2026
Excellent article, and very interesting to read. I find it amusing that this paragraph of Chatrie is "head-scratching" from a legal perspective, when to me (both as a regular user and a professional privacy engineer) this is a pretty straightforward way to map physical privacy onto digital privacy.
Chatrie’s rejection of this argument requires close attention. According to Justice Kagan, the key question was not whether creating particular records were necessary to participate in modern life. Rather, the question was whether the records were part of a category of conventional records associated with the communications tool itself. As Justice Kagan puts it, the records deemed exempt from the third party doctrine are ones that form part of “conventional cell-phone usage.” Chatrie’s explanation of the point is worth restating in full:

The Government’s app-by-app, feature-by-feature method of granting Fourth Amendment protection misapprehends the very nature of modern cell-phone use. Pretty much everything a person does on a smartphone requires some kind of opt-in—an “affirmative act” beyond “powering up” to utilize a given app or service. Consider sending an email on Gmail, uploading a photo to Google Photos, or adding a calendar entry to Google Calendar. None happens solely by dint of the phone’s operation; each requires, as Location History does, an “optional add-on.”. And each activity, like using Location History, results in sharing information with a third-party tech company—turning over private materials to live on that company’s servers. The Government wishes to disconnect all those uses from the mere act of carrying a turned-on cell phone (the thing that generates CSLI), with only the latter receiving assured Fourth Amendment protection. But that is to imagine that all of us are living in dumb flip-phone days. The point of carrying smartphones is to use what is on them—as Carpenter said, to use the apps and “services they provide.” That is what has become a “pervasive and insistent”—even “indispensable”—”part of daily life.” And so that is what Carpenter insulated from the third-party doctrine. A cell-phone user is not to be viewed as sharing private information with third parties—which then can be freely passed on to the government—just by doing the ordinary things cell-phone users do.

It’s important to unpack this passage, as it introduces a new concept into Fourth Amendment law that is likely to be at the center of a great deal of future litigation. According to this passage, there is a category of “ordinary things cell phone users do” that, across the board, is not to be deemed voluntarily disclosed to “third-party tech companies.” Our present society has a new thing—”modern-cell phone use,” not just from “dumb flip-phone[s],” but from smartphones that come with a “conventional” and “ordinary” set of services “on them.” “Activities” associated with those conventional services are, apparently en masse, “insulated from the third-party doctrine.”

This is head-scratching paragraph, and Section III will try to puzzle through what it might mean. But the key for now is that Chatrie creates a new constitutional category of “ordinary” or “conventional” uses of technology. The “ordinary” or “conventional” uses of common devices are treated with heightened Fourth Amendment protection, apparently making even factually knowing and voluntary disclosure of those uses to “third-party tech companies” not truly voluntary as a matter of law.
173
Reposted by str4d
Jeffrey Vagle @jvagle.me · 02/08/2026
If a technology *can* be abused, it *will* be abused. This goes doubly for those in positions of power. Technology policy can be difficult, but we should never lose sight of this fact.
38233
str4d @str4d.xyz · 30/07/2026
Film you've watched more than six times with a gif. Hard mode: no Star Trek, Star Wars, LOTR, Marvel, Disney, or Ghibli.
static.klipy.com
The Italian Job Mini Cooper on Stairs
Alt: The Italian Job - Mini Cooper on Stairs
021
Reposted by str4d
ePrint Updates @eprint.ing.bot · 24/07/2026
Bob DyLean: A Framework for the Symbolic Analysis of Cryptographic Protocols in Lean (Théophile Wallez, Cas Cremers) ia.cr/2026/1493
Abstract. Over the last decades, symbolic (Dolev-Yao) methods for the analysis of security protocols have proven to be effective to analyze and establish strong guarantees for widely deployed protocols and systems, such as TLS 1.3, E-voting protocols, EMV, and MLS. On the one hand, analysis methods like Tamarin and ProVerif provide automation and support for user-defined equational theories. On the other hand, methods like DY* offer more flexible and modular reasoning, but hardcode threat models and do not support custom equational theories.

We present DyLean, a framework for the symbolic analysis of cryptographic protocols in the Lean theorem prover. Our framework comprises both a flexible general-purpose symbolic semantics, as well as a concrete proof methodology.

DyLean allows defining protocols and expected security properties; its semantics and equational theories can be customized by the user. Furthermore, the semantics are agnostic of the specific proof methodology: our goal is to provide a generic framework that can be used by the community as a foundation to develop various proof methodologies.

Moreover, we provide a concrete proof methodology inspired by DY, based on trace invariants. Thus, DyLean inherits from the qualities of DY: it is able to analyze protocols involving unbounded loops or datastructures, and is able to compose security proofs in a variety of scenarios. Our proof methodology improves on DY* by allowing for user-defined equational theories and threat models. We exercise DyLean on several focused case studies, which include protocols using merkle trees, ratcheting protocols, post-quantum protocols, and protocols analyzed under different equational theories, which demonstrates that DyLean can effectively analyze protocols with each of these features.
Image showing part 2 of abstract.
084
Reposted by str4d
Fucking Every Word @everyword.bsky.social · 20/07/2026
fucking cryptographers
111130
str4d @str4d.xyz · 19/07/2026
Finally
040
str4d @str4d.xyz · 14/07/2026
luv 2 think I'll make a quick release of a project with a new feature, and instead end up having to cut multiple bugfix releases as I find things I missed several years ago 🫠
040
str4d @str4d.xyz · 11/07/2026
My Raspberry Pi Tailscale exit node is not routing. I can't SSH in because I don't remember its password, and I don't remember which laptop I set it up from (for pubkey access). I can't change the password in the CLI because I can't find my micro HDMI adapter. Guess I'm reflashing it yet again! 🫠
9262
str4d @str4d.xyz · 09/07/2026
That was fun! I've played similar games before but not that allowed using letters multiple times; that took a bit for my brain to route through.
Smush, 9 July 2026.
306 points, pangram first, no hints.
🟨🟩🟩
🥞⭐🥞
🟩🟩🥞
010
str4d @str4d.xyz · 09/07/2026
The outcomes from this Rust rewrite that interest me: - Introduced 19 regressions, all now fixed. - Fixed 128 bugs that were present in the Zig version. - Cost $165,000 of API tokens, took 1 engineer 11 days. Not feasible for any open-source codebases, but *way* cheaper than 3 engineers for 1 year.
Pre-merge, this took 5.9 billion uncached input tokens, 690 million output tokens, and 72 billion cached input token reads — around $165,000 at API pricing. By hand, I think this would've taken 3 engineers with full context on the codebase about a year, during which time we wouldn't be able to improve Node.js compatibility, fix bugs, fix security issues or implement new features. We never would've done that. The realistic alternative was to do nothing and keep fixing the bugs at the top of this post forever.
2583
Reposted by str4d
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 08/07/2026
I don't get why anybody is listening to Jacob Applebaum. My cat has about the same expertise in cryptography, and has never been credibly accused of sexual abuse. She's also a lot cuter.
Photo of a donut with an opening showing the pitch black interior. The void has eyes
32814
str4d @str4d.xyz · 07/07/2026
oh noooooo
000
str4d @str4d.xyz · 06/07/2026
That was exhausting just to watch!
030
str4d @str4d.xyz · 06/07/2026
I am not normally a football person, but games like this one are quite exceptional.
120
str4d @str4d.xyz · 05/07/2026
What a race.
140
str4d @str4d.xyz · 04/07/2026
Every time I think I'm getting a handle on the bounds of what an AI model can handle on its own, it makes a fuckup significant enough to force me to stop what it's doing and continue hand-holding it. And I have no idea whether or not this is due to the provider making their model dumber on the fly.
1170
str4d @str4d.xyz · 01/07/2026
Did anyone set up an image/video post labeller trained on Mango Mussolini's face (and his associated cabinet)? @aendra.com maybe you have leads (or know of XBlock derivatives)?
221
str4d @str4d.xyz · 30/06/2026
Interesting artifact of the way @bsky.app does embeds: because they are stored in the post itself (via an app.bsky.embed.external record), they don't change when the article itself changes (e.g. this article has been retracted).
120
str4d @str4d.xyz · 27/06/2026
I was *certain* the images in the quoted post were GIFs of an old CRT recording until I tapped them. @bsky.app you got a stylesheet bug somewhere, your gallery is vibing a bit too hard.
131
Reposted by str4d
rahaeli @rahaeli.bsky.social · 16/06/2026
Your periodic reminder that people are *more* abusive online when they're using their "real names" than when they're using a persistent pseudonym and this effect has been replicated in literally every study that has ever been done
5350411670
str4d @str4d.xyz · 14/06/2026
The ancient contracts call us forth once more.
094
str4d @str4d.xyz · 13/06/2026
They're raising a white flag at the Kennedy center.
071
str4d @str4d.xyz · 13/06/2026
It's 5:30am in the UK and I am still watching. This is my World Cup.
051
str4d @str4d.xyz · 09/06/2026
The privacy risks (very nicely outlined herein) are one of the core motivations for the personal assistant system I'm currently building for myself. That and I really want the hackability I get from a system I fully control (Per-task encrypted secrets? Seamless local models? Cyberdeck integration?)
1134
Reposted by str4d
Sophie E. Hill @sophieehill.bsky.social · 09/06/2026
"nudity today, political speech tomorrow" In five words, @signal.org has given a more trenchant critique of government surveillance tech than 99% of UK legislators, pundits, and NGOs.
Surveillance Is Not Safety: A statement on the UK's latest threat to privacy
June 8, 2026
Children deserve to be safe, protected, and nurtured. They do not deserve surveillance, funding cuts, and cover-ups. Children also deserve their human right to privacy, as does everyone. The UK government's demand that all content on all devices sold or used in the UK be scanned on the presumption of nudity, using a dystopian combination of age verification and content scanning, will not safeguard children. It endangers us all, whilst strengthening Apple, Google, and Microsoft's market dominance and their control over our most personal information.
Forcing all UK residents to prove their age and/or have all their content scanned, simply to exercise their fundamental right to communicate, is a perilous proposition. We know that mass surveillance and censorship capabilities, however sincere-sounding the promises of those who initiate them are, never remain narrowly scoped. Once created, they will be expanded, forming a dangerous tool that will be wielded both in the UK and abroad to censor and surveil whatever they might consider "threats" or "harmful content."
Promises that this system will only run on-device are cold comfort. Wherever it runs, including the "camera" itself once it is in place on UK devices - its scope will be defined by the whims and proscriptions of the government to detect nudity today and political speech tomorrow. We know from history that once in place, there will be an inevitable authoritarian expansion of the kind of content and people these technologies will be expected to surveil.
We also know such tools will be leveraged to automatically report people to government authorities. We have already seen law enforcement agencies ask for similar widely-scoped powers which are ripe for exploitation in an increasingly tenuous political landscape.
This proposal will not keep children safe. Child safety looks like well-funded education, robust social services, a…
5213138
str4d @str4d.xyz · 09/06/2026
Fun quirk: the app.bsky.embed.images Lexicon allows at most 4 images, so this post uses a new app.bsky.embed.gallery Lexicon without that restriction. The old app doesn't know about the new Lexicon, so it doesn't show any images. Would be nice to instead see "update your app to view this content".
Screenshot of the quoted post before updating the Bluesky app. The text is the same, but the carousel of images is missing, and there is no indication that any images were supposed to be present.
140
str4d @str4d.xyz · 07/06/2026
Been a while since I had a post escape containment. Normally when I wake up to the 30+ notifications icon, it's because @eprint.ing.bot is posting 😄
171
str4d @str4d.xyz · 06/06/2026
Claude has successfuly convinced me that it is unsafe to use for large projects. It reads skills / user instructions at the start of the session, but once the project itself is in context, there is enough pressure even with 1M context that it is reliably forgetting both the skills and instructions.
3331544
str4d @str4d.xyz · 05/06/2026
Ooh, another bad Claude Code permissions failure mode from @anthropic.com: requests are a stack (LIFO) instead of a queue (FIFO). You can be in the act of pressing Enter after reviewing a request, when another request takes over the permissions UI (frequent with ultracode), and steals the approval.
1101
str4d @str4d.xyz · 30/05/2026
Claude Opus getting progressively stupider since I started using it (at 4.6) has been both frustrating, and helped me work out how to (attempt) constraining it to not make mistakes. Doesn't help that it is now ignoring the actual text of skills in favour of its own memory of them from first load...
380
str4d @str4d.xyz · 27/05/2026
Ooh, I've wanted something like this for years! Their Supercon 2024 talk has some great details about how this performance is achieved.
youtube.com
Supercon 2024: Wenting Zhang - Making E-Ink Go Fast
YouTube video by HACKADAY
1181
Reposted by str4d
Zack Whittaker @zackwhittaker.com · 23/05/2026
If someone wants to leak me a copy of this app (either .apk or .ipa), please reach out on Signal — my username is zackwhittaker.1337 — and I would be keen to run this app through Burp Suite to see how it works. Happy to grant anonymity.
govexec.com
The White House is ordering agencies to place its new app on all employees’ government phones
The newly created, often overtly political app places the Trump administration into unprecedented and “dangerous” territory, IT experts say.
231145406
str4d @str4d.xyz · 23/05/2026
This is a perfectly normal way to configure permissions for a piece of software.
A permissions setting for Claude. It allows five different ways that Claude has previously asked to check the exit code of a process. They are all slight variations on the same `echo "exit=$?"` pattern. There is no way to guarantee that Claude uses a single pattern.
2271
str4d @str4d.xyz · 19/05/2026
Been struggling for the last few years to work with lead-free solder, and I assumed it was a skill issue. Turns out I was Technically Correct: I'd accidentally recalibrated my iron 100°C lower when setting it up, so my 350°C setting was actually running just barely above the solder's melting point.
1261
Reposted by str4d
Randall Munroe @xkcd.com · 18/05/2026
Speedrun xkcd.com/3246/
Comic. [Person 1 sitting at desk typing on laptop while Person 2 with shoulder-length hair stands behind.] PERSON 1: Aw man, speedrun.com removed my world record just because I listened to lateralus and ænima to get in the flow. PERSON 2: Oh, a copyright thing? PERSON 1: No, they don’t allow tool-assisted speedruns.
145103842080
str4d @str4d.xyz · 12/05/2026
You know you're designing a good website when Claude has to look up arXiv preprints to figure out how to render it.
151
Reposted by str4d
Tyler King @tyleraking.com · 09/05/2026
This website shows you what your browser is leaking about you. sinceyouarrived.world/taken
sinceyouarrived.world
taken.
A web page that tells you what your browser gave away the moment you arrived. No login, no form, no permission. Most pages do this. None of them tell you.
491483734
str4d @str4d.xyz · 08/05/2026
I get sufficient impetus / dopamine to update the ePrint author list for cryptography.social and @eprint.ing.bot roughly every 6 months 😅 This time I got through the bot's notifications just in time for Eurocrypt (which I'd planned to attend, but plans changed). I hope everyone is having fun there!
cryptography.social
Cryptography Social
081
str4d @str4d.xyz · 07/05/2026
UK local election: voted!
080
str4d @str4d.xyz · 04/05/2026
Finally got the ADHD dopamine wall above my project table correctly Tetrised 😁 Art from @iahfy.bsky.social, @blushyspicy.bsky.social, @qtori.art, @kajin.bsky.social, @defconscavhunt.bsky.social, and @nasawebb.extwitter.link.
A wall of framed art above a desk. From top left:
- Cyber Revy, by IAHFY
- "Cosmic Cliffs" in Carina Nebula, by NASA James Webb Space Telescope
- Malevola's Might, by Kajin
- KPop Demon Hunters, by Blushy & Spicy
- Tifa Goth, by Blushy & Spicy
- Shadowheart Goth, by Blushy & Spicy
- Gangster Korra, by IAHFY
- DEF CON 30 Scavenger Hunt list
- HUNTR/X Golden, by QTori
- Punk Aerith, by QTori
- Wanted Poster, by IAHFY
- Assorted enamel pins.

On the left of the desk is a display case with hacker conference badges from MCH 2022, EMF 2024, DEF CON 30, and WHY 2025. Next to it is a blue silicon mat for circuit board soldering.
41066
Reposted by str4d
Matt Keeter @mattkeeter.com · 24/04/2026
Two-pane meme of a woman from a magazine photo.  The first picture has the word "The" superimposed on her face; the second is zoomed in on her face and has the word "What?"
513820
Reposted by str4d
Good Trailcams @goodtrailcams.bsky.social · 23/04/2026
122519581
str4d @str4d.xyz · 21/04/2026
Hi! If you're seeing this in your report queue, the report was likely created by someone using my labeler conformance testing tool. These tests always use an "other" reasonType if available. To ignore them, filter on this reason pattern: atproto-devtool conformance test <RFC3339-UTC> <16-hex-char>
tangled.org
str4d.xyz/atproto-devtool
CLI app for developers prototyping atproto functionality
010