Sign in

str4d

@str4d.xyz
17K followers 474 following 3K posts

Cryptography, privacy, zero knowledge, Rust, Zcash dev, gaming, hardware hackery, art appreciation. He/him. str4d.xyz abyssdomain.expert/@str4d age18f63qx4gk8x7p4lfuwwglqcan7snvp406q5vmk26g9fmpe9c799qqzzr3w

PostsRepliesMedia
str4d @str4d.xyz · 30/09/2026
The polyrhythms do wonders for my ADHD By which I mean "I wonder how I missed it for so long, given how much Tool I listen to"
110
Reposted by str4d
Ryan Boyd @ryanboyd.bsky.social · 21/09/2026
NEW BRAIN DROPPED
med.stanford.edu
Human brain is two separate organs, Stanford Medicine-led research finds
Stanford Health Care delivers the highest levels of care and compassion. SHC treats cancer, heart disease, brain disorders, primary care issues, and many more.
232600781
str4d @str4d.xyz · 09/09/2026
The fix is to set the context limit for these models to be smaller, which means the harness will trigger compaction sooner (before the hard limit is reached). oMLX lets you configure per-model settings, so you could set lower context limits just for the larger models where you encounter this error.
010
str4d @str4d.xyz · 09/09/2026
The problem is that compaction AIUI relies on being able to tell the AI to do the compaction, which means giving it an input of "current context + compaction command". That is strictly longer than the context that oMLX rejected, so compaction would also fail.
110
str4d @str4d.xyz · 09/09/2026
That likely wouldn't have helped with this error, because oMLX has a (configurable) hard-limit of what memory it will allow the model to consume. I've encountered this error when a session went for too long without compaction and the context grew long enough to cross the configured limit.
110
str4d @str4d.xyz · 08/09/2026
It would be really nice if oMLX showed somewhere "this is how much memory will be used by the maximum context size for this model" - currently you only can set this limit in "number of tokens".
010
str4d @str4d.xyz · 08/09/2026
Essentially this means that you're using too large a model. The memory you need to run the model includes: - The model weights itself (what oMLX shows on the model download tab). - The KV cache size (configurable in oMLX). - The context for your query (grows up to the per-model context limit).
200
str4d @str4d.xyz · 06/09/2026
My life right now:
The "epic handshake" meme: two people gripping each other in opposing bicep curls.

Left arm: Middle-aged women looking at my twins.
Right arm: Developers testing GLM-5.3-Flash.
Handshake: "Oh, they're such good weights!"
0154
str4d @str4d.xyz · 04/09/2026
"What do you desire?" Chips and guac. "You summoned me for something so trivial?!" Okay, fast isogenies. "Want salsa with that?"
230
str4d @str4d.xyz · 04/09/2026
Time to pull out every candlestick and candle holder you own, and create a summoning circle
110
str4d @str4d.xyz · 01/09/2026
Yes he did. This was about an hour before the post:
040
str4d @str4d.xyz · 31/08/2026
The pod will eventually need to adopt Continuous Inquiry / Continuous Discussion to keep up with the deployment rate
041
str4d @str4d.xyz · 29/08/2026
The main reason I'd want Polytoken to be open-source at this stage is to figure out why certain things don't work. Fortunately, it has a /feedback command and a very responsive developer, so I can just keep throwing my observations in there instead and forget about them.
140
str4d @str4d.xyz · 29/08/2026
ONE OF US (Soon™️)
030
str4d @str4d.xyz · 26/08/2026
The thing I actually like about Polytoken in this arena is its sane permissions model. I can actually configure it to precisely what I want, something that Claude Code seems almost obtusely insistent on preventing.
010
str4d @str4d.xyz · 22/08/2026
Optimist: The cup is half full Pessimist: The cup is half empty Cryptographic engineer: Your RNG is broken, that's not a uniform distribution.
0132
str4d @str4d.xyz · 21/08/2026
I got curious about what information `cargo install` stores. It does not record whether you used --locked, nor when you installed it (though that could be inferred from binary mtime). There's experimental sidecar-file SBOM support in nightly though.
Contents of the metadata file that `cargo install` uses to track installed binary crates. Some details about installation flags are recorded, as well as the rustc compiler used, but nothing about the dependencies.
010
str4d @str4d.xyz · 20/08/2026
Ah yep, misread which semantic part you were replying to 😅 As noted in another thread, `cargo install --locked` uses the lockfile the crate author published, instead of "latest compatible" which is what `cargo install` (currently) does. So anyone who ran the latter during the window is affected.
120
str4d @str4d.xyz · 20/08/2026
For binary installs through cargo, yep: there's zero automatic updates. You also need to use `-f/--force` to rebuild a binary with newer dependencies if the binary itself hasn't had a new release.
100
Reposted by str4d
The Get Up Kevins @kevinnewburn.bsky.social · 10/08/2026
Happy Zero Cool Day y'all
A screenshot from the movie Hackers.  Zero Cool says that on August 10th he crashed 1507 systems in one day.
31902187
Reposted by str4d
TASBot @tas.bot · 07/08/2026
Are you at DEF CON? Do you have a spare TV or monitor? Please let @dwangoac.tas.bot know. He needs one for the Game Hacking Village.
041
str4d @str4d.xyz · 07/08/2026
"We have DEFCON at home!" The DEFCON at home:
A baby playmat, nappy-changing station and rocking chair. On the wall behind them is a DEFCON flag.
180
str4d @str4d.xyz · 06/08/2026
Excellent article, and very interesting to read. I find it amusing that this paragraph of Chatrie is "head-scratching" from a legal perspective, when to me (both as a regular user and a professional privacy engineer) this is a pretty straightforward way to map physical privacy onto digital privacy.
Chatrie’s rejection of this argument requires close attention. According to Justice Kagan, the key question was not whether creating particular records were necessary to participate in modern life. Rather, the question was whether the records were part of a category of conventional records associated with the communications tool itself. As Justice Kagan puts it, the records deemed exempt from the third party doctrine are ones that form part of “conventional cell-phone usage.” Chatrie’s explanation of the point is worth restating in full:

The Government’s app-by-app, feature-by-feature method of granting Fourth Amendment protection misapprehends the very nature of modern cell-phone use. Pretty much everything a person does on a smartphone requires some kind of opt-in—an “affirmative act” beyond “powering up” to utilize a given app or service. Consider sending an email on Gmail, uploading a photo to Google Photos, or adding a calendar entry to Google Calendar. None happens solely by dint of the phone’s operation; each requires, as Location History does, an “optional add-on.”. And each activity, like using Location History, results in sharing information with a third-party tech company—turning over private materials to live on that company’s servers. The Government wishes to disconnect all those uses from the mere act of carrying a turned-on cell phone (the thing that generates CSLI), with only the latter receiving assured Fourth Amendment protection. But that is to imagine that all of us are living in dumb flip-phone days. The point of carrying smartphones is to use what is on them—as Carpenter said, to use the apps and “services they provide.” That is what has become a “pervasive and insistent”—even “indispensable”—”part of daily life.” And so that is what Carpenter insulated from the third-party doctrine. A cell-phone user is not to be viewed as sharing private information with third parties—which then can be freely passed on to the government—just by doing the ordinary things cell-phone users do.

It’s important to unpack this passage, as it introduces a new concept into Fourth Amendment law that is likely to be at the center of a great deal of future litigation. According to this passage, there is a category of “ordinary things cell phone users do” that, across the board, is not to be deemed voluntarily disclosed to “third-party tech companies.” Our present society has a new thing—”modern-cell phone use,” not just from “dumb flip-phone[s],” but from smartphones that come with a “conventional” and “ordinary” set of services “on them.” “Activities” associated with those conventional services are, apparently en masse, “insulated from the third-party doctrine.”

This is head-scratching paragraph, and Section III will try to puzzle through what it might mean. But the key for now is that Chatrie creates a new constitutional category of “ordinary” or “conventional” uses of technology. The “ordinary” or “conventional” uses of common devices are treated with heightened Fourth Amendment protection, apparently making even factually knowing and voluntary disclosure of those uses to “third-party tech companies” not truly voluntary as a matter of law.
173
Reposted by str4d
Jeffrey Vagle @jvagle.me · 02/08/2026
If a technology *can* be abused, it *will* be abused. This goes doubly for those in positions of power. Technology policy can be difficult, but we should never lose sight of this fact.
38233
str4d @str4d.xyz · 30/07/2026
Film you've watched more than six times with a gif. Hard mode: no Star Trek, Star Wars, LOTR, Marvel, Disney, or Ghibli.
static.klipy.com
The Italian Job Mini Cooper on Stairs
Alt: The Italian Job - Mini Cooper on Stairs
021
str4d @str4d.xyz · 30/07/2026
*looks at the kilometer of gravel road beyond the driveway* *sighs*
010
str4d @str4d.xyz · 29/07/2026
Nice to see Sonar helping out around the place
110
str4d @str4d.xyz · 29/07/2026
It's not scope creep IMO. The PDS is the user's authoritative data store; it needs to store data in as close to the user's intended state as possible, because it may be the only copy of said data. Actual media service is done with CDNs that cache and scale the media appropriately for each use case.
140
Reposted by str4d
ePrint Updates @eprint.ing.bot · 24/07/2026
Bob DyLean: A Framework for the Symbolic Analysis of Cryptographic Protocols in Lean (Théophile Wallez, Cas Cremers) ia.cr/2026/1493
Abstract. Over the last decades, symbolic (Dolev-Yao) methods for the analysis of security protocols have proven to be effective to analyze and establish strong guarantees for widely deployed protocols and systems, such as TLS 1.3, E-voting protocols, EMV, and MLS. On the one hand, analysis methods like Tamarin and ProVerif provide automation and support for user-defined equational theories. On the other hand, methods like DY* offer more flexible and modular reasoning, but hardcode threat models and do not support custom equational theories.

We present DyLean, a framework for the symbolic analysis of cryptographic protocols in the Lean theorem prover. Our framework comprises both a flexible general-purpose symbolic semantics, as well as a concrete proof methodology.

DyLean allows defining protocols and expected security properties; its semantics and equational theories can be customized by the user. Furthermore, the semantics are agnostic of the specific proof methodology: our goal is to provide a generic framework that can be used by the community as a foundation to develop various proof methodologies.

Moreover, we provide a concrete proof methodology inspired by DY, based on trace invariants. Thus, DyLean inherits from the qualities of DY: it is able to analyze protocols involving unbounded loops or datastructures, and is able to compose security proofs in a variety of scenarios. Our proof methodology improves on DY* by allowing for user-defined equational theories and threat models. We exercise DyLean on several focused case studies, which include protocols using merkle trees, ratcheting protocols, post-quantum protocols, and protocols analyzed under different equational theories, which demonstrates that DyLean can effectively analyze protocols with each of these features.
Image showing part 2 of abstract.
084
str4d @str4d.xyz · 25/07/2026
This is similar to my manpage localisation using Fluent: the manpage doc itself is just the structure, with IDs at all text positions. Then the Fluent files contain both the canonical source strings and all translations. If a source string changes, its ID is changed so old translations don't match.
000
str4d @str4d.xyz · 22/07/2026
Heh, I do the exact same thing in Rust, editing the source cache under ~/.cargo which my LSP will happily send my editor to.
020
Reposted by str4d
Fucking Every Word @everyword.bsky.social · 20/07/2026
fucking cryptographers
111130
str4d @str4d.xyz · 19/07/2026
Finally
040
str4d @str4d.xyz · 17/07/2026
I see they are unfamiliar with your prior work.
030
str4d @str4d.xyz · 17/07/2026
This is a branding/marketing choice by the PDS operator. They aren't forced to provide a single default handle tied to the operator identity (if the current impl does, it can be changed). They could instead provide a choice of several domains, or help users get their own domain during onboarding.
140
str4d @str4d.xyz · 17/07/2026
Which I suspect is built using the cyme library, given the developer started in this thread:
140
str4d @str4d.xyz · 17/07/2026
Hubble can probably help you figure out what is going on:
gingerbeardman.com
Hubble—Diagnose your USB problems live and direct
Hubble is a macOS utility that visualises your Mac's USB topology as an interactive canvas. Every host controller, hub, and device is mapped into a zoomable node-and-link diagram with Bezier cables co...
182
str4d @str4d.xyz · 14/07/2026
luv 2 think I'll make a quick release of a project with a new feature, and instead end up having to cut multiple bugfix releases as I find things I missed several years ago 🫠
040
str4d @str4d.xyz · 12/07/2026
I eventually found my micro HDMI cable, so I went the route of flashing a new SD card, booting to that, mounting the NVMe drive I normally use, and modifying its password. And then I looked at /etc/passwd and realised I'd been trying the correct password but typo-ing the username 🙃
1110
str4d @str4d.xyz · 11/07/2026
This starts down a similar route to what Apple does with device encryption: you can recover one device via access to another. Works well if you have a coordinated backplate (which Tailscale does!), but here you also have different levels of node trust to deal with.
100
str4d @str4d.xyz · 11/07/2026
And especially in personal deployments, the credentials to access the Tailscale network are usually the same ones to configure it. I think that's maybe been relaxed a bit recently by allowing more users? But it's likely that "single shared Gmail account" is more common than not.
210
str4d @str4d.xyz · 11/07/2026
The value I'd get from this (or --remote-control in the other thread) is in situations where I threw a low-value server onto my network for a single purpose, and then didn't use it for a while. If it's high value, I either took more time to set it up, or am using it regularly and exercising access.
110
str4d @str4d.xyz · 11/07/2026
For me (using Tailscale personally) it would be awesome (with the obvious UX caveat of it only working on certain nodes). Professionally, I'd want the per-node config to take precedence over central (--ssh prevents remote disable, a --no-ssh prevents remote enable), and ACL who can (or admin only).
370
str4d @str4d.xyz · 11/07/2026
Indeed, `tailscale ssh thisdarnpi` was the first thing I tried to get into it 🫠
111
str4d @str4d.xyz · 11/07/2026
My Raspberry Pi Tailscale exit node is not routing. I can't SSH in because I don't remember its password, and I don't remember which laptop I set it up from (for pubkey access). I can't change the password in the CLI because I can't find my micro HDMI adapter. Guess I'm reflashing it yet again! 🫠
9262
str4d @str4d.xyz · 09/07/2026
That was fun! I've played similar games before but not that allowed using letters multiple times; that took a bit for my brain to route through.
Smush, 9 July 2026.
306 points, pangram first, no hints.
🟨🟩🟩
🥞⭐🥞
🟩🟩🥞
010
str4d @str4d.xyz · 09/07/2026
If they aren't a US employee, they wouldn't have been allowed to use Fable 5 at all during the blockade, which might have prevented them getting the data needed for writing the blog post.
020
str4d @str4d.xyz · 09/07/2026
What other codebases are likely to have: - Languages that would benefit from replacement. - Comprehensive test suites pinning down precise behaviour. - Commercial entities that can spend half-an-engineer yearly salary on a line item. Maybe the COBOL that still exists throughout the banking system?
0100
str4d @str4d.xyz · 09/07/2026
It also depended *heavily* on Bun's existing large and comprehensive test suite, *in a different language* (Typescript, not Zig). The rewrite didn't need to touch the test suite (or its harness presumably), meaning there was no chance of AI-generated semantic drift in what the tests were enforcing.
1140
str4d @str4d.xyz · 09/07/2026
The outcomes from this Rust rewrite that interest me: - Introduced 19 regressions, all now fixed. - Fixed 128 bugs that were present in the Zig version. - Cost $165,000 of API tokens, took 1 engineer 11 days. Not feasible for any open-source codebases, but *way* cheaper than 3 engineers for 1 year.
Pre-merge, this took 5.9 billion uncached input tokens, 690 million output tokens, and 72 billion cached input token reads — around $165,000 at API pricing. By hand, I think this would've taken 3 engineers with full context on the codebase about a year, during which time we wouldn't be able to improve Node.js compatibility, fix bugs, fix security issues or implement new features. We never would've done that. The realistic alternative was to do nothing and keep fixing the bugs at the top of this post forever.
2583