Sign in

voboda

@voboda.com
29 followers 161 following 28 posts

I learn about all kinds of cryptography, and try to use it to make the world a little better. You can see a few explorations at voboda.com

PostsRepliesMedia
Reposted by voboda
Joseph Cox @josephcox.bsky.social · 22/07/2026
You opened a credit card. ICE now knows where you live. Here's how when you open a credit card your address leaves your bank, goes through middlemen companies, and ends up with ICE. ICE plans to use this data for immigration and 'voter fraud'. No warrant More: www.404media.co/you-opened-a...
3317271038
voboda @voboda.com · 22/05/2026
With #localfirst apps and SPAs, DNS hijacks are fatal. All end-user data, even encrypted, is revealed. Anyone else considered this? I'm doing some research, and designing some prototypes.
011
Reposted by voboda
Electronic Frontier Foundation @eff.org · 19/05/2026
"[Palantir workers] joined a company that promised to stop abuses of power, and they are watching it build the tools that make those abuses faster, wider, and harder to undo. The question they are left with is ... at what point does building the machine make you responsible for what it does?"
blusherme.com
Even Palantir Employees Question If They’ve Become the Villains: “We Were Supposed to Stop These Abuses” – Blusher
716347
Reposted by voboda
warrior cop @wyattprivilege.bsky.social · 19/05/2026
I GET LOGGED OUT. BUT I LOG IN AGAIN
149155843099
voboda @voboda.com · 19/05/2026
Lessons learned from zKal blog.voboda.com/parking-zkal/
blog.voboda.com
Parking zKal
I'm parking zKal. Here are my lessons learned. The best place to start is Brewster Kahle's feedback to me when I was in Berlin:
010
voboda @voboda.com · 14/05/2026
If it has 2 sides, it's propaganda
000
voboda @voboda.com · 14/05/2026
Had quite a few "oh shit" moments reading this. And it's mostly stuff I thought I knew. sockpuppet.org/blog/2026/03...
sockpuppet.org
Vulnerability Research Is Cooked
000
voboda @voboda.com · 14/05/2026
jbp.io/2025/05/02/g... "I view GHA runners as public, unsecured shell boxes that I can run scripts on. They can check out and build public code, but at no point should they be given any kind of privileges or secrets."
jbp.io
jbp.io :: GitHub Actions is Someone Else's Computer
000
voboda @voboda.com · 14/05/2026
Dependency inversion, but in space ochagavia.nl/blog/towards...
ochagavia.nl
Towards interplanetary QUIC traffic
Have you ever asked yourself which protocols get used when downloading pictures from the Perseverance Mars rover to Earth? I hadn’t thought about that either, until I came across an intriguing message...
000
voboda @voboda.com · 14/05/2026
You use a bare Git repo with a `post-receive` shell script hook. I use GitHub Actions: remote YAML, swiss-cheese key management, OIDC trust glue, job orchestration, delimiter-delimited metadata, opaque internal headers, microservice spaghetti, bug bounties, and CVEs to match. We are not the same.
000
voboda @voboda.com · 01/05/2026
Quick mitigation: docs.hpc.ut.ee/public/cve-2...
docs.hpc.ut.ee
CVE-2026-31431 Mitigation - HPC Public Documentation
011
voboda @voboda.com · 14/04/2026
that glitch
000
Reposted by voboda
Holobrine @holobrine.bsky.social · 14/04/2026
It struck me that pet names could actually work with the Reticulum network stack more than with IP, because you actually take your Reticulum address with you when you move in the network. You can't do that with IP addresses, hence the need for DNS.
011
Reposted by voboda
Hazel Weakly @hazelweakly.me · 14/04/2026
If I had to identify a list of skills in high impact engineers, it would include: - ecological awe - intellectual humility - respect for the complexity of unfamiliar problems - cross functional communication - resilience engineering - marketing and sales (“Technical skills” aren’t in my top ten)
1222240
voboda @voboda.com · 13/04/2026
Dirty Google games to avoid GDPR compliance for EU accounts? @eff.org
Email screenshot from Google, informing the user the region of their Google account will change to US - California.
000
voboda @voboda.com · 13/04/2026
One European here, saying thanks to the Hungarians who have been standing up for their values. Hope is alive.
010
Reposted by voboda
Kate Sills @katelynsills.com · 13/04/2026
It's pencils down at the hackathon. I put 236 years of US copyright law into a git repository. Every Act of Congress from 1790 to today is a commit. Still some work to be done, and things got frantic at the end, but I'm proud of this! github.com/katelynsills...
github.com
GitHub - katelynsills/copyright-history: Every amendment to US copyright law (1790-present) as a git commit. Browse 236 years of legislation with git log, git diff, and git checkout.
Every amendment to US copyright law (1790-present) as a git commit. Browse 236 years of legislation with git log, git diff, and git checkout. - katelynsills/copyright-history
56816
voboda @voboda.com · 08/04/2026
If anyone's paying attention, I fixed cookies. :) blog.voboda.com/hdk-sessions/
blog.voboda.com
HDK Sessions
The standard session model: user logs in, server stores state, server decides what you're allowed to do. Structurally incompatible with privacy. I've ...
010
voboda @voboda.com · 06/04/2026
well @meri.garden, you get to have all the fun meri.garden/posts/using-...
meri.garden
Using Keyhive in WASM to model capability groups
Demo/POC of using just the delegation parts, in the browser
110
Reposted by voboda
Meri @meri.garden · 06/04/2026
it's pretty fun that the founder of temporal logic was called Arthur Prior
Wikipedia hover box screenshot with portrait and text: Arthur Norman Prior, usually cited as A. N. Prior, was a New Zealand-born logician and philosopher. Prior (1957) founded tense logic, now also known as temporal logic, and made important contributions to intensional logic, particularly in Prior (1971).
0241
voboda @voboda.com · 06/04/2026
"Crypto was a community that had been building for almost a decade. Economic design was what they did. And nobody had addressed the economic design problem that made their conference weeks full of over-hyped but mostly empty events?" Here is my attempt. blog.voboda.com/density-index/
blog.voboda.com
The Density Index
My first Ethereum conference was 20,000 people. The Amsterdam tourist district was a drunken, crypto merch explosion. I wondered how many were setting themse...
000
voboda @voboda.com · 05/04/2026
Working on zkal, I realised I was tackling a general problem: returning to the benefits of open data for communities, but with modern privacy protection for the individual. Came up with a pattern that might be useful (or flawed!) blog.voboda.com/proof-projec...
blog.voboda.com
Proof Projectors
Everyone's focused on what ZK proofs hide. We're missing what they can usefully reveal. Reputation, attendance, commitment, these used to require surveill...
121
voboda @voboda.com · 01/04/2026
Sharing a self-nerd-snipe blog.voboda.com/meeting-wher...
blog.voboda.com
Meeting where AI eyes can't follow
I've applied to the Community Privacy Residency so thought I'd share notes from a cryptographic exploration I come back to every once in a while. What i...
110
voboda @voboda.com · 01/04/2026
"using network architecture to solve issues of power distribution simply shifts bottlenecks rather than eliminating them. A decentralised protocol does not automatically produce decentralised governance, it also moves power to different, less visible places." connectedplaces.online/reports/fedi...
connectedplaces.online
Fediverse Report – #149 – On Protocol Governance
On the complexities of protocol governance.
121
voboda @voboda.com · 31/03/2026
This is the privacy policy I always wanted to write. onelineforyourmind.com/privacy/
onelineforyourmind.com
One Line For Your Mind
000
voboda @voboda.com · 29/03/2026
blog.voboda.com/the-third-fl... A kinda hacker love story for Berlin.
blog.voboda.com
The Third Floor at ethBerlin
ethBerlin is full of rooms you have to find yourself. At the back of the third floor there's a big, quiet room with good light and big windows. You can ge...
121
Reposted by voboda
Simon Willison @simonwillison.net · 24/03/2026
Given today's LiteLLM supply chain attack, what are people's preferred development environment sandboxes on MacOS these days? I think it's time I started running my development environments somewhere where rogue code can't steal all my ~/... credential files
331069
voboda @voboda.com · 10/02/2026
The Moltbot rename and supply-chain attacks that followed: www.malwarebytes.com/blog/threat-... I run all my dev in a hardened container, but this type of attack grabs API keys silently, and uses them to watch communication. Any ideas on mitigation?
malwarebytes.com
Clawdbot’s rename to Moltbot sparks impersonation campaign
This Moltbot impersonation campaign is a case study in supply-chain risk, brand hijacking, and what happens when open source goes viral.
000
Reposted by voboda
ligi @ligi.de · 22/01/2026
We cannot let them get away with this. And the solution is not to chop of a head of this hydra and call it a day - but to fundamentally change how we do things.
121
voboda @voboda.com · 21/12/2025
I'm glad this is coming to the forefront. I was deeply inspired by Nikolai Mushgian's attitude to this ( see nikolai.fyi and look at dmap, dpack and minicash's doc ) I even made a little game about this philosophy for Devcon SEA: immutalists.infinite.build
github.com
031