My students asked me if it was true that the entire Internet was really coded by hand. All those kernels, protocols, router firmware, browsers, databases, etc. Somebody coded these and debugged them by hand?!?!? They used BBEdit?!?!??! The idea that this was even possible seems amazing to them. I can imagine some future Moon Landing like conspiracy theory that says it never happened.
— Вот мой новый VPN сетап. Как вам?
— Ух ты, красивый, вы только посмотрите.
— Только вчера дописал конфиг. sing-box + GeoIP базы Antizapret для сплит-роутинга на клиенте, FakeIP против утечек DNS, Shadowsocks 2022 over Cloak в качестве транспорта. Первый хоп на сервера VK Cloud в России, потом в Нидерланды. Фолбек на коммерческие сервера RedShield через AmneziaWG2.0.
— Оnлично, Бейтман, но всё это пустяки. Смотри. Сплит трафика по приложениям: браузерный трафик идёт через Naive Proxy, тяжёлый трафик — через Hysteria2 с Brutal, на разные VPS, также с мультихопом через Россиию. Telegram через MTProto. Подключено два интернет-провадйера, между которыми роутер переключается по round-robin в случае потери связи. DNS leak исключён за счёт использования DoH к Quad99 и блокировки исходящего трафика на 53 порт. Ну как?
— Красиво. Высший класс. (Не думал, что у него столько вкуса. Не могу поверить, что Брайсу больше понравился стек Ван-Пата)
— Но постойте. Вы ещё ничего не видели. VLESS через Xray-Core с транспортом в виде WebSocket и gRPC — трафик идёт до известных CDN: Cloudflare, NGENIX, Yandex CDN и CDN77, с domain-fronting и ротацией в зависимости от пинга и загрузки. Глобальный фолбек в виде Tor Snowflake (WebRTC) через хоп на резидентный IP в Беларуси, с которым устанавливается параллельный настоящий звонок для маскировки.
— Очень красиво... А покажи-ка VPN Пола Алена.
Какой лаконичный стек... Это же золотой стандарт индустрии... VLESS + Reality + XTLS-Vision + uTLS... И первый хоп подобран со вкусом: белосписочный VPS в Yandex Cloud... Максировка под сертификат Yandex Market из той же подсети, защита от активного пробинга... Боже, даже фолбек есть: нелегальный turn-proxy через абьюз WebRTC звонков Вконтакте...
BREAKING: Do not sit on this!
If you are using this software you are vulnerable to a zero day. A piece of hacker code that unlocks your computer to viruses and malware.
AI has turbocharged hackers. They can now built cyber antiVAX systems faster than vendors can respond!
Time is a great way to show the scale of mega (million), giga (billion), and tera (trillion).
A megasecond ago was March 2026
A gigasecond ago was July 1994
A terasecond ago was 29,663 BCE in the Paleolithic era.
- XZ utils backdoor: found by guy debugging 200ms latency
- LiteLLM hack: found by guy debugging oom issue
These could have been the most impactful compromises ever.
Forget security vendors, weaponize your engineers’ autism.
We discovered a phishing actor that is abusing .arpa to host content on domains that should not resolve to an IP address. The actor uses free services to create domain names from reverse DNS strings for IPv6 tunnels that use the .arpa top level domain. 🧵
Words fastest #Jammer using ground breaking "Silicon-Strike" Technology ⚡️
This jammer is so fast (ns multichirp) & offers such high bandwidth (20GHz) that it can disrupt even the most robust "unjamable" UWB FFH protocols.
#Aaronia#CUAS#CUAV#antidrone#EnforceTac
imagine turning on the hud in your helmet and it starts blasting some chiptune with a rotating 3D ascii clog and "CRACKED BY R00KW0RST: AHEAD OF THE PACK"
someone built a tool that REMOVES LLM CENSORSHIP in 45 minutes with a SINGLE command
its called HERETIC
here is how it works and why everyone is talking about it
We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected.
Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider.
🔗 https://t.co/pDlH3cKnz4
#GreyNoise #ThreatIntel #CyberSecurity #InfoSec
Honestly, buying 1,500 pizzas is way cheaper than deploying some nuclear-powered aircraft carriers across the globe, and the psychological impact is probably huge. It’s also cleaner for the environment!
Scaled from 1,000 to 100,000 users. Here's what broke.
At 5,000 users:
- Single database became the bottleneck
- Added read replicas
At 20,000 users:
- Session storage overwhelmed Redis
- Switched to JWT tokens
At 50,000 users:
- File uploads killed our servers
- Moved to S3 with presigned URLs
At 75,000 users:
- Search became unusable
- Implemented Elasticsearch
At 100,000 users:
- DNS became single point of failure
- Multi-region with Route53 failover
Every stage felt like the final architecture.
None of them were.
Scaling isn't a destination. It's a continuous series of bottleneck discoveries.
Over 20 years ago someone suggested using worm compromised boxes for bounces
1) if they’re haven’t been cleaned up after a year, they’re essentially invisible
2) you already know how to access the box
Think Deeper.
One line of this @SentinelOne blog (🙏 @TomHegel and @milenkowski) stood out to me.
💭"Encrypts and password-protects the archive using 7-Zip with the password @WsxCFt6&UJMmko0, ensuring the data is obfuscated from inspection."
Pretty strong password at first blush. Let's see if @Copilot can figure out why the threat actor may have chosen it.