Wladimir Palant
Software developer and security researcher, browser extensions expert. / searchable
It was of course to be assumed that the reason Russian government pushes Max messenger down everybody’s throat is so that they get full visibility into the communication. So no real surprises here but still good to see this analysis despite Max developers going to great lengths to make analysis harder.
Remember when you had to resort to hacks like this one in order to have some basic privacy? https://palant.info/2009/03/02/getting-rid-of-flash-cookies/
Adobe Flash EOL was six years ago, though it got phased out before that already. A great win for the web platform.
I recommend that you read this article and think long and hard about it. If your first reaction is “half of this is probably not true” then you are part of the problem and this is something you have to fix. If victims speak out in the only way they feel they can, then you have to take this seriously and listen, then think about the structures that enabled their abusers and your role in those.
Also, if you want to keep your faith in humanity I recommend not reading the comments under this article (or maybe no comments under online media in general).
I see news that the #FTAPI data exchange platform has been hacked. And that name actually rings a bell, I’ve written about it a while ago: https://palant.info/2018/07/11/ftapi-secutransfer-the-secure-alternative-to-emails-not-quite/
Back then I found that their claims of data being end-to-end encrypted should be taken with a grain of salt. We might find out now just how large of a grain.
What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (Mozilla’s infrastructure is producing lots of builds).
I have an extreme urge to reimplement Gtk’s ColumnView instead of dealing with the original. Not because of bugs but because of policy decisions. The former can get fixed, the latter won’t be. Like: I’ve never had to deal with a list widget where it was a policy decision not to expose the currently focused row. Some dev: “I need to know the currently focused row to display a context menu.” Gtk devs: “That’s not how you do it, register your context menu for individual cells, then you won’t need to know.” Well, I still need to know the currently focused row, e.g. to restore list state. Or to check whether changing focused row succeeded because there are many conditions where it will fail silently. Not possible, just assume that selection and focus are identical (spoiler: way too often they are not).
Similarly, invalidating a row is a trivial task in pretty much any framework I had to work with except Gtk. Some dev: “My data changed, how do I invalidate a row?” Gtk devs: “You don’t. Make sure that your list item properties are bound to the respective cell properties, then updates will happen automatically. Never mind that there are zero examples showing how to clean up the bindings in case the cell is reused later, surely you will get that implemented correctly.” I have a suspicion that cells are only supposed to be reused per documentation but this doesn’t actually happen in practice because otherwise lots of applications would turn out buggy in very subtle and annoying ways. Either way, in some cases I have complex enough data that managing updates via bindings would be a horrible mess. So I invalidate columns by re-registering their factory, and now I need to find another hack that allows invalidating single rows.
Last time I criticized Gtk I was asked what I was hoping to achieve. Well, nothing at all. I’m just venting. Because Gtk is an extremely frustrating framework to work with, and this is merely a tiny portion of its unfixable issues.
And I thought that the “expert” hired by a certain German publishing house was bad, putting his considerable academic reputation on the line with some complete bullshit arguments (as in: contradicting CS Theory 101 course to support his employer’s line of argumentation). That was a while ago, so I guess that he used students to play the role of cheap text generators. Nowadays that is no longer necessary of course.
LLMs are quickly eroding the concept of truth.
I’m sure that more known people have had to refute claims about them for a while but now it happened to me as well. A researcher from a respectable university contacted me asking for an interview regarding “my position” on a particular topic. The issue: the cited position is the exact opposite of what I’ve always said, and I’m pretty sure that there are zero online sources confirming it to be mine. But whichever LLM they’ve consulted constructed a bullshit controversy where there never was one.
I can refute it this one time of course, and I assume that no such claims will make it into their final publication. But the tendency to rely on LLM-generated “information” is there, even in academia. And once they publish unverified bullshit it becomes “the truth” that LLMs will prioritize in their training and other people will refer to as proof that LLM claims are correct. This is going to be really bad.
One really has to wonder how some decisions were made. So somebody at #BMW thought: “You know, those suckers who paid $50,000 or more for our cars? We should really milk them some more. They probably get bored waiting for their car to start up anyway, let’s show them some ads! We’ll call it a special surprise for the drivers, no way they’ll object then.” Yes, totally reasonable.
Way to destroy a brand’s reputation…
Has been a while since I updated my collection of Chrome extension manifests. Just uploaded another snapshot: https://codeberg.org/palant/chrome-extension-manifests-dataset
Since my last snapshot (January 2025) there has been an outright explosion of extension numbers. With 250k it’s now almost twice as many extension manifests despite no changes on my end. The Chrome Web Store spammers have been very busy…
There have been reports about hundreds of “misleading” VPN extensions in CWS (as in: tricking you into installing, then likely spying on you). But that’s really only the tip of the iceberg, chances of randomly finding a non-malicious Chrome extension appear rather slim at the moment.
Reading this article and (remarkably) its comments is fun: https://arstechnica.com/ai/2026/08/the-new-instagram-logo-is-the-perfect-embodiment-of-ai-slop/
I mean, I do create an occasional icon containing text. I know some issues to watch for but I am by no means a designer, so I probably do a rather bad job. Reading how people perceive this hack job of a logo is remarkably helpful, I’ve learned a few new things to avoid. Also, it helps boost my self-esteem – my icons may not be great, but at least I’m not a multi-billion dollar company.
Even with debug symbols and everything, trying to match compiled Rust code with release optimizations to source code isn’t a healthy activity…
“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.”
Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now…
@cR0w@infosec.exchange Could you please add the image text to the alt text? E.g.:
A toy steering wheel mounted on the dash of the passenger side of a car. Above it the text: “When slopoholics think they’re in control of their machine of lies”


