Suppose, hypothetically, you discovered a 0-click RCE in Omarchy. What would be the maximally funny thing to do with this knowledge?
("Never disclose it to DHH" being table-stakes.)
Remote
Soatok Dreamseeker
@soatok@furry.engineer
He/him. Gay/demi dhole (Cuon Alpinus) furry.
Blogger, programmer, security engineer, cryptography nerd. 30+
Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16)
I don't represent any company, individual, or community.
8572 Followers
2225 Following
50 Posts
Joined November 11, 2022
Open post
Replying to
If you've ever felt a sense of "wow some of these AI enthusiasts are kind of cult-like" you've probably seen the effects of them.
50
0
6
0
Open post
Judging from how folks talk about a fur that passed away recently, as heartwrenchingly sad as that is, it's also a little inspiring.
If one could touch even a hundredth the number of lives he did, in such a positive and uplifting way? Then you're doing incredibly goddamn good.
7
0
1
0
Open post
Seeing Werner Koch's lame response on oss-sec is absolutely confirming my suspicions about the GnuPG team
21
0
3
0
Open post
Every time the Red Cross declares a different level of alarm over blood shortages, my gay ass who is excluded from donating blood is like
"Hmm, do I want to abstain from gay sex for a full calendar year in order to help fix a problem for a system that discriminates against people like me?"
and then I shrug.
129
26
33
2
Open post
lewd joke
I don't drink alcohol but at furry room parties I'm known to ask for something stiff
86
2
9
0
Open post
Since the EU has made Chat Control 1.0 a thing, I should remind everyone that even having a plaintext mode at all is gross negligence for an E2EE system
https://www.patrick-breyer.de/en/eu-parliament-greenlights-chat-control-1-0-breyer-our-children-lose-out/
101
13
95
0
Open post
Vaguely incorrectly remembering the time when
@sophieschmieg@infosec.exchange : "The empty string is the prefix to all strings"
People doing domain separation wrong:
71
5
15
1
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
But let's be real: At least 10% of my reason for doing any of this is because I'm a shitlord at heart.
Do you know how funny it is for folks at cryptography conferences to be like, "Oh I helped design the Keccak permutation that became SHA-3 and later went on to work on sponge-based authenticated ciphers?"
And to want in that moment to be like, "I have a blog. It has stickers!"
You have to be willing to make a total fool of yourself for your own amusement to understand me at all.
42
4
1
0
Open post
Replying to
@da_667@infosec.exchange Meanwhile every one of them is like
"What do you mean you can't afford to run a GPU cluster 24/7 to test your self-hosted models on? You're too poor to even talk to me"
3
3
1
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
Whenever I'm confronted by these sorts of judgments, I'm never quite sure how to feel (let alone react).
Like, sure, it's flattering. I can take compliments!
(If by "take" you actually mean "skillfully deflect", heh. :P)
But I don't like the weird framing it implies.
Cryptography isn't hard because you need to be part of the Special Boys Club of Mega Geniuses.
(I guess they call that Mensa?)
Cryptography is hard because it can go wrong in a lot of subtle ways, many of which fail silently while offering false confidence that puts people in harm's way.
Cryptography requires training, discipline, and a deep curiosity to keep up-to-date with new attacks and blind spots in earlier designs.
It doesn't require being, like, Terrance Tao or Albert Einstein.
30
3
1
0
Open post
RE: https://furry.engineer/@soatok/116925912306713260
I made a rather important update to this post for folks who hadn't been chewing on the threat model of E2EE for the past 4+ years.
https://soatok.blog/2026/07/15/the-long-tail-of-work-left-until-activitypub-has-e2ee/#public-key-profile
31
12
11
0
Open post
Replying to
@da_667@infosec.exchange One of these days a tech bro is going to call me "not even human" and I'm going to drop the furry copypasta on that bitch
2
1
2
0
Open post
Open post
Had a dream I was talking to someone and they told me their middle name was "Sunday" but they were thinking of changing it to "Bureaucratic Friday"
I woke up trying to figure out which way they intended the joke
19
0
0
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
Pulling off a career switch isn't easy, and it requires some degree of privilege to be successful at all, but it's possible. "We have the technology", except not entirely ironic.
21
4
0
0
Open post
About to suit up and head down
10
0
0
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
But it's also just... not true of me at all?
I'm a dumbass quite often. I'm just not afraid to be a dumbass, nor am I in denial about my tendency to make blunders.
My job title is some variant of "Security Engineer"; has been for many years now.
Security Engineering is related to Safety Engineering.
Both disciplines are about studying Failure.
Understanding how systems fail is half of my job. The other half is a weird form of group therapy.
20
1
1
0
Open post
Boosted by @GroupNebula563@mastodon.social
cults, conspiracy theories, misinformation, geopolitics, social media, you name it tbh
The title of this video did not disappoint
https://www.youtube.com/watch?v=6zLCZ_Ic1hI
16
8
6
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
(I included Tao in the last post mostly as a joke because, despite his success in mathematics, he comes across as humble and approachable in everything he writes, and I admire that.)
You can do this too.
Maybe don't roll your own crypto today. That's a team project anyway.
17
2
0
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
At the top of the list, blogging about cryptography is something I do, in part, because excessive gatekeeping is counterproductive and even toxic.
See https://soatok.blog/2021/03/04/no-gates-no-keepers/ for more on the subject ^^
16
1
5
0
Open post
Replying to
What projects are those?
https://soatok.blog/2025/10/15/the-dreamseekers-vision-of-tomorrow/
5
0
1
0
Open post
Amazon can't help themselves when it comes to including "Simple" and "Managed" in a new service name because, looking at their warehouses, the upper management is clearly into S&M.
18
1
3
0
Open post
Replying to
It's around 3 AM on a weekday and I'm writing a long thread. Do you feel lucky?
None of what I described requires a bigger or more special brain to do. Hell, almost anyone can pull this off if they have the right opportunities and invest the time to learn it.
In 2020, I wrote a series to help people get into tech.
https://soatok.blog/furward-momentum-starting-and-growing-an-open-source-project/
Most of what still works today (current job market being what it is) isn't the hard skills part, it's the first step of building a support system.
13
5
2
0
Open post
Replying to
@mattblaze@federate.social I dunno about everyone else, but I plan to be walking around in fursuit!
11
0
1
0
Open post
The prevalence of spaghetti code in core infrastructure is clearly a homage to the Church of the Flying Spaghetti Monster.
17
1
8
0
Open post
I get some weird emails.
How do I break it to them that "Barkane Arts" is a joke organization name that I came up with as a play on the term "computer wizardry" (but with more furry) rather than an LLC registered in any state?
12
0
1
0
Open post
I suspect someone's using an LLM to scrape all of my writing whenever I see anomalies like this.
11
1
1
0
Open post
Replying to
I've emailed IANA requesting it be added to the registry alongside the RFC9421 algorithns.
As Mastodon and other platforms onboard to RFC 9421, the availability of an interoperable specification should allow them to prioritize ML-DSA over, e.g., RSA.
14
0
0
0
Open post
Replying to
I had to repost this manually because the WordPress.com / Jetpack social plugin didn't include the hecking preview image >.<
11
0
1
0
Open post
Open post
Open post
Open post
Replying to
@cliffle@hachyderm.io Alan Turing appreciation is the gay option
Alan Turing fanfiction is the gayer option
Neither precludes "Yes" or "No"
4
1
0
0
Open post
Me, months ago: "Wow, there's nothing I feel like writing about. Work is extremely busy. I'll put it off."
Me, now: "Wow, there are so many things to write about that it's hard to choose which one to finish first. Work is extremely busy. I'll put it off."
4
1
0
0
Open post
Open post
Replying to
@azonenberg@ioc.exchange @hazelnoot@enby.life Browser extensions are your only secure option if you want to use a "web frontend".
2
4
0
0
Open post
The Long Tail of Work Left Until ActivityPub Has E2EE
Separate from my proposal for key transparency for the Fediverse (which I've certainly blogged about a lot), the W3C has been…...
http://soatok.blog/2026/07/15/the-long-tail-of-work-left-until-activitypub-has-e2ee/
2
0
0
0
Open post
Replying to
@theorangetheme@en.osm.town I'm on PrEP. I'm tested for HIV quarterly (which is required, along with a non-reactive test result, to continue receiving PrEP).
1
0
0
0
Open post
Replying to
@ww@xyzzy.link @hazelnoot@enby.life @azonenberg@ioc.exchange An extension would be secure against any instance being compromised unless the author of the extension is also compromised.
If furry.engineer got pwned after this is all rolled out, there's nothing I could do to stop JS served from furry.engineer from stealing my private keys, etc.
However, a browser extension that does all the encryption, signing, and key management outside of the Fediverse domain's DOM entirely would be impervious to malicious JS.
The downside is, as you say, the extension authors could also be compromised. But at least now we're talking about "the evil government needs to push malware onto the endpoint" rather than "passively just snoop on what the server receives for years". The cost of the attack is much, much higher.
(Also, y'know, binary transparency, reproducible builds, and open source software can help!)
https://defuse.ca/triangle-of-secure-code-delivery.htm cc @DefuseSec@infosec.exchange
1
2
0
0
Open post
Replying to
@hazelnoot@enby.life This was prompted by https://pawb.social/post/47167667/23257426 lol
1
10
0
0
Open post
Replying to
Since the poll is closed:
The consensus is "No". Which is also what I believe. Happy to be proven wrong, of course.
0
5
0
0
