Fabio Manganiello<p><a class="hashtag" href="https://manganiello.eu/tag/samsung" rel="nofollow noopener" target="_blank">#Samsung</a> devices from today can no longer install custom ROMs.</p><p>Odin is gone and the <em>Download Mode</em> is also gone, which makes life hard also for repair services that want to restore a device.</p><p>This is your daily reminder that <a class="hashtag" href="https://manganiello.eu/tag/android" rel="nofollow noopener" target="_blank">#Android</a> is a liability, and major hardware manufacturers who ship Google’s version of Android are a liability too.</p><p>We need to get Linux phones to work, and we need manufacturers who are aligned with our principles.</p><p><a href="https://www.androidauthority.com/samsung-disables-odin-removes-download-mode-3648469/" rel="nofollow noopener" target="_blank">https://www.androidauthority.com/samsung-disables-odin-removes-download-mode-3648469/</a></p>
Jan Wildeboer đŸ˜·:krulorange:<p>Don’t call it age verification. Call it centralised personal data collection. And understand that it serves surveillance, not safety for children. Thank you for your cooperation.</p>
PoroCYon<p>re: last few boosts: it used to be the case that all hardware was very hackable, up until 2018 or so. even if the cryptography was solid, the bootcode usually wasn't and then you could run your own linux on it or whatever, in the worst case you'd need a $5 modchip</p><p>unfortunately, by now, hardware vendors have learned how to design chips that are secure against such attacks, even if the bootcode contains simple mistakes. this makes everything much more complicated, and even "all-powerful" modchip attacks are either ineffective, or would cost roughly $500 per device</p><p>(if enough people are interested, I could do a big explainer about what exactly makes these new hardware designs 'impervious', but that's not for this post)</p><p>which is all to say, we really need a political solution to this problem. accepting any sort of law that mandates others to control our own computing devices is disastrous (not just age verification/chat control, but also remote attestation for banking/government apps)</p>
NilĂ©ane<p class="quote-inline">RE: <a href="https://infosec.exchange/@david_chisnall/116160637051672728" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@david_chisna</span><span class="invisible">ll/116160637051672728</span></a></p><p>the question you should be asking yourself is not “what's the best way to verify the age of every single computer user on earth”</p><p>but rather “why the fuck are we trying to verify the age of every single computer user on earth????”</p><p>and the answer to that is: fascism<br>stop. complying.</p>
elly<span class="h-card"><a class="u-url mention" href="https://chaos.social/@sleepyowl" rel="nofollow noopener" target="_blank">@<span>sleepyowl</span></a></span> Intel is extending BootGuard with FSP signing too (which is a blob doing all memory/silicon init magic behind the scenes) which was specifically requested by delusional vendors like AMI.<br><br>We had some heated discussions with their engineers about it because they wanted to move reset vector(!) to be owned by FSP-O before allowing actual firmware to execute (kinda like TF-A on ARM64).<br>Eventually everyone in the meeting went quiet and let me cook, it was a bit comical (me vs. three engineers from Intel), where I suggested extending CSME with it's own cache (as RAM is initialized much later) that can check status of EFUSEs and validate FSP signatures before releasing x86 cores from reset (which is nothing new, that's also what AMD is doing with PSP and PSB) if BootGuard is enabled and board went trough EOM.<br><br>In any case, they wanted to make it mandatory in the beginning. We pushed back, which brought Intel to negotiating table and made them change their minds. You can clearly see though that vendors don't care about openness of their platforms (unless money is involved) and real ROT is in the hardware.<br>Whoever makes the SoC and board, whoever rolls cryptographic keys *truly* owns the platform (or in other words - your hardware belongs to entity burning their signing keys into the "BootROM").<br><br>Circumventing those protections is not viable, saying "I'll buy second-hand" or "I'll buy from China" is simply... delusional. If every piece of hardware would become locked-down, you wouldn't be able to upgrade your hardware past certain point whatsoever. Buying from China might work for now, sure... but guess what would happen if China's SoC manufacturers would get equally as big as let's say, Intel/AMD/Qualcomm?<br>Yep, you've guessed it - same exact thing.
mhoye<p>Again, there is no "age verification", there is only "identity verification", and "identity verification at the OS level" means specifically that there is no such thing as free software in any inclusive, democratic sense and no such thing as "computer ownership" in any way that involves meaningful choice.</p><p><a href="https://chaos.social/@sleepyowl/116126002122086149" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">chaos.social/@sleepyowl/116126</span><span class="invisible">002122086149</span></a></p>
professional box/furniture thrower<p><span class="h-card" translate="no"><a href="https://chaos.social/@sleepyowl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>sleepyowl</span></a></span> Yeah, I've wanted to do a lot of hardware hacking but even good oscilloscopes cost a fortune, not even talking about all the other stuff you need. Every time I see a video people always have expensive equipment and then go "You can do this with any cheap alternative" and sometimes you buy the one cheap thing that can't do what you want it to do because reasons. </p><p>The option to mod THAT thing can be there, but that's ALSO a lot of time and effort. Atp it's a cycle of circumventing trash that our system designed to make it not trash,and then the question becomes 'What the fuck are we doing here?"</p>
A.B. Murrow<p><span class="h-card" translate="no"><a href="https://social.coop/@cwebber" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cwebber</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@sleepyowl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>sleepyowl</span></a></span> Yeah, the total refusal for some folks in FOSS to take this seriously because of a pinky promise in open licensing is going to make us sleep walk into this if we're not careful.</p><p>I think it's pretty easy to put up your blinders and refuse to acknowledge our individual shortcomings. </p><p>Most of us are software folks-- this will be a hardware based lock in. Many of us software people struggle with hardware issues and many of those simply cannot be sidestepped with a clever hack. </p><p>Just look at the ongoing issues with Nvidia drivers, Wayland support, LibreBoot, and standing community conventions like GUIX's tacit refusal to run on anything with proprietary drivers to get a taste of the absolute uphill slog we will all face if the community has to contend with this kind of low-level issue everywhere all at once.</p><p>The thing that drives me nuts too is that, although I suspect some issues on the internet can be solved with clever legislation, I don't think this is the way to do it. AT ALL. This whole thing feels like it was drafted by desperate polititicians who succumbed to a flashy tech bro slide deck and marketing pitches without a single thought to security, maintainence, economic impacts, etc. Like. Y'all. You have massive data centers filled with Linux boxes that some unlucky sod is probably going to get saddled with plugging their own biometrics into just to run a load balancer for the DMV. Does that feel sustainable?</p><p>Its the SaaS equivalent to legislation-- slap a bandaid on it and when people complain, blame them.</p><p>I don't live in either of the states where they're discussing this and my elected legislators are the "stick my fingers in my ears and yell real loud" types. What can I do now to help prevent this from being adopted? Are there any advocacy groups throwing their hat into the ring that we can rally behind?</p>
Soatok Dreamseeker<p>Cryptography engineering has an intrinsic duty of care.</p><p><a href="http://soatok.blog/2026/02/25/cryptography-engineering-has-an-intrinsic-duty-of-care/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">http://</span><span class="ellipsis">soatok.blog/2026/02/25/cryptog</span><span class="invisible">raphy-engineering-has-an-intrinsic-duty-of-care/</span></a></p>
Soatok Dreamseeker<p>I posted this addendum shortly after their blog post went live to address their claims.</p><p><a href="https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">soatok.blog/2026/02/17/cryptog</span><span class="invisible">raphic-issues-in-matrixs-rust-library-vodozemac/#matrix-response</span></a></p>
foolish olivia :olivia_flag:<p>chat this might be a controversial opinion but i think human beings inherently deserve food and shelter and anyone who disagrees deserves to be eaten by mario brothers piranha plant</p>
Pavel A. Samsonov<p>Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus.</p><p>FOSS nerds: the Torment Nexus cannot be ethical until it is Open Source</p>
Schrödinger's Catgirl (Joyce)<p>Go on, circumvent these measures &amp; keep our tech open and free. </p><p>But know that many hackers find basic hardware hacking tools too costly and out of reach. WE&#39;RE OUTRESOURCED.</p><p>PUSH BACK BEFORE THESE POLICIES BECOME NORMALIZED. DON&#39;T RELY ON HACKING ALONE TO SAVE US.</p><p>/END</p>
Schrödinger's Catgirl (Joyce)<p>People who think &quot;oh we&#39;ll just buy Chinese motherboards and chips&quot; or &quot;just use open source hardware&quot;</p><p>WHO FABRICATES THE BOARDS AND CHIPS FOR OSHW? DO YOU BELIEVE STATES LIKE CHINA AREN&#39;T INTERESTED IN SIMILAR MEASURES OF CONTROL?</p><p>This is the tech equivalent of tankie-ism.</p><p>/8</p>
Schrödinger's Catgirl (Joyce)<p>This is why GiovanH&#39;s blog article is a must-read. </p><p>People assume that accessible hacks of invasive systems will always exist, and users hacking their devices is to be expected.</p><p>THIS SHOULDN&#39;T BE A NORM. THIS IS AN ARMS RACE AND WE&#39;RE OUTMATCHED. /7</p><p><a href="https://blog.giovanh.com/blog/2025/10/14/a-hack-is-not-enough/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">blog.giovanh.com/blog/2025/10/</span><span class="invisible">14/a-hack-is-not-enough/</span></a></p>
Schrödinger's Catgirl (Joyce)<p>Again, no one assumes that any system can be made 100% bulletproof. But that was never the point is it? </p><p>The end game is for manufacturers to harden their devices against cheaper tools and raise the barrier to entry such that it costs a fortune for hackers who might even try. /6</p>
Schrödinger's Catgirl (Joyce)<p>There have been vulnerabilities in ME and PSP, and there MAY BE a way for users to bypass these checks.</p><p>But this assumes:<br />- Someone out there will put in labor to circumvent these things and release it freely, even at great expense.<br />- A simple, user doable hack even exists.</p><p>/5</p>
Schrödinger's Catgirl (Joyce)<p>For now, these functions are not strictly enforced or turned on in a lot of consumer devices.</p><p>But is there anything stopping nation states from forcing hardware manufacturers and OEMs to do so? </p><p>What options do you have in such a case? /4</p>
Schrödinger's Catgirl (Joyce)<p>How do these security processors verify the firmware integrity?</p><p>Through a set of cryptographic keys and their hashes, which are used to verify the cryptographic signature of the UEFI firmware. These keys or hashes are *burned* into the processor and cannot be changed. /3</p>
Schrödinger's Catgirl (Joyce)<p>Since the late 2000s, computer chipsets have shipped with security processors like Intel Management Engine and AMD Platform Security Processor. </p><p>Part of their job is to verify that the UEFI firmware is from the computer OEM and has not been tampered with or comes from a 3rd party. /2</p>
Schrödinger's Catgirl (Joyce)<p>A friend, <span class="h-card" translate="no"><a href="https://mas.to/@chloetankahhui" class="u-url mention">@<span>chloetankahhui</span></a></span> has been speaking up against the proposal to enforce age verification at the OS level, and the QRTs to this shows the extent of naivety that a lot of people have. </p><p>No one who does hardware security believes that any system is bulletproof, but do you really think that circumventing these things will always be a simple firmware mod or hardware hack?</p><p>Let&#39;s dive in. /1</p>
Church of Jeff<p><a href="https://mastodon.world/tags/RAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RAM</span></a> <a href="https://mastodon.world/tags/AIslop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AIslop</span></a> <a href="https://mastodon.world/tags/GenerativeAI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GenerativeAI</span></a> <a href="https://mastodon.world/tags/AIcrash" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AIcrash</span></a> <a href="https://mastodon.world/tags/environment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>environment</span></a> <a href="https://mastodon.world/tags/electricity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>electricity</span></a></p>
That Frisian Girl-ishage verification, queerness
Natasha :mastodon: đŸ‡ȘđŸ‡ș<p>Terry Pratchett on <em>militant decency</em> and justifiable <em>anger</em></p>
Schrödinger's Catgirl (Joyce)<p class="quote-inline">RE: <a href="https://chaos.social/@russss/115810455974387777" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">chaos.social/@russss/115810455</span><span class="invisible">974387777</span></a></p><p>Hacker camps and events imo have become too centralized and too big, and I personally think that we should be organizing smaller events and camps of our own, wherever we find ourselves.</p><p>This is an article worth reading and considering: <a href="https://hackaday.com/2025/08/22/finding-a-new-model-for-hacker-camps/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">hackaday.com/2025/08/22/findin</span><span class="invisible">g-a-new-model-for-hacker-camps/</span></a></p>
UnderGND.online<p>Did you enjoy our zines on Archival and Data Distribution, and Vectoralism?</p><p>You can find both digital and printable PDFs on <a href="https://undergnd.online/zine" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">undergnd.online/zine</span><span class="invisible"></span></a></p><p>We don&#39;t just talk about archival and data distribution, we walk the talk! 😉 </p><p>Hence they have also been made available on the Internet Archive: <a href="https://archive.org/details/@undergnd_online" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">archive.org/details/@undergnd_</span><span class="invisible">online</span></a></p>
Schrödinger's Catgirl (Joyce)<p>Anyway, if you&#39;re interested in the hardware, it is open source!</p><p>Check out deadflash&#39;s repository at: <a href="https://codeberg.org/bitowlonline/deadflash-hw/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/bitowlonline/dead</span><span class="invisible">flash-hw/</span></a></p><p>Firmware repo coming soon</p>
Schrödinger's Catgirl (Joyce)<p>At the time this project was conceived in November last year, the ESP32-P4 was the only thing that had USB 2.0 HS, high speed SDIO, which was in a small enough package (10x10 mm QFN) to fit on a flash drive and was reasonably priced. It was on hold until the P4 became generally available.</p><p>I am really excited for <span class="h-card" translate="no"><a href="https://social.treehouse.systems/@bunnie" class="u-url mention">@<span>bunnie</span></a></span> and co&#39;s Baochip <a href="https://bsky.app/profile/baochip.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">bsky.app/profile/baochip.com</span><span class="invisible"></span></a></p><p>It it&#39;s in a really tiny CSP package, and has USB 2.0 HS as well as SDIO. I managed to get a devkit for this: <a href="https://github.com/baochip/dabao" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">github.com/baochip/dabao</span><span class="invisible"></span></a></p>
Schrödinger's Catgirl (Joyce)<p>The goal is not to stop a dedicated attacker such as a hardware hacker (you cannot; anyone with physical access to your hardware will eventually get in) from tampering with the contents, but only to keep out 15 minute opportunists.</p>
Schrödinger's Catgirl (Joyce)<p>The threat we are trying to protect against are far-right nuts finding out the location of dead-drops and putting material like child sexual abuse material on the drive and then calling the cops. A whole community could then be in legal hot water for no reason.</p><p>The purpose of the deadflash drive is to allow communities to put files on the flash drive and distribute them around, while keeping opportunists from tampering with the contents of the drive.</p>
Schrödinger's Catgirl (Joyce)<p>One method of distributing information in a way that would be harder to pin down would be to create &quot;dead drops.&quot;. A flash drive could be placed a hole in the wall on the side of a building, unlocked utility boxes, etc.</p><p>But why not use a regular flash drive for this?</p>
Schrödinger's Catgirl (Joyce)<p>This is in line with <span class="h-card" translate="no"><a href="https://chaos.social/@undergndonline" class="u-url mention">@<span>undergndonline</span></a></span> zines about archival and data distribution, which you can read at: <a href="https://undergnd.online/zine#archival-and-data-distribution" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">undergnd.online/zine#archival-</span><span class="invisible">and-data-distribution</span></a></p><p>We are seeing a rise of policies designed to restrict access to information, both online and offline.</p><p>People in states like Utah wish to go after &quot;Little Free Libraries&quot; by campaigning to make owners of these libraries criminally liable for not adhering to book bans.</p><p><a href="https://www.themarysue.com/utah-book-banners-now-want-to-make-little-free-libraries-susceptible-to-criminal-charges/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">themarysue.com/utah-book-banne</span><span class="invisible">rs-now-want-to-make-little-free-libraries-susceptible-to-criminal-charges/</span></a></p>
Schrödinger's Catgirl (Joyce)<p>I had been working on a project for <a href="https://chaos.social/tags/39C3" class="mention hashtag" rel="tag">#<span>39C3</span></a>, sadly manufacturing and shipping got severely delayed and it didn&#39;t arrive on time (I cri), but here goes anyway: </p><p>This is Deadflash. A flash drive with a ESP32-P4 as a controller. Why bother making a flash drive, and a very expensive one at that?</p><p>tl;dr: It&#39;s mounted read-only by default, and mountable as R/W only after authentication; the point being to distribute files in such a manner that allows you to prove no one tampered with its contents</p>
Schrödinger's Catgirl (Joyce)<p class="quote-inline">RE: <a href="https://chaos.social/@undergndonline/115791173820293831" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">chaos.social/@undergndonline/1</span><span class="invisible">15791173820293831</span></a></p><p>How can we organize against restrictive policies such as age verification? What can hackers and organizers do to make sense of the world around us in the face of cheaply generated AI disinformation?</p><p>If you&#39;re at <a href="https://chaos.social/tags/39C3" class="mention hashtag" rel="tag">#<span>39C3</span></a>, come say hi!</p>
Schrödinger's Catgirl (Joyce)<p>Commenter, you think you know what a computer is? </p><p>Now THIS is a computer:</p>
Schrödinger's Catgirl (Joyce)<p>Embedded dev while on the ICE -- can Joyce get her demo out in time for <a href="https://chaos.social/tags/39C3" class="mention hashtag" rel="tag">#<span>39C3</span></a>?</p>
Sven Slootweg, low-spoons mode ("still kinky and horny anyway")<p>Something I should probably say out loud because it keeps irritating me: corporations open-sourcing some code that they wrote for themselves is <strong>NOT</strong> a "contribution to the commons". It's dumping some scraps to keep up appearances.</p><p>Genuine contributions to the commons look like "understanding what other people need, and making sure that your contributions are also a net positive for them, and not just tailored strictly to your own needs".</p><p>The power of the commons is that it's a shared pool of resources for everyone to mutually benefit from and contribute to. Nobody ultimately benefits from your "SDK" or your "design system" (ie. branding guide) or your highly-specialized UI library or orchestration software, except for you. If at least <em>some</em> part of your work isn't selfless and without commercial benefit, you're not really contributing.</p><p>Almost no companies actually, genuinely contribute to the commons. An example of a company that <em>does</em> do so, however much I dislike them for other reasons, is Valve - their contribution to eg. FEX and the WINE ecosystem are useful for everyone, not just for Valve. Be more like them and less like Google.</p><p>Edit: And to highlight this bit in particular: "contributing to the commons" as a company means <em>maintaining</em> your contribution. Not just dumping it on Github and never looking at it again.</p><p><a href="https://fedi.slightly.tech/tags/foss" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FOSS</span></a> <a href="https://fedi.slightly.tech/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://fedi.slightly.tech/tags/publiccommons" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PublicCommons</span></a></p>
Sven Slootweg, low-spoons mode ("still kinky and horny anyway")<p>For many years, while being poor and still working on FOSS stuff anyway, I was wondering why it seemed to be impossible for me to find any funding even though other projects (often much more sketchy) kept getting funded left and right.</p><p>And over the years, I've started realizing that the answer for a <em>lot</em> of these cases was "because the people getting funded knew the funders personally from fashy circles".</p>
Schrödinger's Catgirl (Joyce)<p>First it was AWS, then it was Microsoft Azure, and now, it&#39;s Cloudflare!</p><p><a href="https://www.independent.co.uk/tech/cloudflare-down-twitter-not-working-outage-b2867367.html" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">independent.co.uk/tech/cloudfl</span><span class="invisible">are-down-twitter-not-working-outage-b2867367.html</span></a></p>