not recommending this tool (I hate its syntax and the way they are implementing things)
just putting it for inspiration or something idk
https://capnproto.org/
another alternative to protobuf codegen
just putting it for inspiration or something idk
https://capnproto.org/
another alternative to protobuf codegen
Do It by Code
48-digit prime numbers every git commit
The Miller-Rabin primality test is an algorithm used to determine if a very large number is a prime number. It is the standard method used in cryptography (like RSA key generation and the git-prime example above) because it is incredibly fast.
1. What is it?
It is a probabilistic algorithm. This is the most important distinction:
* Deterministic tests (like trying to divide the number by every smaller number) give you a 100% correct answer but are impossibly slow for large numbers.
* Miller-Rabin gives you an answer very quickly, but it trades absolute certainty for speed.
The output of the test is either:
1. Composite: The number is definitely not prime (100% certainty).
2. Probably Prime: The number is very likely prime.
2. Why do we need it for SHA-1?
As the source noted, SHA-1 hashes are 160-bit integers. That is a number roughly equal to 10 to the power of 48 (a 1 followed by 48 zeros).
If you used standard division to check if that number is prime, the sun would likely explode before your computer finished. Miller-Rabin can check it in milliseconds.
3. How does it work?
The math relies on Fermat's Little Theorem, which states that if p is a prime number, then for any integer a, a^(p-1) mod p = 1.
Here is the simplified process:
Step 1: The Setup
Let's say we want to test a big number n. We express n-1 in a specific form (2^s * d). This is basically factoring out all powers of 2.
Step 2: The Witness
We pick a random number a (called a base) that is smaller than n. We call this number a "witness."
Step 3: The Interrogation
We run a modular exponentiation calculation using a, s, and d.
* If the math doesn't balance out according to the theorem, a acts as a witness that proves n is Composite. We stop immediately.
* If the math *does* balance out, n passes the test for that specific witness.
Step 4: Repetition
Because there is a tiny chance a composite number could "trick" the test (called a Strong Pseudoprime), we repeat Step 2 and 3 with different random values for a.
Do It by Code
The Miller-Rabin primality test is an algorithm used to determine if a very large number is a prime number. It is the standard method used in cryptography (like RSA key generation and the git-prime example above) because it is incredibly fast. 1. What isβ¦
A simple python implementation of it would be like this: (source)
import random
def is_prime_miller_rabin(n, k=40):
"""Miller-Rabin primality test - probabilistic but very reliable"""
if n < 2:
return False
if n == 2 or n == 3:
return True
if n % 2 == 0:
return False
# Write n-1 as 2^r * d
r, d = 0, n - 1
while d % 2 == 0:
r += 1
d //= 2
# Witness loop
for _ in range(k):
a = random.randrange(2, n - 1)
x = pow(a, d, n)
if x == 1 or x == n - 1:
continue
for _ in range(r - 1):
x = pow(x, 2, n)
if x == n - 1:
break
else:
return False
return True
Media is too big
VIEW IN TELEGRAM
source - @sbrugnadlbot
labs.google/ProjectGenie
Step inside Project Genie: our experimental research prototype that lets you create, edit, and explore virtual worlds. π
labs.google/ProjectGenie
https://en.wikipedia.org/wiki/Bus_factor
The "bus factor" is the minimum number of team members that have to suddenly disappear from a project before the project stalls due to lack of knowledgeable or competent personnel.
For instance, say a team of 30 people produces bread in three necessary steps: mixing ingredients, kneading the dough, and baking. 10 people know how to mix ingredients, all 30 people know how to knead the dough, and 5 people know how to bake. If all 5 people who know how to bake disappear, then the team cannot produce bread, so the team's bus factor is 5. A bus factor of one is a single point of failure.
https://en.wikipedia.org/wiki/Single_point_of_failure
A single point of failure (SPOF) is a part of a system that would stop the entire system from working if it were to fail.
The "bus factor" is the minimum number of team members that have to suddenly disappear from a project before the project stalls due to lack of knowledgeable or competent personnel.
For instance, say a team of 30 people produces bread in three necessary steps: mixing ingredients, kneading the dough, and baking. 10 people know how to mix ingredients, all 30 people know how to knead the dough, and 5 people know how to bake. If all 5 people who know how to bake disappear, then the team cannot produce bread, so the team's bus factor is 5. A bus factor of one is a single point of failure.
https://en.wikipedia.org/wiki/Single_point_of_failure
A single point of failure (SPOF) is a part of a system that would stop the entire system from working if it were to fail.
Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site
https://www.404media.co/exposed-moltbook-database-let-anyone-take-control-of-any-ai-agent-on-the-site
also:
1-Click RCE to steal your Moltbot data and keys
Article, Comments
https://www.404media.co/exposed-moltbook-database-let-anyone-take-control-of-any-ai-agent-on-the-site
also:
1-Click RCE to steal your Moltbot data and keys
Article, Comments
Forwarded from vx-underground
Non-malware schizos asking about why the Notepad++ malware payload was so interesting.
Okay, we'll discuss it without getting too schizo.
First, Rapid7 (and other various Cyber Threat Intelligence vendors) seem to generally attribute the Notepad++ compromise to Chinese APT group "Lotus Bloom". They attribute it to Lotus Blossom because they tend to recycle code segments to save time. Basically, fingerprints.
Lotus Blossom is the invented name intelligence organizations have assigned to a group of Chinese government sponsored hackers. Their true identity is unknown, but speculative. It is not one person, it is likely a group of unknown size, it could two people, it could 15 people.
Lotus Blossom has been active since 2009 (or so they speculate). Lotus Blossom are not noobs who do hacker noob stuff. Lotus Blossom is assigned high-profile tasks. Lotus Blossom does extremely specific targets, most notably they are instructed by the Chinese government to hack government institutions, telecom companies, aviation companies, and critical infrastructure (nuclear power plants, electrical power grids, hydroelectric dams, etc) in Southeast Asia and Central America.
When Lotus Blossom targeted Notepad++, and users in specific regions (presumably Southeast Asia and Central America) attempted to do an update it delivered "Chrysalis Backdoor". Chrysalis Backdoor is the name intelligence companies invented and now call this malware.
Chrysalis Backdoor used a lot of really common malware techniques which truthfully I won't go too much into (API hashing, custom implementations of GetProcAddress, malware nerd stuff). However, what makes this malware very special is it's usage of Microsoft Warbird.
Microsoft Warbird is a proprietary technology which is rarely discussed. It is an internal library Microsoft uses to obfuscate it's instruction set in-memory. In other words, it's Microsoft really fancy custom way of preventing people from reverse engineering what Windows is doing when it's running.
Unknown to me personally (and a lot of people apparently), in the past few years (2023) some security researchers have discovered ways to discretely use Microsoft Warbird and use it as a weapon. Basically, you can use undocumented APIs in Windows to use Warbird for your malware. This provides a way to hide what your malicious code is doing while it's running without needing any external tooling or custom implementations. They're weaponizing Microsoft's anti-tampering and/or anti-reverse engineering technology for malicious purposes. This is extremely impressive because it shows:
1. Lotus Blossom pays close attention to really talented security researchers or...
2. Lotus Blossom has really good security researchers on payroll
Both are totally possible.
The remainder of the Lotus Blossom tooling is fairly generic malware stuff and isn't too terribly impressive. Lotus Blossom (unironically) did a very good job hijacking Notepad++ update infrastructure and weaponizing Microsoft's anti-tampering technology (Warbird).
Okay, we'll discuss it without getting too schizo.
First, Rapid7 (and other various Cyber Threat Intelligence vendors) seem to generally attribute the Notepad++ compromise to Chinese APT group "Lotus Bloom". They attribute it to Lotus Blossom because they tend to recycle code segments to save time. Basically, fingerprints.
Lotus Blossom is the invented name intelligence organizations have assigned to a group of Chinese government sponsored hackers. Their true identity is unknown, but speculative. It is not one person, it is likely a group of unknown size, it could two people, it could 15 people.
Lotus Blossom has been active since 2009 (or so they speculate). Lotus Blossom are not noobs who do hacker noob stuff. Lotus Blossom is assigned high-profile tasks. Lotus Blossom does extremely specific targets, most notably they are instructed by the Chinese government to hack government institutions, telecom companies, aviation companies, and critical infrastructure (nuclear power plants, electrical power grids, hydroelectric dams, etc) in Southeast Asia and Central America.
When Lotus Blossom targeted Notepad++, and users in specific regions (presumably Southeast Asia and Central America) attempted to do an update it delivered "Chrysalis Backdoor". Chrysalis Backdoor is the name intelligence companies invented and now call this malware.
Chrysalis Backdoor used a lot of really common malware techniques which truthfully I won't go too much into (API hashing, custom implementations of GetProcAddress, malware nerd stuff). However, what makes this malware very special is it's usage of Microsoft Warbird.
Microsoft Warbird is a proprietary technology which is rarely discussed. It is an internal library Microsoft uses to obfuscate it's instruction set in-memory. In other words, it's Microsoft really fancy custom way of preventing people from reverse engineering what Windows is doing when it's running.
Unknown to me personally (and a lot of people apparently), in the past few years (2023) some security researchers have discovered ways to discretely use Microsoft Warbird and use it as a weapon. Basically, you can use undocumented APIs in Windows to use Warbird for your malware. This provides a way to hide what your malicious code is doing while it's running without needing any external tooling or custom implementations. They're weaponizing Microsoft's anti-tampering and/or anti-reverse engineering technology for malicious purposes. This is extremely impressive because it shows:
1. Lotus Blossom pays close attention to really talented security researchers or...
2. Lotus Blossom has really good security researchers on payroll
Both are totally possible.
The remainder of the Lotus Blossom tooling is fairly generic malware stuff and isn't too terribly impressive. Lotus Blossom (unironically) did a very good job hijacking Notepad++ update infrastructure and weaponizing Microsoft's anti-tampering technology (Warbird).
Nine-slice (also known as 9-patch or 9-slice scaling) is a classic technique for drawing resizable UI elements (buttons, panels, dialog boxes, etc.) from a single small sprite.
The idea is to divide a sprite into 9 regions:
- 4 corners β drawn as-is, never stretched or tiled
- 4 edges β tiled/stretched in one direction to fill the needed width or height
- 1 center β tiled/stretched in both directions
This lets you render a UI element at any size while keeping the corners crisp and undistorted.
What the code does specifically:
1. Saves the current clip, gets the sprite dimensions.
2. Draws the 4 corners β top-left, top-right, bottom-left, bottom-right β by setting clip regions of cornerWidth Γ cornerHeight at each corner and drawing the sprite frame there.
3. Computes i = width - cornerWidth * 2 (the horizontal space between corners that needs filling) and iMin (the tile size from the sprite's middle section).
4. The while loop tiles the top and bottom edges horizontally β it steps across in increments of iMin, clipping each tile to avoid overdraw.
The image is cut off, but there's almost certainly similar code below for tiling the left/right edges vertically and filling the center.
This is very typical of old J2ME / mobile game UI code where you'd have a single sprite for a button or window frame and needed to draw it at various sizes
The idea is to divide a sprite into 9 regions:
[1 corner][2 edge][3 corner]
[4 edge ][5 fill][6 edge ]
[7 corner][8 edge][9 corner]
- 4 corners β drawn as-is, never stretched or tiled
- 4 edges β tiled/stretched in one direction to fill the needed width or height
- 1 center β tiled/stretched in both directions
This lets you render a UI element at any size while keeping the corners crisp and undistorted.
What the code does specifically:
1. Saves the current clip, gets the sprite dimensions.
2. Draws the 4 corners β top-left, top-right, bottom-left, bottom-right β by setting clip regions of cornerWidth Γ cornerHeight at each corner and drawing the sprite frame there.
3. Computes i = width - cornerWidth * 2 (the horizontal space between corners that needs filling) and iMin (the tile size from the sprite's middle section).
4. The while loop tiles the top and bottom edges horizontally β it steps across in increments of iMin, clipping each tile to avoid overdraw.
The image is cut off, but there's almost certainly similar code below for tiling the left/right edges vertically and filling the center.
This is very typical of old J2ME / mobile game UI code where you'd have a single sprite for a button or window frame and needed to draw it at various sizes
source
StackOverflow post from official staff about how the website hasn't been killed by AI.... is AI generated
source
holy shit bro it's real. the fucking *official stack overflow community manager* made a 100% ai generated post about how stack overflow isn't dead because of ai
Forwarded from HN Best Comments
Re: LiftKit β UI where "everything derives from the golden ratio"
When we designed Chrome, since minimalism was our thing and screens used to be small, A LOT of time was spent on the total vertical space - thin titlebar, slightly bigger tabstrip, and a large toolbar. Lots of discussion, lots of questions
Telling people the height ratios between them followed the golden ratio was a very convenient way to shortcut the bikeshedding and get to "aha, very nice"
The trick was it didn't follow the golden ratio at all because the golden ratio is not some magic number that leads to balance and peace - lighting, rounding, color, and visual strength all dramatically outweigh it
gmurphy, 8 hours ago
When we designed Chrome, since minimalism was our thing and screens used to be small, A LOT of time was spent on the total vertical space - thin titlebar, slightly bigger tabstrip, and a large toolbar. Lots of discussion, lots of questions
Telling people the height ratios between them followed the golden ratio was a very convenient way to shortcut the bikeshedding and get to "aha, very nice"
The trick was it didn't follow the golden ratio at all because the golden ratio is not some magic number that leads to balance and peace - lighting, rounding, color, and visual strength all dramatically outweigh it
gmurphy, 8 hours ago
CVE-2025-66630: predictable, insecure zero-UUID generation in go fiber
Severity: Critical (9.2/10)
Affected version: < 2.52.11
Patched version: 2.52.11
- GitHub Advisory
- patch commit
- CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
#cve #go
Severity: Critical (9.2/10)
Affected version: < 2.52.11
Patched version: 2.52.11
Fiber v2 contains an internal vendored copy of gofiber/utils, and its functions UUIDv4() and UUID() inherit the same critical weakness described in the upstream advisory. On Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. In such cases, these Fiber v2 UUID functions silently fall back to generating predictable values β the all-zero UUID 00000000-0000-0000-0000-000000000000.
On Go 1.24+, the language guarantees that crypto/rand no longer returns an error (it will block or panic instead), so this vulnerability primarily affects Fiber v2 users running Go 1.23 or earlier, which Fiber v2 officially supports.
Because no error is returned by the Fiber v2 UUID functions, application code may unknowingly rely on predictable, repeated, or low-entropy identifiers in security-critical pathways. This is especially impactful because many Fiber v2 middleware components (session middleware, CSRF, rate limiting, request-ID generation, etc.) default to using utils.UUIDv4().
- GitHub Advisory
- patch commit
- CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
#cve #go