Michael Weissbacher's Avatar

Michael Weissbacher

@mweissbacher

Securing Block (Square) infrastructure. Previously security research at Northeastern University. Internationally acclaimed Schnitzel expert πŸ‡¦πŸ‡Ή mweissbacher.com NYC πŸ—½

597
Followers
485
Following
82
Posts
03.07.2023
Joined
Posts Following

Latest posts by Michael Weissbacher @mweissbacher

Preview
Operationalizing Macaroons The Integral Principles of the Structural Dynamics of Macaroons

I wrote a thing! Really I just took dictation as Ben Toews dictated to me and Tim, and then added a muppet to the diagram. But still: this is a neat system, I'm a little proud of it, and so here you go: YET MORE MACAROON CONTENT.

fly.io/blog/operati...

27.03.2025 22:22 πŸ‘ 17 πŸ” 4 πŸ’¬ 2 πŸ“Œ 1
Post image

The Onion is aggressively on sale.

Subscribing helps us hire comedy writers who get health insurance and even food to eat, with their mouths. That food is converted into energy which allows them to make sentences that make the government sad.

Sign up to let this continue:

membership.theonion.com

27.03.2025 17:14 πŸ‘ 3680 πŸ” 766 πŸ’¬ 99 πŸ“Œ 55
Careers at The Onion

GREAT news everyone!

The Onion is hiring! For a bunch of new positions.

Sports Editor (yes, we're bringing it back): jobs.gusto.com/postings/the...

Entertainment Editor (going harder here too): jobs.gusto.com/postings/the...

And a Staff Writer (!): jobs.gusto.com/postings/the...

Apply or die!

25.03.2025 21:49 πŸ‘ 8378 πŸ” 2435 πŸ’¬ 427 πŸ“Œ 198
Post image

Letting the MTA give out automated camera tickets to drivers blocking the bus route outside the bus lane has sped up buses. Who knew

24.03.2025 15:20 πŸ‘ 497 πŸ” 62 πŸ’¬ 4 πŸ“Œ 13
graph of NIH basisfor new drugs

graph of NIH basisfor new drugs

A pie graph worth keeping in mind as the NIH budget plummets jamanetwork.com/journals/jam... for 356 new FDA drugs approved

23.03.2025 16:17 πŸ‘ 4030 πŸ” 1646 πŸ’¬ 60 πŸ“Œ 85
Preview
How to find Next.js on your network How to find Next.js on your network

Next.js dropped a CVSS 9.1 authentication bypass vulnerability (CVE-2025-29927) over the weekend. This flaw is trivially exploitable by sending the header `x-middleware-subrequest: true`. Over 300k hits in Shodan, find more at:

23.03.2025 02:42 πŸ‘ 16 πŸ” 15 πŸ’¬ 0 πŸ“Œ 0
Preview
A 6‑Hour Time-Stretched Version of Brian Eno’s Music For Airports: Meditate, Relax, Study Robert Wyatt, Music for Airports started the idea of slow, meditative music that abandoned typical major and minor scales, brought in melodic ambiguity, and began the exploration of sounds that were designed to exist somewhere in the background, beyond the scope of full attention.

A 6‑Hour Time-Stretched Version of Brian Eno’s Music For Airports. β€œThe tonal field is the same, but now the notes are no attack, all decay.” [openculture.com]

18.03.2025 19:46 πŸ‘ 44 πŸ” 6 πŸ’¬ 2 πŸ“Œ 3
Preview
Wired is dropping paywalls for FOIA-based reporting. Others should follow As the administration does its best to hide public records from the public, Wired magazine is stepping up to help stem the secrecy

They're called public records for a reason. Starting today, WIRED will *stop paywalling* articles that are primarily based on public records obtained through the Freedom of Information Act, becoming the first publication to partner with @freedom.press to offer this for our new coverage.

18.03.2025 13:11 πŸ‘ 91874 πŸ” 23499 πŸ’¬ 1639 πŸ“Œ 2079
Preview
RCS texting updates will bring end-to-end encryption to green bubble chats Lack of encryption was one SMS shortcoming that RCS was created to solve.

If you haven't been tracking, RCS texting is rolling out end-to-end encryption using MLS. This is a huge triumph of the IETF and the collaborative approach to creating internet-grade protocols championed there.

arstechnica.com/gadgets/2025...

16.03.2025 05:46 πŸ‘ 34 πŸ” 4 πŸ’¬ 0 πŸ“Œ 2
Preview
Coffee Boosts Beneficial Gut Bacterium Researchers found a strong connection between coffee and the gut microbiome

Large epidemiologic studies have consistently shown an association between coffee and improved health outcomes. This may be one of the reasons: favorable changes to the gut microbiome 🏒🏒

www.scientificamerican.com/article/coff...

20.02.2025 02:58 πŸ‘ 1284 πŸ” 293 πŸ’¬ 45 πŸ“Œ 69
Preview
The hardest working font in Manhattan A story of a 150-year-old font you have never heard of – and one you probably saw earlier today.

Glorious. aresluna.org/the-hardest-...

17.02.2025 17:01 πŸ‘ 26 πŸ” 6 πŸ’¬ 1 πŸ“Œ 2

we need an associate to join the firm as soon as possible. various reasons inc. half the fed gov't being fired.

employment, civil rights, a bit of suing Elon Musk, some other stuff.

*Virginia* bar required.

I'll get around to posting something formal but email me a resume if you want to apply.

17.02.2025 19:51 πŸ‘ 584 πŸ” 214 πŸ’¬ 9 πŸ“Œ 14
Preview
Amazon’s killing a feature that let you download and backup Kindle books It’s bad if you like to keep ebook backup copies.

hey for anyone who might want to actually own their kindle books instead of renting them, or who might be thinking of switching to kobo etc and will want to convert them to epubs, you now only have one week before amazon kills your ability to download its ebooks www.theverge.com/news/612898/...

16.02.2025 18:08 πŸ‘ 6980 πŸ” 3949 πŸ’¬ 376 πŸ“Œ 394

Microsoft's own research confirms something that was already pretty obvious: relying on a text generating machine to come up with answers erodes critical thinking, and is a method favoured by those who never liked doing critical thinking in the first place

advait.org/files/lee_20...

09.02.2025 10:15 πŸ‘ 7544 πŸ” 2542 πŸ’¬ 137 πŸ“Œ 297

This supposedly complimentary story about one of Musk's greasy goons embodies one of the core problems of DOGE: they were so incompetent they didn't do basic version control or backups, and so lost all their work.

Such people are unfit to be anywhere near critical government infrastructure.

06.02.2025 13:20 πŸ‘ 873 πŸ” 189 πŸ’¬ 36 πŸ“Œ 3
FearNonelnc @RayInsideOut. Here's a list of techies on the ground helping Musk gaining and using access to the US Treasury payment system. Akash Bobba Edward Coristine Luke Farritor Gautier Cole Killian Gavin Kliger Ethan Shaotran 

Elon Musk @elonmusk. You have committed a crime.

FearNonelnc @RayInsideOut. Here's a list of techies on the ground helping Musk gaining and using access to the US Treasury payment system. Akash Bobba Edward Coristine Luke Farritor Gautier Cole Killian Gavin Kliger Ethan Shaotran Elon Musk @elonmusk. You have committed a crime.

Same reply by Musk, but showing the original post was removed as a violation of Twitter rules

Same reply by Musk, but showing the original post was removed as a violation of Twitter rules

an unelected billionaire storming into US agencies, installing his unqualified and unapproved lackeys, purging civil servants, seizing access to sensitive data and payments, unilaterally eliminating federal agencies: fine

identifying the lackeys: illegal

03.02.2025 14:43 πŸ‘ 11625 πŸ” 3232 πŸ’¬ 230 πŸ“Œ 183

My favorite fact about the NYC subway is that there are way more daily riders (about 4 million) than the number of people who fly in the US out of all airports every day (~2.5 million). The scale is hard to get a grasp on.

27.01.2025 14:20 πŸ‘ 4540 πŸ” 975 πŸ’¬ 57 πŸ“Œ 35
Post image

And, there it is: Acting Secretary Benjamine Huffman is terminating "all current memberships on advisory committees within DHS, effective immediately." Including CISA cybersecurity advisory committee.

21.01.2025 20:02 πŸ‘ 78 πŸ” 38 πŸ’¬ 6 πŸ“Œ 17
Biden’s Cyber-Everything Bagel with Carole House
Biden’s Cyber-Everything Bagel with Carole House YouTube video by Security Cryptography Whatever

And we're up, our first episode of this year, this time with video (thankfully not of me): Carole House and the Biden Cybersecurity Everything Bagel.

youtu.be/Pqw0W2crQiM

securitycryptographywhatever.com/2025/01/20/b...

21.01.2025 00:23 πŸ‘ 6 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

COMPUTER SCIENTISTS: "k" means one thousand and twenty-four
STORAGE MANUFACTURERS: "k" means one thousand
DISPLAY MANUFACTURERS [thinking hard]: "K" means nine hundred and sixty

17.01.2025 22:34 πŸ‘ 1826 πŸ” 303 πŸ’¬ 63 πŸ“Œ 22
Preview
Mark Cuban is ready to fund a TikTok alternative built on Bluesky’s AT Protocol Entrepreneur and investor Mark Cuban is ready to fund a TikTok alternative built on Bluesky’s AT Protocol, he shared in a TikTok video posted on Wednesday. In anticipation of the coming U.S. TikTok ban, which will go through on Sunday unless paused by the…

Mark Cuban is ready to fund a TikTok alternative built on Bluesky’s AT Protocol

16.01.2025 18:44 πŸ‘ 31598 πŸ” 4998 πŸ’¬ 976 πŸ“Œ 671
Preview
Data Safety Levels Framework: The foundation of how we look at data in Block Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.

We blogged again! This time about our Data Safety Levels framework, which was inspired by the CDC/WHO Biosafety Levels system and Laboratory Biosafety Manuals. Like biological agents, we also don't want sensitive data to be exposed to humans or escape.

code.cash.app/dsl-framework

16.01.2025 22:00 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Presentation: curl from start to end On Tuesday January 21st 2025, at 16:00 CET (15:00 UTC) I will do a presentation titled as per above. I have not done this one before. The talk will be a detailed explainer and step-by-step going throu...

I've decided to do a little live-streamed #curl presentation on twitch next week:

"curl from start to end". For free of course, no signup. Just show up.

daniel.haxx.se/blog/2025/01...

16.01.2025 20:05 πŸ‘ 23 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Driving blind: NYC subways steered by 1930s tech, paper maps and a lot of hope Ever experience a subway delay at DeKalb Avenue near the foot of the Manhattan bridge? Thank Great Depression era-tech.

This story going inside the β€˜tower’ that controls the DeKalb Interlocking is incredible β€” gothamist.com/news/driving...

16.01.2025 02:35 πŸ‘ 63 πŸ” 12 πŸ’¬ 3 πŸ“Œ 5
A Tour of WebAuthn

Tour of WebAuthn by Adam Langley:
www.imperialviolet.org/tourofwebaut...

23.12.2024 19:16 πŸ‘ 5 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Post image

Chinese hackers (actually, cyber operators) gained control to shut down U.S. ports, power grids, and other critical infrastructure. Intrusions were severe, with key details lost permanently due to erased logs and inadequate tracking. www.wsj.com/tech/cyberse...

05.01.2025 20:18 πŸ‘ 215 πŸ” 114 πŸ’¬ 17 πŸ“Œ 26
1st Microarchitecture Security Conference (uASC '25)

CFP for uASC 25 is still open. We have rolling reviews, and 1 submission is already accepted. If you have interesting results on microarchitecture security (incl. weak threat models or reproducing prior work), check out the CFP at uasc.cc
The CFP closes **Jan 28**

05.01.2025 16:40 πŸ‘ 8 πŸ” 9 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

It’s happening! Tonight, MTA Chair & CEO Janno Lieber unveiled one of the signs at the entrance to the Congestion Relief Zone. Tolling begins at midnight.

Learn more: congestionreliefzone.mta.info

04.01.2025 22:56 πŸ‘ 1171 πŸ” 226 πŸ’¬ 41 πŸ“Œ 128