2026-07-18 14:42:02
from my link log —
An incomplete list of mistakes in the design of CSS.
https://wiki.csswg.org/ideas/mistakes
saved 2021-01-24 https://dotat.at/:/…
from my link log —
An incomplete list of mistakes in the design of CSS.
https://wiki.csswg.org/ideas/mistakes
saved 2021-01-24 https://dotat.at/:/…
the non-news of the solstice is that, surprising no-one, there will not be a leap second at the new year
the difference between UT1 and UTC remains very close to zero and the earth is rotating at very close to 24h per day
BUT LOOK
since i previously posted these charts in march, the length-of-day line (green) has popped upwards
https…
Americans are neither as hostile to socialism as they once were
nor as positive toward capitalism as they have been in the past.
More important than polling, however, is the fact that for many Americans the “communist threat” is a total abstraction.
There are tens of millions of voters (
who were young children when the Soviet Union fell.
There are millions more who weren’t yet born.
For these Americans, communism is as much a concern as the missile gap …
I've finally done it! It took me over five years, but I've *finally* finished a game of #Stellaris!
And now, I need sleep.
Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study
Shanna M. Kahn, John D. Hastings
https://arxiv.org/abs/2607.20713 https://arxiv.org/pdf/2607.20713 https://arxiv.org/html/2607.20713
arXiv:2607.20713v1 Announce Type: new
Abstract: LLM-based coding tools enable non-expert users to generate routine automation scripts that may enter enterprise workflows without meaningful security review. This study examines that risk directly. Code was collected from ChatGPT, Microsoft Copilot, and Google Gemini using identical prompts across three automation domains. Claude Code performed a standardized vulnerability review. Each identified vulnerability was scored using CVSS v3.1 and mapped to the OWASP Top 10:2021 and the MITRE ATT&CK frameworks. Every script contained exploitable vulnerabilities. Nine of the 17 identified vulnerability classes appeared in code from all three models, while 14 of the 17 vulnerability classes appeared in at least two models. The weighted CVSS scores across platforms differed by less than 10%. The risk is not tied to any particular model but rather to the task category. Organizations should therefore ask not which tool to trust, but instead whether LLM-generated automation code should be deployed without review.
toXiv_bot_toot
from my link log —
SUNSPOT: an implant in the SolarWinds Orion build process.
https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/
saved 2021-01-12
Themis Consensus Extension v1: MEV Mitigation by Randomized Delayed Execution and Intent-Hiding Transactions in Application-Specific Blockchains
Shoeb Siddiqui, Mateusz Nowakowski, Stanislav Vozarik, Gleb Urvanov, Peter Kris
https://arxiv.org/abs/2607.21406 https://arxiv.org/pdf/2607.21406 https://arxiv.org/html/2607.21406
arXiv:2607.21406v1 Announce Type: new
Abstract: Maximal extractable value (MEV) arises when privileged participants select, exclude, insert, or reorder pending transactions for private gain. We specify and analyze the Themis Consensus Extension v1, first published by Mangata in 2021. The design separates value extraction by reordering (VER) from value extraction by denial (VED). For VER, block construction and execution occur across consecutive producers: one producer commits a transaction set, and the next derives a publicly verifiable, deterministic, previously un- predictable seed and executes a seed-determined, dependency-preserving permutation. For selective VED, a user may encrypt a transaction for a designated builder and executor. The builder removes an outer layer and commits the opaque inner ciphertext; the executor reveals and executes the plaintext only after commitment. Under selfish but non-colluding validators, an adversary below the underlying consensus fault threshold, secure cryptography, and accountable role performance, the construction limits unilateral post-commit ordering control and hides transaction intent from relays and the builder. It does not provide send-order or receive-order fairness, complete censorship resistance, resistance to builder-executor collusion, or per-transaction price guarantees. We analyze probabilistic extraction, spam, dependent transactions, decryption liveness, session boundaries, total denial, and threshold coalitions. We also document the initial Aura-based Substrate implementation and its subsequent transition to a BABE-based sr25519/VRF seed path, together with delayed execution, Fisher-Yates shuffling, and Xoshiro256 . The result preserves the original proposal while narrowing its claims to explicit assumptions.
toXiv_bot_toot
Queria que o IBGE atualizasse logo a coisinha dos nomes do censo de 2010 pro de 2021...
2010 foi hš muito tempo, os resultados com certeza jš são totalmente diferentes
🇺🇦 #NowPlaying on #BBC6Music's #6MusicsIndieForever
Wet Leg:
🎵 Chaise Longue (6 Music Session, 4 Oct 2021)
#WetLeg
https://longdissonance.bandcamp.com/track/wet-leg-chaise-longue
https://open.spotify.com/track/7iqAuZe5yS0suLQcFfVK39