Corner and Corners 📐
角落和角落 📐
📷 Pentax 6x7
🎞️ Lucky SHD 400 (6x7)
If you like my work, Support by buying me a coffee or a roll of film from PayPal #filmphotography
The Look on the Bystander 👀
凝视旁观者 👀
📷 Pentax MX
🎞️ Ilford FP4 Plus 125 (FF), expired 1994
If you like my work, Support by buying me a coffee or a roll of film from
PayPal https://www.paypal.com/paypalme/ydcdingsite
Wise
Civic Museums V 🏛️
民间博物馆 V 🏛️
📷 Pentax MX
🎞️ LUCKY SHD 400 (FF)
If you like my work, Support by buying me a coffee or a roll of film from
PayPal https://www.paypal.com/paypalme/ydcdingsite
Wise
Seeing Eye Dogs Show, By Vision Australia Radio
Your on air guide to the incredible work that goes in behind the scenes at Seeing Eye Dogs, plus all the latest in dog health, caring and fostering puppies, interviews with experts and more...
Great Australian Pods Podcast Directory: https://www.greataus…
Buzz to Boom: Detecting Message Progression Vulnerabilities in Electron Applications via Segmented Directed Fuzzing
Jianjia Yu, Zhengyu Liu, Ziyang Li, Yu Sun, Yinzhi Cao
https://arxiv.org/abs/2607.20698 https://arxiv.org/pdf/2607.20698 https://arxiv.org/html/2607.20698
arXiv:2607.20698v1 Announce Type: new
Abstract: Electron is a popular framework for building cross-platform desktop applications using web technologies. Such applications consist of multiple processes with different privilege levels that communicate via message passing. When inter-process messages carry attacker-controlled inputs, they can propagate across processes and reach privileged APIs, e.g., command execution. Such a message propagation behavior is characterized as Message Progression Vulnerabilities (MPVs). The exploitation of MPVs is challenging because it often requires multiple steps, e.g., first arbitrary code execution in one process via message passing, and then command injection in another process using another message crafted in the first process. To our knowledge, existing works on Electron security only study unsafe configurations and malicious Document Object Model (DOM) content, i.e., they cannot detect or exploit these vulnerabilities that need to be triggered by complex cross-process exploits via message passing. We present Proton, a segmented directed fuzzing framework for detecting MPVs. Our key insight is to decompose end-to-end fuzzing into per-process segments along message-passing boundaries, where the goals of fuzzing each segment are either: (i) reaching a sink in the current process or (ii) propagating the payload to the next process, to enable the exploration of another process. In the second case, the messages seed the corpus of the next segment. Finally, Proton synthesizes crash inputs from each process to validate end-to-end exploits. We evaluate Proton against 589 real-world Electron applications, resulting in 23 zero-day MPVs. Among them, 22 lead to OS command execution, including projects with over 50k GitHub stars. We responsibly disclosed all findings. To date, we have received 13 acknowledgments, 11 fixes, and 11 CVEs, including a bug bounty from Vercel.
toXiv_bot_toot
This is the most detailed picture of a human cell ever made 🧪
https://www.instagram.com/reel/DX1CGIZMKJs/?igsh=NTc4MTIwNjQ2YQ
Classical Acceptance Is Not Hybrid Authentication: Measuring X.509 Verifier Semantics in Post-Quantum Migration
Taesung Kim, Boheung Chung, Keonwoo Kim, Yousung Kang
https://arxiv.org/abs/2607.20800 https://arxiv.org/pdf/2607.20800 https://arxiv.org/html/2607.20800
arXiv:2607.20800v1 Announce Type: new
Abstract: A relying party validating a hybrid X.509 certificate --- carrying both a classical and a post-quantum credential --- must distinguish whether its accepting judgment rests on the post-quantum evidence or only on the classical path. To preserve compatibility, the separable designs place that evidence where classical path validation may ignore it. A verifier can then validate the classical path and accept while the post-quantum evidence never bears on the decision --- a valid classical result silently promoted to a hybrid conclusion it did not establish. We measure this across eight path-validation stacks (seven independent codebases), in nine validation modes, over six certificate schemes. Under a hybrid-required policy, nearly every stack parsing a separable hybrid certificate accepts on the classical path without making the post-quantum evidence outcome-bearing; one enforcing mode instead fractures interoperability over a signature-input encoding not yet interoperably profiled; and stacks that verify post-quantum signatures still do not enforce the binding by default: the gap is structural, not explained by missing primitive capability alone. Under lifecycle desynchronization the downgrade is realized: when a bound post-quantum credential is revoked while the classical certificate stays valid, the default path still accepts, because the bound credential lies outside the decision's scope. Binding success is not authentication success. We contribute a specification-derived verifier model and an executable, policy-parametric reference contract --- what a verifier must recognize, verify, make outcome-bearing, and check before reporting a validation as hybrid --- with a diagnosis of why standards do not require it.
toXiv_bot_toot
Perfection Because It Doesn’t Exist ☀️
完美因为完美不存在 ☀️
📷 Nikon F4E
🎞️ Kentmere 400
If you like my work, Support by buying me a coffee or a roll of film from
PayPal https://www.paypal.com/paypalme/ydcdingsite
Wise
Urban Illusions and Fallacies - A Day In The Park III ⛲️
城市的幻影和谬误 - 公园的一天 III ⛲️
📷 Pentax MX
🎞️ ERA 100, expired 1993
If you like my work, Support by buying me a coffee or a roll of film from PayPal https://paypal.com/paypalme/ydcdingsite
Urban Illusions and Fallacies III 🏙️
城市的幻影和谬误 III 🏙️
📷 Pentax 6x7
🎞️ Kentmere Pan 200 (6x7)
If you like my work, Support by buying me a coffee or a roll of film from PayPal https://paypal.com/paypalme/ydcdingsite