💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
banner
hackancuba.bsky.social
💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
@hackancuba.bsky.social
Linuxero, informático y algo más... Me gustan las impresoras :) | GPG 0x35710D312FDE468B | Matrix: @hackan:http://mozilla.org | Mastodon: @[email protected]
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
I just vibecoded with exe.dev and Opus 4.5 a backoffice for our FIPS 140 validation, with a separate view for the lab (where they can also upload test vectors), public links for clients, and guided scripts for testing.

I have not looked at the code once. It works great.

I am... processing this.
January 2, 2026 at 5:16 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
If you are a resident of California, the state now has a portal where you can demand deletion of your personal data from 500+ registered data brokers with a single request form, for free.

consumer.drop.privacy.ca.gov
consumer.drop.privacy.ca.gov
January 2, 2026 at 2:26 AM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Really big age release coming tomorrow! 🎅🏻

- native post-quantum keys
- built-in recipients for hw plugins
- age-inspect tool
- plugin framework
- batchpass plugin
- many improved error messages
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age
age-encryption.org
December 24, 2025 at 12:02 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Using an age keyserver as a demo, this article demonstrates how to add a transparency log to a centralized service step-by-step.

We use Tessera for the tlog, VRFs for privacy, and the Witness Network. It all takes just 500 lines to integrate!

The result of years of work making tlogs accessible.
Building a Transparent Keyserver
We apply a transparency log to a centralized keyserver step-by-step, in less than 500 lines, with privacy protections, anti-poisoning, and witness cosigning.
words.filippo.io
December 19, 2025 at 3:32 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
If you want to help seed the Certificate Transparency archive (github.com/geomys/ct-ar...), there is now an RSS feed for your BitTorrent client! Don't forget to set unlimited seed ratio ✨

raw.githubusercontent.com/geomys/ct-ar...
GitHub - geomys/ct-archive: A directory of archived Certificate Transparency (CT) logs and tools to archive RFC 6962 and Static CT logs.
A directory of archived Certificate Transparency (CT) logs and tools to archive RFC 6962 and Static CT logs. - geomys/ct-archive
github.com
December 17, 2025 at 7:00 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Hey hey!
Go Slimey Go! is now out!!
Muy cousin and his team worked super hard to bring this project to life.
Support Latin games 😎😃
store.steampowered.com/app/3215230/...
#GoSlimeyGo
Save 20% on Go Slimey Go! on Steam
Help Slimey, our tiny slippery protagonist, visit his friends for some well deserved teatime after some thrilling platforming challenges!
store.steampowered.com
December 12, 2025 at 8:19 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
My Draw Steel Adventure Tools!

This spreadsheet helps you create combat encounters, montages, negotiations, and more, all following official recommendations! Available on my Patreon at patreon.com/Alphastream

www.youtube.com/watch?v=DtbB...

#DrawSteel #TTRPG
December 12, 2025 at 9:11 PM
Hey hey!
Go Slimey Go! is now out!!
Muy cousin and his team worked super hard to bring this project to life.
Support Latin games 😎😃
store.steampowered.com/app/3215230/...
#GoSlimeyGo
Save 20% on Go Slimey Go! on Steam
Help Slimey, our tiny slippery protagonist, visit his friends for some well deserved teatime after some thrilling platforming challenges!
store.steampowered.com
December 12, 2025 at 8:19 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
We only have a few of these left from the Dicefunder earlier this year and we will be selling them on Friday.
Good King Omund's Box of Dice
A new game for a new age! Draw Steel is the breathtaking new, action-oriented, fantasy RPG from MCDM that’s both fun to play and fun to run!
shop.mcdmproductions.com
November 26, 2025 at 7:11 AM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
November 26, 2025 at 11:36 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
movie: we can't trace their payload, it's behind two layers of base64!

computer knowers: *groan*

reality:
November 25, 2025 at 1:17 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
This is amazing, have people seen this??

www.youtube.com/watch?v=BhOe...
Level 4 DRAW STEEL Metal Troubadour - Riffs and a Song for the abilities!
YouTube video by BarcodeDM
www.youtube.com
November 19, 2025 at 10:46 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
November 21, 2025 at 2:45 AM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
The “peace plan” for Ukraine is just a framework for Russia & the US to take assets away from Ukrainian recovery, and to ensure Russia evades accountability for war crimes

Europe can, and must, craft better with Ukraine

A point by point analysis of the shambles:

www.greatpower.us/p/28-points-...
28 Points Later
A definitive guide to the Russian zombie diplomacy of Trump’s peace plan for Ukraine — aka what happens when you let the Russians eat your brains
www.greatpower.us
November 21, 2025 at 9:22 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Draw Steel Ancestries, Part One!

youtu.be/97wxQueVXcc
Draw Steel Ancestry Guide - Part 1! #drawsteel
YouTube video by Matthew Colville
youtu.be
November 22, 2025 at 3:16 AM
@hellomcdm.bsky.social hey guys, i have a quick question regarding discord: i was trying to join the server but it errors out; observing the request, i see a 403 response with "the user is banned from this guild", which is interesting, as I have never been in the server before :thinking:
any clues?
November 8, 2025 at 12:26 AM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Some of the OPM memos ordering federal employees to return to offices and ordering hiring freezes were written by people who worked on Project 2025, according to metadata on the documents www.404media.co/opm-memos-to...
Memos to Federal Employees Were Written By People With Ties to Project 2025, Metadata Shows
James Sherk and Noah Peters appear as the authors of memos sent by the Office of Personnel Management.
www.404media.co
January 27, 2025 at 11:43 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
Accelerando is one of my favorite sci-fi novels. I would say it's been highly influential in tech.
Today I learned it is available for free under a CC license below.

(Yes, I am kind of slow for ebook news I prefer the physical stuff)

www.antipope.org/charlie/blog...
Accelerando - Charlie's Diary
I hope that if you enjoy the ebook you'll consider buying my other books, but this is the only reminder you'll get. (I'm not into shareware with nag screens ...)
www.antipope.org
January 10, 2025 at 6:59 PM
Reposted by 💚🧡 𝘏𝘢𝘤𝘒𝘢𝘯
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.

Looks like this got caught by chance. Wonder how long it would have taken otherwise.
Woah. Backdoor in liblzma targeting ssh servers.

www.openwall.com/lists/oss-se...

It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…

Now I’m curious what it does in RSA_public_decrypt
March 30, 2024 at 5:13 PM
A new #Blake2Signer major is incoming!
Likely to be released this week 🤘, but it could happen next one 😎
January 10, 2024 at 12:29 AM
Blake2Signer Xmas Edition: gitlab.com/hackancuba/b...

A patch release w/ less than minor changes, but ensuring support for Python 3.12 (and upcoming releases) and PyPy 3.10. Also, this is the last one supporting Python 3.7, as a new major is up ahead, simply to ditch it :D
Release v2.5.3 · HacKan / blake2signer · GitLab
Release v2.5.3 All release tags are signed, and release packages are also signed. Always check signatures prior using this software.
gitlab.com
December 27, 2023 at 5:22 PM
So, what's this twitter?
August 31, 2023 at 1:38 AM