Downloads
Humane Intelligence | Advancing AI Auditing & Impact
Humane Intelligence is a tech nonprofit. A platform for model evaluators & learners to professionalize algorithmic auditing and real-time AI impact assessments.
Gram
A free open source social media platform without ads or tracking! Connect with millions of people around the world on the Fediverse (Federated Universe).
Cyd - Claw back your data from Big Tech
Automatically delete your data from tech platforms, except for what you want to keep
iocaine
The deadliest poison known to AI
ZADZMO code
The long and winding road to safe browser-based cryptography
Browser-based cryptography has struggled with a longstanding chicken-and-egg problem that predates many features of the modern web, and while some of those features have reduced the problem’s severity, the issue remains: What is the basis for trusting the code that performs browser-based encryption?
DadaDodo
Authorization Matters
I've become very interested in the topic of authorization over the last year and plan to write about it more. I hope you'll follow along.
Block AI scrapers with Anubis
I got tired with all the AI scrapers that were bullying my git server, so I made a tool to stop them for good.
The Powerful AI Tool That Cops (or Stalkers) Can Use to Geolocate Photos in Seconds
For months members of the public have been using GeoSpy, a tool trained on millions of images that can find the location a photo was taken based on soil, architecture, and more. It's GeoGuesser at scale.
Google open sources software composition analysis library
Software composition analysis (SCA) is a process undertaken to identify and track application code dependencies and also track security and compliance Google has open sourced OSV-SCALIBR (Software Composition Analysis LIBRary). With open source vulnerability (OSV) issues always in the spotlight, this could be a welcome development.
OPAL - an Authorization Service for Fine-Grained Permissions
Open Policy Administration Layer (OPAL) is an open-source administration layer for OPA and AWS' Cedar Agent that allows you to keep your authorization layer up-to-date in real time
New Bambu Lab Firmware Update Adds Mandatory Authorization Control System
As per a recent Bambu Lab blog post, its FDM printers in the X1 series will soon receive a firmware update that adds mandatory authentication for certain operations, starting with the firmware upda…
Policy as Code | From Infrastructure to Fine-Grained Authorization
Learn about Policy as Code, its use cases, and challenges from leading software developers. Discover tools and frameworks for policy as code implementation, and dive into policy languages like Rego, Cedar, and OpenFGA.
Proxy Alice: Secret Predictive Messages
Abstract
Evil Models and Exploits: When AI Becomes the Attacker
A look at four ways that AI is reshaping hacking and malware development, and how we can stay vigilant in response.
Impersonate fingerprint of the latest version of Chrome, Firefox, and Edge
Impersonate JA4 and H2 fingerprint of the latest version of Chrome, Firefox
Building AI Agents to Solve Security Challenges
Learn how to build AI agents to solve security challenges using the CrewAI framework.
Mail-in Apostille in California
An Apostille is similar to notarization to certify a document, but intended for use in another country. Apostille is defined by a Hague conv...
A Tour of WebAuthn
Top 5 Cyber Resilience Issues for Network Devices
Why is the cyber resilience of network devices lagging and what can you do about it? The answer: Leverage automation.
Vuls: A Free, Open Source Vulnerability Scanner for Linux
Using an agentless SSH approach, Vuls allows you to scan multiple operating systems using multiple methods, such as fast scan and deep scan.
A Note from our Executive Director
This letter was originally published in our 2024 Annual Report.
The past year at ISRG has been a great one and I couldn’t be more proud of our staff, community, funders, and other partners that made it happen. Let’s Encrypt continues to thrive, serving more websites around the world than ever before with excellent security and stability. Our understanding of what it will take to make more privacy-preserving metrics more mainstream via our Divvi Up project is evolving in important ways.
Open source projects drown in bad bug reports penned by AI
Python security developer-in-residence decries use of bots that 'cannot understand code'
The Simple Math Behind Public Key Cryptography
The security system that underlies the internet makes use of a curious fact: You can broadcast part of your encryption to make your information much more secure.
Back where it started: “Do Not Track” removed from Firefox after 13 years
Firefox isn’t the last browser to drop Do Not Track, but it’s a symbolic end to a long, sad campaign to claw back a little privacy.
On passwords
zudell.io._ blog
Trust Issues - Schneier on Security
This essay appeared as a response in Boston Review‘s forum, “The AI We Deserve.” For a technology that seems startling in its modernity, AI sure has a long history. Google Translate, OpenAI chatbots, and Meta AI image generators are built on decades of advancements in linguistics, signal processing, statistics, and other fields going back to the early days of computing—and, often, on seed funding from the U.S. Department of Defense. But today’s tools are hardly the intentional product of the diverse generations of innovators that came before. We agree with Morozov that the “refuseniks,” as he ...
USB-C cable CT scan reveals sinister active electronics — O.MG pen testing cable contains a hidden antenna and another die embedded in the microcontroller
A small package with a huge malicious potential.