/dev/fd0's avatar
/dev/fd0
floppy@joinstr.xyz
npub1v6qj...nzyr
/dev/fd0's avatar
/dev/fd0 5 days ago
These security incidents highlight the problems with code review and bug bounties, although it would become a debate about confidential transactions.
/dev/fd0's avatar
/dev/fd0 3 weeks ago
My next post is about OHTTP and its usage in payjoin (most overhyped privacy tool) Spoiler: - Relay and directory collusion breaks privacy - Payjoin cannot be used with untrusted senders or colluding servers image
/dev/fd0's avatar
/dev/fd0 1 month ago
The old website has been moved to old.joinstr.xyz and a new minimalist dark-mode website is live at joinstr.xyz. Joinstr now has a community forum at forum.joinstr.xyz that uses Nostr and Squalk. The old SimpleX chat is dead.
/dev/fd0's avatar
/dev/fd0 1 month ago
The next wave of AI-assisted attacks won't be about discovering bugs but about subtly introducing vulnerabilities into code that pass review unnoticed.
/dev/fd0's avatar
/dev/fd0 1 month ago
The easiest way to contribute to finding bugs without using too many AI tokens: - Find projects with multiple implementations or libs - Prepare a fuzzing harness for differential fuzzing - Run the fuzzer - Report the findings