Brendan Ribera
banner
brendan.threebrothers.org
Brendan Ribera
@brendan.threebrothers.org
Christian. Cyclist, hacker, startup grunt, Melville fanatic, math geek. 4 kids. Married. e^(iπ)+1=0

"Yet is there hope. Time and tide flow wide."
That thing where you mill flour to bake sourdough (and corn bread) to make the best homemade stuffing ever…

… and your teenage daughter dubs you a Trad Husband 😂.

I’m doing something right here.
November 28, 2025 at 4:08 AM
Today's "apish swiping confuses iOS keyboard" headlines feature the word "levain."

It seems Apple have taken upon themselves to name my sourdough starter, and I now have a recurring reminder to "feed Dietrich." 🤌 🥐
November 6, 2025 at 5:19 PM
At the risk of failing to learn lessons 8, 9 & 14, I'll share these words. There is wisdom here.

scholars.org/contribution...
Twenty Lessons on Fighting Tyranny from the Twentieth Century
Americans are no wiser than the Europeans who saw democracy yield to fascism, Nazism or communism. Our one advantage is that we might learn from their experience. Now is a good time to do so. From acr...
scholars.org
October 28, 2025 at 4:53 PM
“Always be comic in a tragedy. What the deuce else can you do?”
August 1, 2025 at 8:47 PM
Reposted by Brendan Ribera
The existence of Norway implies the existence of Nandway.
May 24, 2025 at 6:18 PM
Reposted by Brendan Ribera
All the news is bad
Is there any other kind?
Talking At The Same Time
YouTube video by Tom Waits - Topic
www.youtube.com
March 12, 2025 at 9:42 PM
Reposted by Brendan Ribera
It should be PHYSICALLY IMPOSSIBLE to drive this fast on city streets.
Video to save you the click:
January 29, 2025 at 6:19 PM
Reposted by Brendan Ribera
Security flaws in a Subaru web portal let hackers unlock, start ignition or access a year of detailed location history for millions of cars.

The flaws are now patched. But they revealed powerful tracking abilities that Subaru employees can still access. www.wired.com/story/subaru...
Subaru Security Flaws Exposed Its System for Tracking Millions of Cars
Now-fixed web bugs allowed hackers to remotely unlock and start millions of Subarus. More disturbingly, they could also access at least a year of cars’ location histories—and Subaru employees still ca...
www.wired.com
January 23, 2025 at 1:04 PM
Ugh.
In December, Google made a major announcement: they're ending their ban on device fingerprinting.

This could dramatically reshape the future of web tracking and could have dire consequences on user privacy and your ability to stay safe online.

https://pvcy.org/YVOAFu
January 10, 2025 at 3:31 PM
Reposted by Brendan Ribera
Mister Rogers never misses
January 2, 2025 at 8:38 PM
December 17, 2024 at 9:55 PM
Beautiful.
November 28, 2024 at 3:49 AM
10 years ago I was posting vines and bitly links via Twitter. Two of these things are completely broken now. Open web standards, portable data, etc - please!
October 23, 2024 at 6:27 PM
"On two occasions I have been asked,—'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out?' [...] I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question."

www.gutenberg.org/files/57532/...
Passages from the Life of a Philosopher; by Charles Babbage; a Project Gutenberg ebook.
www.gutenberg.org
October 8, 2024 at 4:21 PM
I'm late to the party, and probably also alone there, but: Ubuntu making its TPM-backed FDE compatible require snapd / not work through debs is... hot garbage.

ubuntu.com/blog/tpm-bac...
TPM-backed Full Disk Encryption is coming to Ubuntu | Ubuntu
Discover Ubuntu’s latest security enhancement: TPM-backed Full Disk Encryption (FDE). This experimental feature in Ubuntu 23.10 offers improved data protection without the need for passphrases […]
ubuntu.com
October 5, 2024 at 12:13 AM
I just received a Very Serious political email reminding me that Seattle treats its middle-class voters like "an ATM machine."
a blonde woman is sitting in a kitchen with the words `` sure , jan . '' written on her face .
ALT: a blonde woman is sitting in a kitchen with the words `` sure , jan . '' written on her face .
media.tenor.com
September 9, 2024 at 8:07 PM
That thing when `do-release-upgrade` kills sshd / restarts and you're stuck in a reentry blackout, wondering if and when your system will come back.
September 3, 2024 at 7:14 PM
💎
Tom Waits - "Get Behind The Mule" (Spiritual)
"Get Behind The Mule" (Spiritual) by @tomwaits Listen Here: https://tomwaits.ffm.to/gbtms Written by Tom Waits & Kathleen Brennan Vocals & Wurlitzer: Tom Waits Motion Graphics Editor: Sarah Sheikh Bridge https://mobiuseditorial.com/ LYRICS Molly be damned smote Jimmy the Harp With a horrid little pistol and a lariat she's goin to the bottom and she's goin down the drain Said she wasn't big enough to carry it Well the rampaging sons of the widow James Jack the cutter and the pock marked kid Had to stand naked at the bottom Of the cross And tell the good lord what they did Tell the good lord what they did They had to get behind the Mule in the morning and plow Had to get behind the Mule in the morning and plow They had to get behind the Mule in the morning and plow Get behind the Mule in the morning and plow Jesus of Nazareth told Mike of the Weeds Was born at this time for a reason And when I'm dead I'll be dead a long time But the wine is so red and so pleasin' Big Jack Earl was 8'1' He stood in the road and he cried He couldn't make her love him Couldn't make her stay but tell the good Lord that he tried Had to get behind the Mule in the morning and plow Had to get behind the Mule in the morning and plow Got to get behind the Mule in the morning and plow Get behind the Mule in the morning and plow Choppity chop goes the axe in the woods You gotta meet me by the fall down tree Shovel of dirt upon a coffin lid I know they'll come lookin for me boys I know they'll come a-lookin for me The dusty trail from Atchison to Placerville Saw the wreck of the Weaverville stage A Yankee traitor drinkin' old lemonade I was stirring my brandy with a nail Someday I have to get behind the Mule in the morning and plow I have to get behind the Mule in the morning and plow I have to get behind the Mule in the morning and plow Get behind the Mule in the morning and plow FOLLOW TOM WAITS ▶ Store: https://tomwaits.ffm.to/store ▶ Website: http://www.tomwaits.com ▶ Facebook: https://www.facebook.com/tomwaits ▶ Instagram: https://www.instagram.com/tomwaits ▶ Twitter: https://twitter.com/TomWaits ▶ YouTube: https://youtube.com/@tomwaits ▶ Spotify: https://spoti.fi/3LC1qg9 ▶ Apple: https://apple.co/3v3UGlz ▶ Amazon: https://amzn.to/3rWIqkK #tomwaits #getbehindthemule
www.youtube.com
August 9, 2024 at 5:18 PM
How you can tell that maybe, just maybe, your kids are logged in to your Google account.
June 27, 2024 at 11:32 PM
Reposted by Brendan Ribera
[aesop rock voice] frog lots in illiopolis
Frog Lots
Illiopolis, IL
June 25, 2024 at 8:58 PM
Reposted by Brendan Ribera
Okay, Taylor. It’s either HIM or ME.
June 2, 2024 at 5:41 AM
Ah, May. When the Federal government finally repays the interest-free loan they've insisted I give them each year.
May 2, 2024 at 2:10 AM
Reposted by Brendan Ribera
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.

Looks like this got caught by chance. Wonder how long it would have taken otherwise.
Woah. Backdoor in liblzma targeting ssh servers.

www.openwall.com/lists/oss-se...

It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…

Now I’m curious what it does in RSA_public_decrypt
March 30, 2024 at 5:13 PM