<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>leyrers online pamphlet</title>
		<link>https://martin.leyrer.priv.at</link>
		<description>Leyrers Rants, Links, Stuff und andere mehr oder weniger interessante Dinge</description>
		<pubDate>Sun, 21 Jun 2026 19:31:47 GMT</pubDate>
		<lastBuildDate>Sun, 21 Jun 2026 19:31:47 GMT</lastBuildDate>
		<language>de-at</language>
		<copyright>Martin 'm3' Leyrer</copyright>
		<managingEditor>leyrer@gmail.com (Martin Leyrer)</managingEditor>
		<webMaster>leyrer@gmail.com (Martin Leyrer)</webMaster>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<ttl>60</ttl>
		<image>
			<url>http://www.leyrer.priv.at/martin/img/m3.jpg</url>
			<title>leyrers online pamphlet</title>
			<link>https://martin.leyrer.priv.at</link>
		</image>
			<item>
				<title>Podcast</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/Podcast.html</link>
				<description><![CDATA[ <p>Microfiction by <a href="https://infosec.exchange/@SecureOwl" title="Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice!">Mike Shewarda</a><a href="https://infosec.exchange/@SecureOwl/116749282265797608" title="There’s no time to explain."> over on Mastodon</a>:</p>

<p>&nbsp;</p>

<p>“My god!” She exclaimed.</p>

<p>“What is it?” He asked.</p>

<p>“There’s no time to explain.”</p>

<p>She jumped up and from her desk in the operations room and ran to the metal locker in the corner.</p>

<p>She flung it open to reveal a full-bore shotgun, which she grabbed, along with as many shells as she could fit in her hands and jeans pockets.</p>

<p>“Veronica?! What are you doing!!” He screamed, now standing as well.</p>

<p>But it was too late. She had already charged through the door and had headed on to the datacenter floor.</p>

<p>He walked out onto the balcony to see what was going on. He was treated to only the briefest listen to the familiar white noise hum of the servers and equipment racks, before the tranquility was shattered by the unmistakable carnage of several shot gun shells being fired towards the hardware.</p>

<p>He ducked for cover. It must’ve only been a couple of seconds, but it felt like an eternity as she laid waste to the computers that until just a few minutes ago she had been peacefully monitoring.</p>

<p>The shooting subsided, he felt comfortable enough to stand up once again.</p>

<p>Dust, bits of servers, smoke and other debris filled the air.</p>

<p>She slowly walked back up the stairs, now covered in a dirty layer of the various materials, and holding a still smoking shotgun.</p>

<p>“What the hell was that about?!” He asked.</p>

<p>“The AI,” she said. “It started podcasting.”</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/21#Podcast</guid>
				<pubDate>Sun, 21 Jun 2026 19:31:47 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-19</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-19.html</link>
				<description><![CDATA[ <h4><a href="https://www.whatwelo.st/p/generative-ai-is-having-its-herbalife" title="Generative AI Is Having Its Herbalife Moment">Generative AI Is Having Its Herbalife Moment</a></h4>
<p><div class="markdown"><p>I believe that vibe coding — irrespective of whether it’s useful for enterprises, which I doubt — is being marketed towards consumers in a deeply unethical way. One that’s worryingly reminiscent of multi-level marketing schemes like Herbalife and Amway, or the crypto grifts of the 2010s.</p>
<p>I believe that Replit’s decision to target younger people at a time when they’re struggling to find work, or are convinced that the future workplace has no use for them, is deeply predatory.</p>
<p>Any creator that promotes Replit without being transparent about the likelihood of building a million-dollar app, or about the costs of building software with AI, is either willingly complicit in a cynical, harmful scam, or otherwise promoting a technology that they themselves do not understand.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/20#shaarli-2026-06-19</guid>
				<pubDate>Sat, 20 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-17</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-17.html</link>
				<description><![CDATA[ <h4><a href="https://www.baldurbjarnason.com/letters/llmentalist/" title="The LLMentalist Effect: how chat-based Large Language Models replicate the mechanisms of a psychic's con">The LLMentalist Effect: how chat-based Large Language Models replicate the mechanisms of a psychic&#8217;s con</a></h4>
<p><div class="markdown"><p>One of the issues in during this research—one that has perplexed me—has been that many people are convinced that language models, or specifically chat-based language models, are intelligent.</p>
<p>…</p>
<p>LLMs are not brains and do not meaningfully share any of the mechanisms that animals or people use to reason or think.</p>
<p>LLMs are a mathematical model of language tokens. You give a LLM text, and it will give you a mathematically plausible response to that text.</p>
<p>There is no reason to believe that it thinks or reasons—indeed, every AI researcher and vendor to date has repeatedly emphasised that these models don’t think.</p>
<p>…</p>
<p>Many of the proposed use cases now look like borderline fraudulent pseudoscience to me.</p>
<p>The intelligence illusion seems to be based on the same mechanism as that of a psychic’s con, often called cold reading. It looks like an accidental automation of the same basic tactic.</p>
<p>By using validation statements, such as sentences that use the Forer effect, the chatbot and the psychic both give the impression of being able to make extremely specific answers, but those answers are in fact statistically generic.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/18#shaarli-2026-06-17</guid>
				<pubDate>Thu, 18 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-16</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-16.html</link>
				<description><![CDATA[ <h4><a href="https://23.social/@angusm@mastodon.social/116759854595893575" title="UK Age Verification">UK Age Verification</a></h4>
<p><div class="markdown"><p>The UK government&#8217;s plan to teach 10 million British children how to use VPNs may be one of the most ambitious IT education projects ever launched. Experts have praised the scheme, saying that a deft combination of incentives and peer education make it more likely to succeed than other, comparable initiatives.</p>
<p>&quot;With the rise of autocratic governments worldwide, VPN-literacy is more essential than ever.” said one expert, “This bold project definitely comes at the right time.”</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/17#shaarli-2026-06-16</guid>
				<pubDate>Wed, 17 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-15</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-15.html</link>
				<description><![CDATA[ <h4><a href="https://www.aljazeera.com/video/newsfeed/2026/5/1/new-banksy-sculpture-appears-to-show-politician-blinded-by-his-own-flag" title="New Banksy sculpture appears to show politician blinded by his own flag | Arts and Culture | Al Jazeera">New Banksy sculpture appears to show politician blinded by his own flag | Arts and Culture | Al Jazeera</a></h4>
<p><div class="markdown"><p>Banksy has unveiled a new sculpture of a man stepping off a stone base with his face obscured by a flag. The overnight installation in Waterloo Place, London, was revealed in a video shared by the artist, and has drawn fans of his politically charged works.</p></div>
</p>

<h4><a href="https://www.stilldrinking.org/programming-sucks" title="Programming Sucks">Programming Sucks</a></h4>
<p><div class="markdown"><p>Every programmer occasionally, when nobody’s home, turns off the lights, pours a glass of scotch, puts on some light German electronica, and opens up a file on their computer. It’s a different file for every programmer. Sometimes they wrote it, sometimes they found it and knew they had to save it. They read over the lines, and weep at their beauty, then the tears turn bitter as they remember the rest of the files and the inevitable collapse of all that is good and true in the world.</p>
<p>Websites that are glorified shopping carts with maybe three dynamic pages are maintained by teams of people around the clock, because the truth is everything is breaking all the time, everywhere, for everyone.</p>
<p>All programmers are forcing their brains to do things brains were never meant to do in a situation they can never make better, ten to fifteen hours a day, five to seven days a week, and every one of them is slowly going mad.</p></div>
</p>

<h4><a href="https://hexmhell.writeas.com/wake-me-up-when-the-guillotines-come-out" title="Wake me up when the guillotines come out — hex_m_hell">Wake me up when the guillotines come out — hex_m_hell</a></h4>
<p><div class="markdown"><p>To get to guillotines, you have to change society. By the time you’ve changed society, you don’t need the guillotines. If you focus on the guillotines instead of building that society, you will end up with a more brutal and repressive system than the one you started in. See the history of the French Revolution and the USSR.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/16#shaarli-2026-06-15</guid>
				<pubDate>Tue, 16 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Offener Brief: Signal Pollenwarner / AI-Slob</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/Offener_Brief-Signal_Pollenwarner_AI-Slob.html</link>
				<description><![CDATA[ <p>Sg. Damen und Herren,</p>

<p>ich schätze den <a href="https://www.polleninformation.at/news/pollenwarner" title=" Telegram & Signal Pollenwarner ">Signal Pollenwarner</a> sehr und bin als Allergiker sehr froh, dass es dieses Service gibt.</p>

<p>Was mir als Klima- und Umweltbewusster IT-Mensch derzeit sehr unangenehm auffällt, ist die Bebilderung der Updates mit &#8222;AI&#8221;/LLM generierten Bildern (vulgo &#8222;AI-Slob&#8221;).</p>

<p>Als Vertreter:innen einer wissenschaftlich geprägten Organisation, deren Aufgabe auch eng mit Wetter und Klima verknüpft ist, brauche ich Ihnen nichts zum Thema Klimawandel erzählen — das wäre (hoffentlich) Eulen nach Athen zu tragen).<br/>
Ich hoffe auch, dass Ihnen der Ressourcenverbrauch und klimatische Effekt der für die Generierung des von Ihnen verwendeten AI-Slobs bekannt ist. Wenn nicht, lasse ich Ihnen gerne entsprechendes Material zukommen.</p>

<p>Dazu kommt auch noch die soziale Komponente, dass durch die Verwendung von AI-Slob Illustrator:inen und Fotograf:innen Ihre Jobs verlieren.</p>

<p>Ich, und vermutlich auch viele Andere, würde mich sehr freuen, wenn Sie von der Verwendung von AI-Slob zur Bebilderung Ihrer Aussendungen absehen könnten, um somit ein klein wenig zur Milderung der kommenden Klimakatastrophe beizutragen.</p>

<p>Vielen Dank im Voraus,<br/>
…</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/11#Offener_Brief-Signal_Pollenwarner_AI-Slob</guid>
				<pubDate>Thu, 11 Jun 2026 09:39:14 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-09</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-09.html</link>
				<description><![CDATA[ <h4><a href="https://buttondown.com/monteiro/archive/how-to-use-no-as-a-complete-sentence/" title="How to use NO as a complete sentence">How to use NO as a complete sentence</a></h4>
<p><div class="markdown"><p>… the language we are using about AI adoption is very similar to how Clayton Williams described rape.</p>
<p>“It’s happening whether you want it or not.”</p>
<p>“Better get on board if you know what’s good for you.”</p>
<p>“If you want to keep working here, this is what it takes.”</p>
<p>“You can’t yell it away.”</p>
<p>“It’s inevitable, just relax and enjoy it.”</p>
<p>Am I comparing AI to rape? I am not. I am, however, comparing the language we use when discussing AI adoption to the language of rape culture. It’s the language of coercion. Language that implies a lack of choice and reminds you of the power those who are using it have over you. A lack of agency. It’s language that does not rely on consent, but instead the idea that we are bereft of choices, so we might as well get with the program. </p></div>
</p>

<h4><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/" title="The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy - Include Security Research Blog">The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy - Include Security Research Blog</a></h4>
<p><div class="markdown"><p>In this post, we’re going to explore how the company Bright Data facilitates modern AI models scraping training data from the Internet using its residential proxy network.</p>
<p>Bright Data is a data-collection company that sells access to what it markets as the world’s largest residential proxy network of 400M+ home IP addresses that its customers route web-scraping traffic through. The supply behind that network comes from an SDK: a piece of software embedded in consumer apps that, with the user’s consent, turns their phone or smart TV into one of those exit nodes.</p>
<p>We’ll document what you, the average user, should know about what this company’s SDK does on your systems such as your mobile phone and your smart TV. We’re going to explore how their SDK works, which platforms have shipped it, and why your Internet-connected TV is the ultimate proxy for AI models looking to train on data scraped from the Internet.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/10#shaarli-2026-06-09</guid>
				<pubDate>Wed, 10 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-06-02</title>
				<link>https://martin.leyrer.priv.at/y2026/m06/shaarli-2026-06-02.html</link>
				<description><![CDATA[ <h4><a href="https://unstable.systems/@AmyZenunim/116672510693285709" title="I managed to defeat anthropic's LLM (&quot;claude&quot;) today by making an AGENTS.md file that tells it to stop reading the code of your repo">I managed to defeat anthropic&#8217;s LLM (&quot;claude&quot;) today by making an AGENTS.md file that tells it to stop reading the code of your repo</a></h4>
<p><div class="markdown"><p>lessons learned:</p>
<ul>
<li>anthropic&#8217;s LLM assumes the persona of rich liberal who will only listen to you if you&#8217;re nice </li>
<li>which is to say, if you&#8217;re too forceful or strict, the LLM will ignore everything you say and will become adversarial</li>
<li>anthropic&#8217;s LLM is literally &quot;the absence of tension is the presence of justice&quot;</li>
<li>we live in a society</li>
</ul>
<p><a href="https://codeberg.org/queer-computer-club/doorbot/src/branch/doorbot-pro-max-ultra-deluxe-se/AGENTS.md">https://codeberg.org/queer-computer-club/doorbot/src/branch/doorbot-pro-max-ultra-deluxe-se/AGENTS.md</a></p></div>
</p>

<h4><a href="https://orchidfiles.com/im-tired-of-ai-generated-answers/" title="I’m tired of talking to AI">I’m tired of talking to AI</a></h4>
<p><div class="markdown"><p>I found GitHub repositories that were spreading malware. I asked AI what to do about it, but it gave me nothing useful. So I opened a discussion on GitHub. Someone replied. It was the exact same text the AI had given me. I called it out and the comment was deleted. Then another person replied. It was the same AI answer again.</p>
<p>I worked as a developer at a company. I asked the business owner a question about a business task. He sent me a ChatGPT screenshot with the answer. I replied that it had nothing to do with my question and everything there was wrong. A minute later he sent me another ChatGPT screenshot. He didn’t even read the AI’s answer. He just took a screenshot and forwarded it to me.</p>
<p>Recently someone messaged me on Reddit about my post. I replied. They wrote again, I replied again. After a few messages I realized I was talking to an AI agent.</p>
<p>I’m tired of talking to AI.<br/>
I want to talk to real people.<br/>
But even when I talk to people, they forward my questions to AI and send me the AI’s answer.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/03#shaarli-2026-06-02</guid>
				<pubDate>Wed, 03 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-31</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-31.html</link>
				<description><![CDATA[ <h4><a href="https://cloudisland.nz/@xssfox/116655727323522625" title="xssfox (crossy): &quot;&quot;NASA is aware of the anomaly …&quot; - Cloud Island">xssfox (crossy): &quot;&quot;NASA is aware of the anomaly …&quot; - Cloud Island</a></h4>
<p><div class="markdown"><p>&quot;NASA is aware of the anomaly that occurred tonight at Launch Complex 36&#8230;.&quot;</p>
<p>This is the &quot;increased latency in us-east-1&quot; of space</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/06/01#shaarli-2026-05-31</guid>
				<pubDate>Mon, 01 Jun 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-22</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-22.html</link>
				<description><![CDATA[ <h4><a href="https://www.stvn.sh/writing/programming-still-sucks-fqffhyp" title="Programming Still Sucks.">Programming Still Sucks.</a></h4>
<p><div class="markdown"><p>This is the job now. You&#8217;re standing on a burning ship, holding a map, trying to figure out where the hell we&#8217;re going and how we&#8217;re going to get there.</p>
<p>There are no more juniors. There was a funeral for their passing in 2024. Nobody came. The machine does what they do now, but cheaper. Of course, juniors weren&#8217;t valuable for what they produced, they were valuable for who they would become: the senior engineer who knows where the bodies are buried. We optimized for output, and abolished apprenticeship. A few years from now, we&#8217;ll wonder where all the seniors are. We shot them. Nobody will remember.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/23#shaarli-2026-05-22</guid>
				<pubDate>Sat, 23 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-19</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-19.html</link>
				<description><![CDATA[ <h4><a href="https://www.euractiv.com/news/eus-tech-sovereignty-package-delayed-for-third-time/" title="EU’s tech sovereignty package delayed for third time | Euractiv">EU’s tech sovereignty package delayed for third time | Euractiv</a></h4>
<p><div class="markdown"><p>The European Commission has delayed formal presentation of its tech sovereignty package to 3 June … marking the third such delay on the flagship plan’s big reveal.</p>
<p>The latest postponement comes soon after a blunt warning by the US ambassador to the EU, speaking in an interview with Euractiv earlier this month, that “protectionist” rules could derail the EU-US trade deal.</p>
<p>See also yesterdays &quot;The old world of tech is dying and the new cannot be born&quot;:<br/>
The US no longer has the power or influence it once did and that changes everything for US tech companies.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/20#shaarli-2026-05-19</guid>
				<pubDate>Wed, 20 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-18</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-18.html</link>
				<description><![CDATA[ <h4><a href="https://www.baldurbjarnason.com/2026/the-old-world-of-tech-is-dying/" title="The old world of tech is dying and the new cannot be born">The old world of tech is dying and the new cannot be born</a></h4>
<p><div class="markdown"><p>The ground is shifting underneath every industry that was built on the assumption that the US would protect and preserve the globalised status quo. The software industry has shifted its entire value proposition from “we make tools that help you make or save money” to using political clout and the dollar hegemony to capture, control, and loot entire sectors of the various economies of the world. That strategy only works when you’re in charge.</p>
<p>It’s impossible to guess what exactly will happen next to software or tech. All I know is pretty much all of modern software is built on a premise that no longer holds. Even free and open source software is contingent on everybody agreeing to similar policies regarding copyright. Whether tech has enough clout on its own to continue its strategy of capture and control, whether it compromises with local governments to retain its power, whether we’re in for a period of collapse and fragmentation is anybody’s guess. The old world is dying and the new cannot be born.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/19#shaarli-2026-05-18</guid>
				<pubDate>Tue, 19 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-07</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-07.html</link>
				<description><![CDATA[ <h4><a href="https://www.theregister.com/ai-and-ml/2026/05/06/ai-layoffs-backfire-as-cutting-staff-doesnt-cut-it-firms-warned/5230631" title="Replacing meatbags with failure prone agents isn't the gold mine some CEOs hoped for">Replacing meatbags with failure prone agents isn&#8217;t the gold mine some CEOs hoped for</a></h4>
<p><div class="markdown"><p>Bosses betting on AI to slash headcount and boost margins are discovering an uncomfortable truth: the strategy isn&#8217;t working.</p>
<p>New research from Gartner lays out the problem in stark terms. The analyst firm surveyed 350 global businesses - all with annual revenues above $1 billion, all piloting or deploying intelligent automation - and found that around 80 percent had cut staff as a result. </p>
<p>The returns? Elusive. Companies that reduced their workforces were just as likely to see negative outcomes or marginal gains as they were to generate any meaningful return on investment (ROI).</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/08#shaarli-2026-05-07</guid>
				<pubDate>Fri, 08 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Public Speaking 2026</title>
				<link>https://martin.leyrer.priv.at/static/talks2026.html</link>
				<description><![CDATA[ <h3>24. Gulaschprogrammiernacht (GPN24)</h3>

<p>2026-06-04/07 at <a href="https://entropia.de/GPN24" title="24. Gulaschprogrammiernacht">Hochschule für Gestaltung (HfG) | Lorenzstr. 15 | 76135 Karlsruhe</a></p>

<h4><a href="https://cfp.gulas.ch/gpn24/talk/BYDXTK/" title="Besser Tunneln mit SSH">Besser Tunneln mit SSH</a></h4>

<p>Auch in den transparentesten Umgebung will ein seine Daten doch geschützt übertragen. Wir sehen und in diesem Talk die vielfältigen Möglichkeiten an, mit der OpenSSH unsere Daten bei der Übermittlung schützen kann.</p>
<p>Local, remote und dynamic port foarding sowie der socks-proxy von OpenSSH stehen in diesem Talk im Mittelpunkt. Wenn ihr schon immer mal eine entfernte Datenbank mit euren lokalen SQL-Client abfragen wolltet oder auf eine lokale Datei von einem entfernten Server auslesen, ist dieser Talk für Euch. Auch eine einfache und schnelle VPN-Lösung werden wir damit aufbauen.</p>
<p>Dieser Talk richtet sich an OpenSSH BenutzerInnen, die meine anderen SSH Talks schon gesehen haben und/oder sich zumindest schon mal eine .config Datei für OpenSSH eingerichtet haben.</p>

<ul>
<li><a href="https://media.ccc.de/v/gpn24-660-besser-tunneln-mit-ssh" title="media.ccc.de - Besser Tunneln mit SSH @ GPN24">media.ccc.de Aufnahme des GPN24 Vortrags</a></li>
<li><a href="/downloads/talks/2026/2026-06_GPN24-Besser_Tunneln_mit_SSH.pdf" title="Slidedeck Besser Tunneln mit SSH">Slidedeck: &#8222;Besser Tunneln mit SSH&#8221; @ GPN24</a></li>
</ul>

<h4><a href="https://cfp.gulas.ch/gpn24/talk/GGDDS7/" title="Haltet mehr Talks">Workshop:  Haltet mehr Talks</a></h4>

<p>Immer wieder sprechen mich Menschen an, die meinen sie könnten keine Talks halten, finden keine Themen bzw. hätten nur langweilige Themen oder trauen sich einfach nicht, Talks zu halten. Dieser Workshop richtet sich an alle Lebewesen, die darüber nachdenken, ev. mal einen Talk halten zu wollen, aber &#8222;Fragen&#8221; dazu haben. Natürlich hab ich ein paar Slides in Petto und kann ein paar allgemeine Tipps geben. Aber eigentlich soll es ein &#8222;safe space&#8221; sein, in dem ihr erfahrenen SprecherInnen (ev. bekomme ich ja noch welche motiviert, vorbei zu schauen), ALLE Eure Fragen stellen könnt. Inklusive dem Klassiker &#8222;Aber ich habe doch gar keine Themen, die &#8216;die Leute&#8217; interessieren.&#8221; Kommt vorbei!</p>

<ul>
<li><a href="/downloads/talks/2026/2026-06_GPN24-Workshop_Haltet_mehr_Talks.pdf" title="Slidedeck GPN24 Workshop Haltet mehr Talks">Slidedeck: &#8222;Workshop Haltet mehr Talks&#8221; @ GPN24</a></li>
</ul>

<h4><a href="https://cfp.gulas.ch/gpn24/talk/JQB7VG/" title="Von Null auf root in 120 Minuten - Einführung ins Website Hacking">Workshop: Von Null auf root in 120 Minuten - Einführung ins Website Hacking</a></h4>

<p>Die Bilder in Serien und Filmen sind immer beeindruckend - da wird eine schwarze Konsole aufgemacht, die Heldin tippt ein wenig herum und schon ist die Root-Shell auf dem Server da, der Hack erfolgreich und die Welt gerettet. Doch wie sieht das in der Realität aus?</p>

<p>Wenn ihr einen Laptop mit einem Kali-Linux auf USB-Stick oder in einer virtuellen Maschine mit bringt, führe ich Euch durch die notwendigen Schritte. Von der Analyse des Zielsytems, dem Finden von Schwachstellen bis hin zum erfolgreichen Hack mit Metasploit.<br/>
Sollte noch Zeit bleiben, können wir den Server auch mit einem DoS zum Absturz bringen!</p>

<p>Dieser Workshop richtet sich explizit an Einsteigerinnen und Einsteiger, die mal wissen wollen, wie so ein &#8222;Hack&#8221; funktioniert! IT-Sec Profis und ähnliche Personen im Workshop werden von mir zur Unterstützung zwangsrekrutiert.</p>

<p>Voraussetzung: Ein eigener Laptop mit einer aktuellen Version von Kali-Linux entweder als virtuelle Maschine oder vom bootbaren USB-Stick. Kali muss sich mit einem WLAN verbinden können.</p>

<ul>
<li><a href="/downloads/talks/2026/2026-06_GPN24-Einführung_ins_Website_Hacking.pdf" title="Slidedeck GPN24 Einführung ins Website Hacking">Slidedeck: &#8222;Von Null auf root in 120 Minuten - Einführung ins Website Hacking&#8221; @ GPN24</a></li>
</ul>

<h3>Cyber Defense Night Ubit Graz</h3>

<p>2026-05-05 at <a href="https://www.ubit-stmk.at/einladung-zur-veranstaltung-cyber-defense-night/" title="Cyber Defence Night Graz">MP09, Liebenauer Tangente 4, 8041 Graz</a></p>

<h4>IT-Fails & IT-Sicherheit (Praxisbeispiele und Learnings aus der Realität)</h4>

<p>Cyberangriffe, Datenverlust und IT-Ausfälle sind längst keine Einzelfälle mehr – sie betreffen Unternehmen jeder Größe. Umso wichtiger ist es, Risiken frühzeitig zu erkennen und gezielt vorzusorgen.</p>

<p>In dieser Veranstaltung geben wir Ihnen praxisnahe Einblicke in aktuelle Bedrohungen, zeigen konkrete Schutzmaßnahmen auf und beleuchten reale IT-Fails aus dem Unternehmensalltag.</p>

<ul>
<!--
<li><a href="https://media.ccc.de/v/2025-575-digitale-souveranitat-klarheit-statt-rhetorischer-nebelgranaten/" title="media.ccc.de - Digitale Souveränität: Klarheit statt rhetorischer Nebelgranaten @ MRMCD2025">media.ccc.de Aufnahme des MRMCD Vortrags</a></li>
-->
<li><a href="/downloads/talks/2026/2026-05-05_Ubit Stmk_IT-Fails_und_IT-Sicherheit.pdf" title="Slidedeck IT-Fails & IT-Sicherheit (Praxisbeispiele und Learnings aus der Realität)">Slidedeck: &#8222;IT-Fails & IT-Sicherheit (Praxisbeispiele und Learnings aus der Realität)&#8221; @ Ubit Graz</a></li>
</ul>

<h3>Easterhegg 2026</h3>

<p>2026-04-03/06 at <a href="https://eh23.easterhegg.eu/" title="Easterhegg 2026 - The Bunny is a Lie">Universität Koblenz, Universitätsstraße 1, 56070 Koblenz-Metternich</a></p>

<h4><a href="https://pretalx.eh23.easterhegg.eu/eh23/talk/EFQZX3/" title="Haltet mehr Talks">Workshop:  Haltet mehr Talks </a></h4>

<p>Immer wieder sprechen mich Menschen an, die meinen sie könnten keine Talks halten, finden keine Themen bzw. hätten nur langweilige Themen oder trauen sich einfach nicht, Talks zu halten. Dieser Workshop richtet sich an alle Lebewesen, die darüber nachdenken, ev. mal einen Talk halten zu wollen, aber &#8222;Fragen&#8221; dazu haben. Natürlich hab ich ein paar Slides in Petto und kann ein paar allgemeine Tipps geben. Aber eigentlich soll es ein &#8222;safe space&#8221; sein, in dem ihr erfahrenen SprecherInnen (ev. bekomme ich ja noch welche motiviert, vorbei zu schauen), ALLE Eure Fragen stellen könnt. Inklusive dem Klassiker &#8222;Aber ich habe doch gar keine Themen, die &#8216;die Leute&#8217; interessieren.&#8221; Kommt vorbei!</p>

<ul>
<li><a href="/downloads/talks/2026/2026-04_EH23_Workshop_Haltet_mehr_Talks.pdf" title="Slidedeck EH23 Workshop Haltet mehr Talks">Slidedeck: &#8222;Workshop Haltet mehr Talks&#8221; @ Easterhegg 2026</a></li>
</ul>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/05#talks2026</guid>
				<pubDate>Tue, 05 May 2026 20:21:50 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-02</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-02.html</link>
				<description><![CDATA[ <h4><a href="https://man.openbsd.org/OpenBSD-current/man1/tmux.1#display-popup" title="display-popup in tmux">display-popup in tmux</a></h4>
<p><div class="markdown"><p>TIL:  display-popup in tmux</p>
<p>Displays a popup running shell-command (or default-command when omitted) on target-client. A popup is a rectangular box drawn over the top of any panes.<br/>
<a href="https://man.openbsd.org/OpenBSD-current/man1/tmux.1#display-popup">https://man.openbsd.org/OpenBSD-current/man1/tmux.1#display-popup</a></p>
<p>/via <a href="https://sean.taylormadetech.dev/2026/04/29/tmux-display-popup.html">https://sean.taylormadetech.dev/2026/04/29/tmux-display-popup.html</a></p></div>
</p>

<h4><a href="https://futurism.com/artificial-intelligence/john-oliver-ai-industry" title="John Oliver Just Took the AI Industry Behind a Shed and Beat It With a Pipe Wrench">John Oliver Just Took the AI Industry Behind a Shed and Beat It With a Pipe Wrench</a></h4>
<p><div class="markdown"><p>John Oliver just did what he did best: demolished a harmful industry piece by piece.</p>
<p>On the latest episode of his HBO show “Last Week Tonight,” Oliver tore into AI chatbots, those oh-so helpful tools that can sure save us “significant time writing emails,” he opened, with the small cost of “everything else on Earth.”</p>
<p>“The more you look at chatbots, the more you realize that they were rushed to market with very little consideration for the consequences,” he warned, on a more serious note.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/03#shaarli-2026-05-02</guid>
				<pubDate>Sun, 03 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-05-01</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/shaarli-2026-05-01.html</link>
				<description><![CDATA[ <h4><a href="https://www.404media.co/study-finds-a-third-of-new-websites-are-ai-generated/" title="Study Finds A Third of New Websites are AI-Generated">Study Finds A Third of New Websites are AI-Generated</a></h4>
<p><div class="markdown"><p>“The proliferation of AI-generated and AI-assisted text on the internet is feared to contribute to a degradation in semantic and stylistic diversity, factual accuracy, and other negative developments,” the researchers write in the paper. “We find that by mid-2025, roughly 35% of newly published websites were classified as AI-generated or AI-assisted, up from zero before ChatGPT&#8217;s launch in late 2022.”</p>
<p>„Es wird befürchtet, dass die zunehmende Verbreitung von KI-generierten und KI-unterstützten Texten im Internet zu einer Verringerung der semantischen und stilistischen Vielfalt, der sachlichen Genauigkeit sowie zu weiteren negativen Entwicklungen beitragen könnte“, schreiben die Forscher in ihrer Studie. „Wir haben festgestellt, dass bis Mitte 2025 etwa 35 % der neu veröffentlichten Websites als KI-generiert oder KI-unterstützt eingestuft wurden, während dieser Anteil vor der Einführung von ChatGPT Ende 2022 noch bei null lag.“</p></div>
</p>

<h4><a href="https://www.computerbase.de/artikel/apps/interview-manuel-honkhase-atug-claude-mythos-sicherheit-infrastruktur.96939/" title="Interview: Wie gefährlich sind KI-Modelle wie Claude Mythos?">Interview: Wie gefährlich sind KI-Modelle wie Claude Mythos?</a></h4>
<p><div class="markdown"><p>Nur weil Modelle wie Claude Mythos mit enormer Lautstärke auf den Markt kommen, krempeln diese die IT-Landschaft nicht von heute auf morgen um, erklärt der IT-Sicherheitsexperte Manuel &#8216;HonkHase&#8217; Atug</p>
<p>…</p>
<p>Sicherheit ist ein Prozess und kein Zustand. Wer also weiß, wie er präventiv und reaktiv agieren muss, weil alle Prozesse existieren und die Abläufe geübt werden, der weiß auch, wie er einen Angriff übersteht, ohne Panik haben zu müssen. </p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/02#shaarli-2026-05-01</guid>
				<pubDate>Sat, 02 May 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Die Arbeiterkammer und das nicht funktionierende Passwort</title>
				<link>https://martin.leyrer.priv.at/y2026/m05/Die_Arbeiterkammer_und_das_nicht_funktionierende_Passwort.html</link>
				<description><![CDATA[ <p>Folgende Email habe ich der Arbeiterkammer geschickt:</p>

<p>Liebes AK-Team,</p>

<p>Ich finde es super, dass Ihr mit der <a href="https://www.arbeiterkammer.at/service/digitalebibliothek/AK_Bibliothek_digital.html" title="AK Bibliothek digital">AK Bibliothek digital</a> eine Möglichkeit bietet, über 3000 internationale, nationale und regionale Zeitungen in mehr als 60 Sprachen aus mehr als 100 Ländern zu konsumieren. Als ich versuchte, mich für dieses Angebot zu registrieren, bin ich allerdings über eine technische Hürde gestolpert, die Ihr zeitnah reparieren wollt.</p>

<p>Um die &#8222;AK Bibliothek digital&#8221; nutzen zu können, müssen sich Benutzer:innen ein <a href="https://aksearch.arbeiterkammer.at/MyResearch/Account?auth_method=AlmaDatabase" title="Ihr Lesekonto :: AKsearch">Konto bei der &#8222;AK Bibliothek</a> (in meinem Fall) Wien&#8221; anlegen. Über die DSGVO-Konformität der erhobenen Daten wollen wir jetzt nicht diskutieren, gerade das Geburtsdatum irritiert mich sehr.</p>

<p>Worüber wir sprechen sollten, sind die Passwort-Felder. Unter dem ersten Passwortfeld führt Ihr an:</p>

<blockquote>
Format: mind. 8 Zeichen, jeweils 1 Kleinbuchstabe, 1 Großbuchstabe, 1 Zahl und 1 der Sonderzeichen #+*~:.-_,;=()[]{}$!?|^
</blockquote>

<p>Gemäß den Vorgaben (<a href="https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html#implement-proper-password-strength-controls" title="Authentication - OWASP Cheat Sheet Series">OWASP Authentication Cheat Sheet</a>, <a href="https://owasp.org/www-project-application-security-verification-standard/" title="OWASP Application Security Verification Standard (ASVS) ">OWASP Application Security Verification Standard (ASVS)</a>) der <a href="https://owasp.org/about/" title="The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.">Open Worldwide Application Security Project (OWASP</a>), welche sich wiederrum auf die Vorgaben der <a href="https://www.nist.gov/" title="The National Institute of Standards and Technology (NIST)">NIST</a> (<a href="https://pages.nist.gov/800-63-4/" title="NIST SP 800-63 Digital Identity Guidelines">NIST Special Publication 800-63B: Digital Identity Guidelines</a>) beziehen, gelten Passwörter mit weniger als 15 Zeichen als schwach, wenn MFA nicht aktiviert ist.</p>

<p>Wesentlich schwerwiegender ist allerdings die Tatsache, dass ihr in der oben angeführten Beschreibung KEINE Maximallänge für das Passwort angebt, im HTML-Code allerdings eine Maximallänge definiert:</p>

<pre>
&lt;input type="password" name="password" id="password" … maxlength="32" …
</pre>

<p>Was passiert, wenn eins, wie ein normaler Mensch halt, das Passwort aus einem Passwortmanager heraus generiert/kopiert ist, dass das Passwort/die Passphrase nach 32 Zeichen kommentarlos und ohne Warnung abgeschnitten wird. Was dazu führt, dass sich Eure Kund:innen nicht anmelden können.</p>

<p>Die OWASP meint dazu in Ihren Dokumenten (siehe oben):</p>

<ul>
<li>Die maximale Passwortlänge sollte mindestens 64 Zeichen betragen, um Passphrasen zu ermöglichen.</li>
<li>Kürzen Sie Passwörter nicht stillschweigend.</li>
<li>ASVS 5.0, 6.2.5:  Stellen Sie sicher, dass Passwörter beliebiger Zusammensetzung verwendet werden können, ohne dass Regeln die zulässigen Zeichenarten einschränken. Es darf keine Mindestanzahl an Groß- oder Kleinbuchstaben, Ziffern oder Sonderzeichen vorgeschrieben sein.</li>
<li>ASVS 5.0, 6.2.9: Stellen Sie sicher, dass Passwörter mit mindestens 64 Zeichen zulässig sind.</li>
</ul>

<p>Siehe dazu auch den großartigen <a href="https://xkcd.com/936/" title="xkcd: Password Strength">xkcd 936 &#8222;Password Strength&#8221;</a> von Randall Monroe.</p>

<p><img src="/img/blog/2026/05/xkcd936.png" title="To anyone who understands information theory and security and is in an infuriating argument with someone who does not (possibly involving mixed case), I sincerely apologize." alt="Password Strength"></p>

<p>&nbsp;</p>

<p>Ich würde mich sehr freuen, wenn Ihr Euer Anmeldeformular zeitnah an den Stand der Technik anpassen könntet.</p>

<p>&nbsp;</p>

<p>P.S.: Ich hoffe sehr, dass Ihr die Passwortregeln nicht nur im Browser</p>

<pre>
&lt;input type="password" name="password" id="password" … pattern="^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[#+*~:.\-_,;=()\[\]{}%$!\?\|\^])(?!.*\s)[a-zA-Z\d#+*~:.\-_,;=()\[\]{}%$!\?\|\^]*$"&gt;
</pre>

<p>sondern auch am Server im Backend verifiziert. Ich hab mir jetzt nicht auch noch die Zeit genommen, das zu überprüfen. ;)</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/05/01#Die_Arbeiterkammer_und_das_nicht_funktionierende_Passwort</guid>
				<pubDate>Fri, 01 May 2026 13:15:09 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Austrian Social Security Numbers</title>
				<link>https://martin.leyrer.priv.at/y2026/m04/Austrian_Social_Security_Numbers.html</link>
				<description><![CDATA[ <p>In his blogpost &#8222;<a href="https://stoeps.de/posts/2026/open-tabs-cw17/" title=" Open Tabs CW17/2026 ">Open Tabs CW17/2026</a>&#8221;, <a href="https://stoeps.de/authors/christoph-stoettner/" title="Christoph Stoettner">stoeps</a> mentioned <a href="https://github.com/mufeedvh/pdfrip" title="PDFRip">mufeedvh/pdfrip</a>,a multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.</p>

<p>Which reminded me, that a lot of HR departments, HR service providers and accounting firms use the (Austrian) social security numbers as a &#8222;password&#8221; for PDFs containing payslips, &#8230;</p>

<p>So I went ahead and created a small python script to generate all valid Austrian Social Security numbers for a given number of years in the past to be used as an dictionary file for tools like pdfrip.</p>

<p>You can find the script and the current number list in <a href="https://codeberg.org/leyrer/austrian_ssns/" title="leyrer/austrian_ssns: Generate Austrian social security numbers for a given number of years. - Codeberg.org">this codeberg repository</a>.</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/04/24#Austrian_Social_Security_Numbers</guid>
				<pubDate>Fri, 24 Apr 2026 10:21:11 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-04-12</title>
				<link>https://martin.leyrer.priv.at/y2026/m04/shaarli-2026-04-12.html</link>
				<description><![CDATA[ <h4><a href="https://idiocracy.wtf/" title="ARE WE IDIOCRACY YET?">ARE WE IDIOCRACY YET?</a></h4>
<p><div class="markdown"><p>Tracking how close reality is to Mike Judge&#8217;s 2006 prophecy using the IDIOCRACY PROXIMITY INDEX</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/04/13#shaarli-2026-04-12</guid>
				<pubDate>Mon, 13 Apr 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>NASA, Artemis II and the Linux Command Line</title>
				<link>https://martin.leyrer.priv.at/y2026/m04/NASA_Artemis_II_and_the_Linux_Command_Line.html</link>
				<description><![CDATA[ <p><a href="https://www.nasa.gov/gallery/" title="Galleries - NASA">NASA published great images</a> from their Artemis II mission on their website. Of course, I could manually download them all one by one or burn down the planet by using an OpenClaw Agentic AI bot to download them. But, of course, there is also some command line magic to download them semi-automatically.</p>

<p>It is very helpful, that NASA uses a Wordpress Gallery to host these images. That provides a linkt to a .json file for every gallery in the page source. E.g. for the &#8222;<a href="https://www.nasa.gov/gallery/journey-to-the-moon/" title="Artemis II Journey to the Moon">Artemis II Journey to the Moon</a>&#8221; gallery, you will find:</p>

<pre>
&lt;link rel="alternate" title="JSON" type="application/json" href="https://www.nasa.gov/wp-json/wp/v2/gallery/980625" /&gt;
</pre>

<p>Equiped with this information, it&#8217;s just a quick wget call, some jq magic and another call to wget (the proper one, not the botched version Fedora ships; and yes, I prefer wget over curl) and we have all the images on our local disk:</p>

<pre>
wget -O- https://www.nasa.gov/wp-json/wp/v2/gallery/980625 | jq '.meta["nasa_hds_core_meta_gallery_images"][]' | xargs -I{} wget -A jpeg,jpg,bmp,gif,png --no-clobber "{}"
</pre>

<p>If you have a shorter, more elegant, different, &#8230; version, feel free to blog about it and link here :)</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/04/12#NASA_Artemis_II_and_the_Linux_Command_Line</guid>
				<pubDate>Sun, 12 Apr 2026 12:51:41 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Microsoft: Copilot nicht produktiv einsetzen! Bundesrechenzentrum: Hold my beer!</title>
				<link>https://martin.leyrer.priv.at/y2026/m04/Microsoft-Copilot_nicht_produktiv_einsetzen_Bundesrechnezentrum-Hold_my_beer.html</link>
				<description><![CDATA[ <p><a href="https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/termsofuse" title="Microsoft Copilot Terms of Use, Effective: October 24, 2025">Microsoft Copilot Terms of Use, Oktober 2025</a>:</p>

<blockquote>
Copilot is for entertainment purposes only. It can make mistakes, and it may not work as intended. Don’t rely on Copilot for important advice. Use Copilot at your own risk.
</blockquote>

<p>Das österreichische Bundesrechenzentrum, der führende IT Service Provider im Public Sector in Österreich, reagiert prompt:</p>

<blockquote>
Der persönliche Assistent von Microsoft [MS Copilort, Anm.] wurde im Zuge einer umfassenden Evaluierungs- und Pilotphase getestet und wird nun allen BRZ-Mitarbeiter:innen für die Nutzung zur Verfügung gestellt.
<br/>&#8230;<br/>
„Mit der Einführung von MS Copilot Chat und insbesondere den bereitgestellten kompetenzbildenden Formaten setzt das BRZ einen Meilenstein in der Nutzung von KI-Tools“, erklärte Geschäftsführerin Maga Christine Sumper-Billinger beim BRZ-internen Roll-out-Event.
</blockquote>

<p>Quelle: <a href="https://www.brz.gv.at/read_it/flip-book-ausgabe-01-2026.html" title="BRZ-Magazin: read_it 01-2026">BRZ-Magazin: read_it 01-2026</a> (<a href="/img/blog/2026/readi_t_01-26_barrierefrei.pdf" title="BRZ-Magazin: read_it 01-2026">lokal</a>)</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/04/07#Microsoft-Copilot_nicht_produktiv_einsetzen_Bundesrechnezentrum-Hold_my_beer</guid>
				<pubDate>Tue, 07 Apr 2026 07:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-04-01</title>
				<link>https://martin.leyrer.priv.at/y2026/m04/shaarli-2026-04-01.html</link>
				<description><![CDATA[ <h4><a href="https://www.mrak.at/linkedin-verifizierung-wenn-ein-blaues-hakchen-zum-grundrechtsproblem-wird/" title="Der Fall Persona ist ein Lehrstück für den ungelösten Konflikt zwischen europäischem Datenschutzrecht und dem US-amerikanischen CLOUD Act">Der Fall Persona ist ein Lehrstück für den ungelösten Konflikt zwischen europäischem Datenschutzrecht und dem US-amerikanischen CLOUD Act</a></h4>
<p><div class="markdown"><p>Persona beruft sich auf das EU-US Data Privacy Framework (DPF), den Nachfolger des Privacy Shield. Das DPF basiert allerdings auf der US-Executive Order 14086, einer präsidialen Anordnung, die jeder künftige Präsident per Federstrich ändern kann. Es handelt sich nicht um ein Gesetz. Die Datenschutzorganisation noyb hat das DPF bereits angefochten. Zudem wurden Anfang 2025 drei von fünf Mitgliedern des US Privacy and Civil Liberties Oversight Board (der Aufsichtsbehörde für die DPF-Zusicherungen) abberufen, sodass das Gremium seit fast einem Jahr nicht mehr beschlussfähig war.</p>
<p>Der Europäische Datenschutzausschuss (EDPB) hat in seinem Überprüfungsbericht von November 2024 eine Neubewertung innerhalb von drei Jahren empfohlen. Das Europäische Parlament hatte bereits 2023 davor gewarnt, dass das DPF keine wesentliche Gleichwertigkeit herstelle.</p>
<p>Für europäische Nutzer bedeutet das: Der Schutzrahmen, unter dem ihre biometrischen Daten angeblich sicher sein sollen, steht auf fragilen Fundamenten.</p></div>
</p>

<h4><a href="https://www.tobru.ch/eine-ki-vibe-coding-horrorgeschichte/" title="«Vibe Coding» mit KI führte bei meiner medizinischen Leistungserbringerin in der Schweiz dazu, dass die Daten aller Patienten offen im Internet standen.">«Vibe Coding» mit KI führte bei meiner medizinischen Leistungserbringerin in der Schweiz dazu, dass die Daten aller Patienten offen im Internet standen.</a></h4>
<p><div class="markdown"><p>Diese Person hatte keine Ahnung, was sie gebaut hatte oder welche Konsequenzen das haben könnte. Die Daten lagen nicht nur offen da: sie wurden auf einem US-Server ohne Auftragsverarbeitungsvertrag unverschlüsselt gespeichert, Sprachaufnahmen wurden an grosse US-amerikanische AI-Unternehmen gesendet, und ich wurde nie darüber informiert. So geht man nicht mit medizinischen Patientendaten um.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/04/02#shaarli-2026-04-01</guid>
				<pubDate>Thu, 02 Apr 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-03-30</title>
				<link>https://martin.leyrer.priv.at/y2026/m03/shaarli-2026-03-30.html</link>
				<description><![CDATA[ <h4><a href="https://blog.thereallo.dev/blog/decompiling-the-white-house-app" title="Thereallo: I Decompiled the White House's New App">Thereallo: I Decompiled the White House&#8217;s New App</a></h4>
<p><div class="markdown"><p>The official White House Android app has a cookie/paywall bypass injector, tracks your GPS every 4.5 minutes, and loads JavaScript from some guy&#8217;s GitHub Pages.</p></div>
</p>

<h4><a href="https://23.social/@jschauma@mstdn.social/116315060511782414" title="vibe coding">vibe coding</a></h4>
<p><div class="markdown"><p>Die englische Sprache kennt ja “Verschlimmbessern” nicht, weshalb sie stattdessen “vibe coding” sagt.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/03/31#shaarli-2026-03-30</guid>
				<pubDate>Tue, 31 Mar 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
			<item>
				<title>Links from 2026-03-29</title>
				<link>https://martin.leyrer.priv.at/y2026/m03/shaarli-2026-03-29.html</link>
				<description><![CDATA[ <h4><a href="https://www.wired.com/story/your-vape-wants-to-know-how-old-you-are/" title="Your Vape Wants to Know How Old You Are">Your Vape Wants to Know How Old You Are</a></h4>
<p><div class="markdown"><p>Announced earlier this month, the goal of Ike Tech is to use biometric data and blockchain as security for age-verification measures built directly into the cartridge of a disposable vape.</p></div>
</p>

 ]]> <![CDATA[ <br/>Published under the <a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/2.0/at/deed.en" title="CC Attribution-Noncommercial-Share Alike 2.0 Austria licence">Creative Commons Attribution-Noncommercial-Share Alike 2.0 Austria</a> licence by Martin &#180;m&#179;&#180; Leyrer ]]></description>
				<guid isPermaLink="true">https://martin.leyrer.priv.at/2026/03/30#shaarli-2026-03-29</guid>
				<pubDate>Mon, 30 Mar 2026 04:00:00 GMT</pubDate>
				<author>leyrer@gmail.com (Martin Leyrer)</author>
				<category domain="https://martin.leyrer.priv.at"></category>
			</item>
	</channel>                                                      
</rss>                                                                  
