I used HTTP headers to cause Tor onion sites to resolve attacker supplied hostnames to get them to leak DNS, with the potential for deanonymization and uncovered (or rediscovered) a ring of dodgy sites offering fake services in the process.

Example code to do this yourself is supplied in the write-up.

A quick and easy way to undo many gains in end user security in recent years is to publish a Browser Plugin, JavaScript and PHP Library that, when given an image of a QRCode, produce the corresponding TOTP code. Optionally gives ones for future times too.

Featherduster is a cool cryptanalysis tool and library that I didn’t know existed and would have saved me a good bit of work if I had.

Why don’t secure messenger apps have a QRCode pre-shared key option for physically sharing PSKs? You can mix the PSK into the crypto and use it to make it post-quantum secure if it can be shared OOB.

*galaxy brain*: signal should use the safety number verification process to establish a symmetric shared secret between the partys that's mixed into the key generation process so that signal messages are post-quantum safe.

Flight-sim devs say hidden password-dump tool was used to fight pirates
Installer ran a "Chrome Password Dump" tool on copies suspected of piracy.

