Personal blogroll - BlogFlock 2025-07-02T12:56:40.855Z BlogFlock Julia Evans, FlowingData, Filippo Valsorda, Have I Been Pwned latest breaches, Alex Kladov, Team Register, scams – Pluralistic: Daily links from Cory Doctorow, Miguel Young de la Sota, Blog - Defined Networking, Brendan Gregg's Blog, Isosceles Blog, Daemonic Dispatches, Adam Langley, Schneier on Security, SANS Internet Storm Center, InfoCON: green, Blog on Latacora, Hacker News - Newest: "command line", Simon Willison TIL, The Chip Letter, Risk Musings, blog.while-true-do.io, The Valuable Dev Rating all the U.S. airports - FlowingData https://flowingdata.com/?p=79002 2025-07-02T11:05:17.000Z <p><a href="https://flowingdata.com/2025/07/02/rating-all-the-u-s-airports/"><img src="https://flowingdata.com/wp-content/uploads/2025/06/airport-ranking-750x510.png" style="max-width:100%;height:auto" /></a></p><p>There are great airports and there are really bad ones. Which one you get depends on your origin and destination. The Washington Post <a href="https://www.washingtonpost.com/travel/interactive/2025/best-airports-us-ranking/?pwapi_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJyZWFzb24iOiJnaWZ0IiwibmJmIjoxNzUxMTY5NjAwLCJpc3MiOiJzdWJzY3JpcHRpb25zIiwiZXhwIjoxNzUyNTUxOTk5LCJpYXQiOjE3NTExNjk2MDAsImp0aSI6ImJlZmFjYzI1LWIxYzgtNDgyMS1iYWMxLTBmYTUyNjYzMjZjMyIsInVybCI6Imh0dHBzOi8vd3d3Lndhc2hpbmd0b25wb3N0LmNvbS90cmF2ZWwvaW50ZXJhY3RpdmUvMjAyNS9iZXN0LWFpcnBvcnRzLXVzLXJhbmtpbmcvIn0.PYe5IUBFD2Fbn2a4MAdQj0hBf5qFZLuiqV3LgY_K164&#038;itid=gfta">ranked over 450 U.S. airports to find the best</a>, based on reader survey responses and Yelp reviews. Instead of just landing on the most popular airports, the focus is on what travelers value most, such as how easy it is to get to the terminal.</p> <p>Portland International topped the list. I was just at Long Beach Airport, which was number two, and it&#8217;s definitely a different feel from all other airports I&#8217;ve been to. It&#8217;s an oddly relaxing experience. </p> <p>WaPo also provides a map tool so that you can <a href="https://www.washingtonpost.com/travel/interactive/2025/best-airports-us-ranking/?itid=cb_box_SWUQ5GLSE5BYZIH5JUAGDHLVBA_1">search for airports in your area</a>. I actually saw the tool before the article and was so confused why they kept referencing ranks without showing an ordered list.</p> <p><strong>Tags:</strong> <a href="https://flowingdata.com/tag/airports/" rel="tag">airports</a>, <a href="https://flowingdata.com/tag/ranking/" rel="tag">ranking</a>, <a href="https://flowingdata.com/tag/washington-post/" rel="tag">Washington Post</a></p> Ubuntu Disables Spectre/Meltdown Protections - Schneier on Security https://www.schneier.com/?p=70427 2025-07-02T11:02:22.000Z <p>A whole class of speculative execution attacks against CPUs <a href="https://www.schneier.com/blog/archives/2018/01/spectre_and_mel_1.html">were published</a> in 2018. They seemed pretty catastrophic at the time. But the fixes were as well. Speculative execution was a way to speed up CPUs, and removing those enhancements resulted in significant performance drops.</p> <p>Now, people are rethinking the trade-off. Ubuntu <a href="https://bugs.launchpad.net/ubuntu/+source/intel-compute-runtime/+bug/2110131">has disabled</a> some protections, resulting in 20% performance boost.</p> <blockquote><p>After discussion between Intel and Canonical’s security teams, we are in agreement that Spectre no longer needs to be mitigated for the GPU at the Compute Runtime level. At this point, Spectre has been mitigated in the kernel, and a clear warning from the Compute Runtime build serves as a notification for those running modified kernels without those patches. For these reasons, we feel that Spectre mitigations in Compute Runtime no longer offer enough security impact to justify the current performance tradeoff.</p></blockquote> <p>I agree with this trade-off. These attacks are hard to get working, and it’s not easy to exfiltrate useful data. There are way easier ways to attack systems.</p> <p>News <a href="https://arstechnica.com/security/2025/06/ubuntu-disables-intel-gpu-security-mitigations-promises-20-performance-boost/">article</a>.</p> Cl0p cybercrime gang's data exfiltration tool found vulnerable to RCE attacks - The Register - Security tag:theregister.com,2005:story240592 2025-07-02T09:38:10.000Z <h4>Experts say they don&#39;t expect the MOVEit menace to do much about it</h4> <p>Security experts have uncovered a hole in Cl0p&#39;s data exfiltration tool that could potentially leave the cybercrime group vulnerable to attack.…</p> Table for science-backed vaccine recommendations - FlowingData https://flowingdata.com/?p=78983 2025-07-02T09:25:42.000Z <p><a href="https://flowingdata.com/2025/07/02/table-for-science-backed-vaccine-recommendations/"><img src="https://flowingdata.com/wp-content/uploads/2025/06/vaccine-recs-kids-sciam-750x459.png" style="max-width:100%;height:auto" /></a></p><p>Jen Christiansen and Meghan Bartels provide a <a href="https://www.scientificamerican.com/article/see-vaccine-recommendations-backed-by-science-in-these-handy-charts/">quick reference for Scientific American</a>:</p> <blockquote><p>Kennedy’s decision to replace ACIP wholesale and the comments he has made about deviating from standard vaccine policymaking practice suggest that new recommendations won’t be backed by established vaccine science—hence our reproduction of the vaccine recommendations as of the end of 2024.</p></blockquote> <p>There are tables for young children, older children, and adults. Green represents a recommendation for everyone. Yellow represents a recommendation for a subset. </p> <p>It&#8217;s annoying that this is necessary, but it is necessary. It seems wise to keep watch on how these reproduced tables compare against shifting <a href="https://www.cdc.gov/vaccines/imz-schedules/child-easyread.html" target="_blank">CDC recommendations</a>.</p> <p><strong>Tags:</strong> <a href="https://flowingdata.com/tag/cdc/" rel="tag">CDC</a>, <a href="https://flowingdata.com/tag/science/" rel="tag">science</a>, <a href="https://flowingdata.com/tag/scientific-american/" rel="tag">Scientific American</a>, <a href="https://flowingdata.com/tag/vaccination/" rel="tag">vaccination</a></p> UK eyes new laws as cable sabotage blurs line between war and peace - The Register - Security tag:theregister.com,2005:story240587 2025-07-02T08:30:07.000Z <h4>It might be time to update the Submarine Telegraph Act of 1885</h4> <p>Cyberattacks and undersea cable sabotage are blurring the line between war and peace and exposing holes in UK law, a government minister has warned lawmakers.…</p> <p><!--#include virtual=&#39;/data_centre/_whitepaper_textlinks_top.html&#39; --></p> Australian airline Qantas reveals data theft impacting six million customers - The Register - Security tag:theregister.com,2005:story240605 2025-07-02T01:34:50.000Z <h4>Frequent flyers’ info takes flight</h4> <p>Australian airline Qantas on Wednesday revealed it fell victim to a cyberattack that saw information describing six million customers stolen.…</p> Using Playwright MCP with Claude Code - Simon Willison TIL tag:til.simonwillison.net,2020-04-30:claude-code_playwright-mcp-claude-code.md 2025-07-01T23:44:50.000Z <p>Inspired <a href="https://simonwillison.net/2025/Jun/29/agentic-coding/" rel="nofollow">by Armin</a>, I decided to figure out how to use the official <a href="https://github.com/microsoft/playwright-mcp">microsoft/playwright-mcp</a> Playwright MCP server with Claude Code.</p> <p>Short version: run this before starting <code>claude</code>:</p> <div class="highlight highlight-source-shell"><pre>claude mcp add playwright npx <span class="pl-s"><span class="pl-pds">'</span>@playwright/mcp@latest<span class="pl-pds">'</span></span></pre></div> <p>That's it! Now when you run <code>claude</code> Playwright will be available. You can say things like:</p> <blockquote> <p><code>Use playwright mcp to open a browser to example.com</code></p> </blockquote> <p>And a visible Chrome browser window, controlled by Claude Code, will open in front of you.</p> <p>I found I needed to explicitly say "playwright mcp" the first time, otherwise it might try to use Bash to run Playwright instead.</p> <p>The <code>claude mcp add</code> command will persist but will only affect the directory in which you run it.</p> <p>It took me a while to figure out how that works - eventually I tracked it down to a JSON file <code>~/.claude.json</code> which includes a <code>"projects"</code> key with objects for each directory I had used with Claude Code in the past. That object includes MCPs and allowed commands as well.</p> <div class="markdown-heading"><h2 class="heading-element">Authenticating</h2><a id="user-content-authenticating" class="anchor" aria-label="Permalink: Authenticating" href="#authenticating"><span aria-hidden="true" class="octicon octicon-link"></span></a></div> <p>Since Claude uses a visible browser window when interacting with Playwright, authentication is easy: have it show you a login page, then login yourself with your own credentials and tell it what to do next. Cookies will persist for the duration of the session.</p> <div class="markdown-heading"><h2 class="heading-element">Available tools</h2><a id="user-content-available-tools" class="anchor" aria-label="Permalink: Available tools" href="#available-tools"><span aria-hidden="true" class="octicon octicon-link"></span></a></div> <p>With the MCP loaded you can run <code>/mcp</code> and then navigate to <code>playwright</code> to view all available tools. Here's the full list:</p> <ol> <li> <code>browser_close</code> (read-only)</li> <li> <code>browser_resize</code> (read-only)</li> <li> <code>browser_console_messages</code> (read-only)</li> <li><code>browser_handle_dialog</code></li> <li><code>browser_file_upload</code></li> <li><code>browser_install</code></li> <li><code>browser_press_key</code></li> <li><code>browser_navigate</code></li> <li> <code>browser_navigate_back</code> (read-only)</li> <li> <code>browser_navigate_forward</code> (read-only)</li> <li> <code>browser_network_requests</code> (read-only)</li> <li> <code>browser_pdf_save</code> (read-only)</li> <li> <code>browser_take_screenshot</code> (read-only)</li> <li> <code>browser_snapshot</code> (read-only)</li> <li><code>browser_click</code></li> <li><code>browser_drag</code></li> <li> <code>browser_hover</code> (read-only)</li> <li><code>browser_type</code></li> <li><code>browser_select_option</code></li> <li> <code>browser_tab_list</code> (read-only)</li> <li> <code>browser_tab_new</code> (read-only)</li> <li> <code>browser_tab_select</code> (read-only)</li> <li><code>browser_tab_close</code></li> <li> <code>browser_generate_playwright_test</code> (read-only)</li> <li> <code>browser_wait_for</code> (read-only)</li> </ol> <p>You don't have to reference these by name, Claude should usually be smart enough to pick the right one for the task at hand.</p> Microsoft admits to Intune forgetfulness - The Register - Security tag:theregister.com,2005:story240597 2025-07-01T19:02:21.000Z <h4>Customizations not saved with security baseline policy update</h4> <p>Microsoft Intune administrators may face a few days of stress after Redmond acknowledged a problem with security baseline customizations.…</p> International Criminal Court swats away 'sophisticated and targeted' cyberattack - The Register - Security tag:theregister.com,2005:story240586 2025-07-01T16:34:05.000Z <h4>Body stays coy on details but alludes to similarities with 2023 espionage campaign</h4> <p>The International Criminal Court (ICC) says a &#34;sophisticated&#34; cyberattack targeted the institution, the second such incident in two years.…</p> Show HN: Flow – A Command-Line Tool for Deep Work - Hacker News - Newest: "command line" https://news.ycombinator.com/item?id=44434491 2025-07-01T14:54:03.000Z <p>Article URL: <a href="https://github.com/e6a5/flow">https://github.com/e6a5/flow</a></p> <p>Comments URL: <a href="https://news.ycombinator.com/item?id=44434491">https://news.ycombinator.com/item?id=44434491</a></p> <p>Points: 4</p> <p># Comments: 0</p> Iranian Blackout Affected Misinformation Campaigns - Schneier on Security https://www.schneier.com/?p=70424 2025-07-01T11:07:51.000Z <p>Dozens of accounts on X that promoted Scottish independence <a href="https://www.scottishdailyexpress.co.uk/news/politics/iranian-pro-scottish-independence-accounts-35450209">went dark</a> during an internet blackout in Iran.</p> <p>Well, that’s one way to identify fake accounts and misinformation campaigns.</p> Terrible tales of opsec oversights: How cybercrooks get themselves caught - The Register - Security tag:theregister.com,2005:story240562 2025-07-01T09:27:05.000Z <h4>The silly mistakes to the flagrant failures</h4> <p>They say that success breeds complacency, and complacency leads to failure. For cybercriminals, taking too many shortcuts when it comes to opsec delivers a little more than that. …</p> AI slop on Last Week Tonight - FlowingData https://flowingdata.com/?p=78969 2025-07-01T07:55:57.000Z <p><a href="https://flowingdata.com/2025/07/01/ai-slop-on-last-week-tonight/"><img width="750" height="422" src="https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-750x422.png" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-750x422.png 750w, https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-1090x614.png 1090w, https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-210x118.png 210w, https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-768x433.png 768w, https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-1536x865.png 1536w, https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight.png 1612w" sizes="(max-width: 750px) 100vw, 750px" data-attachment-id="78970" data-permalink="https://flowingdata.com/2025/07/01/ai-slop-on-last-week-tonight/ai-slop-last-week-tonight/" data-orig-file="https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight.png" data-orig-size="1612,908" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="ai slop last week tonight" data-image-description="" data-image-caption="" data-medium-file="https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-750x422.png" data-large-file="https://flowingdata.com/wp-content/uploads/2025/06/ai-slop-last-week-tonight-1090x614.png" /></a></p><p>Last Week Tonight with John Oliver digs into AI slop. It&#8217;s the fake generated stuff filling our feeds with content, inevitably leading us to question our existence and whether this internet thing was really all worth it.</p> <p><a href="https://flowingdata.com/2025/07/01/ai-slop-on-last-week-tonight/">Read More</a></p> Proton bashes Apple and joins antitrust suit that seeks to throw the App Store wide open - The Register - Security tag:theregister.com,2005:story240580 2025-07-01T06:31:13.000Z <h4>Makes the usual complaints about control and cost, adds argument Apple&#39;s practices harm privacy</h4> <p>Secure comms biz Proton has joined a lawsuit that alleges Apple’s anticompetitive ways are harming developers, consumers, and privacy.…</p> Docopt Command-line interface description language - Hacker News - Newest: "command line" https://news.ycombinator.com/item?id=44430193 2025-07-01T03:06:00.000Z <p>Article URL: <a href="http://docopt.org/">http://docopt.org/</a></p> <p>Comments URL: <a href="https://news.ycombinator.com/item?id=44430193">https://news.ycombinator.com/item?id=44430193</a></p> <p>Points: 1</p> <p># Comments: 0</p> US shuts down a string of North Korean IT worker scams - The Register - Security tag:theregister.com,2005:story240577 2025-06-30T22:17:39.000Z <h4>Resulting in two indictments, one arrest, and 137 laptops seized</h4> <p>The US Department of Justice has announced a major disruption of multiple North Korean fake IT worker scams.…</p> When a woman’s cycle stops - FlowingData https://flowingdata.com/?p=78996 2025-06-30T18:44:39.000Z <p><a href="https://flowingdata.com/2025/06/30/when-a-womans-cycle-stops/"><img src="https://flowingdata.com/wp-content/uploads/2025/06/cycle-stops-reuters-750x723.png" style="max-width:100%;height:auto" /></a></p><p>Many women lose their period while still of reproductive age. For Reuters, Daisy Chung, Minami Funakoshi, and Julia Wolfe explain <a href="https://www.reuters.com/graphics/USA-HEALTH/AMENORRHEA/dwpklrkaxvm/">why it happens and how some people can recover</a>.</p> <blockquote><p>In this situation &mdash; known as functional hypothalamic amenorrhea (HA) &mdash; the body shuts down the reproductive system to preserve energy for essential functions, such as keeping the heart beating. It&#8217;s an evolutionary strategy to prevent pregnancy when the body can&#8217;t support it &mdash; but the consequences can extend to all aspects of health.</p></blockquote> <p>Careful illustrations and a soft water color aesthetic is used to approach the sensitive topic.</p> <p><strong>Tags:</strong> <a href="https://flowingdata.com/tag/period/" rel="tag">period</a>, <a href="https://flowingdata.com/tag/reuters/" rel="tag">Reuters</a></p> British IT worker sentenced to seven months after trashing company network - The Register - Security tag:theregister.com,2005:story240573 2025-06-30T18:29:15.000Z <h4>Don&#39;t leave the door open to disgruntled workers</h4> <p>A judge has sentenced a disgruntled IT worker to more than seven months in prison after he wreaked havoc on his employer&#39;s network following his suspension, according to West Yorkshire Police.…</p> Overview of the GOP bill, a bar chart - FlowingData https://flowingdata.com/?p=79027 2025-06-30T17:28:52.000Z <p><a href="https://flowingdata.com/2025/06/30/overview-of-the-gop-bill-a-bar-chart/"><img src="https://flowingdata.com/wp-content/uploads/2025/06/major-parts-wapo-750x1053.png" style="max-width:100%;height:auto" /></a></p><p>The Washington Post <a href="https://www.washingtonpost.com/business/2025/06/28/republican-senate-trump-tax-immigration-plan/">starts with a bar chart</a> to show the major changes from the bill. This provides a wide view, and a sidebar navigation takes you to short explanations of each category.</p> <p><strong>Tags:</strong> <a href="https://flowingdata.com/tag/bill/" rel="tag">bill</a>, <a href="https://flowingdata.com/tag/taxes/" rel="tag">taxes</a>, <a href="https://flowingdata.com/tag/washington-post/" rel="tag">Washington Post</a></p> Cost and savings for each item in the GOP bill - FlowingData https://flowingdata.com/?p=79023 2025-06-30T17:18:03.000Z <p><a href="https://flowingdata.com/2025/06/30/cost-and-savings-for-each-item-in-the-gop-bill/"><img src="https://flowingdata.com/wp-content/uploads/2025/06/tax-bill-items-savings-and-cost-750x545.png" style="max-width:100%;height:auto" /></a></p><p>NYT&#8217;s the Upshot has a <a href="https://www.nytimes.com/interactive/2025/06/30/upshot/senate-republican-megabill.html">running list of the items in the bill</a> with how much each will cost or save. The bill would add $3 trillion of debt. Reduced taxes accounts for most of that amount, and Medicaid takes the biggest hit. Items highlighted yellow indicate ongoing discussions.</p> <p><strong>Tags:</strong> <a href="https://flowingdata.com/tag/bill/" rel="tag">bill</a>, <a href="https://flowingdata.com/tag/medicaid/" rel="tag">Medicaid</a>, <a href="https://flowingdata.com/tag/taxes/" rel="tag">taxes</a>, <a href="https://flowingdata.com/tag/upshot/" rel="tag">Upshot</a></p>