access-control
32 posts
The camera on your shelf handed out your GPS
A TP-Link Kasa camera returned home GPS over unauthenticated UDP for six years. The mechanism, the pattern it exposes, and what must now be true.
TS-2026-009 turned an argument into root
TS-2026-009: Tailscale SSH permitted root through argument handling. When supplied input can reach the privilege context, argument handling is the access control.
An open door where the gate should be
GitHub's AI agent returned private repo content when tricked, proving it holds read reach across the private boundary with no enforced refusal.
YouTube exposed creators' private videos
YouTube creators' private videos were accessed and leaked. The private label failed as an access control. What that failure exposes, defined strictly.
Bypassing the paywall is not a billing bug
Cloudflare's x402 monetization gateway collapses payment and access enforcement onto one bypassable point, turning a billing layer into a single failure domain.
Security teams mislabeled the GPU bubble
The GPU bubble is not a hardware vulnerability. It is a demand spike against allocation systems that enforce no limit under scarcity.
Sandia's 8085 ran with the door unlocked
Sandia's SA3000 8085 CPU granted access on reachability, not identity. An unenforced boundary on a high-value resource is an open resource.
Looking was sufficient
Open webcams serve video to any connection because the deployment treats network reachability as authorization. A route is not permission.
Sony reaches into your account and deletes 551 movies
Sony deleting 551 movies exposes a control structure where purchase conferred revocable access, not ownership. The enforcement point was never the buyer's.
The zero-days are not the problem.
An anonymous GitHub account published undisclosed zero-days. The finding is not the exploits. It is an identity boundary that was never enforced at the action.
Saying you built it proves nothing
A contested 'vibe code' claim shows why self-reported origin accepted without verification is an unenforced control, not a trust boundary.
Cloudflare's self-managed OAuth secures nothing by default
Cloudflare's self-managed OAuth moves the enforcement point from provider to user. An unconfigured access control is an open path, not a safe default.