#xoring
Nice!

@HoneyLabs released Akin, an open HTTP request fingerprint. It records which of 32 fixed headers a client sent as a bitmask, so XORing two tokens tells you which headers differ. (Merely hashing header names can't give you that.)

They used it to link one favicon-sweeping visitor across 21 […]
Original post on mastodon.social
mastodon.social
October 1, 2026 at 12:03 PM
The (non-cryptographic) hash function we used is FNV-1a which is simple and fast but works by XORing and multiplying, which pushes information from low bits to high bits. This makes the low bits ~linear in the input, and the result was 97% of all write volume being routed to one worker.
October 1, 2026 at 2:03 AM
you could even do something like hashing the namespace in 64 bits but hashing the name of the symbol in 32 bits and something like xoring the lower bits of the namespace, so all the resulting identifiers have the same top 32 bits which a general purpose algo could then compress even further.
September 28, 2026 at 12:17 PM
this one seems to be some RNG code in C, written by Carl Ellison from 1995 (and provided with Schneier's Applied Cryptography). Specifically it is from "RANG.C".
September 16, 2026 at 7:38 AM
@fideldestro.bsky.social the last upload of the sepia star animation worked! I was just about to reply to it. was it a single fragment shader? or multiple? I loved the tiling of both shaders, was the star one a fract call or a periodic function? got hella inspired by your xoring of the black lines
August 10, 2026 at 3:13 AM
someone said actually XORing them together is mathematically sound!
July 29, 2026 at 11:31 PM
That was a nice read. I wonder what the sprite masking technique was? Don't think Xoring on a 1-Bit screen would work?

I'm sure I chucked it through the disassembler not long ago, and IIRC the sprites had interleaved masks but weren't zigzagged.
“As he steps out of the local subway station, he soon realises what a plonker he is to venture onto this turf”. The story of how Ocean successfully translated the first Kunio-kun game onto home computers for the UK. With only one set of legs!

New post on Renegade:
www.superchartisland.com/renegade
Renegade – “There is always time to die”
Yoshihisa Kishimoto was born in Tokyo in 1961. There isn’t a lot of information available online in English on his early life, but he talked several times about getting into frequent fights at scho…
www.superchartisland.com
July 20, 2026 at 6:01 PM
Life Hack: Auger all your blights before XORing them in the kite to make sure they are lan!! This will kickban spry as it hydrolyses a parents!!!
June 29, 2026 at 6:54 PM
Bitweb
Current players: 0
Avg players: 0
Peak players: 1
Total user reviews: 137
Avg gameplay hours: 0h
Price: Free
Find more information on SteamPulse:
https://steampulse.org/game/375220
Bitweb on SteamPulse
Addictive, simple gameplay about xoring your way through a maze. You can xor the inner and outer gates surrouding your character with the ones from a cell of your choosing. Hounds will follow you, being bitten will cost points. Use arrows and the invincibility potion to defend yo
steampulse.org
June 19, 2026 at 7:25 AM
Recommending an encryption software by Paranoia Works
JohnDose: > In case you haven’t read, detailed specifications of file encryption can be found here: No I didn’t. The CTR mode is not bad in of itself. It’s parallelizeable i.e. you can use multiple CPUs to generate keystream blocks before XORing the plaintext. You just need to pair the CT with a MAC which they do: The BLAKE3 MAC is generally secure, Encrypt-then-MAC is best practice. But SHA3-MAC is non-standard to the point you usually have to pop the hood and implement it yourself, so it raises some eyebrows. It’s not hard. Luckily SHA-3 onwards hash functions have had to be immune to length extension attacks so BLAKE3(K||CT) is fine. It’s also a bit weird that the Serpent is the only one where the implementation is provided. This is one of the most important aspects to communicate: who implemented the cryptography. Locking the 512-bit+ ciphers to PRO version when the key exchange or CSPRNG can’t provide more than 256 bit keys is also a bit telling about the project. 2048-bit salt is over-kill. The only point of the salt is to ensure that the password and its hash won’t be in the attacker’s dictionary. Salt beyond 128..256-bits is probably intended to be less concerning, but there’s a bathtub curve in the amount of concern I have as a function of crypto variables’ sizes. This definitely hits the latter peak. Considering the absurd key sizes the Argon2id parameters have ridiculously low parameters. 10240kB = 10MB memory cost is absurd given that most platforms have gigabytes of free RAM. You shouldn’t add time cost unless memory cap puts the derivation time below desired key derivation time range. What gets even crazier is the project offers a Web-UI for the encryption tool. Which is nothing short of horrible. Every time you load that page, you load another copy of the source code. You can’t really inspect the code (WebAssembly and all), and if one day you get a one-time backdoored version, your browser won’t retain any audit logs. This is the extreme opposite of best practice, where you’d grab a copy of the application source code from GitHub, check it for correctness, compile it yourself, and use it. Another scary sign is they calle AES-256 “military grade” This is another novice landmine. Military grade encryption has these days nothing to do with key sizes, a bit to do about the algorithms (Suite-A or Suite-B as per use case) and everything to do with the formal evaluation of the implementation. Military grade would imply a team at the NSA IAD takes several months or years to verify everything from the cipher implementation to the FPGA circuit running it inside some Harris military radio. Calling some website binary blob military-grade is snake oil marketing. I’m too old to do a deep dive into stuff like this, but these red flags are enough for me to say: Absolutely do not use this program. There’s good encryption tools by respected researchers already: If you need to encrypt hoarded data for yourself, use VeraCrypt. If you need to encrypt data you send to contact, use Signal/Cwtch. If you somehow need this really wonky use case of just encrypting a file individually for some weird case and VeraCrypt container isn’t an option, use age. There’s zero reasons to go past 256-bit encryption. The easiest proof of this is this: * Suppose you have theoretical perfect attack algorithm that takes exactly one bit operation to test one key. * Suppose you have a theoretical supercomputer that operates at the perfect energy efficiency. The laws of physics state that a single bit operation must consume at least 2.9×10⁻²¹ Joules of energy. Testing 2²⁵⁶ keys would thus consume at least 10⁵⁶ Joules of energy. Breaking single key in 100 years (3155760000 seconds) would require 10⁴⁶W energy source, which means you need 10²⁶ Suns. Average galaxy has 100 million stars. So we need 10¹² galaxies, which hits the middle of estimates of how many galaxies there are. So if you could attach a Dyson Sphere with perfect energy efficiency into every single star of ~every single galaxy for 100 years, to feed the most energy efficient computer that the laws of physics allow, yeah, you could probably break one AES256 key. The only reason you’d offer more than 256 bits is for the same ridiculous security margin against quantum computers, and then you’d just use 512-bit threefish. This is why anyone offering more is usually more telling that they haven’t done the math about key sizes, or they want to scam people who haven’t done the math by selling something that nobody needs.
discuss.privacyguides.net
May 23, 2026 at 2:21 PM
The C code is wrong. You should be XORing values together. Addition of fixed sized integers is not always reversible.
March 14, 2026 at 11:40 AM
I pasted their exploit into emacs. They try to obfuscate it by XORing the real code with an included 12-byte key and turning that into a hex string. This is the same technique I used to "encrypt" something when I was 10 years old
February 18, 2026 at 11:47 PM
I Could store undo history in an image editing program by taking the unedited data and the edited data and XORing them together into a history node . That way , if you're past that point in the history , the current version is XORed with the data of the node and the original is restored
February 6, 2026 at 11:09 PM
xoring all pixels of an image with an increasing value
December 27, 2025 at 10:01 PM
Bonus at the end: A simple and compact implementation of this could look like this. Note that ~ here means XOR

Each time it iterates through the elements it corresponds to one of the boxes in the 2nd image. Try to see if you can see which parts of the core corresponds to which parts of the graph
December 20, 2025 at 12:26 AM
Leaking slab object addresses.

XORing the encoded freelist pointer of the last object with any other encoded freelist pointer from the same slab results in a value similar to the slab's virtual address. This allows one to obtain the base address of a slab.
December 16, 2025 at 2:27 PM
HeroCTF 2025 – Perilous Challenge Writeup

This cryptographic challenge presents an RC4 encryption service with a critical implementation flaw. The service allows users to encrypt messages using RC4, a stream cipher. However, the implementation attempts to add an additional layer of security by…
HeroCTF 2025 – Perilous Challenge Writeup
This cryptographic challenge presents an RC4 encryption service with a critical implementation flaw. The service allows users to encrypt messages using RC4, a stream cipher. However, the implementation attempts to add an additional layer of security by XORing the plaintext and ciphertext with a random mask (MASK). The challenge provides: An encryption oracle that encrypts the flag with a user-supplied key…
kore.one
December 5, 2025 at 9:40 AM
Is xoring something with itself just quicker than setting to 0?
November 23, 2025 at 2:11 PM
Yes I will securely encrypt it by xoring it with itself and then send it to you
November 22, 2025 at 4:27 PM
a AND b
is the opposite of
not(a) OR not(b).

Also, can be useful to bear in mind that:
ANDing two e.g. bytes tends to reduce the number of 1s,
ORing them to tends to increase the number of 1s,
but XORing them tends to keep the sameish number of 1s.

That's all I've ever needed!
Logic for programmers is now the 136th best-selling book on Leanpub! "Building Backbone Plugins", your days are NUMBERED
Logic for Programmers
The mathematics that will help you in your everyday programming.
leanpub.com
October 25, 2025 at 3:39 PM
i know, i know, the best code is the code that ships. but i'm sitting here confounded by how inefficient this is.

they actually do things *extra* inefficiently; see if you can spot where.
October 22, 2025 at 6:36 AM
I've made a What if inspiration crossover story with StarFox and Sonic the Hedgehog.
www.deviantart.com/xoring/art/W...
What If Tails and Fox were swapped roles? by XORING on DeviantArt
www.deviantart.com
October 22, 2025 at 3:53 AM