3 ms·
> Every part of this statement is alarming. The document itself is creepy as fuck. Have you seen the bspatch exploit and its comments? I've dabbled with iOS mu
by jbreakz 10y ago
> Every part of this statement is alarming.
The document itself is creepy as fuck. Have you seen the bspatch exploit and its comments? I've dabbled with iOS multimedia, and I know browser/JIT exploits get pretty complex, but this really takes the fucking piss. The unknown authorship and the fact that someone probably spent weeks to detonate a nuclear device against the software equivalent of a tree house in full seriousness and with no sense of absurdity is chilling.
Besides that, how many exploit coders in the public sphere even bother with FBSD nowadays? It just doesn't attract much interest from them, with everybody doing Windows, Mac, Linux, and mobile. Yet to someone this mattered a great deal. The jemalloc stuff could be skill-transferred from Firefox exploitation, though the exploit delves into compression routines and stdio internals as well.
Pit that against the "everybody calm down" complacency of the average Linux developer/fanboy, and you know they don't stand a chance. I haven't looked at Linux package managers in detail, but I can see them getting completely ass-raped at the "non-cryptanalytic" level in all their bloat.
Fact is, the open-source community is simply not paranoid enough to defend against nation-state talent.
And no offense to the FBSD secteam--I've doubtless made many more coding blunders than all of them put together--but I couldn't help but laugh at this:
"After discussion with the author of bspatch (Colin Percival, a former FreeBSD Security Officer himself"
It's a completely unnecessary detail, seemingly added for reasons of pride, but having the opposite effect from that intended, with no sense of irony. :-)