5 ms·
I am both terrified and in awe at the technical prowess it takes to discover these vulnerabilities, let alone exploit them. Meanwhile I sit here fumbling with w
by lancemurdock 5y ago
I am both terrified and in awe at the technical prowess it takes to discover these vulnerabilities, let alone exploit them. Meanwhile I sit here fumbling with writing custom hooks
- booi 5y agoIf I can write 4 lines of code without an error it’s a good day.
- stevewodil 5y agoThank you for making me feel okay with myself
- BitwiseFool 5y agoHeck, if I can get existing code to build properly on my local machine before I even modify it, it's a good day.
- LouisSayers 5y agoThis made me laugh - I'm setting up some projects on a new machine and going through this process atm. Tried to get one going on Window Subsystem for Linux and had some issues so putting it on my old Mac just to get it to run. I will be happy when it does!
- faeyanpiraat 5y agoUse vagrant
- andrew_ 5y agoI'm a 10x engineer. Guaranteed to be 10x bugs to lines written.
- Groxx 5y agoI think I wrote 3 lines last week. I'm still not confident that it's error-free.
- jodrellblank 5y agoDon't get as far as 6, and they won't find something in them to hang you.
- XMPPwocky 5y agoTo be clear, most of the folks doing this sort of security research are probably worse programmers than your average senior dev, or at least not noticeably better. It's a distinct skillset. To whatever extent they might build software that's more secure than the average dev's, that really comes down to applying their security skills and toolset to their own software- thinking like an attacker- not any particular skill at software engineering.
- YetAnotherNick 5y ago> most of the folks doing this sort of security research are probably worse programmers than your average senior dev, or at least not noticeably better. Hard disagree. Maybe you can argue that they might not have skillset/experience of writing good quality code but they need to know the very in depth of each of the component from javascript to kernel. It's not a separate skill. It's the same skill as what senior dev do only the folks who write exploit need to understand allocations in bit level detail in each layer of the machine in which code is executed. eg I would recommend seeing the coding episodes of geohot who was a hacker and look how fast he could write the "ordinary" code like setting up website and other things.
- VMtest 5y agodefine programmer, programmer is not software engineer by default they are exploiting the 'quality' codebase written by your so-called average dev or software engineers and since when software engineering does not take security into account?
- saagarjha 5y agoOf course, this is not always true: a lot of good security researchers are software engineers as much as they are exploit authors. Writing tooling isn't sexy, but sometimes you just have to do it, and if you don't do a good job you aren't going to be able to use it.
- TheSpiceIsLife 5y agoSoftware exploits and tooling don’t need to bug free, they just have to work some of the time on some devices under some circumstances. Luck too. The birthday lottery still plays a roll: being born with the particular set of predispositions, and the right family and environment to encourage strengthening those predispositions.
- arthurcolle 5y agoThere are so many layers of abstractions that interoperate to some degree that these vulnerabilities will only continue to be found/exploited, forever, in the end of time.
- ukeepbelieving 5y agoStatus Quo: yes Nonexistent ideal: No way, Jose. Your infotech is owned because it is fundamentally unsound. There's a huge gap between cutting edge security research at the hardware level and the implementation of consumer hardware/os's Fuchsia is a good start.
- ukeepbelieving 5y agoLots of interesting stuff going on here: https://spectrum.ieee.org/tech-talk/computing/embedded-systems/darpa-hacks-its-secure-hardware-fends-off-most-attacks https://spectrum.ieee.org/tech-talk/computing/embedded-syste... Microsoft IoT for Azure has some interesting hardware developments pertinent to separation of public facing hardware and out of band control mesh
- TechBro8615 5y agoIt’s a dichotomy – they rely on people like us to create the bugs they can exploit :)
- deleted 5y ago[deleted]