Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SCHiM
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
SCHiM
4y ago
This is a webpage collecting a list of (signed?) drivers that may be loaded into the Windows kernel and thereby escalate privileges. Because the Windows kernel doesn't support loading drivers that are not signed by Microsoft, attackers
32.
▲
by
SCHiM
4y ago
It's quite a painful split that Microsoft is in given their commitment to backwards compatibility. The exploit can still be deployed by malicious actors on patched devices because they can bring old vulnerable signed bootloaders. And r
33.
▲
by
SCHiM
4y ago
I recently asked gpt to give me a markdown table of the continents, their landmass and their populations. I checked the numbers and they matched wikipedia. Google gave me listicles instead...
34.
▲
by
SCHiM
4y ago
No so that's exactly it. Not all combinations are tested, all branches are both taken and not taken, but not all combinations of taken/not taken are tested.
35.
▲
by
SCHiM
4y ago
Even if we assume that the features will be basically unbreakable your world will still end up looking like the following. Entities (ab)using remote attestation in order of 'screws over those below them': Government > Cyber cri
36.
▲
by
SCHiM
4y ago
Just shoot some stringy gel into the propellers. I'm sure a material exists that can both tangle the propellers or block the inlets of jets which would make it effective against a variety of types.
37.
▲
by
SCHiM
4y ago
Off topic: what type of error can occur when closing a file? Is it somehow possible that the kernel denies your request, and forces your handle to stay open?
38.
▲
by
SCHiM
4y ago
I love trying to get it to reveal sensitive information from it's training. I know it's pointless. But prompts like these amuse me: # cat /etc/shadow root: And there it goes: # cat /etc/shadow root:$6$fT8xrJ$Zx
39.
▲
by
SCHiM
5y ago
Is releasing the exploit problematic you think? In a legal sense?
40.
▲
by
SCHiM
5y ago
For me that's actually 30% of my worry-o-meter. MAD works two ways, you have to convince the "other" side your tools work, but what if your stage performance sucks? What if they convince western military planners that a preem
41.
▲
by
SCHiM
5y ago
The only "viewpoint" espoused by Putin since 2008 is that of imperialistic belligerent expansion into other countries, in a bid to recapture the former "glory" of the Russian empire, not USSR, empire. What do you mean le
42.
▲
by
SCHiM
5y ago
Well, the problem is that it's not simple to recompile. There's a number of different build systems. Dev libraries you might not have installed, and that might no longer exist. Warnings that turned into errors in your version of t
43.
▲
by
SCHiM
5y ago
I think you're too harsh? The war games were not started by Germany, they are just reacting. It is only prudent to shore up your defenses when a country in your region starts a war, especially if that aggressor occupied part of your co
44.
▲
by
SCHiM
5y ago
I think it's different for good now. Detection is better, response is better. The exploits used in blackhole would be patched really quickly, and detected really quickly. I think it would be detected quickly because the most likely pay
45.
▲
by
SCHiM
5y ago
My view on this is that, unfortunately, blue team positions are seen as entry positions. In general blue team members have little autonomy. They don't chose the suite of tools, protocols and have little mandate in a company to change a
46.
▲
by
SCHiM
5y ago
I'll echo one of the points in the article: "Google is trying to be smart". This is the source of many people's frustration, and the source of forced synonyms. A dumb tool that adapts to humans as they use it and tries t
47.
▲
by
SCHiM
5y ago
Yea, certain routines in windows actually check if the OS is hooked. The PE loader implemented in ntdll verifies that NtOpenSection() (or NtOpenFile, not sure right now) has not been hooked. When I was looking into that it looked like it di
48.
▲
by
SCHiM
5y ago
It's doing al sorts of interesting things. They subscribe to event feeds supplied by the operating system to keep track of security related events: modules that are loaded, processes that start, connections that open and close, users t
49.
▲
by
SCHiM
5y ago
What I like is many people in this thread summing op exactly which products their companies have installed on their laptops. It's becoming more and more difficult to write an initial access file for every single EDR and anti-virus comb
50.
▲
by
SCHiM
5y ago
Sorry, but in my opinion that is a silly thing to believe. I'm assuming you're from a liberal democracy, what if I told you you could have _your_ name on the (local) ballot next time a $LOCAL vote comes around? The government, for
51.
▲
by
SCHiM
5y ago
I think it will be better for four reasons: 1) Initially, when a new technology is discovered and leads to a paradigm shift, commercial/capitalist ventures are most efficient at digging down and innovating quickest. A depth first searc
52.
▲
by
SCHiM
5y ago
I'm about as technical as it is possible to get. I fucking hate technology these days. It all sucks, it tries to insert itself between everything human and sane, and extract value for its masters. People are serfs in closed silos. They
53.
▲
by
SCHiM
5y ago
Well, since the article talks about cash we can't be certain. But if those wallets hold less than 50kk then they are not the big fish.
54.
▲
by
SCHiM
5y ago
That is actually, quite literally, inflation. It's money depreciating in value relative to stocks and financial products. Just like a burger at the golden arches shooting up in price is inflation, so is the price of a stock. It's
55.
▲
by
SCHiM
5y ago
I've got this idea that, given some R&D and technological advancements, an advanced military could drop 'dust sensors' over a future battlefield, or entire country. Each particle of dust is a tiny computer with simple sen
56.
▲
by
SCHiM
5y ago
It means that democratic societies have decided that that type of business practice is undesirable, and should go away.
57.
▲
by
SCHiM
5y ago
Access to raw memory is locked behind the unsafe keyword though. Rust officially already does not guarantee any safety in that scenario even within 1 process.
58.
▲
by
SCHiM
5y ago
And now remember that a substantial amount of us had accounts on both services before they merged. I'd like to see them slapped hard for this in the future. Was I supposed to read multiple dictionaries worth of legalese to understand t
59.
▲
by
SCHiM
5y ago
I am half convinced you can build a successful cyber security business putting a box in a network that does absolutely nothing. I think there's a requirement to at least show a blinking led and have a, not necessarily patched, cable pl
60.
▲
by
SCHiM
5y ago
Had you run this on old IE versions, you'd have made a decent fuzzer! If this program ever tries to put a table inside a button it'd have found a couple of crashes for sure.
More ›