Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
axoltl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
axoltl
2y ago
You are, of course, 100% correct. In my haste to explain the 'sourcing' behaviour of the errata I accidentally jumped to the sinking verbiage. Input pins are "pressure gauges", not "flow meters".
32.
▲
by
axoltl
2y ago
I frequently have to interface with custom on-the-wire protocols and the PIO block is fantastic. Situations where I'd used to need a CPLD or full-blown FPGA I can now do with a sub-$1 microcontroller. It significantly reduces developme
33.
▲
by
axoltl
2y ago
So normally when you have a microcontroller pin and you configure it as an input, you expect it to SINK current (as in, take voltage 'in'). The bug is that if the external voltage is between 1V and 2.5V (I don't remember the
34.
▲
by
axoltl
2y ago
I haven't completely thought through this, but I can see issues with porting PIO-USB [0] for example. USB relies on a few different pulls to Vcc and Gnd with pre-defined values. On the host side you have to pull your signal lines to gr
35.
▲
by
axoltl
2y ago
The E9 errata has evolved since the early days when the built-in pull-downs were implicated. The issue is related to the input pad macro sourcing excess (120uA) current when the external voltage is between Vil and Vih. This causes the pad t
36.
▲
by
axoltl
2y ago
I'm sad these seem to not have the fix for the E9 errata, making them entirely unsuitable for a lot of projects. I'll keep using the RP2040 instead, but the extra oomph of the M33's over the M0+'s would've been very
37.
▲
by
axoltl
2y ago
The bottom 2 bytes of a pointer contain two bits of the slide, assuming it's even a pointer into the kernelcache itself. I'd take half a sandwich.
38.
▲
by
axoltl
2y ago
Could you elaborate on the hardware timers? How are these different from the timers that exist in the microcontroller, and what design changes are required in hardware? Or is your point that the outputs from these timers can't be muxed
39.
▲
by
axoltl
2y ago
That's basically how this works, but manufacturing electronics at a massive scale requires some more flexibility. For example, capacitors have a pretty large tolerance (sometimes +/- 20%) and LEDs have quite a bit of variety in wh
40.
▲
by
axoltl
2y ago
I'd love for a third party to verify the claim! I'm just giving you an overview of the work that went into making this a thing, knowing full well you have absolutely no reason to trust me. The LED being "hard-wired" is a
41.
▲
by
axoltl
2y ago
Right, so this is all defense in depth. That LED is sort of the last line of defense if all others have failed, like: The exploit mitigations to prevent you from getting an initial foothold. The sandboxing preventing you from going from a l
42.
▲
by
axoltl
2y ago
Apologies. OTP is One-Time-Programmable. The physical implementation of this varies, in this specific case it was efuses (anti-fuse, actually). It's used for things like calibration data. For a camera it contains information about the
43.
▲
by
axoltl
2y ago
I was not very popular with the camera firmware folks for a while. They had to re-architect a bunch of things as they used to occasionally power on the camera logic without powering the sensor array to get information out of the built-in OT
44.
▲
by
axoltl
2y ago
Macbooks have a dedicated ALS (Ambient Light Sensor). They don't use the camera.
45.
▲
by
axoltl
2y ago
No firmware is required. Macbooks manufactured since 2014 turn on the LED whenever any power is supplied to the camera sensor, and force the LED to remain on for at least 3 seconds. (Source: I architected the feature)
46.
▲
by
axoltl
2y ago
I worked on this feature for Apple Macbooks around 2014 as the security architect. All Macbooks since then have a camera indicator LED that is (barring the physical removal of the LED) always on at least 3 seconds. This feature is implement
47.
▲
by
axoltl
2y ago
I happen to have some first-hand knowledge around the subject! In 2014 someone did a talk[0] on disabling the camera on some older Macbooks. It was fairly trivial, basically just reflashing the firmware that controlled the LED. I worked on
48.
▲
by
axoltl
2y ago
Two modes are described, one is direct acoustic interference. That one's an active mode where sound waves are cancelled out and the fabric effectively is "just" a speaker. The second is a passive method where the sound is dam
49.
▲
by
axoltl
2y ago
There's a decent amount of data protected by Class A keys (which are only available when a device is 'actively unlocked') and some amount of data protected by Class B keys (which are asymmetric keys to allow data to be encryp
50.
▲
by
axoltl
2y ago
I think I understand what you're trying to say, in that Infowars can be seen as a form of performance art or meta-humor. There might be some small number of people that enjoy the content as such, but the overwhelming majority of viewer
51.
▲
by
axoltl
2y ago
Are you implying that Alex Jones is just "doing a bit"? If so, could you explain to me what the comedic intent was behind the whole "denying a tragedy happened and encouraging the harassment of families mourning the loss of t
52.
▲
by
axoltl
2y ago
Or you could read their published security guide at https://help.apple.com/pdf/security/en_US/apple-platform-sec... For the May 2024 version the section on iCloud Keychain is on page 158.
53.
▲
by
axoltl
2y ago
This doesn't look to be the same. Apple's talking about performing computation in their cloud in a secure, privacy-preserving fashion. Samsung's paper seems to be just on local enclaves (which Apple's also been doing sin
54.
▲
by
axoltl
2y ago
First off, the salad fork expression is going into my repertoire, it is excellent. Second, I will say that evilsocket has a bit of an abrasive and impulsive communication style and that can make for fairly adversarial conversations. Combine
55.
▲
by
axoltl
2y ago
I want to clarify that I think that everyone involved wants to do the "Right Thing". What I'm arguing about is that there are different schools of thought in the vulnerability research community as to what the "Right Thi
56.
▲
by
axoltl
2y ago
As a security researcher myself, we've been having the discussion about "right way" and "wrong way" for a long time. The consensus so far is that there is no consensus, and what the "right way" is changes.
57.
▲
by
axoltl
2y ago
You're making it sound like there is a well-agreed-upon way of disclosing vulnerabilities ("_proper_ practice"). I'm a security researcher and this particular discussion has been going on for well over a decade at this p
58.
▲
by
axoltl
2y ago
Canonicals little jab under the "importance of coordinated disclosure" section rubs me the wrong way. They seem to be under the impression the recipient of a vulnerability report gets to set the rules, much like when a project rec
59.
▲
by
axoltl
2y ago
Are you using the Vision Pro, or are you relying on 3rd party information? I use the Vision Pro every day and I have several apps open at the same constantly. That said, it is currently only one macOS screen and macOS apps don't bridge
60.
▲
by
axoltl
2y ago
In my experience just hot sulfuric acid works fairly well if you're looking to just get the die out. Just don't leave it too long or you won't have any bond pads left...
More ›