Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
besselheim
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
besselheim
10y ago
Still, he'd have been better off staying quiet about it, in case he changed his outlook in years to come.
32.
▲
by
besselheim
10y ago
Who are these mythical self-made 0.0001%? All the ones I've heard about relied on family wealth and connections, inheritance, and most often worker exploitation. The filthy rich do enjoy this ego-feeding narrative that it was all just
33.
▲
by
besselheim
10y ago
Sounds like he just turned down a rather nice job offer, and burned his bridges by being publicly disgruntled about it.
34.
▲
by
besselheim
10y ago
It should really be .gov.us rather than a top level domain.
35.
▲
by
besselheim
10y ago
Android apps can also contain native code. Indeed, WhatsApp includes such libraries, to help with Curve25519 encryption, video encoding, voice over IP, and other functionality.
36.
▲
by
besselheim
10y ago
I remember setting this up about a decade ago on some old electroplating control system front end. It worked very well - unlike the rest of the software on there. Unfortunately the DOS program it was being used to remote was highly picky on
37.
▲
by
besselheim
10y ago
You can use the -quiet or -ign_eof options to disable this.
38.
▲
by
besselheim
10y ago
You could type them over openssl s_client instead.
39.
▲
by
besselheim
10y ago
I really don't see the resonance between these events. The damage to signals intelligence capabilities, through the leaking of classified documents, was deliberately and maliciously done through the actions of Snowden himself, most lik
40.
▲
by
besselheim
10y ago
I'm suspicious of his primary motivation being a distaste of global mass surveillance. This passage is especially damning: > Snowden would later publicly claim that his "breaking point" - the final impetus for his unautho
41.
▲
by
besselheim
10y ago
Interesting read, and sheds some more light on Snowden's motivations and attitude. I thought it quite ironic that while he complains about supposed privacy violations of Americans, he was doing the exact same thing - on a smaller scale
42.
▲
by
besselheim
10y ago
I imagine if he'd been the victim of a deliberate hit-and-run, you'd be saying something like "so to be clear, you want someone to be imprisoned because they drove a car."
43.
▲
iOS 10.1.1 and MacOS 10.12 kernel privilege escalation
(bugs.chromium.org)
1 points
by
besselheim
10y ago
|
0 comments
44.
▲
by
besselheim
10y ago
Not always. For example the village built up by the Cadbury family in Bournville was designed to favour the wellbeing and living standards of their workers: https://en.wikipedia.org/wiki/Bournville
45.
▲
by
besselheim
10y ago
They already emulate a Linux kernel, in recent Windows 10 releases: https://msdn.microsoft.com/commandline/wsl/about
46.
▲
by
besselheim
10y ago
I think the Linux equivalent would be more like interrupting the boot process at the GRUB menu, then adding "init=/bin/sh" onto the kernel command line, so Linux boots into a root shell.
47.
▲
by
besselheim
10y ago
Only the connection history - hostname and date/time of access, and only if authorised for an investigation. It's akin to the phone companies logging each number called. This isn't as intrusive as people are making it out to
48.
▲
by
besselheim
10y ago
I had a couple of machines from Hush Technologies (long since out of business), also ~10 years ago. They were passively cooled through a finned chassis, connected to the CPU and other hotspots by heat conducting pipes. Like yours, sounds li
49.
▲
by
besselheim
10y ago
Agreed, it's much easier for quick bugfixes on code that you otherwise don't want to invest your time into.
50.
▲
by
besselheim
10y ago
I don't think this is the case here though. It's been a few days since reporting the vulnerability, not months. We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example),
51.
▲
by
besselheim
10y ago
The problem is that Google also said this: > The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLo
52.
▲
by
besselheim
10y ago
The future patch that Google should have coordinated their disclosure with.
53.
▲
by
besselheim
10y ago
This is flawed reasoning, as the vast majority of people will defend against it by installing the patch.
54.
▲
by
besselheim
10y ago
No, just sceptical of their claim to be protecting users by disclosing early.
55.
▲
by
besselheim
10y ago
I can't imagine that Microsoft have refused to fix this vulnerability though, otherwise this would have been mentioned in the blog post. There's no good reason for Google not to respect coordinated disclosure here. Making an arbit
56.
▲
by
besselheim
10y ago
Looks like a conveniently written policy for hitting their competitors with to me. What is certain is that Google pick and choose when to apply these disclosure time limits, they're not set in stone.
57.
▲
by
besselheim
10y ago
At the same time it allows exploit writers to quickly add this to their kits. I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know th
58.
▲
by
besselheim
10y ago
Yes, I believe what you describe in your second paragraph is most likely to be the case, given that coordinated disclosure is the standard approach to protecting users.
59.
▲
by
besselheim
10y ago
Advertising the details of an exploitable vulnerability before the vendor has patched is protecting users now? I don't buy this motive at all.
60.
▲
by
besselheim
10y ago
There's this Technet article, which also tells you how to dial it down or disable it: https://technet.microsoft.com/en-gb/itpro/windows/manage/con... I don't see the problem with ignoring the h
More ›