Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bri3d
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
bri3d
5mo ago
Yes? It is regularly; both the firmware or the OS can deliver updates depending on configuration. The Raptor Lake CPUs in question have gone through an enormous number of microcode revisions already due to quite famous voltage scaling issue
92.
▲
by
bri3d
5mo ago
There's another blog post going into more depth about the issue here: https://fgiesen.wordpress.com/2025/05/21/oodle-2-9-14-and-in... where they speculate that it seems to relate to both other clock-rela
93.
▲
by
bri3d
5mo ago
Linked in the Bugzilla thread is a really nice in depth investigation of the same issue with high register aliases in a similar algorithm (Huffman coding) but in an entirely different product: https://fgiesen.wordpress.com/2
94.
▲
by
bri3d
5mo ago
Yes, exactly. Historically you would make some simple image processing software that will align the grid and then look for properties at each specific bit position. Usually die shots are highly imperfect (the delayering usually leaves some
95.
▲
by
bri3d
5mo ago
I discussed this at length in the last thread: https://news.ycombinator.com/item?id=48137059 We know how PIN-locked BitLocker works, and it requires unwrapping using a key sealed behind a TPM PIN policy and stretching it us
96.
▲
by
bri3d
5mo ago
WinRE ending up with a different version of fstx.dll in it seems like a pretty standard Microsoft (or any other big company) thing to have happen? Again, it all comes down to whether you think the drift was a malicious internal fork or a si
97.
▲
by
bri3d
5mo ago
> This also means you don't have to patch all the winRE thumbdrives out there because their secureboot signatures can simply be revoked, meaning they can't pass TPM validation anymore, therefore they won't be able to decry
98.
▲
by
bri3d
5mo ago
Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519 Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it'
99.
▲
by
bri3d
5mo ago
In this case the body of evidence is still quite powerful though, given that not only do we not have any forensic evidence of compromise from a phone with Lockdown Mode, but in all public cases where chains were RE'd back out of the fo
100.
▲
by
bri3d
5mo ago
Most ways to collect boot time are a "Required Reason API," so they declare through NSPrivacyAccessedAPITypeReasons, meaning AppLovin apps are (unsurprisingly) lying about what they are doing with the data. There's a fair amo
101.
▲
by
bri3d
5mo ago
I strongly disagree that there is no evidence that Lockdown mode is effective; there have been numerous exposed, active iOS exploitation campaigns of which none have worked against Lockdown mode. When we're trying to prove a negative,
102.
▲
by
bri3d
5mo ago
Ubuntu does this with Hardware Backed Encryption option in the installer, which I think they’re trying to move up the list (it’s already the default in Ubuntu Core, which makes sense for that application). I didn’t find it too difficult to
103.
▲
by
bri3d
5mo ago
> I wonder why that wasn't mentioned in the previous article, and why an intermediate key is even necessary in the first place. Not sure what you mean by belt and suspenders by the way. Belt and suspenders = the industry standard te
104.
▲
by
bri3d
5mo ago
> If the TPM required a PIN to extract anything, I think there would be no need to manually decrypt anything in software as they show with the python code. Like I specifically pointed out, it's belt and suspenders. > Of course I
105.
▲
by
bri3d
5mo ago
Right, this is a Windows auth bypass that works with Bitlocker enabled; using TPM-only Bitlocker you are vulnerable to _any_ postboot authentication bypass or memory content extraction technique, this is just a particularly stupid / we
106.
▲
by
bri3d
5mo ago
I'm glad we were able to move past "We don't know how that mechanism works, it could just be a totally separate gate that IS bypassable" and into the actual way the mechanism works! > The article shows that the PIN-en
107.
▲
by
bri3d
5mo ago
> What will it take for more companies to truly understand their risks with Windows and being locked into Microsoft’s platforms? What? Most Linux distributions don't even enable FDE by default, and even when they do, they frequently
108.
▲
by
bri3d
5mo ago
https://blog.scrt.ch/2024/10/28/privilege-escalation-through... https://post-cyberlabs.github.io/Offensive-security-publicat... Yes, the PIN is entangled with the key material. The admin PIN
109.
▲
by
bri3d
5mo ago
We can just do research to figure that out? The recent trend towards conspiracy theories against things that are trivially discoverable is so frustrating. https://post-cyberlabs.github.io/Offensive-security-publicat... htt
110.
▲
by
bri3d
5mo ago
> So isn't an obvious approach to just cut Bambu out altogether and just create a FOSS cloud alternative, supporting the remote aspects that the users want to retain? Yes, you can do this with HomeAssistant and other tools. > Not
111.
▲
by
bri3d
5mo ago
This is fair and I should have been more clear that I meant “possible under their current self-imposed constraints;” of course it’s all software so anything is possible (for the record, I also agree that this is a much harder problem than p
112.
▲
by
bri3d
5mo ago
I think the enterprise “LAN Mode” is actually the thing this repo is emulating / replacing, which the consumer printers (might?) also support, where the cloud auth token is still in play but prints are (ostensibly, in a much more diffi
113.
▲
by
bri3d
5mo ago
No, the binaries aren’t necessary in LAN + Developer mode.
114.
▲
by
bri3d
5mo ago
This looks to be a clone of the prior state of the repository that caused all the Bambu drama earlier this week. I did a ton of research because I didn't understand what people wanted here, and this is what's going on: Right now,
115.
▲
by
bri3d
5mo ago
> OrcaSlicer-bambulab: if the goal of this fork-of-a-fork is to bypass Bambu's cloud servers, why would it still need to "impersonate" the UA and communicate with Bambu's servers (as Bambu claimed)? Wouldn't the
116.
▲
by
bri3d
5mo ago
What did `orcaslicer-bambulab` actually do? My understanding is that right now, you can run your printer in LAN or USB mode without Bambu's cloud, and this is supported natively by OrcaSlicer (or any slicer using USB), but you lose som
117.
▲
by
bri3d
5mo ago
I'm actually really confused about the language used in the recall; I looked at the Cybertruck manual and the brakes look like a "conventional" design where the studs are set into the hub and go through the rotor, so this fai
118.
▲
by
bri3d
5mo ago
Modern gas crate powertrain swaps which include engine management usually have the same restrictions; GM Connect and Cruise, Hellcrate, Ford Performance, etc. What you’re describing with LS swaps is unique to kits that come with no engine m
119.
▲
by
bri3d
5mo ago
> Haskell gives you tools to encode these incantations in types so they cannot be forgotten. This is, for my money, the single most valuable thing the language offers a production engineering organization. Haskell is admittedly, probably
120.
▲
by
bri3d
5mo ago
It had hot code editing and a hot code editing debugger. To me, these were the main features that were interesting about VB6 vs. Delphi. Delphi won in basically every other axis (databinding, real OO, visual inheritance, etc.). Also, while
More ›