Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bri3d
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
151.
▲
by
bri3d
6mo ago
Your idea is much more accurate; see my sibling comment. It's basically using C or C++ as an intermediate representation for machine code, rather than trying to recreate the game's higher-order logic/structure or source code.
152.
▲
by
bri3d
6mo ago
It's more nuanced than that; the approach you're describing is usually called "decompilation." The difference is how far one goes in hoisting the "source code;" in this "recompliation" approach the so
153.
▲
by
bri3d
6mo ago
Yes, once we reach the broader conversation (I actually didn't initially grasp that the OP post was a sub-article under another one on LWN which then linked out to yet another article called "Vulnerability Research is Cooked"
154.
▲
by
bri3d
6mo ago
> Can linters find these? Perhaps fuzzing? That's what syzbot / syzkaller does, as mentioned in the article, with somewhat similar results to the AI-fuzzing that they've been experiencing recently. The issue that Linux mai
155.
▲
by
bri3d
7mo ago
Not really the same. There are proposals to require OEMs to install driver monitoring, but it’s usually IR camera based rather than blow in a tube fuel cell based. These systems are probably going to be a mess but the technology isn’t reall
156.
▲
by
bri3d
7mo ago
Irrelevant to this issue - the devices didn’t get bricked over the air, but rather they have a “calibration” time lock which must be reset at a service center and the service centers are ransomwared.
157.
▲
by
bri3d
7mo ago
The issue here is not an OTA thing, for what it’s worth. That is to say, it’s not that these devices phoned home directly and a cloud server is down; rather, these devices require periodic “calibration” (due to a combination of regulation,
158.
▲
by
bri3d
7mo ago
It's not new - fault injection as a vulnerability class has existed since the beginning of computing, as a security bypass mechanism (clock glitching) since at least the 1990s, and crowbar voltage glitching like this has been widesprea
159.
▲
by
bri3d
7mo ago
In terms of fault injection as a security attack vector (vs. just a test vector, where it of course dates back to the beginning of computing) in general, satellite TV cards were attacked with clock glitching at least dating back into the 19
160.
▲
by
bri3d
7mo ago
What you're saying is true, but the OP has a point too. What's basically happening is that as things get faster the lifetime of training data decreases because the system becomes more sensitive to environmental conditions, so trai
161.
▲
by
bri3d
7mo ago
You played in hard mode in a weird sense; more modern DDR versions are in a backwards sense "easier" if you're buying the IP, because a lot of the training has moved to boot time and is handled by the vendor IP rather than ne
162.
▲
by
bri3d
7mo ago
I agree with this, I just don't think I agree with the Beagle approach (CRDT on AST as the source of truth) vs. the Git method (bytewise files as the source of truth) with something alongside. Like, I think it's way easier to add
163.
▲
by
bri3d
7mo ago
IMO this really isn’t a huge problem for this project specifically, since that part is outsourced to tree-sitter which has a lot of effort behind it to begin with. I think this project is incredibly cool as a line of research / thought
164.
▲
by
bri3d
7mo ago
100% agree. I think AST-driven tooling is very valuable (most big companies have internal tools akin to each operation Beagle provides, and Linux have Coccinelle / Spatch for example), but it's still just easier implemented as a l
165.
▲
by
bri3d
7mo ago
I generally agree; for most organizations the product is the value and as long as the product gives some semblance of functionality, improving along any technical axis is a cost. Organizations that spend too much on engineering principles u
166.
▲
by
bri3d
7mo ago
This is really interesting to me; I have the opposite belief. My worry is that any idiot can prompt themselves to _bad_ software, and the differentiator is in having the right experience to prompt to _good_ software (which I believe is also
167.
▲
by
bri3d
7mo ago
I don't think the ancient nature of the exploit chain has much bearing on the origin. I think it points away from the actual 2025 campaigns being USG-attached, but I don't think anyone was suggesting that to start with - the Googl
168.
▲
by
bri3d
7mo ago
I'm very familiar with CFG flattening and other obfuscation techniques, thanks. That's interesting; I suppose I must not have touched the parts of the platform that use them, and I've touched a fair amount of the platform. Ag
169.
▲
by
bri3d
7mo ago
This seems odd to me. I have never seen obfuscation techniques in first party Apple software - certainly not in Espresso or ANECompiler and overall nowhere at all except in media DRM components (FairPlay). Apple are really the major OS comp
170.
▲
by
bri3d
7mo ago
This doesn’t seem that weird to me? * They haven’t said the source isn’t available to them, just that the closed nature of the ANE means they can’t use it in OSS. * They’ve repeated constantly that it can’t do backprop and isn’t useful for
171.
▲
by
bri3d
7mo ago
It also makes a lot of really useful features like on device OCR, captions, voice isolation, temporal antialiasing in metalfx, an enormous host of things in the apple pro apps, etc. work
172.
▲
by
bri3d
7mo ago
SkySafe ( https://skysafe.io ) | Wireless Engineer (SDR) | San Diego, CA | REMOTE or HYBRID At SkySafe we build drone detection and tracking at scale. I am looking for a Wireless Communications Engineer with SDR expertise to join
173.
▲
by
bri3d
8mo ago
I agree; I didn't want to editorialize too much as I think the writeup stands on its own. My takeaway was that in this case, even an author with a clear and extreme bias against this sort of thing could find only unfortunately-common b
174.
▲
by
bri3d
8mo ago
The referenced write-up based on the Persona front end code is here: https://vmfunc.re/blog/persona I definitely recommend reading this primary source before drawing conclusions about the code as most of the secondary
175.
▲
by
bri3d
8mo ago
Everyone should read this comment, it does a really eloquent job explaining the situation. The fundamental thing to understand is this: The things you hear about that people make $500k for on the gray market and the things that you see peop
176.
▲
by
bri3d
8mo ago
Even though I agree with the conclusion with respect to pricing, I don't think this comment is generally accurate. Most* valuable exploits can be sold on the gray market - not via some bootleg forum with cryptocurrency scammers or in a
177.
▲
by
bri3d
8mo ago
Quite good, it’s first party supported by AMD (ROCm LLVM, with a lot upstreamed as well) where it’s fairly widely used in production. This project is a super cool hobby/toy project but ZLUDA is the “right” drop in CUDA replacement for
178.
▲
by
bri3d
8mo ago
The lack of CUDA support on AMD is absolutely not that AMD "couldn't" (although I certainly won't deny that their software has generally been lacking), it's clearly a strategic decision. Supporting CUDA on AMD would
179.
▲
by
bri3d
8mo ago
Completely different layer; tinygrad is a library for performing specific math ops (tensor, nn), this is a compiler for general CUDA C code. If your needs can be expressed as tensor operations or neural network stuff that tinygrad supports,
180.
▲
by
bri3d
8mo ago
Claude is doing the decompilation here, right? Has this been compared against using a traditional decompiler with Claude in the loop to improve decompilation and ensure matched results? I would think that Claude’s training data would includ
More ›