Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bri3d
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
181.
▲
by
bri3d
8mo ago
They are contractors. The public face of Ghidra works at Praxis, for example.
182.
▲
by
bri3d
8mo ago
Yes, it’s from the late 90s/early 00s, but why is it strange to see Java?
183.
▲
by
bri3d
8mo ago
Agree. IDA is surely the “primary” tool for anything that runs on an OS on a common arch, but once you get into embedded Ghidra is heavily used for serious work and once you get to heavily automation based scenarios or obscure microarchitec
184.
▲
by
bri3d
8mo ago
For UI based manual reversing of things that run on an OS, IDA is quite superior; it has really good pattern matching and is optimized on this use case, so combined with the more ergonomic UI, it’s way way faster than Ghidra and is well wor
185.
▲
by
bri3d
8mo ago
It’s better in some dimensions and not others, and it’s built on a fundamentally different architecture, so of course they use both. Ghidra excels because it is extremely abstract, so new processors can be added at will and automatically ha
186.
▲
by
bri3d
8mo ago
When you buy a subscription plan, you’re buying use of the harness, not the underlying compute / tokens. Buying those on their own is way more expensive. This is probably because: * Subscriptions are oversubscribed. They know how much
187.
▲
by
bri3d
8mo ago
> Didn't companies historically own their own compute? As group-of-cats racks, usually, which is a totally different thing. Way "back in the day" you'd have an IT closet with a bunch of individually hand-managed serve
188.
▲
by
bri3d
8mo ago
They’re players in a newish market segment called “hyperconverged,” basically “you buy a rack and it runs your workload, you don’t worry about individual systems/interconnect/networking etc because we handled it.” Oxide seem to be
189.
▲
by
bri3d
8mo ago
I don’t know who they see as competitors in market positioning (ie, who is selling against them on their target buyer’s calendar). But the space is called hyperconverged computing and there are a few other players like Scale Computing build
190.
▲
by
bri3d
8mo ago
> Baseless FUD. This is a fascinating thing to post on an article about… bypassing UEFI Secure Boot? PKFail, BlackLotus/BatonDrop, LogoFail, BootHole, the saga continues. If you’ve ever audited a UEFI firmware and decided it’s going
191.
▲
by
bri3d
8mo ago
What if my threat model is "compromised the disk imaging / disk supply chain?" This is a plausible and real threat model, and represents a moderate erosion, like I said. UEFI Secure Boot is also just not a meaningful counterm
192.
▲
by
bri3d
8mo ago
> You are missing the point Of the GPLv3 sentence? No, it's dishonest rhetorically. Of the piece? Also I don't think so, exploiting the shims is a fun way to prove that Secure Boot is silly but we already knew that, and by 2019
193.
▲
by
bri3d
8mo ago
What would be the point of this change? It erodes security in some moderately meaningful way (even easier to supply chain new computers by swapping the boot disk) to add what amounts to either a nag screen or nothing, in exchange for some i
194.
▲
by
bri3d
8mo ago
By 2019, when the parent article was written, I don't think that was a good read on the situation. By 2026, when the parent comment was written, I really don't think it's a good read on the situation.
195.
▲
by
bri3d
8mo ago
https://wiki.archlinux.org/title/Unified_kernel_image#ukify_...
196.
▲
by
bri3d
8mo ago
With almost all modern motherboard firmware you can enter Setup mode and use KeyTool to configure the trust store however you want, starting from enrolling a user PK (Platform Key) upwards. It’s generally a lot more secure to avoid the use
197.
▲
by
bri3d
8mo ago
> It's really funny to me that Microsoft's attempt to finally stamp out desktop Linux once and for all failed This conspiracy was never true and never happened. First off, note that the first version of the thing in the article
198.
▲
by
bri3d
8mo ago
> Most motherboards include only Microsoft keys as trusted Is this really true, in 2019 when this was written or today? I haven’t seen a motherboard that didn’t let me enroll my own keys in a really long time. Laptops are a different sto
199.
▲
An open replacement for the IBM 3174 Establishment Controller
(github.com)
42 points
by
bri3d
8mo ago
|
9 comments
200.
▲
by
bri3d
8mo ago
Looking more closely, it looks like there are some "North" sides (platforms) with ABI shims (currently Linux and OP-TEE), but others (Windows, for example), would still require recompilation. > If you have to recompile, you mig
201.
▲
by
bri3d
8mo ago
It's both; it's aimed at hosting a single user program on another userspace, but also seems to have its own kernel as well? The "North" part seems to be what I think you'd traditionally think of as a library OS, and
202.
▲
by
bri3d
8mo ago
It's a library that is linked to in place of an operating system - so whatever interface the OS provided (syscalls+ioctls, SMC methods, etc.) ends up linked / compiled into the application directly, and the "external interfac
203.
▲
by
bri3d
8mo ago
> you can’t expect every game studio to have the expertise to write secure, reliable kernel drivers. If someone wants to sell something that comes with a driver, the driver needs a modicum of care applied to it. This is of course also on
204.
▲
by
bri3d
8mo ago
This is a great writeup. It looks like this driver is being actively used in malware, too: https://www.fortinet.com/blog/threat-research/interlock-rans...
205.
▲
by
bri3d
8mo ago
A KDS subscription is $30 / 3 days. https://kiatechinfo.snapon.com/J2534DiagnosticsAndProgrammin... They claim that only an expensive J2534 interface is "recommended" (a weasely way to get around compliance r
206.
▲
by
bri3d
8mo ago
Let me introduce you to Citibike? Also, this is more like "I sell a service called take a bike to the grocery store" with a clause in the contract saying "only ride the bike to the grocery store." I do this because I am
207.
▲
by
bri3d
8mo ago
It will also be interesting to see which model is more sustainable once the money fire subsidy musical chairs start to shake out; it all depends on how many whales there are in both directions I think (subscription customers using more than
208.
▲
by
bri3d
8mo ago
This is how every cloud service and every internet provider works. If you want to get really edgy you could also say it's how modern banking works. Without knowing the numbers it's hard to tell if the business model for these AI p
209.
▲
by
bri3d
8mo ago
You can buy this product, right here: https://platform.claude.com/docs/en/about-claude/pricing That's not the product you buy when you a Claude Code token, though.
210.
▲
by
bri3d
8mo ago
The subscription services have assumptions baked in about the usage patterns; they're oversubscribed and subsidized. If 100% of subscriber customers use 100% of their tokens 100% of the time, their business model breaks. That's wh
More ›