Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chc4
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
151.
▲
by
chc4
3y ago
Yeah, I'd suspect that binwalk output to be junk from the flash tripping heuristics: "MySQL database" is one of those heuristics that a lot of random binary files trip spuriously for who knows what reason. Practically every o
152.
▲
by
chc4
3y ago
I don't use it at all. The handful of times I have tried to ask ChatGPT questions or to implement some algorithm it has made up or gotten wrong integral parts.
153.
▲
by
chc4
3y ago
IDA and Ghidra, which they mention at the bottom, along with Binary Ninja which they didn't, have decompilers that will output C source-ish from compiled assembly. Variables and functions without symbols in the binary are just given un
154.
▲
by
chc4
3y ago
Related: The "missing" graph datatype already exists. It was invented in the '70s https://news.ycombinator.com/item?id=39606885
155.
▲
by
chc4
3y ago
Most of the time you shouldn't worry too much about all the edge cases. I mostly use it for a general query for variant analysis of some fixed bug, which will have false positives but also give you a list of actual code positions you c
156.
▲
by
chc4
3y ago
Datalog is basically more of a paradigm than a single language: the "core" is just that you have Horn clauses and facts, and synthesize more facts (usually to fixedpoint) using those clauses. Everything on top is basically up to t
157.
▲
by
chc4
3y ago
In cybersecurity there's a startlingly large amount of Datalog: CodeQL compiles down to Datalog and runs via Souffle, Joern expresses program analysis in Datalog, there are a lot of hand-rolled rules inside companies using Datalog to c
158.
▲
by
chc4
3y ago
https://www.whitehouse.gov/wp-content/uploads/2024/02/Final-... uses Rust as an example of a memory safe language that meets low-overhead requirements, such as for aerospace.
159.
▲
by
chc4
3y ago
Time to reset the "days since MBAs ran a company into the ground" ticker, I guess?
160.
▲
by
chc4
3y ago
"based on Futamura Projections" is kind of cheating: they don't have a `mix` specialization function, which is the entire point of Futamura's paper. They're doing automatic symbolic execution using operator overload
161.
▲
by
chc4
3y ago
Reminds me of an ancient Roblox hack I heard about, where they had a non-production staging version of the website that users could sign up for (with accompanied "nothing here is permanent" banner). A new administrator user accoun
162.
▲
by
chc4
3y ago
Making Magic Eye pictures from circuit board layers is super cool, I'm surprised how well it works even with the fairly low resolution images
163.
▲
Poor Man's 3D Tomography
(zetier.com)
5 points
by
chc4
3y ago
|
1 comments
164.
▲
by
chc4
3y ago
Funnily enough, ARM has another difference here on top of just having a non-TSO memory model: LL/SC atomics solve the ABA problem, because the word holding the queue head has been written to and the store-conditional fails, even though
165.
▲
by
chc4
3y ago
For the concurrent queue at the bottom, the issue is with the ABA problem where you're guaranteed to execute the atomic compare-and-swap correctly, but you aren't guaranteed that the same pointer value means the queue is in the sa
166.
▲
by
chc4
3y ago
Template JITs in general aren't a new technique, but Copy-and-Patch is a specific method of implementing it (leveraging a build time step to generate the templates from C code + ELF relocations).
167.
▲
by
chc4
3y ago
raw_ptr<T> is in fact a smart pointer wrapper that mitigates exploitation of most use-after-frees https://security.googleblog.com/2022/09/use-after-freedom-mi...
168.
▲
by
chc4
3y ago
It doesn't cache ASTs or bytecode, or invoke clang/LLVM at runtime. It copies as bytes the assembly body of the compiled functions that act as stencils, using ELF relocations as locations of where to patch in values.
169.
▲
by
chc4
3y ago
Sweet! I tried playing around with implementing a copy-and-patch style JIT in Rust before, but unfortunately between the lack of `ghccc`-style register-heavy calling convention and (still!) having no way to guarantee tailcalls, rustc doesn&
170.
▲
Strange Loops in Magic the Gathering
(outsidetheasylum.blog)
2 points
by
chc4
3y ago
|
0 comments
171.
▲
by
chc4
3y ago
That immediately jumped out to me as well. I'm not sure their scheme can easily support a "hand decrement" instruction, either, since then the reused physical register might still have OoO instructions in flight using it and
172.
▲
by
chc4
3y ago
Haha, I don't know anything about AI training but that's a really cute trick.
173.
▲
by
chc4
3y ago
Sparky is the Arena AI, but no one ever accused it of being a good Arena AI - it is very much only there for the new player experience of playing against a dumb computer when you're first exposed to the game and don't know the r
174.
▲
by
chc4
3y ago
I love well designed POSIX APIs, such as "this will silently corrupt memory if you use an FD above FD_SETSIZE, which you have no control over and have no sane way of remapping if it does happen".
175.
▲
by
chc4
3y ago
There is also https://rinkcalc.app/ https://github.com/tiffany352/rink-rs/ which is an alternative to Frink written in Rust
176.
▲
by
chc4
3y ago
That isn't in-band signaling, that's encapsulating one protocol in another.
177.
▲
by
chc4
3y ago
clang-tidy is mentioned in the blog post, and what I personally use - it does do control flow and dataflow analysis to find double frees or missing frees from any possible program trace (though doesn't do any interprocedural analysis,
178.
▲
by
chc4
3y ago
Android already supports enabling kCFI[0], and says they saw negligable performance and code size impact. Even if it was 5%, security mitigations with a large security impact probably make sense to enable for a lot of usecases. 0: https:&#
179.
▲
by
chc4
3y ago
APEX namespace membership is managed by the ld.txt config file for the dynamic linker, iirc. You can probably just remove the com.android.conscrypt line, or remove the entire conscrypt APEX package from the system and unpack the libs into &
180.
▲
by
chc4
3y ago
I mean, you still have root and APEX packages aren't doing anything tricky specifically to stymie modifications - they're just mounted file systems. You're still going to be able to modify system certificates, it's just
More ›