Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
frederikvs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
frederikvs
9y ago
To be specific, only certain types of overflow are undefined behaviour. Signed integers and pointers have undefined behaviour on overflow. Unsigned integers on the other hand are defined to wrap around to 0. For those interested, good place
92.
▲
by
frederikvs
9y ago
The C standard allows the compiler to do this, so it's definitely not a bug in the compiler.
93.
▲
by
frederikvs
9y ago
The standard says the compiler is allowed to make that change. The standard says the programmer writing that piece of code is wrong. So no, it's not a bug in the compiler, the compiler is complying with the standard. You could make a c
94.
▲
by
frederikvs
10y ago
Thanks, very interesting reads. Makes one wonder why these things aren't default on a linux distro... As an embedded software developer it's a bit inconvenient that it's all focused towards the big distributions (ubuntu, RHEL
95.
▲
by
frederikvs
10y ago
what would be included in a "basic hardening"?
96.
▲
by
frederikvs
10y ago
Very insightful post, thanks! I still stand by calling it stolen ideas though: if you go to PARC, see some cool stuff, and then come home and build it again for yourself, that's stealing an idea. But the main point I was trying to make
97.
▲
by
frederikvs
10y ago
It's funny how he says "Don't do this big 'think different'... screw that", apparently without realising that Apple did exactly what he's talking about. Almost all of Apple's big innovations were stol
98.
▲
by
frederikvs
10y ago
Makes one wonder how they achieved this. I can find a passing mention of a "special C variant that makes it much more difficult to write security holes"[0], but no more details on whether they enforce this (and how), nor on other
99.
▲
The Correctness-Security Gap in Compiler Optimization (2015) [pdf]
(nebelwelt.net)
2 points
by
frederikvs
10y ago
|
0 comments
100.
▲
by
frederikvs
10y ago
It's 0xCCCCCCCD in hex, which looks a lot more structured at least. Though how exactly this makes sense is still unclear :-) [edit] and playing around with the increment of x it keeps throwing in some magical values which are a repeati
101.
▲
by
frederikvs
10y ago
Wait, that contains no loop. Is clang using mathematical rules for series summation? Awesome!
102.
▲
by
frederikvs
10y ago
It's an interesting point you make, that other editors also turn out to have some form of composability. However, the fact that this is the first time I've heard somebody talking about this might have some underlying meaning. Mayb
103.
▲
by
frederikvs
10y ago
it's the "a bit more involved" that makes it very weak in comparison. The power of the dot command is exactly that it takes one single keystroke to repeat the last action. You don't have to think in advance "I may w
104.
▲
by
frederikvs
10y ago
As a vim user, I have to disagree with the "Not vim" part. Learning only vi would lose too many of the advantages of vim. Use vim, learn vim all the way. If/when you're working on an "old" vi (e.g. the one in b
105.
▲
by
frederikvs
10y ago
Can you point me to some documentation from atom or sublime, where they explain which kinds of selections you can make? I wasn't aware that certain editors seem to have many modes of selection, and a quick web search doesn't revea
106.
▲
by
frederikvs
10y ago
I'd advise you to learn vim, for a couple of reasons. The main one is the concept of composability [0] - in vim, you're speaking a mini-language. You have commands (delete, copy, make uppercase,...), and a number of movements (rig
107.
▲
by
frederikvs
10y ago
Awesome, thanks. I had heard of the kernel self protection project, but didn't realise that they'd also maintain such a nice list :-)
108.
▲
by
frederikvs
10y ago
"unprivileged namespaces, something I think should be off by default in all Linux distributions given its history of security vulnerabilities." Does anyone know where to find more advice like this? Which features of the kernel to
109.
▲
by
frederikvs
10y ago
Haven't seen that lecture yet, but something sure does seem out of place : java first appeared in 1995. If there's a book from 1986 showing java code, those pesky time lords have been at it again. Anyway, I can see some logic behi
110.
▲
by
frederikvs
10y ago
From TFA : "Such requests are encrypted with DES ( ECB mode ) however the encryption key is hardcoded inside the application itself (thus known to an attacker)." The word "however" seems to imply that the first part of t
111.
▲
by
frederikvs
10y ago
But at least now you know what's in there, what's going on behind the scenes. And on top of that, it's filled with all sorts of brand new bugs and vulnerabilities! ;-)
112.
▲
Google Test Automation Conference
(youtube.com)
5 points
by
frederikvs
10y ago
|
0 comments
113.
▲
by
frederikvs
10y ago
e.g. only root can get access to the seed. Then the attacker would already need to have root, so then you're in huge trouble anyways. And yes, it may be weaker than a full-random solution. But a pseudorandom system that gets accepted i
114.
▲
by
frederikvs
10y ago
Couldn't they do something that's "repeatably random"? So that in case of a bug, you can extract some information from your kernel on its current randomisation, and then another kernel can use this information to repeat
115.
▲
by
frederikvs
10y ago
Same could be said for any number of protocols. DNS itself laid claim to all use of a system for doing things with domain names. TCP laid claim to all use of a protocol to control transmissions of any sort. ND laid claim to all protocols th
116.
▲
by
frederikvs
10y ago
The github page [0] states that "The In The Wild exploit relied on using ptrace." Now, I'm wondering what purpose ptrace serves, aside from debuggers? Why don't we just disable this by default on production systems (wher
117.
▲
by
frederikvs
10y ago
Is this related to DNS service discovery (DNS-SD, RFC6763), or is it just a very poor choice of words?
118.
▲
by
frederikvs
10y ago
The author has some freedom to choose how to define death in this case, yes. But then he should include the definition he used. Otherwise it's just fear mongering.
119.
▲
by
frederikvs
10y ago
correct, among others it checks youporn. For this check it needs send a request to that domain, which may get flagged in certain corporate IT systems.
120.
▲
by
frederikvs
10y ago
from the article : 'the newly created Next Space Technologies for Exploration Partnerships or “NextSTEP” program' They might have just googled for their abbreviations first, so that they wouldn't collide with an important his
More ›