Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
notactuallyben
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Binary Ninja 5.0 – Gallifrey released
(binary.ninja)
4 points
by
notactuallyben
1y ago
|
0 comments
2.
▲
by
notactuallyben
2y ago
Vulnerabilities in the Linux kernel would have a similar impact to a macOS kernel bug. It’s a myth that “more eyes means more secure” for OSS ;-) - it can be true, but often that’s not the reason
3.
▲
by
notactuallyben
2y ago
Yep, I don't think there's any disagreement with that, especially when you look at things like Tianfu cup in general. Any country that can, essentially wants to do offensive cyber.
4.
▲
by
notactuallyben
2y ago
Are you suggesting that western exploit sellers are selling bugs to western governments and also BRICS? that sounds not very likely. All of this stuff is very complicated ethically, but I don't think you can simply say that it is alway
5.
▲
by
notactuallyben
2y ago
It's not true anymore due to the new generation of hackers that came up, and it's unpolite to dox them if they don't want to be known for it, but for a period, about a third of Google Chrome/Project Zero security all cam
6.
▲
by
notactuallyben
2y ago
also TAG and other Google security people hired from former Western sigint :)
7.
▲
by
notactuallyben
2y ago
firstly, very unlikely that zerodium are supplying bugs they use (could be internally developed, or developed by a more trusted domestic defence contractor). What about if the targets are like Osama Bin Laden's (* INSERT MORE MODERN TE
8.
▲
by
notactuallyben
2y ago
Interesting blog post that was long overdue, I think Google should probably disclose all the details (URLs/actors responsible, methodology for catching these exploits ITW and targeting) around the ITW samples when they kill the bugs, s
9.
▲
by
notactuallyben
2y ago
while beg bounty people can be annoying, you have to remember that people aren't obligated to sit down and find free bugs for any company (especially not a big one) - why would i sit down and look at some code for free for some giant c
10.
▲
by
notactuallyben
3y ago
Yup. You can just have your crafted webp (This is the patch for the ImageIO bug https://chromium.googlesource.com/webm/libwebp/+/902bc919033... ) image with the .png extension (inside your passkit - https:&#x
11.
▲
by
notactuallyben
4y ago
So I got a little bit of time to check ( https://github.com/Biktorgj/quectel_eg25_recovery/tree/EG25G... - the NON-HLOS), and it's still actually running a Qualcomm Hexagon baseband (40mb binary by Qualte
12.
▲
by
notactuallyben
4y ago
I didn’t check, and on mobile now. But I would be very surprised if that was the actual baseband (more just a wrapper around it).
13.
▲
by
notactuallyben
4y ago
Yep in most cases, but not always configured the best. Logic flaws seem the best way to go :)
14.
▲
by
notactuallyben
4y ago
None use Linux, most just use BSD licence software (or things like openssl). I haven’t seen any GPL code at all tbh. But yep, would be nice if it was open source, although not sure how much that would help (only if sufficiently motivated a
15.
▲
by
notactuallyben
4y ago
This is not true on pretty much any phone post 2014ish. Pretty much all platforms have IOMMU's or similar separation mechanisms. source: did baseband vr commercially
16.
▲
by
notactuallyben
4y ago
Great work from P0 (and Keen lab). but this statement about baseband mitigations is only partially true. Huawei Balong platform has ASLR and stack canaries now (and some Infineon too I believe), and all baseband platforms are improving (eve