Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ryuuchin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
ryuuchin
10y ago
I agree, the only thing I was really taking issue with is calling it a "golden solution". When in fact it is just a (useful) mitigation. TRR might better fit the description of a "golden solution" although it is still t
62.
▲
by
ryuuchin
10y ago
ECC isn't really the golden solution. It will likely just turn rowhammer into a DoS instead of something which is exploitable (and even with ECC it can still be exploitable just harder). While this is an improvement I wouldn't c
63.
▲
by
ryuuchin
10y ago
> since edge has gotten lastpass and adblock There's also an experimental version of uBlock for it as well[1]. [1] https://github.com/nikrolls/uBlock-Edge#microsoft-edge
64.
▲
by
ryuuchin
10y ago
> I've read that Chrome is more secure, in terms of integrity when attacked, which of course can help privacy (i.e., confidentiality). I've read that it's due to Chrome's security model, but I'd be interested if
65.
▲
by
ryuuchin
10y ago
Just one thing worth mentioning. If you use the exact same filter lists in ABP and uBlock Origin[1] then the end result should be IDENTICAL (if it's not it's a bug) save for the fact that uBlock does things faster and more effici
66.
▲
by
ryuuchin
10y ago
> If I had Private Mode always active, then I could use Firefox's own Tracking Protection, but I thought Privacy Badger is enough and is made by the EFF which I trust. If you enable uBlock Origin's Disconnect filters then Firef
67.
▲
by
ryuuchin
10y ago
> (You can ctrl-shift-n in Chromium/Chrome if you need to turn off all extensions for a quick look at something.) You can keep extensions enabled in Chrome as well when using incognito. You just have to explicitly enable it on the
68.
▲
by
ryuuchin
10y ago
So yet another KASLR bypass. Reminds me of[1]: > Consider this our "I told you so" that we hope you'll remember in the coming years as KASLR is "broken" time and again. Then again, in this offensive-driven indust
69.
▲
by
ryuuchin
10y ago
Does ECC memory make this harder to pull off? I was under the impression that ECC memory does not mitigate rowhammer although it may make it harder[1]. > Tests show that simple ECC solutions, providing single-error correction and double
70.
▲
by
ryuuchin
10y ago
Well another thing to keep in mind with this one in particular is that there is no way to mitigate it. grsecurity can't help with this kind of bug, nothing can so it may not just be about reliability of this exploit but the fact that
71.
▲
by
ryuuchin
10y ago
Some of these features can be accomplished simply through blocking javascript.
72.
▲
by
ryuuchin
10y ago
> It will take about three or four refreshes before you can whitelist everything necessary to get Youtube working. First youtube, then s.ytimg.com, then googlevideo.com, THEN you might finally get a video. > Any page with a Google Cap
73.
▲
by
ryuuchin
10y ago
uMatrix provides a more fine grained approach to blocking and has an interface to match this. uBlock's interface can be easier for a more coarse grained approach (see dynamic filtering, medium mode).
74.
▲
by
ryuuchin
10y ago
You can change this behavior in both NoScript and uMatrix. In uMatrix all you have to do is disable first party scripts in the global (*) profile. NoScript defaults to the opposite (don't allow any scripts) but the behavior can be ch
75.
▲
by
ryuuchin
10y ago
How to safely generate random numbers on Windows[1][2]: #include <windows.h> #define SystemFunction036 NTAPI SystemFunction036 #include <ntsecapi.h> #undef SystemFunction036 RtlGenRandom(buf, size); This is more
76.
▲
by
ryuuchin
10y ago
> If you turn off Windows Defender Real Time Protection it explicitly tells you "You can turn this off, but if it's off for a while we'll turn it back on". It turns itself on upon next reboot, it seems. I don't r
77.
▲
by
ryuuchin
10y ago
Just for the record if you disabled the Windows 10 update properly[1] I'm pretty sure it would never bother you and you could never accidentally install it. I'm not saying I approve of what Microsoft did with the W10 upgrade but i
78.
▲
by
ryuuchin
10y ago
If I understand this change correctly it removes background zeroing of freed pages. What effect will this have on security? Grsecurity adds a feature which allows the linux kernel to sanitize freed pages[1]. I realize that the idle time f
79.
▲
by
ryuuchin
10y ago
Part of me thinks it's a lack of direction which has limited Mozilla/Firefox in the past/currently(?). Like the dropping of 64-bit support (which they reversed) which I think showed a clear lack of direction on what they wan
80.
▲
by
ryuuchin
10y ago
> That implies running Windows, though. Indeed. My knowledge on Linux is pretty limited but I seem to remember that Nvidia fixed something which let you use Pax/grsecurity protections you otherwise couldn't. This still implie
81.
▲
by
ryuuchin
10y ago
> Flash and Media Plugins (video decoders, EME/DRM) have already been sandboxed for several releases. Firefox provides its own sandboxing now? Flash used to use a subset of the Chrome sandbox for Flash but that was restricted to th
82.
▲
by
ryuuchin
10y ago
> There are real mitigations (W^X, ASLR, stack cookies) We've had these for nearly a decade with other software. Have they completely stopped bugs/exploits in that time? I'm not trying to take away from the usefulness of
83.
▲
by
ryuuchin
10y ago
I think you can do some things with chroots[1] that you otherwise couldn't although I could be wrong. My knowledge on Chrome's linux sandboxing (just for comparison) is kind of limited. I'm sure there are other protections
84.
▲
by
ryuuchin
10y ago
And the Windows equivalent (win32k lockdown)[1]. This restricts a number of win32k syscalls including all GDI ones. Chrome already uses this mitigation for renderer processes and has support for PPAPI plugin processes on their dev/be
85.
▲
by
ryuuchin
10y ago
Angle (the OpenGL -> DirectX thingy) actually acts as a sanitizer for GPU commands so in a sense browsers which use Angle already have some protection over this. While I think complete protection is impossible through the use of Angle a
86.
▲
by
ryuuchin
10y ago
Moving to a multi-process architechture has a number of benefits but security is certainly one of them. While currently it doesn't really add anything from a security perspective the ability to run rendering in a separate process will
87.
▲
by
ryuuchin
10y ago
> By that definition Chrome is the only browser that sandboxes. I believe most Chromium based browsers could also fall under that category although I admit that's just being pedantic. Furthermore at least Edge and to the lesser exte
88.
▲
by
ryuuchin
10y ago
It's the lack of defense in depth which I would say is disappointing more than anything. Firefox prior to e10s pretty much ran everything save for NPAPI plugins in the same process. Perhaps it is "sandboxed" in the code but
89.
▲
by
ryuuchin
10y ago
Indeed. Perhaps I should've been more specific in my wording of it but I was more referring to the snake oil claims with respect to performance tweaks and to a lesser extent privacy tweaks as well. A number of privacy "tweaks&qu
90.
▲
by
ryuuchin
10y ago
Some of it is legit I suppose but a lot of it reads like snake oil. Also I'm not sure "Securing" Windows 10 is accurate here as we'll see shortly. It seems to really mostly be about "Optimization and Privacy"
More ›