Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ylk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
ylk
4y ago
In Judo you don’t take a beating, magically absorb all the force and then release it all in a gigantic blow that sends the opponent flying towards the moon, shattering it on impact, like in an anime. The stuff you describe doesn’t have anyt
62.
▲
CHERIoT: Rethinking security for low-cost embedded systems
(microsoft.com)
5 points
by
ylk
4y ago
|
0 comments
63.
▲
by
ylk
4y ago
> nobody is sending email to alsdkjfadf@domain That’s actually the kind of spam I used to receive on a very short domain with a catch-all. I guess they loop through short domain names and then try to brute-force the local part.
64.
▲
by
ylk
4y ago
Thanks for clarifying. My confusion stemmed from the fact that the bug is supposed to affect pixel 6 devices, which aren’t listed in the QPR2 updates but were explicitly mentioned in the update to r37p0.
65.
▲
by
ylk
4y ago
as far as I can tell GrapheneOS doesn't have the patch, yet. the most recent mention on their releases page is for the 2022120300 release: > kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): update Mali GPU driver to r3
66.
▲
by
ylk
4y ago
My android comment was taking yours, turning it around and taking it to the extreme to illustrate a point. And no, I never asked why we would need to verify the security researcher’s claims (but sure, you should). 1. Dma54rhs says Apple’s (
67.
▲
by
ylk
4y ago
What if everyone is wrong about the effectiveness of Android’s mitigations? Then iOS would be more secure. Could you please make concrete a point?
68.
▲
by
ylk
4y ago
What do you want to verify exactly? Do you think Apple is lying about what lockdown mode does? Why would they do that? Could you at least say what your opinion is based on? But it is possible to verify what it does, the same way you would f
69.
▲
by
ylk
4y ago
There is CHERI, which seems pretty cool: “CHERI extends conventional hardware Instruction-Set Architectures (ISAs) with new architectural features to enable fine-grained memory protection and highly scalable software compartmentalization. T
70.
▲
by
ylk
4y ago
Thunderbird includes an RSS client
71.
▲
by
ylk
4y ago
It’d make for a really great story if someone were able to prove that WhatsApp isn’t e2ee and instead sends copies of all message contents to meta. You could just go ahead and decompile the app to do that, then write it up and get #1 on HN.
72.
▲
by
ylk
4y ago
The malware will just take the session cookie. Some actions still require 2FA approval, but it’s not many, iirc.
73.
▲
by
ylk
4y ago
> I'd like to be able to do very basic audits of how programs work and precisely what they're doing, and also modify their behavior in simple ways (change hardcoded servers, change program execution flow, disable or enable cert
74.
▲
by
ylk
4y ago
See the other comments for why the parent is wrong. > I really wish we had some way to protect ourselves until the patch is widely available. I would hope/expect that the OpenSSL project has no indication that this vulnerability is
75.
▲
by
ylk
4y ago
The keys aren’t stored in the browser. The browser just forwards to the hardware. Switching from one password/-key manager to another is going to be more of an issue. But you should be able to add an additional passkey once logged in t
76.
▲
by
ylk
4y ago
> to clarify, if my user set up passkey on their iPhone and that's the only method of authentication for my website, they just wouldn't be able to sign in if they lost that iPhone? That used to be the case. Since iOS 16 they ar
77.
▲
by
ylk
4y ago
Please don’t take this the wrong way, but googling is a very important skill to have. There’s quite a bit of information out there and I’ll basically just repeat what you can find online already. You’re additionally not very specific about
78.
▲
by
ylk
4y ago
> Hex-Rays did ultimately release IDA Home, but you have to sign up for an account to even find out what their hobbyist license costs. It was all over their release announcement and Twitter, iirc. From their website: “For the price of $3
79.
▲
by
ylk
4y ago
For IDA Home they do give you their cloud decompiler for 64-bit binaries: “The 64-bit PC, ARM and PPC come with a compatible cloud-based Decompiler currently in beta testing mode” https://hex-rays.com/products/idahome&#
80.
▲
by
ylk
4y ago
It’s not r2 or ghidra, but binary ninja has signature libraries: “The matching algorithm is inspired by FLIRT, which was designed with similar requirements in mind.” https://binary.ninja/2020/03/11/signature-l
81.
▲
by
ylk
4y ago
More details here, but the article is in Dutch: https://archive.ph/Abxqp
82.
▲
by
ylk
4y ago
If you translate this article you’ll see that they didn’t just do 20 million in revenue, they made 18 million in profit with 18 employees, 11 of them being devs: https://archive.ph/Abxqp
83.
▲
by
ylk
4y ago
The original title was 4 chars too long, so I cut the „leading“ from it: „Consortium led by Smartfin acquires leading cybersecurity software provider Hex-Rays“
84.
▲
Consortium led by Smartfin acquires [ ] cybersecurity software provider Hex-Rays
(smartfinvc.com)
3 points
by
ylk
4y ago
|
1 comments
85.
▲
by
ylk
4y ago
Privileged is the wrong word, but GP is not entirely wrong. What you linked to is only the first part of the exploit and analysis. From the conclusion of the second post, which analyses the sandbox escape: > Perhaps the most striking tak
86.
▲
by
ylk
4y ago
> I expect it to prevent attack vectors used by these APTs It does, it just doesn't close all attack vectors used by APTs. They say[0]: > Turning on Lockdown Mode [...] further hardens device defenses and strictly limits certai
87.
▲
by
ylk
4y ago
I'd say don't let yourself be discouraged by GP. Just look into a company before you apply. Many have public reports and/or security research, both of which you could use as indicators. Here's a repo with lots of public
88.
▲
by
ylk
4y ago
> which exposes a regular RSA key With newer Yubikeys you can also use ECC PGP keys: > Support for Elliptic Curve Cryptographic Algorithms have been added to the YubiKey 5.2.3 and above firmware. https://developers.yubico.c
89.
▲
by
ylk
5y ago
That’s what diceware is for: https://theworld.com/~reinhold/diceware.html
90.
▲
by
ylk
5y ago
It is and will continued to be used in areas where security is important. This is from November 2020, I’d expect them to use it even more by now: > But we also use Rust to deliver services such as Amazon Simple Storage Service (Amazon S3
More ›