Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @_minipli
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @_minipli
-
Very proud and happy to join the team
https://twitter.com/grsecurity/status/1223577524095127552 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Point being, the fix for CVE-2018-19854 (the re-introduced bug of CVE-2013-2546 and CVE-2013-2547) took
@RedHat a year to backport,@CentOSProject additional 2 months until this got fixed in their 8.1 release. ... Customer support
not worth fixing CVEs in time?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
a myth from the same academic jokers^Wresearchers who graced us with their ASLR 'research' in the past: in https://res.mdpi.com/d_attachment/applsci/applsci-09-04229/article_deploy/applsci-09-04229-v2.pdf … table 2 shows RAP vulnerable to ret2user (it isn't, after all we invented KERNEXEC/i386 in 2003 and UDEREF in 2006 :) but everybody else not...
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CVE is broken but CIDs can’t be the cure:https://twitter.com/grsecurity/status/1186620639827976192 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Said, but true. Older kernels, especially enterprise ones, are missing fixes for publicly known vulns.
https://twitter.com/grsecurity/status/1180066453128728576 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Some people take security more serious than others. Worth a read!https://twitter.com/grsecurity/status/1168972902936563723 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
https://git.kernel.org/linus/4368c4bc9d36 … — what a great mess
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Me: Hmmm. Have you ever asked someone who was really busy and focused on something to spend half a day doing something else? X : Yes. Me : That half a day cost a week. That's context switching.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Sometimes in adult life you have to tell other people something that will make them sad, and I really do not enjoy these situations. My first instinct is always to comfort, and there are situations where that is neither appropriate nor possible.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Thread on exploit mitigations. Below are rules I wrote for a good mitigation a while ago: “Before you ship a mitigation...
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Perhaps defenders must invest 100x more than attackers, perhaps the number is 10x, perhaps it is 1000x. Reality is that the number of people reading critical code to clean it up is *less* on defense than on offense.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
https://lwn.net/Articles/790036/ … Wait till people find out the big plugin improvement they announced was adding 2 lines of code, KSPP banks on nobody ever looking into the detailspic.twitter.com/ifstSnmtDK
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
ZombieLoad: New Intel CPU vulnerability discovered in collab by researchers from TU Graz, Cyberus Technology, and Worcester Polytech Institute: https://www.cyberus-technology.de/posts/2019-05-14-zombieload.html …pic.twitter.com/wkR5znPPfE
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
“Sometimes, the elegant implementation is just a function. Not a method. Not a class. Not a framework. Just a function.” - John Carmack
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
https://github.com/llvm-mirror/llvm/commit/863ea8c618b1f88ba8c9ec355a07cb3783481642 … academic research not at its best. it took too long considering how since the beginning the only realistic threat model was 'arbitrary read-write' (slide 5 in https://pax.grsecurity.net/docs/PaXTeam-H2HC15-RAP-RIP-ROP.pdf …). i hope that people won't waste another 2 decades on such 'defenses'.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
https://arxiv.org/pdf/1811.03165.pdf … This paper should cite PaX's KERNEXEC plugin which has effectively done the same for the kernel for > 7 years: https://pax.grsecurity.net/docs/PaXTeam-H2HC12-PaX-kernel-self-protection.pdf … or if only academic works count, could have cited kGuard: https://cs.brown.edu/~vpk/papers/kguard.login12.pdf … PS: it's general protection fault

pic.twitter.com/yudA7oYxEo
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Something people don't realize: there is no one upstream who is "in charge" of making sure vuln fixes (even known vulns with CVEs) are applied to LTS kernels. If a patch conflict isn't trivially resolved, unless someone else does the work, backporting sometimes just never happens
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Here's another fun story we can finally talk about: multiple infoleaks in the Linux kernel crypto API that sat in the code for a year and a half. Some fine use of strncpy got replaced with the problematic and infoleak-inducing strlcpy: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4473710df1f8 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Reminded during the 4.19 port the repeating theme of kernel devs still not understanding what they upstream from us: compare https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/scripts/gcc-plugins/randomize_layout_plugin.c#n363 … to https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/include/linux/mm_types.h?id=c1a2f7f0c06454387c2cd7b93ff1491c715a8c69 … . it cost the totally unnecessary realignment of a hundred lines of code in a core VM structure /o\.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mathias Krause proslijedio/la je Tweet
Those who don't read pax-future.txt are doomed to reinvent it.
#securityproverbsHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.