Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @_riatre
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @_riatre
-
Riatre proslijedio/la je Tweet
It just goes on to show that in the absence of detailed official information, people are perfectly happy to make up an explanation without never mind verifying it, but not even trying to see if it is consistent or reasonable! This is wrong.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Late to the party but yeah, confirmed this bug can indeed be used to fake signature of any ECDSA intermediate CA. Left side is an unpatched VM. Didn't bother filling all those strange x509 extension fields required by modern browsers so no fancy in browser screenshot.pic.twitter.com/Q9oFeajaWz
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#CVE-2020-0601 But seriously, I can't believe it that it really was only comparing public key, more so some parts of the code compares MD5(public_key) before patch, insane...Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#CVE-2020-0601 If I didn't read the code wrong, it may need slightly different certificate list construction to exploit Authenticode signature / other scenarios.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I like how their implementation uses undocumented flags of a public API...
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
Slides of
@halvarflake’s#drivingit19 talk “Security, Moore’s law, and the anomaly of cheap complexity”. Important points how the abundant complexity we see today relates to general-purpose computing. Imho, thinking of security as “absence of unintended functionality” could help. https://twitter.com/halvarflake/status/1190628289020342272 …pic.twitter.com/z1guWFESlg
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
one of the most interesting things about this work is that it might be the gateway drug that finally leads to widespread deployment of real memory safety for C and C++https://twitter.com/kayseesee/status/1157803186444525575 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
In fact 11 USB bugs in the first few hours. But we know >100 are coming. That's all triggerable by anything plugged into USB. Kudos to
@andreyknvlhttps://twitter.com/andreyknvl/status/1116670018345930752 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
Fuzzilli, my JavaScript engine fuzzer, is now open source: https://github.com/googleprojectzero/fuzzilli … \o/ Keep an eye on the Project Zero bugtracker in the next few weeks for some of the bugs found with it. Also let me know if you encounter any problems when using it! :)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Spent like an hour remapping L -> N, T -> Y, B -> D, ...
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
ClusterFuzz, an infrastructure used for fuzzing Chrome and OSS-Fuzz, is open source now! Enjoy responsibly :) Blog: https://opensource.googleblog.com/2019/02/open-sourcing-clusterfuzz.html … Code: https://github.com/google/clusterfuzz …
#fuzzing#chrome#oss#security#clusterfuzzHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
Low cost/janky China implant: take an ATtiny microcontroller, solder it onto the unused SOIC8 SPI flash footprint on a Supermicro motherboard (pinout is compatible), program it to override some reads, stick a decoy transformer/coupler coil on top.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So, can we finally have full trusted boot (preferably customizable) on all components of modern x86 servers after this big blow? Sure it does not help if the entire supply chain is poisoned but it can at least make things harder.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
T8020 has pointer authentication ayyyyyyyyyyyyyyyyyy iOS exploitation is great again
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Solved. Finally. Wasted way too much time on the final challenge T_T
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
It's 2018 and AWS Lightsail's "SSH key pair manager" still does not accept ed25519 public keys, nor ECDSA.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
There is a finite supply of most things except new JS frameworks and new ML frameworks.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
This speculation saga just keeps getting worse and worse, which goes on to show that there's a huge disconnect between CPU designers and security researchers. This is the CPU equivalent of foo = bar[untrusted]; if (untrusted > bound) return 0; do_stuff(foo);. Who does that?!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Economics is too hard for me :<
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Riatre proslijedio/la je Tweet
I’m so tired of non-economists telling me about the magic of cryptocurrency. This paper is a public service. Here’s an ungated version: http://faculty.chicagobooth.edu/eric.budish/research/Economic-Limits-Bitcoin-Blockchain.pdf …https://twitter.com/Noahpinion/status/1011022993370243072 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.