Hector Martin

@marcan42

If it ain't broke, I'll fix it! · 壊れてねぇのに直すぞ!日本語でもOK! · He/him.

Tokyo, Japan
Vrijeme pridruživanja: svibanj 2009.

Tweetovi

Blokirali ste korisnika/cu @marcan42

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @marcan42

  1. Prikvačeni tweet
    1. svi 2019.

    I did two live hacking streams recently, one about patching the firmware of a MIDI keytar and one about adding support for USB audio on a DJ controller to Linux! They're long, but this is what real-time reversing looks like :-)

    Poništi
  2. proslijedio/la je Tweet

    🌟Information🌟 On February 5th (9:00 UTC) I’m releasing a song! 🥁🎶 
It’s a warm and positive song that will cheer you up. 🌸 The singer is… a secret until release! Look forward to it! ✨
 It’s such a special collaboration. ♪ Don’t miss it! 💗 👑

    Prikaži ovu nit
    Poništi
  3. 27. sij

    So, what's the right SMTP/IMAP client to use on iOS? I use K-9 Mail on Android, but asking for a friend who uses iOS...

    Poništi
  4. 27. sij

    There's bugs, and then there's "major app feature is literally unusable for the entire non-English-speaking world and also English speakers can't use apostrophes or emoji". For years. Google, you're good at killing things. If you don't care about IMAP/SMTP support, kill it.

    Prikaži ovu nit
    Poništi
  5. 27. sij

    I just found out that GMail on iOS has been completely broken for IMAP/SMTP accounts for years, turning anything non-ASCII into ????? when sending messages. Multiple people have complained since 2018 with no answer. What the hell, ?

    Prikaži ovu nit
    Poništi
  6. 27. sij

    Hey, my CPU fan is brok-oh.

    Poništi
  7. 26. sij

    News: "Evil Google is listening in on people having sex!!!" Reality: the hotword detector is just crap. Also, turn on the accessibility mode to hear that blip every time it triggers (i.e. when it starts sending audio to home base, even if it later decides it was a false trigger)

    Prikaži ovu nit
    Poništi
  8. 26. sij

    When the Google Home hotword detector triggers on... brass.

    Prikaži ovu nit
    Poništi
  9. 24. sij

    Is there really no way to forward an internal TLD with BIND without sticking `rndc nta -lifetime 2d <tld>` into your crontab? Because this is ridiculous. Yes, I know I'm hijacking a nonexistent TLD for local use. Everyone does this with authoritative zones. Let me use forward.

    Poništi
  10. 24. sij

    Gentoo's minimum system requirements now include quantum computing. You need USE flags to be simultaneously on and off.

    Poništi
  11. 17. sij

    Worth noting that RFC5480 disallows custom ECC curves for PKIX, and of course they are also verboten in the WebPKI. But both crypt32 and OpenSSL seem to support it.

    Poništi
  12. 17. sij

    It just goes on to show that in the absence of detailed official information, people are perfectly happy to make up an explanation without never mind verifying it, but not even trying to see if it is consistent or reasonable! This is wrong.

    Prikaži ovu nit
    Poništi
  13. 17. sij

    I don't understand how everyone is falling into the trap of talking about "validating" ECC params or using the wrong ones or whatever, and completely handwaving the way this actually works. If you *think* about how this should work, it doesn't make sense.

    Prikaži ovu nit
    Poništi
  14. 17. sij

    And by the way, the fact that I had to come out and make this explanation is *yet again* another example of the sorry state of tech security reporting, by both media and infosec folks themselves. Like every single article about this bug is wrong and makes no sense.

    Prikaži ovu nit
    Poništi
  15. 17. sij

    (And we can already do this exact thing for FDE on desktops/laptops, so it's not like it's novel)

    Prikaži ovu nit
    Poništi
  16. 17. sij

    I don't know why nobody offers this option of split FDE/unlock codes by default (neither iPhones nor stock Android). It's such a massive no-brainer to increase security to basically "unbreakable" under an entire class of practical attack scenarios.

    Prikaži ovu nit
    Poništi
  17. 17. sij

    Sure, you can try to attack my phone from a powered-but-locked state, but if you screw up and it reboots, or if you attempt any boot chain attacks, or if the battery runs out, you are *not* getting in. Period.

    Prikaži ovu nit
    Poništi
  18. 17. sij

    Thread about numeric passcode strength on iPhones. And *this* is why I consider my rooted Android phone to be more secure than iPhones under a whole category of attack scenarios. Because I can use separate 25-character full ASCII *startup* password and an 8-digit *unlock* code.

    Prikaži ovu nit
    Poništi
  19. 16. sij

    So it's not that Windows uses the wrong curve parameters or anything like that, it's that at some point the key used to index into a validated cert cache is (serial, pub) when it should be (serial, pub, params). As they say, one of the hardest problems in CS is caching.

    Prikaži ovu nit
    Poništi
  20. 16. sij

    To clarify the Windows crypto fail: The problem isn't in signature validation. The problem is the *root store/cache*. CryptoAPI considers an (attacker-supplied) root CA to be in the trust store if its public key and serial match a cert in the root store, Ignoring curve params.

    Prikaži ovu nit
    Poništi
  21. 16. sij

    Reminds me of setting the RSA sig to all-0 on the Wii and bruteforcing a hash that starts with 00 (because they used strncmp and no padding check and 0^e=0 mod n). Degenerate crypto exploits are fun.

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·