Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @subreption
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @subreption
-
Subreption LLC proslijedio/la je Tweet
KSPP fairy tale du jour: https://www.openwall.com/lists/kernel-hardening/2019/02/20/18 … … (hint: if RANDKSTACK was inspired by stackjacking then how could the supposed inspiring presentation have talked about it? perhaps because in reality it had already existed for almost a decade? :))
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
For FreeBSD, DYMASEC-ng provides full kernel heap protection down to the lowest allocation unit, including randomization and integrity protection for meta-data with a ~212 (base GENERIC) vs 220 (w/ almost all features enabled) of measured kernel time impact (synth. benchmark).
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The next generation of DYMASEC (originally funded by US DARPA) for Linux provides hypervisor-free protection against all known kernel heap exploitation techniques with <14% performance impact (in concurrent synthetic benchmarks), inc. full uninit-use/use-after-free protection.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
After years of doing essentially zero public work, and mostly diversifying our projects involving RF and physical security R&D, we will be publishing some announcements soon, including the next generation of DYMASEC (our dynamic memory safety tech for *BSD/Linux/Windows/HVs)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The blatant piggybacking -w/o credit- of KERNHEAP/DYMASEC by the KSPP/linux-hardened project (also involving IP from the grsecurity project, easily the most plagiarized pioneering work in our field) goes on: https://github.com/anthraxx/linux-hardened/commit/a7567b789ece5ac65e07e2f1a1a096b346cd53bc#diff-4f86c03fe66c75bd50afc8e320349281 … https://github.com/anthraxx/linux-hardened/commit/a0d99d0603eb191753a986e20bc790c69a5c10a9#diff-4f86c03fe66c75bd50afc8e320349281 …https://github.com/anthraxx/linux-hardened/commit/dcd8d8e4057290d918abfd6e7c4e04db3a51f756#diff-4f86c03fe66c75bd50afc8e320349281 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Blatant copyright infringement in CopperheadOS, direct match of DYMASEC & KERNHEAP's code to tag SLUB objects: https://github.com/copperhead/linux-hardened/commit/f8c9acde1cf862820a63499154bc00ea2097932a … Too bad the DYMASEC algorithm and internals can't be stolen verbatim without earning a ticket to court? :(
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DYMASEC/KERNHEAP ref. impl. was registered for IP protection in the US Copyright Office in August 2015: Reg. # TXu001987227 / 2015-08-24 :>
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The Fisher-Yates shuffle technique for rand. freelist pointers (Linux) and in-SLAB obj. indexes for FreeBSD was implemented in DYMASEC ~2011
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Google "takes" from KERNHEAP/DYMASEC (described in Phrack 66, funded by DARPA CFT c. 2011) without credit:https://medium.com/@mxatone/randomizing-the-linux-kernel-heap-freelists-b899bb99c767#.2zyfpq2mh …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Subreption LLC proslijedio/la je Tweet
Without quantifying how much (or little) benefit security development processes achieve, developers *and* consumers are left in the dark.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When "user" and "industry" reviews give security/antivirus products solid reviews.... but the CIA gives them 0/0.... something is wrong.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
“Vault7 leak exposing the AV industry failings” #avfails#vault7https://twitter.com/i/moments/839144626095271936 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The
#Vault7 leak is roasting the whole of the AV industry, especially F-Secure, AVG, Avira, some Kaspersky gems. Marketing must be livid.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Old news: AV engines plagued by engine/detection time-out related bypasses (AVG, F-Secure et al). So much for truth in advertisement in AV.pic.twitter.com/yUCYSILc25
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When the CIA says your product is "lower tier" and poses "minimal difficulty". AV Industry: worrying about reviews, not "getting owned".pic.twitter.com/ldztHGkhGl
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The most morally reprehensible form of theft is theft of ideas. It's not merely an IP or $ crime. It sabotages all incentives to innovate.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
We pulled KERNHEAP away from public availability in 2010 after catching glimpses of abuse similar to what apparently happened to grsecurity.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
OS X users should direct their hatred where it belongs: its maker. 8 years after MoAB, OS X still plagued with admin group vulnerabilities.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Perhaps the Month of X Bugs fad might need resurrection to motivate Google/Apple into competence (re: reactions against
@qwertyoruiop, etc).Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Google might think Android devices market fragmentation makes exploits difficult. The unfortunate reality:http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.