log☇︎
185900+ entries in 0.064s
asciilifeform: ag3nt_zer0: learn ru or mandarin
asciilifeform: the 'mircea is a gurl' meme lives on, in that thread
asciilifeform: we learned the seekrit.
asciilifeform: hanbot you can turn off the android now
asciilifeform: l0l, we all knew!
asciilifeform: 'I sort of hope she crashed and burned on this one..'
asciilifeform: and doesn't crash.
asciilifeform: pair of 'aa' cells runs it for a MONTH
asciilifeform: and runs msdos, even. complete with xmm!
asciilifeform: i was playing with a hp200lx, it is orders of magnitude more responsive than 'iPnohe' etc. for note taking, text editing, spreadshits, etc
asciilifeform: and it isn't as if we don't have history to learn from.
asciilifeform: it has to start out as an abstract 'don't shit in your drinking water'
asciilifeform: slow, painful process, like teaching the water closet to india.
asciilifeform: the poor english folks have not invented this technology yet. so gotta teach'em.
asciilifeform: pocket-sized version of same.
asciilifeform: see also: http://log.bitcoin-assets.com/?date=28-07-2014#774690 http://log.bitcoin-assets.com/?date=28-07-2014#774691 http://log.bitcoin-assets.com/?date=28-07-2014#774692 ☝︎☝︎☝︎
asciilifeform: usg's most effective weapon is the learned helplessness of schmucks who accept 'being pwned is inevitable fact of life'
asciilifeform: mats: folks who begin from 'mitigation' position, cannot win by definition. they aren't even trying to. just to 'lose more slowly' ☟︎
asciilifeform: http://www.coindesk.com/itbit-adds-nsa-veteran-to-advisory-board << mega-l0l
asciilifeform: mortician.
asciilifeform: but to advocate it as some kind of actual state of the art, is another thing.
asciilifeform: now, if some schmuck wants to pay you to administer medicine to a corpse, go ahead.
asciilifeform: ergo 'mitigation' is medicine for a corpse.
asciilifeform: or whatever your favourite c tool was
asciilifeform: how many of these would be caught by, e.g., 'cyclone' ?
asciilifeform: (or at least read the medalists' entries)
asciilifeform: mats: ever play 'underhanded c contest' ?
asciilifeform: why not maginot line!
asciilifeform: did mats just use great wall of cn as example of 'secure' ! ☟︎
asciilifeform: l
asciilifeform: l0
asciilifeform: regardless of whether folks run 'lint' or whatnot on their own shit.
asciilifeform: the cost of dredging up an 0day from the infinite stash of stuxnetiana is still zero (for usg)
asciilifeform: holy fuck is mats telling us now that winblowz can be lived with ?
asciilifeform: Belxjander: AmigaOS ?!
asciilifeform: !up Belxjander
asciilifeform: ew
asciilifeform: (compile would be 50x slower, yes. but only compile.)
asciilifeform: this was to have been for ~development~ only.
asciilifeform: slow.
asciilifeform: but upside is that we aren't passing around a massive binary turd. ☟︎
asciilifeform: then again, 99% of the time spent by folks who aren't me, thus far, appears to have been spent chasing various annoying little misconfigurations
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1237091 << if you recall, this was my original (~6 mo. ago) suggestion for how to do development on therealbitcoin. but a number of folks (chiefly mircea_popescu) did not like it. for entirely logical reasons ☝︎
asciilifeform: sinking on the ship is - voluntary.
asciilifeform: mats: plenty of islands to take your chances on.
asciilifeform: good times.
asciilifeform: 'mitigations' in which we can make plenty of (imaginary) money digging for holes in, aha
asciilifeform: the ultimate systemic solution is 'fits-in-head'
asciilifeform: (burn the whole fucking lot, and start with sane programs written by sane people for sanely designed machines) ☟︎
asciilifeform: there is always the obvious solution.
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1237194 << solution to what ? ☝︎
asciilifeform: he was in his early 20s, iirc, and it was an upgrade from driving truck, so looked like a good job.
asciilifeform: they didn't even 'clearance' the slaves, as this costs far too much and eats into the margins
asciilifeform: i know a fellow who used to work in one of those farms
asciilifeform: phf: this labour is traditionally contracted out, aha
asciilifeform: phf: perhaps my perspective is a little skewed because i do hardware.
asciilifeform: a simple calculation shows that - unless one is extraordinarily lucky - the effort which goes into finding a typical vuln, vs the typical 'bug bounty' offered by, e.g., microshit, works out to approximately u.s. minimum wage.
asciilifeform: and/or do not want to give aid and comfort to usg.
asciilifeform: because they are not 19
asciilifeform: the point i was trying to make is that: i hypothesize that the '0day market' consists very largely of folks who are sitting on 0day and not 'marketing' at all ☟︎
asciilifeform: it is virtually always the same kind of thing.
asciilifeform: but occasionally read the slides, at the instigation of colleagues and various other folks
asciilifeform: for the record, i have never attended such an event
asciilifeform: BingoBoingo: the way it presently works is that the seller is at the total mercy of the buyer. disposable 19y.o. puts up with this because he is fucked in the head. a grown man - typically - does not
asciilifeform: also fewer 'eiffel towers built of matchsticks' - elaborately labyrinthine 'rube goldberg' machines, like the last third of that slide deck, which ultimately sum to 'i read a 486 manual taken from a dumpster'
asciilifeform: phf: there was, at one time, considerably less flavour of scammitude and in-your-face lying
asciilifeform: but simply because scorched earth.
asciilifeform: it isn't even because i expect to meet up with folks who pay the 'fair price' at some future time,
asciilifeform: where plenty of folks just sit on the goods, 'because fuck you'
asciilifeform: but what they have really succeeded in is creating a 'fuck-you market'
asciilifeform: while giving the goods away for almost nothing
asciilifeform: where thousands of disposable 19-year-olds fight for a chance to publicly measure their cocks
asciilifeform: vendors want the 0day market to be a 'tournament market' ☟︎
asciilifeform: here's an observation:
asciilifeform: BingoBoingo: ... if you find it you can sell it. << not quite. i, for instance, can't sell it ☟︎
asciilifeform: phf: except that my fucking ~~~486~~~ reference manual describes smm
asciilifeform: BingoBoingo: one reason for this change is that ~actual~ exploits are (or are at least now thought to be) worth money.
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1237135 << so, i read the slides. 1) 20MB powerpoint pdf turd?!!! wtf, people. 2) the picture which implies priv escalation is disingenuous. there is, just as i said earlier, no esclation. you gotta be in ring0 to move the apic window. NONE OF THIS SHIT WAS SECRET, how did they even get a talking slot at 'blackhat' ? ☝︎
asciilifeform: hanbot ?
asciilifeform: anyone still remains who tried to build rotor, but could not ?
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1237071 << congrats pete_dushenski ! ☝︎
asciilifeform: http://www.theregister.co.uk/2015/08/04/intel_pays_double_for_women_and_ethnic_minorities << mega-l0l ☟︎
asciilifeform: where the cpu needs to do a certain brief chore in an os-agnostic way
asciilifeform: pete_dushenski: the typical application for smm is items like the screen brightness keys found on laptops
asciilifeform: including, say, your ethernet card
asciilifeform: the apic thing is also a snore, in the sense of NO SHIT anything that sits on the bus can read from arbitrary physical ram
asciilifeform: (ring0 code can still trigger smi by writing particular vendor-specific magic to the southbridge, but this is in no sense a vuln)
asciilifeform: likewise you can turn off all sources of smi (system managament interrupt) that put the machine in smm handler to begin with
asciilifeform: including nothing at all
asciilifeform: if you run coreboot (aka linuxbios) you get to put whatever the fuck you want in smram ☟︎
asciilifeform: which nonsense
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1237119 << howling idiocy. smm has been in the official docs, from intel and amd both, since 486. ☝︎
asciilifeform: then we can go full circle to the old days when there was no such thing as a car you couldn't start by hand
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1236984 << can't wait for these to come with a cranked dynamo (preferably in the cab proper, perhaps somewhere under dashboard?) ☝︎
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1236842 << all three of these were translated (the traditional ru single-voice crappy dub) and i saw'em as a boy ☝︎
asciilifeform: funny how these things get recycled forever.
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1236937 << i read some variant of this claptrap on usenet, in, when, '96 ? ☝︎
asciilifeform: i am not a clairvoyant, cannot read your hard disk ! gotta give me something to work with. ☟︎
asciilifeform: from this point on, this applies to anyone who wants help in building the thing
asciilifeform: http://log.bitcoin-assets.com/?date=13-08-2015#1236905 << please post your rotor directory tree. ☝︎