422100+ entries in 0.268s

phf: i
think
that's
the biggest advantage NSA has incidentally, because
they can print money,
they can probably just spin up a
team for every single "core dump on a funny input" and bring it
to a point where it'll successfully eat a shellcode. older salaried reversers simply don't have
time or desire for
that sort of stuff.
that's in software world anyway.
☟︎ mats: just shrinking
the attack surface a bit.
mats: there is no systematic solution
to be had
☟︎ phf: i dunno, i
think people sit on a lot of denial of service, but developing
that
to a working exploit
takes
time and unhealthy level of juvenile ocd.
phf: c solutions
that address problems at
the core
phf: when was
that exactly? because i stopped following infosec in 2003 (i
think last
toorcon i've been
to was 2005) and looking at it now not much has changed.
the releases are definitely a lot less interesting, because of
the 0day market, but when i ragequit it was
the same shit. weak releases by pushy guys in faux military gear as a norm, occasional interesting stuff from
the usual suspects and practically negative desire
to come up with systemati
☟︎ phf: i
think you have higher expectation of what should be coming out of security conferences.
toorcon, schmoocon, defcon, blackhat (though i always
though bh is like a grownup version) always seemed like a poc||gtfo in a face-to-face with beer format
BingoBoingo: <asciilifeform> BingoBoingo: ... if you find it you can sell it. << not quite. i, for instance, can't sell it << You have well founded suspicions of what happens
to
the unannoited who sell
BingoBoingo: Seems people finally got
the memo
that if you find it you can sell it.
phf: asciilifeform: i
think
that's a standard blackhat fair. i
think
the useful part is another cubbyhole
to put rootkit fallback hooks, but it's presented like an earth shattering revelation, because
BingoBoingo has a feeling asciilifeform could be
the entire speaker slate at blackhat with
things known since
time immemorial. A few years ago I
thought
things being presented were novel. Now I look at
the program and see loads of snore.
pete_dushenski: and with
that, i'm off
to have my weary joints and hulking muscles massaged good and proper. adieu !
assbot: Logged on 13-08-2015 14:44:54; pete_dushenski: shinohai: wonder of wonder, miracle of miracles, i
took rotor by
the hand,
turned him around and - miracle of miracles - led him
to
the promised land !
phf: seems reminiscent of bios virii from back
then. "if you boot
this floopy..! well, no shit"
pete_dushenski: "So Domas looked
through Intel's sample SMM code, which is provided
to firmware vendors
to bake into motherboards. It
turns out
that pretty much all vendors use Intel's
template SMM code."
pete_dushenski: asciilifeform: so amd is no cure for
this nonsense ? and i'm guessing ppc is in
the same boat ?
pete_dushenski: "When
the Pentium Pro (a P6 family chip) arrived in 1995, Intel allowed kernel-level developers
to reprogram
the local APIC so
that it would appear elsewhere in physical memory.
This was handy for moving
the local APIC out of
the way of low-level software
that expected
to use
that high 0xFEE00000 address for something else."
pete_dushenski: "old intel products like all old computing hardware is unsafe at any speed. please
to upgrade
to latest blackbox for maximal safety and suckoority"
pete_dushenski: "The good news is
that Intel spotted
the howler in its processor blueprints, and corrected
the issue: chips built from January 2011 and onwards (Sandy Bridge Core CPUs and later) are not affected. " << highly suspicious
pete_dushenski: if
this doesn't have you hunting
the local classifieds for amd opterons and fxes, i dunno what will
assbot: Intel left a fascinating security flaw in its chips for 16 years – here's how
to exploit it •
The Register ... (
http://bit.ly/1NsN0tX )
pete_dushenski: "Thanks for your support! Please drive
to E.Bumfuck, Ontario on
Tuesday between 2 and 3 pm
to make a donation, where we accept Disneyland
Tickets or Hershey Park rain-date vouchers."
pete_dushenski: "Imagine for a second
that you see a great street juggler. He deserves a
token of your appreciation. However instead of putting a hat out, he puts a sign up:"
pete_dushenski: it may go back
to
the 2-3 per week it was in its first ~6 months before it ramped up
to
the current 4-5 per week
pete_dushenski: funkenstein_: i imagine
that contravex posts will either become shorter or slightly less frequent, but we shall see
pete_dushenski: ;;later
tell williamdunne can we see about having frass.woodcoin.org
to scoopy's roster ? please and
thanks
funkenstein_: frass.woodcoin.org <-- another place I display my ignorance from
time
to
time
funkenstein_: I am hoping you will still be able
to contravex us regulary even with new arrivals :)
funkenstein_: I've been busy but got several pieces started and
torn up ;)
funkenstein_: perhaps in some way similar
to simply passing around a massive virtual machine file (yes I'm fishing for a correction on
this)
☟︎ pete_dushenski: funkenstein_ speaking of nothing, are you still blogging much ? and what was
the name of your site again ?
funkenstein_: I must say
the rotor is a software release like no other I have seen, yes very deterministic
funkenstein_: wow
that looks like a mega-review, consistent with his recommendation for book reviewers linked earlier :)
pete_dushenski: cool. i'm currently wandering
through 'inside
the whale'
pete_dushenski: funkenstein_: lol cheers. i'm sorta surprised i didn't need more help
than i did
funkenstein_: The man has a great point, but, where did
this
thing start
that humans are not animals, and in what crib do I find it
to strangle it?
☟︎ shinohai: I liked
this morning article as well. You may have noticed I fumbled
the syntax.
funkenstein_: "For man only stays human by preserving large patches of simplicity in his life, while
the
tendency of many modern inventions-in particular
the film,
the radio and
the aeroplane-is
to weaken his consciousness, dull his curiosity, and, in general, drive him nearer
to
the animals."
pete_dushenski: shinohai: wonder of wonder, miracle of miracles, i
took rotor by
the hand,
turned him around and - miracle of miracles - led him
to
the promised land !
☟︎ assbot: Logged on 13-08-2015 05:01:16; wilbns: ducktales, gummy bears and
talespin over here.
assbot: Logged on 13-08-2015 04:55:16; mircea_popescu: <phf> i
thought
Thompson was mostly a polemicist, are
there any articles of his where he successfully "blows a lid" off something? << no.
assbot: Logged on 13-08-2015 04:55:04; mircea_popescu: asciilifeform linked cryptome article badly stitched
together effort of random derp
to get his name out
there ?
gribble: Bitfinex BTCUSD
ticker | Best bid: 263.44, Best ask: 263.45, Bid-ask spread: 0.01000, Last
trade: 263.45, 24 hour volume: 13872.40075161, 24 hour low: 263.33, 24 hour high: 270.09, 24 hour vwap: None
assbot: Logged on 13-08-2015 06:38:31; *: BingoBoingo contemplates selling BTCTalk account and entering a deed of sold in
the bot, but...
shinohai: Here in
the Southern US you can identify
the real deal easily.
The have crude signs
that advertise
their produce with
the most horrific spelling possible.
☟︎