HN user

Zironic

64 karma
Posts0
Comments24
View on HN
No posts found.

I'm a bit perplexed by the choice of Nintendo Switch as the example hardware. I was under the impression that the switch was locked down and you can't run offset based cheat software like cheatengine on it.

You're looking at the wrong market. Games Workshop are not a "battlefield simulation" company. They're a miniature company or if you want to look at it more broadly, they're a company selling molded plastic.

The battlefield simulation is only a means to an end of convincing consumers to buy high margin plastic.

If it was a real company that would be the case. However from what I've read the journalists looking into BAC Consulting has found it to be a company in name only with no actual offices or hungarian employees.

It makes me slightly curious which company Israel convinced to actually produce these pagers and radios.

For instance, when Apollo Gold lisenced their pagers to a little known hungarian company, having their brand used as a bomb delivery device in the middle-east was not something they would have had on their list of potential brand risks.

So now companies engaged in international business not only have to consider exposure to the usual fraud, but also if their counterpart is actively malicious.

It's also likely going to make nation states start thinking about supply chains they maybe didn't before. How do you know someone didn't put explosives in your mice, keyboards, monitors, headsets and various other things that were probably manufactured in china?

Yeah, I can't say I'm a big fan of this massive scale booby trapping devices all over civilian society and I suspect most nation stats are not very happy about this either. The EU is probably not going to be happy at all about Israel using an EU flagged company to do it either.

This is going to create a lot of distrust in the international supply chain.

It's not about mutable memory attacks, it's about not understanding the purpose of argv[0]. argv[0] is an argument, you are supposed to be able to set it to whatever you want. You are not supposed to rely on an argument to identify a program, that is nonsensical.

The problem here isn't argv[0], the problem is security software not understanding what argv[0] is and if you want security software to better be able to identify processes, the solution isnt changing argv[0], it's implementing an actual process ID checking.

If I had to guess blindly based on their writeup, it would seem that if their Content Configuration System is given invalid data, instead of aborting the template, it generates a null template.

To a degree it makes sense because it's not unusual for a template generator to provide a null response if given invalid inputs however the Content Validator then took that null and published it instead of handling the null case as it should have.

Add additional validation checks to the Content Validator for Rapid Response Content. A new check is in process to guard against this type of problematic content from being deployed in the future.

Enhance existing error handling in the Content Interpreter.

They did write that they intended to fix the bugs in both the validator and the interpreter. Though it's a big mystery to me and most of the comments on the topic how an interpreter that crashes on a null template would ever get into production.

Do Skis Get Blunt? 2 years ago

Carving is extremely popular in Alpine skiing. The thing to keep in mind though is that a perfect carve on a perfectly sharp ski means you are literally ice-skating downhill. That means you will go very very fast, much faster then most people are comfortable with on the harder slopes.

So what people do is instead of carving perfectly, they deliberately slip to create some friction and slow themselves down.