HN user

amckenna

477 karma
Posts1
Comments160
View on HN

"After this story published, Apple told [Kim Zetter] they just posted the instruction about the DIT to their web site yesterday [MAR 21], timed to the public release of the researchers' findings, which means that developers were not told to do this fix prior to yesterday's release" [1]

The mitigation for the issue was posted in coordination with the publishing of the vulnerability. Given that the mitigation only applies to the M3 processor, it's reasonable to assume that there is no currently known mitigation for the M1 and M2 processors.

[1] https://www.zetter-zeroday.com/apple-chips/

Kim Zetter has a great post walking through some details and commentary across a few sources, related to the vulnerability - https://www.zetter-zeroday.com/apple-chips/

The cryptographic key itself isn’t placed in cache. But bits of material derived from the key gets placed in the cache, and an attacker can piece these bits together in a way that allows them to reconstruct the key, after causing the processor to do this multiple times. The researchers were able to derive the key for four different cryptographic algorithms: Go, OpenSSL, CRYSTALS-Kyber and CRYSTALS-Dilithium.

[Green] notes that in theory this attack might be used to break the TLS cryptography that a computer’s browser uses to encrypt communication between their computer and web sites, which could allow attackers to decrypt that communication to extract a user’s session cookie for their Gmail or other web-based email account and use it to log into the account as them.

I really don't understand how they can make this statement:

The report states that when the car started, security video shows the owner in the driver's seat, contradicting reports at the time of the April 17 accident that the seat was empty when the car crashed.

Those two things aren't contradictory at all. The car's journey could have started with the driver in the driver's seat, but been empty when the crash occurred. A lot can happen in the time between the start and the end.

I believe the difference here is the temperature. If you look at KSTAR's operating tests you can see that they have run for 72 seconds in the past, so they must be implying 20 seconds at > 100M, or their statement about the 20s runtime would be invalidated by their own operating history.

What's more - the scientific article about the Tore Supra 2003 test is paywalled, but based on the abstract it looks like it was a test of: "simultaneously heat removal capability and particle exhaust in steady-state fully non-inductive current drive discharges" and not a test of maximum sustained temperatures.

[1] https://en.wikipedia.org/wiki/KSTAR [2] https://www.sciencedirect.com/science/article/abs/pii/S09203...

This is where I diverge from Jimmy, as he is misinterpreting what the commenter is saying. The commenter is talking about _audit logs_ of changes to Wikipedia being kept in WORM compliant record, which is a good idea - audit logs should be immutable. Jimmy seems to be interpreting the comment as saying the pages of Wikipedia should be immutable, which obviously should not be the case.

Exactly. The case is not alleging that Walmart is engaging in a broad conspiracy, despite what the title of the article seems to suggest. It is simply saying that the plantif was terminated when he brought up to management that there were issues with how they were conducting business - "Walmart did not properly address these issues, its failure to do so could have serious long-term implications for its critically important e-commerce business."

Correct. There were several goals with the launch. The primary was successful payload insertion, the secondary goals were the successful return of the outer two boosters to land, and the central booster to a drone ship down range (success unknown). Additionally the goal was to recover the fairings, but the success of that is not publicly known at this time.

On a related note here is a proposal for a recent update to the animal emoji set. It's interesting to see the factors they consider when choosing whether or not to integrate a new emoji. I didn't know that much thought went into what they chose.

This was a very helpful explanation, thank you! Does using hexagons represent the start of a paradigm shift for mapping applications or is it something that has been used for a while? This is the first I have heard of it, but based on your explanation it makes a lot of sense.

Vitamin D is fat soluble and isn't cleared by the body as quickly as other vitamins such as B. Therefore it can be taken in higher doses, but less frequently. This is often done for convenience sake. A 3000-5000IU pill every week is easier to remember than a 500-600IU pill every day.

Take a few minutes to read the blog posts by the creator. Writing aside the general process and motivation around creating a custom hashing algorithm is very strange -

"Curl-P was created by following the idea of simplicity. While de-jure I can say that it was me who created Curl-P, de-facto it was created by a primitive AI created by me. That wasn’t AI of general purpose; an improved version of the AI is working on the final version of Curl now while I’m writing this post. This situation is quite funny because it look unusual, interesting if in the future we’ll see cases similar to https://www.theguardian.com/world/2016/jan/06/monkey-selfie-... but with an AI instead of an animal. By the way, there are a lot of attempts to create a lightweight hashing function, I’d be grateful if someone confirmed or refuted my observation that Curl-P is winning this competition.

IOTA was created to be immune to quantum computer attacks, today I have revealed that it was also created to be immune to attacks from an AI. IOTA was the very first distributed ledger technology to consider imminent threat from technologies which look exotic now. NSA already validated our prediction regarding quantum computers. I think that the both threats (QC and AI) have equal chances to become real in the near future and I’m confident that in few years we’ll see confirmations that the prediction about AI was prophetic too. If someone hasn’t got it yet – IOTA is about the future and it relies only on those paradigms which pass the test of critical thinking."

- http://come-from-beyond.com/time-for-a-paradigm-shift-has-co...

IOTA's relationship with top-tier companies was more than nebulous it was intentionally deceptive. They stated they had a partnership with Microsoft's Azure, when in fact they were simply using some Azure services. I don't think it's fair to claim I have a partnership with AWS just because I host a website on an EC2 instance.

Those aren't equivalent comparisons. The issues with Ethereum have all been with regards to implementations of applications on top of the ETH layer - parity bug and DAO hack being the two biggest. Neither was due to mistakes in the underlying Ethereum protocol, both had to do with something that someone made using Ethereum.

If I make a vulnerable website it's not nginx/Django/Postgres's fault.

The reason Ethereum hasn't taken over the dominant position yet probably has more to do with Bitcoin's superior brand penetration. Most Bitcoin holders that I know personally have very little actual understanding of how any of the crypto currencies work under the hood, so they follow the general sentiment of the community/press and do not invest based on technical merits.

That may be the case with their free accounts or money earning YouTube accounts, but that is not the case for subscription based GSuite business accounts. The GSuite accounts are set up so that an offending user is a sub-account of the parent GSuite account. They will ask the parent account owner to suspend the user's account and take measures to fix the violations, but they wont unilaterally suspend the parent account.

Bingo. While there are issues with the developers and their decision making process the real issue is with the large mining conglomerates that control huge portions of the network. They have enormous influence on what changes are actually rolled out and have generally been unwilling to implement changes that will affect their profits. Google for the drama around ASICBOOST, Bitmain, and SegWit.

I totally agree that most web pentesters don't generally need to know how buffer overflow and binary exploitation techniques work but I think an understanding of how low level systems function and how they can be exploited is useful across all security sub-fields.

I don't think Offensive Security is trying to pump out exploitation experts from their entry level cert program. Maybe the higher levels OSCE and OSEE. The intro cert emphasizes breadth over depth. It felt a lot like a cert built around the Exploitation Hackers Handbook.

I think you're thinking of the certs in the wrong light. They are meant to validate baseline knowledge and proficiency, not mastery. If you want to validate mastery you need to look at the persons personal record and work product.

Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was a real application, albeit an old one), find the crash, figure out stack space, figure out bad characters, find the right JMP ESP or equivalent instructions in a loaded library, write shell-code, encode shell-code, slap it all together, hope your hex math doesn't suck, run the exploit. No DEP, ASLR bypass, SEH manipulation, use after free, or heap related work - I learned that on my own.

Their web app challenges were fun too. LFI to code execution, SQL injection, things like that. They have a bunch of network related recon, standard red-teaming stuff.

The OSCE involves ASLR bypass, AV bypass, and using egg hunters.

The big thing about the OSCP, OSCE, OSEE certs is that you actually have to _do_ all of the stuff they teach you. Not a multiple choice or written question in sight. For the test they drop you in a network with vulnerable machines and you have 24, 48, and 72 hours (depending on the cert) to get code execution on each through various techniques. It was challenging, interesting, and satisfying.

Edit - it's worth mentioning that I still find vanilla buffer overflows on projects. These days most thick-client applications that I see are old as hell and are still vulnerable to exploitation techniques from decades ago. So while the skills that the cert makes you prove are cursory and introductory, they are still useful. In any case it's a good starting place for those that want to learn stuff on their own but do better when they are given the push to prove it.

The author of the article doesn't represent all western views any more than you represent Turkey. However, given the fact that we have a chance to interact here (thanks Internet!) tell me/us what you would like me/us to know about your country that you feel is being seen incorrectly.

The best way to combat ignorance is through education.

I think the point is more that security certifications CAN be worthless and you don't NEED them, but that doesn't make them inherently bad/worthless. I think the author's argument should be that the industry has begun to rely on them too heavily for vetting. That makes sense though because it can be very difficult to vet the skills of a client. The hiring process is very time consuming so if you see two candidates and one has "proven" they at least have some baseline skill in an area then they will lean on that for decision making in the same way they look at education or self reported experience.

Experience on a resume is self reported so that is an even worse indicator of skill than a cert. At least one of those two involved external validation by a 3rd party.

I think there are a few good ones out there and getting them ensure the person has at least a baseline knowledge of some subject. I have worked in the industry for years as a pentester, but I still went and got my OSCP and OSCE for fun. A lot of it was review, but it was nice to fill in some gaps and practice things I hadn't had as much experience with.

Certs are like college degrees, you can get by without them, but it can be easier if you have them. You will probably learn some things along the way and the provide a foundation for later studying or pursuit. You don't NEED them, but you don't need a lot of things in life, that doesn't make them worthless.

Don't know if you have taken it in the last year or so since they updated it, but it's pretty tough. You may be able to use a public exploit to elevate your shell once on a box, but getting code execution was the difficult part. One of the challenges involved fuzzing, writing custom buffer overflow exploits, and dealing with weird stack pivots. That only got me about 20% of the way to passing the test. All in 24hrs. My girlfriend was taking the GPEN at the same time. While I was banging my head against a debugger she was making flash cards. I think that highlighted the difference between the certs.

She went through standard TSA searches - scans, pat downs, and explosive chemical swabbing. (I travel twice a month and have TSA-Pre and I still have to go through that 1/3 of the time). She was then questioned about the nature of her travels. Upon return she was questioned about her travels, the contents of a CD she had, why she tried to open up a bank account abroad, and where the thousands of dollars she left with went. I don't think it was unreasonable for border patrol to be suspicious. Their job is to investigate suspicious behavior and from their perspective they don't know whether the woman was telling the truth or not, but the facts of the matter do raise suspicion. I would be a bit more worried if they didn't ask all of those questions and investigate the issue, why else are we paying them?