I feel like the dream of static analysis was always a pipe.
When the payment for vulns drops i'm wondering where the value is for hackers to run these tools anymore? The LLMs don't do the job for you, testing is still a LOT OF WORK.
HN user
I feel like the dream of static analysis was always a pipe.
When the payment for vulns drops i'm wondering where the value is for hackers to run these tools anymore? The LLMs don't do the job for you, testing is still a LOT OF WORK.
lots of security issues form at the boundaries between packages, zones, services, sessions, etc. Static analysis could but doesn't seem to catch this stuff from my perspective. Bugs are often chains and that requires a lot of creativity, planning etc
consider logic errors and race conditions. Its surely not impossible for llm to find these, but it seems likely that you'll need to step throught the program control flow in order to reveal a lot of these interactions.
I feel like people consider LLM as free since there isn't as much hand-on-keyboard. I kinda disgree, and when the cost of paying out these vulns falls, I feel like nobody is gonna wanna eat the token spend. Plenty of hackers already use ai in their workflows, even then it is a LOT OF WORK.
Thanks, this is very good information!
To answer your question, I thought it might just be slightly harder to extract secrets or exploit a running process directly. Thats all I was saying.
5G CSS is harder yes, but keep in mind that most 5G is the 5G_NSA variety, and is really just riding on the same cell bands, no mmwave here. You probably notice that your phone often slips out of 5g, or you inhabit different modes here.
Essentially, 5G is sort of a lie. Phones spend a lot of time exchanging information via 4g/lte, and just like 2g/3g and 3g/4g, there are simply downgrades that can be performed in the field, without getting too far into the weeds.
5G matters not for this.
well, a concerted attack could easily subvert the baseband if you have a few million dollars and the correct letterhead or private contacts.
GrapheneOS really wants the software in the phone to not pwn the phone. This is good. Its a different, and much more difficult problem to secure the connection to the telco, and the larger internet, because the transport is attacker controlled.
Think of it this way: Say you use Qubes because security is valued very highly for you. Even if you run Qubes, if your router is controlled by your attacker, what kind of a security guarantee could you really get for yourself?
GrapheneOS have hardened_malloc which is a huge advantage, I think. It makes the weird machines problem much harder. I would say be very careful, because you can still get previews of images, or old and weird media formats that could be exploitable, and android/GrapheneOS doesn't have the same sorts of policy as say Apple with the iMessage blast door. They control safari, etc.
Android's attack surface seems pretty jagged. For example there is only one webrender engine on iOS, where you can run anything you like on Android/GrapheneOS.
fyi a Cell Site Simulator can masquerade as the legitimate telco operator and push type 0 messages to the handset.
What that means is they can push malicious settings and configurations (Definitely) and probably malicious firmware to the handset at will. They don't need to code this, they buy the software packages from the usual suspects. Adversary simply needs to put a drt box or a hailstorm or what-not close enough to the handset to do the work.
The baseband can do a lot, it has dma (if I recall correctly) and can almost certainly screen look, and extract information from some but not all base bands. This varies.
GrapheneOS cannot really influence this, but hardened_malloc could conceivably help. What would be great is a bench firmware re-flash, but I don't want to do this every single day.
Cool!
I just popped in to add that NASA employee Charles White, a scientist involved with the Mars Rover project, also helped make a Burning Man Mars Rover Car (back before Playa Burning Man was completely and utterly torched twice over by Military Industrial Complex Vacationers and Billionaires) and you can hear an interview with him here on Charles White's yt channel: https://youtu.be/BKGROOedAgI ( Mars Rover Art Car interview with Ray Cirino and Charles White )
Charles White is a pretty good guy in my opinion, we play the same video game (EvE: Online) Where Charles White is a very, very well known community member who is known as "The Space Pope". He officiates weddings at our Iceland Fanfest gathering and also runs a Suicide Prevention Outreach group in EvE: Online, as well as teaching leadership skills.
Here's Charles White giving a presentation as an Official NASA employee about Space and our solar system at EvE Fanfest 2016: https://www.youtube.com/watch?v=Atm6Y_JYPEU
Heres a interview about EvE: Online with the Space Pope: https://www.youtube.com/watch?v=dWuj7LfyN4U
anyhow sorry to hijack this about EvE: Online but we have lots of cool people like Scott Manley playing, too: https://www.youtube.com/watch?v=huZlA0eg12U
I mean it was fine for these guys because they got huge press and happen to be in an industry that can handle this. They've got experience, current employment, industry contacts, and there's really barely a functional college curriculum, or certification track for this. You #1 need to be trusted to break in since you know, they teach each other how to break into high-security facilities.
I really just wanna point out that getting contracts for government administrative building is already like, way in and near the top of the game, this could have set them back 9 months or none at all, still, someone has to be held accountable when there is an obvious miscarriage like this.
I mean they called their boss! They had a special letter! Why didn't shitty sheriff just like demand that the security chief come out and make some calls? 600k sounds fair I suppose but 6 years sure doesn't when its an elected official!
Sure it does, it just always relied on external encoders.
I use audacity for recording vinyl occasionally, but for CD audio I have a bunch of cli scripts. Much easier.
I have, they're tiny shoes and it'll lock up your rear wheels at best.
I would suggest that anybody reading NOT try this unless you have a quite large and empty lot with no public access. Pay close attention, they are not called Emergency Brakes, they are called Parking Brakes.
The stated purpose of these brakes are to ensure your car wont roll away while parked. Anybody with a manual transmission knows the ritual of shifting into 1 or Reverse and turning their wheels toward the curb while parked even while the parking brake is engaged.
They won't serve you in an emergency. Here's Mitch Hedberg on "Emergency brake": https://www.youtube.com/watch?v=kMKV1B0vuI8
They also don't really stop a moving car, its a parking brake.
Just wanted to add, a EPB used for emergency stop in his scenario is just using the regular stopping brakes, its not an emergency brake either.
You can almost always pop the cable (if you have to) and hit the rotor with a hammer, or use a puller.
If that doesn't work you hit it with a hammer from the other side until the parking brake shoes pop out of the pins and come off with the rotor.
Most people doing the right thing use a torque limiter to "gun" the wheel on and then set final torque with the tires just touching the ground (for friction) which is totally adequate.
The thing people might forget is to clear the corrosion off of the wheel and hub which can be a problem if it breaks away as you drive.
Thats the same case with all brakes in use more or less. Also modern brakes have two hydraulic systems, in the case that one of the loops (front or rear) breaks there should be sufficient pressure to apply the brakes still.
Sometimes its front/rear and sometimes it is diagonal, but it should still do the emergency trick.
At the time hacker meant informal programmer, among other things. “I’m hacking on my book review website” “I’m hacking on a desktop filesharing app.” Those hackers sometimes got a nice swing at it and this place has indeed always been a finance-friendly venue for these nerds to commingle.
It’s 2025 and things move along. People still post their file sharing tools here, but yeah I agree that it does hit different now.
Very related:
Its almost certainly cocaine
I feel like we could do better, quite easily. People are very gung-ho (jing-go?) on this and it seems clear to me that we can use our significant technological advantages and investigatory prowess to target these bad actors just like any other day at the office.
This is quite the departure and it is quite troubling to me. The ESA launch site is down there iirc, seems like we have natural allies who would join a push, but instead we sent a carrier group.
The chilling effect of the executive. The current admin leverages government agencies against the corporation who will report on this if not to their liking.
And more!
The preferred response is to downvote and move on.
Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.
That’s not all that was added in there
Well, to steel man this a bit, Citizen’s United codified unlimited spending on political causes by nearly anyone.
John Sirota has spent quite a bit of effort on journalism on this subject.
Sorry to double reply, I forgot to mention what is likely the source of this interest. Recently, Kyle Hill produced this 30 minute video explaining why we may want to re-examine the LNT dose model https://www.youtube.com/watch?v=gzdLdNRaPKc
There is a little more than that.
A guitarist who plays electrified isn't just playing the guitar; the entire signal chain becomes the instrument. Everything from the room to the fingers of the player alter the sound and how a person plays their instrument and for some even the temperature of the room makes a concrete, quantifiable difference.
Music appreciation is largely cultural as well. The history of music is full of people hearing sounds, becoming accustomed to them and reproducing them with a novel variation. This is exemplified by many recent genres like hip hop, rap, jazz, rock, folk music and so on. There were and are entire genres of music and specific artists that revolve around certain tools. For example the Sunn brand of amplifier, especially the Model T which is venerated by some subgenres of metal or Jimmy Hendrix and his Fuzz Face pedal (and his wah and octaver and amp, and .....)
Naturally, musicians seek to pay homage to and recreate the atmosphere and feel of a specific song, instrument, artist, genre or time period. Until fairly recently, modeling and digital tools had a lot of trouble replicating the sound and interaction of these vintage, analog circuits and even today the most straightforward way to achieve a specific style is often to simply buy or clone the old-school original instruments and equipment.
While digital modelling has come a long way, arguably surpassing most of the original equipment, the rarity, variation and uniqueness leads players to continually seek out the Real Deal in order to achieve an authentic style or sound.
An example of this entire idea is the DRUMETRICS collective, whose entire purpose is to write and record new and modern performances with original vintage instruments and recording equipment. Heres a link to one: "Pale Horse" https://www.youtube.com/watch?v=vZqoFf859Xw
They’re probably doing that so your kid or some kid can use it and leave the penny tray because they aren’t trying to make money off of it anymore.
It’s just for fun, sounds like a nice gesture.
This is why they are so risk averse, there indeed are incredible dangers and if varies per place.
Operators, manufacturers and service have spent a long time making what we have very reliable in what are now pretty old designs. If a new pump manufacturer appeared in the scene, everyone making decisions needs to assess the reliability vs a well-known quantity of reliability.
This is what I mean when I say risk averse, and the mortar in the bricks are the suppliers and services. The record doesn’t show worse and worse throughout time, everyone in a nuclear safety related industry knows what to expect and what is expected of their production. Changing even this linear no-threshold model would incur a LOT of engineering, process development/improvement and risk analysis, which none of them want to do.
If you’re the one that screws up, it can be a nasty stain.
Sometimes it does, for example, just like gp mentions, a tube rectifier in a single ended amp can have a voltage “sag” that interacts with the rest of the system and causes an interactive “color” in the output, especially when amplifying larger voltage swings of bass notes and chords.
There are quite a few effects like this. In a modern design this would be eliminated, but sometimes “bad” is good :)
Nuclear Safety is extremely risk averse and the mortar in the bricks are incumbents for whom the strict regulations protect. Anecdotally, it is a very paranoid industry, for better or worse.
Allowing higher radiation dose does sound bad, but I would urge you to delve into the Linear No-Threshold Model. We have the lion's share of a century of cancer and health data and the results are somewhat counterintuitive.
Here is a short video statement from Robert B Hayes from NC State university: https://youtu.be/kFMKPpiiJgw
This is relevant to HN because it is entirely possible that Flock Safety helped the FBI here.
It's just as likely that mass cellular surveillance tools like IMSI catchers were used, and its a near certainly that social media and tech platforms germane to HN's audience (you (the reader) may work for one!) have also contributed to locating this person.
These tools and the allowances we give LEO and being turned towards good-faith 1st amendment activities like carrying signs and freely assembling.
At the same time, earlier this year Salt Typhoon showed us that geopolitical adversaries used these same tools in secret against our government and industry leaders (Like the ones you work for!)
Important discussion to have.