niconiconi is a user on cybre.space. You can follow them or interact with them if you have an account anywhere in the fediverse.

niconiconi @niconiconi@cybre.space

Pinned ping

WARNING, pinned: toots mostly consist of non-CWed Internet memes, anime memes, personal debates, politics, sometimes discussion of controversial ideologies (but it's probably in Chinese w/ CW), even worse, mostly written in Chinese which you cannot understand. Only occasionally posting FLOSS and security-related news and opinions. Wants to follow? Proceed with care. All the views and opinions expressed here is my personal, not necessarily (and mostly, not) related to any organization I am affiliated to.

Pinned ping

I've... exploited 0days you programmers wouldn't believe.
[*contemptuous laugh*]
ROP shellcode on non-executable memory ran as the machine of Turing.
I watched Offset2lib pwns ASLR near the stack of kernel space.

All those bugs won't be fixed in time, like
[*cough*] dereference... to... NULL,
Time...to...
segfault (core dumped)

niconiconi relayed

I guess now that I've resolved to order a block of static IPs from my ISP I can move all (minus one) of my VPSes into the basement lab instead and actually save money that I can invest in more equipment for the lab.

Wednesday I will celebrate my independence by leaving as much of the cloud behind as I can in a day.

:blobthinkingcool:

>probe voltage divider with a scope
>doesn't work....
>???????
>aha! both USB & scope is Earth-referenced
>unplugging laptop charger
>connect scope ground to Vcc
>whole row of USB Hub went down
>oh no my HDD!
>laptop is still connected to external monitor
>which is Earth-referenced!

Isolation transformer to laptop & monitor without Earth (!!!) solves the problem.

I've heard engineers destroying 10k of equipment by attempting to float the scope and forgetting the USB/RS-232. So here's how it happens...

niconiconi relayed

@niconiconi @vertigo @uranther @ajroach42 little known fact that #Apple decided to replicate this user experience on iPhone 4: wired.com/2010/06/iphone-4-hol

History repeats itself: the article even starts with te same joke!

niconiconi relayed

@uranther @ajroach42 (For starters, it used cooperative multitasking. But even then, a task switch was *very* expensive because it had to swap out a chunk of globally shared address space. It was like trying to get MS-DOS "taskers" to multitask by faking a task-switch as quickly as possible.)

What are some other unusual and fun ways to use an oscilloscope, besides using the X-Y mode as a vector display?

niconiconi relayed

@niconiconi They can't hide their tricks any longer. Every researcher under the sun is now chasing their Intel CVE glory.

niconiconi relayed

What's the difference between a laptop and a notebook, you ask?

If you can use it on your lap without suffering discomfort or burns, it's a laptop - otherwise it's a notebook

Source:
gph.is/2vBipru

niconiconi relayed

if you identify a box somewhere in the interwebz as a command & control server, is there an acknowledge place to report to the #infosec community to contribute to banlists/defense/research?

niconiconi relayed

@niconiconi @uranther @ajroach42 yeah, I'm more looking for a CPU with an exposed bus. otherwise, I could try and write an emulator that runs bare metal on a commodity ARM SoC

niconiconi relayed

Received my SMT stencil today, got the stencil made for less than 5 USD (25 CNY w/ shipping), and all you need to do was sitting at home and clicking a button to pay! Shenzhen is a quite a miraculous city for hardware hacking.

niconiconi relayed

By combining ASLR, NOEXEC, CFI, SafeStack, and the other hardening techniques, #HardenedBSD provides a pretty hostile environment for exploit authors. That's not to say exploitation is impossible; rather, it becomes much more difficult and time consuming.

3/3

niconiconi relayed

Did you know that #HardenedBSD's feature set includes more than ASLR? We have also implemented PaX NOEXEC, integrated non-Cross-DSO CFI, and many other features.

We're working hard on Cross-DSO CFI. Control Flow Integrity (CFI) is a powerful exploit mitigation.

1/3

niconiconi relayed

1990, meet 2018: How far does 20MHz of Macintosh IIsi power go today?
It turns out you can use a nearly 30-year-old bit of hardware for today's demands.

arstechnica.com/features/2018/

/cc @ajroach42

niconiconi relayed

"It’s actually a big myth that search engines need to track your personal search history to make money or deliver quality search results" - DuckDuckGo's CEO explains how it’s become profitable without gathering user data
quora.com/What-is-the-revenue-

niconiconi relayed

A lot of people assume DNA is pretty much you have this so you'll look like this or similar thing, but you have many layers of coding on top of that, firstly a gene could be a regulatory of another gene, promoter, or it could be protein coding. A protein coding gene can code multiple proteins via Alternative Splicing , and Methylation, Acetylation, or Phosphorylation of histones can change expression of the gene, in fact when you learn something new this is happening in your brain.

想想在这一点几平方厘米的芯片上,就能走 180W+ 的功率,才会感到人类科技的发达程度……

GPU 这几天快热死了,赶紧维护一下……

niconiconi relayed

"If a QST's beamed into the ionosphere and no one is around to QSO it, does it make a QSL?"