Live data from Hacker News

Viewing profile — notactuallyben

notactuallyben

HN member
Joined
Fri, Mar 17, 2023, 3:29 AM UTC
HN karma
27
Public activity
16 items

About notactuallyben

No profile information was provided.

Recent public activity

  1. story
  2. comment
    Comment #42192576

    Vulnerabilities in the Linux kernel would have a similar impact to a macOS kernel bug. It’s a myth that “more eyes means more secure” for OSS ;-) - it can be true, but often that’s…

  3. comment
    Comment #40790629

    Yep, I don't think there's any disagreement with that, especially when you look at things like Tianfu cup in general. Any country that can, essentially wants to do offensive cyber.…

  4. comment
    Comment #40788383

    Are you suggesting that western exploit sellers are selling bugs to western governments and also BRICS? that sounds not very likely. All of this stuff is very complicated ethically…

  5. comment
    Comment #40788349

    It's not true anymore due to the new generation of hackers that came up, and it's unpolite to dox them if they don't want to be known for it, but for a period, about a third of Goo…

  6. comment
    Comment #40788232

    also TAG and other Google security people hired from former Western sigint :)

  7. comment
    Comment #40788139

    firstly, very unlikely that zerodium are supplying bugs they use (could be internally developed, or developed by a more trusted domestic defence contractor). What about if the targ…

  8. comment
    Comment #40780717

    Interesting blog post that was long overdue, I think Google should probably disclose all the details (URLs/actors responsible, methodology for catching these exploits ITW and targe…

  9. comment
    Comment #40574605

    while beg bounty people can be annoying, you have to remember that people aren't obligated to sit down and find free bugs for any company (especially not a big one) - why would i s…

  10. comment
    Comment #37451421

    Yup. You can just have your crafted webp (This is the patch for the ImageIO bug https://chromium.googlesource.com/webm/libwebp/+/902bc919033... ) image with the .png extension (ins…

  11. comment
    Comment #35196338

    So I got a little bit of time to check ( https://github.com/Biktorgj/quectel_eg25_recovery/tree/EG25G... - the NON-HLOS), and it's still actually running a Qualcomm Hexagon baseban…

  12. comment
    Comment #35195759

    I didn’t check, and on mobile now. But I would be very surprised if that was the actual baseband (more just a wrapper around it).

  13. comment
    Comment #35194547

    Yep in most cases, but not always configured the best. Logic flaws seem the best way to go :)

  14. comment
    Comment #35194538

    None use Linux, most just use BSD licence software (or things like openssl). I haven’t seen any GPL code at all tbh. But yep, would be nice if it was open source, although not sure…

  15. comment
    Comment #35192660

    This is not true on pretty much any phone post 2014ish. Pretty much all platforms have IOMMU's or similar separation mechanisms. source: did baseband vr commercially

  16. comment
    Comment #35192647

    Great work from P0 (and Keen lab). but this statement about baseband mitigations is only partially true. Huawei Balong platform has ASLR and stack canaries now (and some Infineon t…