Viewing profile — notactuallyben
notactuallyben
HN member- Joined
- Fri, Mar 17, 2023, 3:29 AM UTC
- HN karma
- 27
- Public activity
- 16 items
- HN profile
- View on Hacker News ↗
About notactuallyben
No profile information was provided.
Recent public activity
- story
-
comment
Comment #42192576
Vulnerabilities in the Linux kernel would have a similar impact to a macOS kernel bug. It’s a myth that “more eyes means more secure” for OSS ;-) - it can be true, but often that’s…
-
comment
Comment #40790629
Yep, I don't think there's any disagreement with that, especially when you look at things like Tianfu cup in general. Any country that can, essentially wants to do offensive cyber.…
-
comment
Comment #40788383
Are you suggesting that western exploit sellers are selling bugs to western governments and also BRICS? that sounds not very likely. All of this stuff is very complicated ethically…
-
comment
Comment #40788349
It's not true anymore due to the new generation of hackers that came up, and it's unpolite to dox them if they don't want to be known for it, but for a period, about a third of Goo…
-
comment
Comment #40788232
also TAG and other Google security people hired from former Western sigint :)
-
comment
Comment #40788139
firstly, very unlikely that zerodium are supplying bugs they use (could be internally developed, or developed by a more trusted domestic defence contractor). What about if the targ…
-
comment
Comment #40780717
Interesting blog post that was long overdue, I think Google should probably disclose all the details (URLs/actors responsible, methodology for catching these exploits ITW and targe…
-
comment
Comment #40574605
while beg bounty people can be annoying, you have to remember that people aren't obligated to sit down and find free bugs for any company (especially not a big one) - why would i s…
-
comment
Comment #37451421
Yup. You can just have your crafted webp (This is the patch for the ImageIO bug https://chromium.googlesource.com/webm/libwebp/+/902bc919033... ) image with the .png extension (ins…
-
comment
Comment #35196338
So I got a little bit of time to check ( https://github.com/Biktorgj/quectel_eg25_recovery/tree/EG25G... - the NON-HLOS), and it's still actually running a Qualcomm Hexagon baseban…
-
comment
Comment #35195759
I didn’t check, and on mobile now. But I would be very surprised if that was the actual baseband (more just a wrapper around it).
-
comment
Comment #35194547
Yep in most cases, but not always configured the best. Logic flaws seem the best way to go :)
-
comment
Comment #35194538
None use Linux, most just use BSD licence software (or things like openssl). I haven’t seen any GPL code at all tbh. But yep, would be nice if it was open source, although not sure…
-
comment
Comment #35192660
This is not true on pretty much any phone post 2014ish. Pretty much all platforms have IOMMU's or similar separation mechanisms. source: did baseband vr commercially
-
comment
Comment #35192647
Great work from P0 (and Keen lab). but this statement about baseband mitigations is only partially true. Huawei Balong platform has ASLR and stack canaries now (and some Infineon t…