Viewing profile — osy
osy
HN member- Joined
- Wed, Jul 10, 2019, 3:42 PM UTC
- HN karma
- 657
- Public activity
- 83 items
- HN profile
- View on Hacker News ↗
About osy
No profile information was provided.
Recent public activity
-
comment
Comment #44481848
STM32H7 is just an example. Most (all?) STM32 with has hardware SPI slave support. For example the STM32F030C8T6 is on JLCPCB as a basic part (no per-part cost for assembly) at $0.…
-
comment
Comment #43219659
Until basic features like cloud backup/restore[1] works on GrapheneOS, they are irrelevant when talking about sophisticated targeted attacks. Your random journalist uncovering corr…
-
comment
Comment #42571278
> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new P…
-
comment
Comment #41999213
All they did was release technical drawings for a proprietary connector they designed to interface with their products. That's not what "open source" means. They're not releasing a…
-
comment
Comment #41897587
I've been shouting at the void for years ( https://gist.github.com/osy/45e612345376a65c56d0678834535166 ) about how TPM doesn't bring any practical security and was originally intr…
- story
-
comment
Comment #41284317
I use this to stream my ROG Ally to my Vision Pro on long plane rides. The latency is crazy low.
- story
-
comment
Comment #40571570
It's true that nobody is expected to balance a binary tree as part of the job but the point of these questions is to see how you approach the problem and how you communicate your s…
-
comment
Comment #40345478
Yes, where did you think Meta get their idea from? It's the same as lying down mode and hand gestures...
- story
-
comment
Comment #39268718
Yes really. The lack of any working implementation in production systems is an issue (D-RTM + encrypted sessions), something that Apple has done in an equivalent threat model since…
-
comment
Comment #39244718
TPM is insecure against physical attacks by design: https://gist.github.com/osy/45e612345376a65c56d0678834535166 The only secure implementation is called D-RTM which requires a lev…
-
comment
Comment #38568441
They are all denial of service bugs. I.e. crashes/hangs. No remote code execution or disclosure of sensitive data. Glad they were able to figure out the branding though.
-
comment
Comment #38405765
The screenshot is (obviously) from a jailbroken phone. Currently nobody with a stock phone can reproduce it (through Console on a Mac with Developer Mode enabled) although you are …
-
comment
Comment #37437535
Yes, when implemented correctly (I've never seen Google's implementation so I can't comment), D-RTM + Secure Boot is good. If Microsoft would give us this before shoving TPM down o…
-
comment
Comment #37437489
The exact argument was made in the article > There are a plethora of attacks on TPM in the past but we need to be clear that a system that is widely attacked does not necessarily m…
-
comment
Comment #37437457
This is not the way TPMs are used by most of the industry. For example, Microsoft and now Canonical are advertising it as a way to do FDE which Microsoft has known to be broken sin…
-
comment
Comment #37437393
> This sounds like the rant of a typical Linux fanboy Hi, it's me the Linux fanboy whose entire personality is making Hackintosh and VM apps for iOS. Just a friendly reminder that …
- story
-
comment
Comment #36921901
What’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized privileged access anywhe…
- story
- story
- story
-
story
Tell HN: Beware of Uber Eats Scam
Proof and details here: https://twitter.com/DontStealMacOSY/status/1512491161751068673 In short, when there are no couriers available, Uber Eats will only show self-delivery restau…