Live data from Hacker News

Viewing profile — osy

osy

HN member
Joined
Wed, Jul 10, 2019, 3:42 PM UTC
HN karma
657
Public activity
83 items

About osy

No profile information was provided.

Recent public activity

  1. comment
    Comment #44481848

    STM32H7 is just an example. Most (all?) STM32 with has hardware SPI slave support. For example the STM32F030C8T6 is on JLCPCB as a basic part (no per-part cost for assembly) at $0.…

  2. comment
    Comment #43219659

    Until basic features like cloud backup/restore[1] works on GrapheneOS, they are irrelevant when talking about sophisticated targeted attacks. Your random journalist uncovering corr…

  3. comment
    Comment #42571278

    > I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new P…

  4. comment
    Comment #41999213

    All they did was release technical drawings for a proprietary connector they designed to interface with their products. That's not what "open source" means. They're not releasing a…

  5. comment
    Comment #41897587

    I've been shouting at the void for years ( https://gist.github.com/osy/45e612345376a65c56d0678834535166 ) about how TPM doesn't bring any practical security and was originally intr…

  6. story
  7. comment
    Comment #41284317

    I use this to stream my ROG Ally to my Vision Pro on long plane rides. The latency is crazy low.

  8. story
  9. comment
    Comment #40571570

    It's true that nobody is expected to balance a binary tree as part of the job but the point of these questions is to see how you approach the problem and how you communicate your s…

  10. comment
    Comment #40345478

    Yes, where did you think Meta get their idea from? It's the same as lying down mode and hand gestures...

  11. story
  12. comment
    Comment #39268718

    Yes really. The lack of any working implementation in production systems is an issue (D-RTM + encrypted sessions), something that Apple has done in an equivalent threat model since…

  13. comment
    Comment #39244718

    TPM is insecure against physical attacks by design: https://gist.github.com/osy/45e612345376a65c56d0678834535166 The only secure implementation is called D-RTM which requires a lev…

  14. comment
    Comment #38568441

    They are all denial of service bugs. I.e. crashes/hangs. No remote code execution or disclosure of sensitive data. Glad they were able to figure out the branding though.

  15. comment
    Comment #38405765

    The screenshot is (obviously) from a jailbroken phone. Currently nobody with a stock phone can reproduce it (through Console on a Mac with Developer Mode enabled) although you are …

  16. comment
    Comment #37437535

    Yes, when implemented correctly (I've never seen Google's implementation so I can't comment), D-RTM + Secure Boot is good. If Microsoft would give us this before shoving TPM down o…

  17. comment
    Comment #37437489

    The exact argument was made in the article > There are a plethora of attacks on TPM in the past but we need to be clear that a system that is widely attacked does not necessarily m…

  18. comment
    Comment #37437457

    This is not the way TPMs are used by most of the industry. For example, Microsoft and now Canonical are advertising it as a way to do FDE which Microsoft has known to be broken sin…

  19. comment
    Comment #37437393

    > This sounds like the rant of a typical Linux fanboy Hi, it's me the Linux fanboy whose entire personality is making Hackintosh and VM apps for iOS. Just a friendly reminder that …

  20. story
  21. comment
    Comment #36921901

    What’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized privileged access anywhe…

  22. story
  23. story
  24. story
  25. story
    Tell HN: Beware of Uber Eats Scam

    Proof and details here: https://twitter.com/DontStealMacOSY/status/1512491161751068673 In short, when there are no couriers available, Uber Eats will only show self-delivery restau…