Earlier quoted context omitted.
Diversity is a sign of health in an ecosystem. But, increasing diversity directly isn't really viable. Question is, why is diversity low? In my opinion, Web, OSes and CPUs suffer from being overly complicated, closed-source ridden, non-modular systems-within-systems. Basicly, the opposite of what the Unix philosophy advocates.
Diversity is low because of the massive amounts of capital Google has. Both in terms of money and power.
Hackers used zerodays to infect Windows, iOS, and Android users
71–80 of 156 posts
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#72Re: Hackers used zerodays to infect Windows, iOS, and Android users
#73Been playing with tools like angr lately and learning more about binary analysis. It seems to me that "automatic exploit generation" is improving quite a bit where the infrastructure for analysis is a little tricky to set up, but then you can direct that infrastructure to analyze the code for you. The bad guys and good guys are in a race to find new exploits faster (they always have been) but I've been pretty amazed…
>I might just go back to pen and paper at this point. Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago. You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That…
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#74Earlier quoted context omitted.
The reason why general computing sites don't recommend it is because users won't be happy when they can't sign into their bank or use other websites they wish to use. The average user doesn't know anything about how sites are constructed. Telling them to use uMatrix is non sensical. Though that's not to say there's good advice on these kinds of sites. I've seen a "Windows 10 tips" list from a very popular site tellin…
Yep Regarding Update/UAC Please blame microsoft. I don't want forced updates when I am working. And many time I have encountered issues like computer not booting. After updates they prompts "Please install our cool new software called edge". I want security update not the marketing update. So I make a compromise and disable update all together. Why not give linux style update where I can review each and every package…
Linux Distros are just bundles of software that make up the operating system.
So if your compromise is that you don't want new Windows 10 updates because they also bundle in new features rather than using an OS like linux, then it'd be your fault if you get hacked via an exploit that was patched in an update.
Microsoft aren't going to care.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#75Been playing with tools like angr lately and learning more about binary analysis. It seems to me that "automatic exploit generation" is improving quite a bit where the infrastructure for analysis is a little tricky to set up, but then you can direct that infrastructure to analyze the code for you. The bad guys and good guys are in a race to find new exploits faster (they always have been) but I've been pretty amazed…
>I might just go back to pen and paper at this point. Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago. You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That…
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#76>The importance of keeping apps and OSes up to date and avoiding suspicious websites still stands. Unfortunately, neither of those things would have helped the victims hacked by this unknown group. Disabling Javascript would have helped. You can even use tools like uMatrix to set exceptions per site so you're not exposing yourself to every single site on the internet by default. Though you won't see online news sites…
Yes uMatrix is crucial. But alas it has been discontinued as I understand.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#77Earlier quoted context omitted.
> Disabling Javascript would have helped Thank you for saying that. I'm one of first in 2005/2006 advocating JS rendering in the browser. JS in the browser has really gotten out of hand. I no longer advocate to do everything on the client/browser side. A web site should just work without JS.
Normal websites should absolutely, but actual webapps don't necessarily need to. Modern JS allows for very capable audio, video and 3d web applications inside the browser. The alternative if it wasn't for JS would be to build desktop apps, which would introduce a completely new set of problems and potential security risks.
For sure, audio, video do not need JS to function.
Yes you need JS for 3d webGL, but it also opened another can of worm that allows company to fingerprint GPU pretty much anyone who is not using Safari regardless if you are in incognito mode.
What most web developer don't realize browser was build to be a sandbox to protect you from the world wide web. Seems like the current trend is tear down that sandbox for usability and functions. Which is fine, then advertise that browser with JS enabled pretty much open you all that risk. It should be in the educational to the public as well as the first page of any browser that doesn't sandbox GPU finger printing.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#78If a PC is infected I can (and should) reinstall everything from scratch. That should remove the malware, barring some super resistant malware that hides in the BIOS or something like that. What do you do on an iOS device? Does a full device reset reinstall the OS, or does it simply remove all user settings? I feel like the locked down nature of iOS makes it harder to attack, but if an attack goes thru it would also…
A full reinstall of iOS--done by putting the device into DRU mode and then entirely re-imaging it over USB with iTunes from a firmware image--really does reinstall everything on the system that can possibly be changed by anyone (like, excepting code that is so fixed it isn't upgradeable even by Apple)... if anything you sometimes get some settings left around in awkward places for some of the lower-level components (…
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#79Earlier quoted context omitted.
I would not understand that you were using that to indicate sarcasm—I would think you were emphasizing the fact that they're experts. I also don't think that usage is in any style guide, so you're not going to see journalists doing it. On the other hand, using quotation marks to indicate sarcasm or irony is normal use and is in style guides. You just have to rely on context to differentiate. The headline of the linke…
I don't know why started using it but it's in wiktionary so everyone should (!) understand it: https://en.wiktionary.org/wiki/ (!) I don't know why started using it but it's in wiktionary so "everyone should" understand it: https://en.wiktionary.org/wiki/ (!) I guess, as you also mentioned, without enough context around it, both are hard to understand.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#80It's like being in the arms trade: what matters is who you decide to trade with.
Honestly, I'd rather see myself as anti-cyber-war at this point, like anti-war protests, meaning telling people to use computers for less critical tasks, and disengaging from certain areas.