Regarding the last section, is 40k a reasonable price for one month of security analysis? Does this mean that a good security researcher make about 500k/yr?
Compromising OpenWrt Supply Chain
11–20 of 105 posts
Re: Compromising OpenWrt Supply Chain
#12That's why open source can never compete with business grade closed source stuff: - they fixed the in 3 hours instead of making customers wait 6 months for a patch (if any) - they did not try to sue the reporter of the issue - they did not even tell the users to throw away the "outdated" but perfectly working devices, offering a small discount to buy new
Re: Compromising OpenWrt Supply Chain
#13First of all, nice writeup. I am a bit surprised that so much GPU power was needed to find such short collision but it was nice to see his implementation nevertheless. Regarding the last section, is 40k a reasonable price for one month of security analysis? Does this mean that a good security researcher make about 500k/yr?
Re: Compromising OpenWrt Supply Chain
#14Re: Compromising OpenWrt Supply Chain
#15First of all, nice writeup. I am a bit surprised that so much GPU power was needed to find such short collision but it was nice to see his implementation nevertheless. Regarding the last section, is 40k a reasonable price for one month of security analysis? Does this mean that a good security researcher make about 500k/yr?
Re: Compromising OpenWrt Supply Chain
#16Loving this. I wonder how people even come up with an idea of truncating hashes. For what purpose or benefit?
Re: Compromising OpenWrt Supply Chain
#17Loving this. I wonder how people even come up with an idea of truncating hashes. For what purpose or benefit?
Re: Compromising OpenWrt Supply Chain
#18Loving this. I wonder how people even come up with an idea of truncating hashes. For what purpose or benefit?
when you upgrade from sha1 to sha256 but you don't want to change your data format for storing the integrity checks / keys.
Re: Compromising OpenWrt Supply Chain
#19Re: Compromising OpenWrt Supply Chain
#20First of all, nice writeup. I am a bit surprised that so much GPU power was needed to find such short collision but it was nice to see his implementation nevertheless. Regarding the last section, is 40k a reasonable price for one month of security analysis? Does this mean that a good security researcher make about 500k/yr?