Live data from Hacker News

Anonymous GitHub account mass-dropping undisclosed 0-days

github.com

391–400 of 407 posts

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#391

Earlier quoted context omitted.

I'm more worried about AV software. Code that also needs to be able to parse a large number of file formats, opens every file that enters your computer through one of many pathways, and generally runs at a high privilege level. A huge attack surface that's easy to reach and with far reaching consequences if it can be exploited. Add to this that it's in wide use, often even mandated by corporate IT and its recipe for…

In theory the parsing could run at a low privilege level subprocess. Root/admin is only needed to get the bytes.

That’s generally too slow though; these things run in kernel space as they scan every I/O stream. Context switching and memory copies would kill performance.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#392
post #54
post #40

0-days-vibes-vulns ? There should be a new category, for spotting and handling the em-dashes of this brave new world of vulns and making the old fossils like me only picking my head up for the old painfully still hand-crafted artisanal ones instead. A kind of label, like free-range for eggs, in sum.

Yes, big pet peeve of the new world. Every em dash is apparently an AI trigger. Back in my day, they were a sign of great respect within my people.

To me em dashes have always just been an annoyance. For example, Word and OneNote were (and likely still are) very keen on converting every dash to an em-dash by default, and I frequently find myself needing to immediately undo that.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#393

Earlier quoted context omitted.

I'm more worried about AV software. Code that also needs to be able to parse a large number of file formats, opens every file that enters your computer through one of many pathways, and generally runs at a high privilege level. A huge attack surface that's easy to reach and with far reaching consequences if it can be exploited. Add to this that it's in wide use, often even mandated by corporate IT and its recipe for…

> I'm more worried about AV software Media codecs pretty much, single-handedly even, drove about a new era of defenses and mitigations in Android: https://blog.isosceles.com/the-legacy-of-stagefright / https://archive.vn/x3d0Y

AV as in antivirus, not audio/visual

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#394

Earlier quoted context omitted.

In theory the parsing could run at a low privilege level subprocess. Root/admin is only needed to get the bytes.

That’s generally too slow though; these things run in kernel space as they scan every I/O stream. Context switching and memory copies would kill performance.

https://i.imgur.com/t5jDXrt.png

"Why don't we unpack malware in the kernel" - "And so the search for intelligent life continues..."

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#396
post #346
post #264

Earlier quoted context omitted.

This is how it's always been. The law just produces another axis of strength that is easier to gatekeep.

Nope, it reduces the issue even if it isn't solving it entirely. Without laws and law enforcement, anyone with bigger muscles than you could break your nose just because they feel you looked at them the wrong way.

So? Anyone with a badge can wreck your life with zero consequences, even if they're a pipsqueak. Many of these individuals absolutely hate being looked at the wrong way.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#398

Earlier quoted context omitted.

How many victims are known to be exploited by video codecs? Compare that with the wider landscape of how victims are being exploited.

Codec vulnerabilities in the browser have been a recurring source of exploits, as have similar vulnerabilities in phone messenger apps. The phone ones are particularly bad because phones typically preprocess received media files (for thumbnailing etc) so a vulnerability here can sometimes be chained into a remotely triggered near-instant compromise. I don’t know if there is data on exploits due to downloaded media bu…

If said videos or media are doing that, there would be a corpus of samples by now. I'm very sceptical of this.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#399
post #151
post #97

Earlier quoted context omitted.

Kinda does?

Doesn't at all. You can take cash, keep cash and spend cash without any bank being involved. Cash is more anonymous than crypto and (if it's USD) accepted just about everywhere. Banks give you an advantage with transaction security and deposit insurance, but that's dealing with money and not cash.

I understand that it is different in the US, but most countries’ cash is printed by some kind of central bank.
Post reply on HN