The slides for the #radare2 #ai presentation made by @pancake are now public! Check them out while they are still hot! https://github.com/radareorg/radare2-extras/blob/master/r2ai/local/r2ai.pdf
"Risky Biz News: China admits NSA hacked Huawei
In other news: iOS zero-days used to hack Egyptian presidential candidate; new Sandman APT targets telcos across the world; Russia's largest travel agency breached by pro-Ukraine hackers."
https://riskybiznews.substack.com/p/china-says-nsa-hacked-huawei
How about a Friday WIP video? Metal Gear for the MD/Genesis. #metalgear #genesis #megadrive
#libwebp 1.3.2 has two #security related flaws that have been fixed in main:
• Fix invalid incremental decoding check:
https://github.com/webmproject/libwebp/commit/95ea5226c870449522240ccff26f0b006037c520
• Fix next is invalid pointer when WebPSafeMalloc fails:
https://github.com/webmproject/libwebp/commit/dce8397fec159c9edfeec7c6388cb81428c87ed8
While these are not as easy to exploit as CVE-2023-4863 it seems evident that there has been some gaps in libwebp fuzzing at google. Also CVE-2023-4863 was obviously assigned to a wrong project. #infosec #vulnerabilities #cve
Need to know whether a piece of hardware is supported by free software? #hNode has you covered! Its search engine will help you verify #freesoftware compatibility. https://u.fsf.org/3uj
100MHz FM transmitter from 1982, 25 Watts that we used for 3 months of non-licensed radio broadcast. A few coils in power amplifier are missing, and 2N6081/2N6082 (wrong marking) replaced the very expensive original BLY87/BLY89 (~$80-100 for a pair in those days!).
A while ago I tested #nostr and all i found was cryptobros and porn. Today it seems like the porn issue is under control and the feed seems nicer.
Clients got significant UI improvements, but still it feels a bit dangerous to post on a place where data spreads beyond author's control.
I managed to remove notes i published. But in theory all devs say this is UB. Considering there are tons of relays replicating and caching data, some users may still see it.
About this privacy topic it makes me think about the fact that we are not aware enough about all the data we give away and the false feeling of controlling it. Maybe being anonymous instead of having your real persona in this network is the way to go.. but still, i have mixed feelings with this interesting technology (yeah i like the protocol and it's simplicity)
Thoughs?
Live in 115 minutes...
"Unidentified Anomalous Phenomena Independent Study Report"
https://www.youtube.com/watch?v=idJKLP5hcuQ
"Risky Biz News: Malware found on Rust's Crates repository"
https://riskybiznews.substack.com/p/malware-found-on-rust-package-repository
Spent some time implementing a cheap-ass custom ring bus for CoreScore that I have had in my head for a long time now.
Resource usage improved a bit and P&R time was 20% shorter on the midrange FPGAs I tried. Will be very interesting to see how much this affects the highest CoreScore where P&R times can be 48h right now. I suspect both time and resource savings will be more significant on larger devices
Today's threads (a thread)
Inside: The Sacklers woulda gotten away with it if it wasn't for those darned meddling feds; and more!
Archived at: https://pluralistic.net/2023/08/11/justice-delayed/
1/
"Intel DOWNFALL: New Vulnerability Affecting AVX2/AVX-512 With Big Performance Implications" https://downfall.page/
"Latest updates on Flat_z’s PS5 Exploit chain" https://wololo.net/2023/07/29/latest-updates-on-flat_zs-ps5-exploit/
-"When the going gets weird, the weird turn pro..."