"Yet is there hope. Time and tide flow wide."
… and your teenage daughter dubs you a Trad Husband 😂.
I’m doing something right here.
… and your teenage daughter dubs you a Trad Husband 😂.
I’m doing something right here.
It seems Apple have taken upon themselves to name my sourdough starter, and I now have a recurring reminder to "feed Dietrich." 🤌 🥐
It seems Apple have taken upon themselves to name my sourdough starter, and I now have a recurring reminder to "feed Dietrich." 🤌 🥐
scholars.org/contribution...
scholars.org/contribution...
Is there any other kind?
Is there any other kind?
The flaws are now patched. But they revealed powerful tracking abilities that Subaru employees can still access. www.wired.com/story/subaru...
The flaws are now patched. But they revealed powerful tracking abilities that Subaru employees can still access. www.wired.com/story/subaru...
This could dramatically reshape the future of web tracking and could have dire consequences on user privacy and your ability to stay safe online.
https://pvcy.org/YVOAFu
www.gutenberg.org/files/57532/...
www.gutenberg.org/files/57532/...
ubuntu.com/blog/tpm-bac...
ubuntu.com/blog/tpm-bac...
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
www.openwall.com/lists/oss-se...
It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…
Now I’m curious what it does in RSA_public_decrypt
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.