No matter how much you want it, you can't use a clever definition of "cloud native" to pretend that you compete with the AWS/Azure/Google stack. And please don't try to fool people with a wonky definition, it will backfire eventually. "There is no cloud just other people's computers" means you don't understand what modern developers are doing with clouds. https://berthub.eu/articles/posts/the-european-cloud-ladder/
Activity spinning up on GitHub for people playing with the bug, but also at least a few possibly vulnerable code bases:
The author of the blog post mentioned in my previous post initially predicted KEV but then reconsidered. I suspect they're right but it will it will depend on if any big commercial J2EE is vulnerable as deployed on TomCat. To that end, the following from the VMware folks looked interesting:
"Record labels attempt to bankrupt Internet Archive over grandpa's dusty old 78s"
We hope that the inter-relations between Huawei's lobby office in Brussels and the offices in key EU member states like Germany are taken into account in the ongoing corruption and bribery investigations, too. For market access in Europe, Berlin is a key lobby hot spot for chinese tech. #HuaweiGate
honggfuzz alive and kicking. stack based buffer overflow in libxml2 - https://issues.oss-fuzz.com/issues/392687022
I remember in the mid ‘90s, Bill Gates said something like ‘if the car industry had improved at the same rate as the computer industry, cars would go at a thousand miles per hour and get thousands of miles per gallon’ and someone at a car manufacturer replied that their customers are quite glad that the cars don’t crash several times a day.
I am starting to wonder if Tesla is an elaborate piece of performance art in support of this joke.
"the real question is if we can convince European governments and Europeans to innovate for their continued survival as a free and (climate) safe continent" - no pressure people.
My slides from today's talk about Static Program Analysis. I go into how data flow analysis (like taint propagation in CodeQL) works from first principles - should be digestible with some first-year university maths knowledge
Hey hey, you thought there be no #nakeddiefriday today? Here we go!
Today's entry is an Infineon/Siemens SAB-C167CR-LM, a microcontroller based on the C166 core. The die is in pleasant-looking pastel colours. :-) The die has pin 1 in top left corner. I'll do a short thread.
Many thanks to @debauer for supplying the samples!
SiPron page with more info and full-res map: https://siliconpr0n.org/archive/doku.php?id=infosecdj:infineon:sab-c167cr-lm
Less than 30 minutes until our 5.0 live stream! Join us to see all the latest features either on dev now or coming very soon:
https://www.youtube.com/@vector35/live
Kernel Shared Cache, Unions, Stack Array Creation, and so much more...
🧟♂️ Finding dead bodies
A pad about find dead code using code coverage tools.
It was made by one of us for a talk at the rev.ng hour of some years ago.
More effort than required was put in the image but the results was undoubtedly great.