I can FINALLY announce the news! I have been awarded a British Academy small grant!!
This work will be on safeguarding knowledge about floppy disks! The project will include working with @dpc_chat @JennyMitcham @anj on gathering floppy disk information in one place. But will also include interviewing floppy disk experts across communities and cleaning floppy disks with different techniques with the conservation department at the Cambridge University Library!!
Finished the #FSWA training by @stevenseeley and found something cooler than calc.exe to pop: The almost 30 years old dialer.exe. And yes, it's on PATH
In March 2019, I broke a story about how Facebook had been storing unencrypted password data for hundreds of millions of Facebook users.
Today, the lead European Union privacy regulator fined Meta ~$100 million for that security/privacy failure, which Facebook said could have allowed any one of its 200,000 employees to see the plaintext passwords for up to 600M accounts.
“Do we need to worry about cups?”
“No we’ve got a handle on it”
OpenPrinting/CUPS project decided to publish my related-but-different finding (in code that is about to all go away) https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq86-c7g6-r2h8
Some soft skills insight I gathered over my long career as a security researcher and shitposter:
Thanks for following my Ted speech
#Ghidra 11.2 released
Documentation links with HTML preview (generated links point to raw repo contents):
https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_11.2_build
Thunderbird for Android is coming soon! Find out how to get involved, from beta testing to localization to support and more, in our shiny new contributor guide!
(Seriously, by soon, we mean soon!)
#Thunderbird #Android #OpenSource
https://blog.thunderbird.net/2024/09/contribute-to-thunderbird-for-android/
Mark Zuckerberg says the individual work of most creators isn’t valuable enough for it to matter. First of all, FUCK you, Mark. Another billionaire thinks an artist's work, such as images/art, books, music, text, and other things, has no value. People can't even browse IG or FB without downloading your shity app. Why don't you allow everyone to scrap those IG/FB posts? This guy is a menace to society and doesn't care if someone will lose their livelihood so that he can have another 100 billion.
Unath RCE in CUPS which triggers after a print job - affects most desktop linux flavors https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
Hackers showed me (there's video) how a website vulnerability let them locate, unlock, honk the horn, start ignition of any of millions Kias in seconds, just by reading a car's license plate.
They found similar bugs for a dozen carmakers over the last two years.
https://www.wired.com/story/kia-web-vulnerability-vehicle-hack-track/
I am teaching a course on Linux kernel exploitation, and I mentioned the indeterminism of the objects in the physmap to the class. An example I showed is the struct task_struct of the first process, systemd. Even with KASLR disabled, that address will always differ on every boot. I said the CPU is fundamentally indeterministic, but my answer is too vague. I will read the Linux kernel initialization code to see if I discover anything interesting. Still, I would appreciate it if someone could give me a more detailed answer or point me in the right direction.
(gdb) p/x init_task->tasks->next
$76 = 0xffff888005028890
(gdb)
(gdb) p/x init_task->tasks->next
$77 = 0xffff88800502bb90
(gdb)
(gdb) p/x init_task->tasks->next
$79 = 0xffff88800502d510
(gdb)
A jockey who is paralyzed from the waist down lost his ability to walk after a small battery for his $100,000 exoskeleton broke and the manufacturer refused to fix it because it was more than 5 years old
Greetings, cool people. The Internet Archive is having our yearly celebration event in October. The announcement and the link to getting tickets to attend are here:
https://blog.archive.org/2024/08/19/celebrate-with-the-internet-archive-on-october-22nd-23rd/