Posts
2577
Following
629
Followers
1407
"I'm interested in all kinds of astronomy."
Is there a reason why #Rust is so minimalist with keywords? For example the `if let` syntax is completely unreadable to me.

Also, things like `&_` make googling for errors practically impossible.
1
0
7
In case if anyone is looking for them, #38c3 streams are here:

https://streaming.media.ccc.de/38c3
0
4
7
repeated

In 50 minutes I’ll present some awesome hardware hacking on Apple’s new USB-C controller at - would love to see you there!

2
5
0
repeated

Remark concerning #8243:

We would do well to remember the names of the pilots who died.

They fought for over an hour with a mortally wounded plane to get it as good as possible to the ground.

They had now yaw, no rudder, no ailerons, no flaps, only the power level of the engine as means of control.

Air Traffic Control denied them the use of the closest airports and sent them to cross a sea.

What they have shown is courage in the face of insurmountable odds. They knew exactly what their chances were. Their airmanship was on the highest possible level.

Their names are Igor Kshnyakin and Aleksandr Kalyaninov.

To the media: please don’t give any airtime to the obviously disinformation spreading speaker of the Kremlin and report about those who saved 29 lives.

6
16
0
repeated

TIL that with a linker script, you can have emojis as ELF section names.

I need an opportunity to use this knowledge.

1
3
0
repeated

Picard management tip: Take your leisure time seriously. A relaxed captain is a sane captain.

0
3
0
repeated

Here's a no-cost, non-denominational, last-minute gift idea.

Reach out to people who made a positive difference in your life but with whom you have not been in touch for a while. Tell them that they were a force for good in your life. Thank them.

Be generous -- pass on this idea. Spread some joy.

1
20
0
repeated

One the twelfth day of Christmas, the true goat gave to thee: https://infosec.press/screaminggoat/patch-tuesday , which is a list of vendors' security advisory landing pages and their schedule.

Disclaimer: Not every vendor is listed, and their patching cycle may be different than what I categorized them as, but it's a good starting point. Ideally, you'd be tracking the ones you care about using RSS anyway.

Merry Christmas Infosec Mastodon

3
7
0
[RSS] A design flaw in the Windows 3D Pipes screen saver pointed out by a customer

https://devblogs.microsoft.com/oldnewthing/20241224-00/?p=110675
0
0
1
[RSS] An Initial Analysis of Adobe ColdFusion CVE-2024-53961

https://www.hoyahaxa.com/2024/12/an-initial-analysis-of-cve-2024-53961.html
0
2
0
[RSS] ghidralib - A Pythonic Ghidra standard library

https://github.com/msm-code/ghidralib

#Ghidra
0
1
3
[RSS] A functionally complete decompilation of LEGO Island (1997)

https://github.com/isledecomp/isle
0
0
1
[RSS] Starship, Star Fox 64 recompilation project

https://github.com/HarbourMasters/Starship
0
0
0
OK, this is my summary for today

#Rust
1
0
9
repeated

Hewlett Packard report that they are spotting AI-generated malware in the wild, not through complex analysis or watermarking, but because… it is weirdly well-commented. https://threatresearch.ext.hp.com/wp-content/uploads/2024/09/HP_Wolf_Security_Threat_Insights_Report_September_2024.pdf

2
10
0
I'm at about third of the 100 #Rust exercises and I think we just got to the "Draw the rest of the fucking owl" part 🖊
0
1
13
I find CVE-2024-40896 (Raptor/libxml2 XXE) very educational:

Based on the analysis[1] it's a nice example of Chesterton’s Fence[2], while its discovery[3] underlines the importance of automated testing for regressions and known dangerous behavior.

[1] https://www.openwall.com/lists/oss-security/2024/12/25/2 (thx @alexandreborges for sharing!)
[2] https://fs.blog/chestertons-fence/
[3] https://gitlab.gnome.org/GNOME/libxml2/-/issues/761
0
2
5
repeated
Show older