(¥) you might have to figure out some details
(¥) you might have to figure out some details
Unfortunately not for anyone who has activated the auto-update feature on his/her Xbox, as the latest system software version seems to include a higher kernel version than supported by the collateral-damage exploit.
> No action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware.
I guess Microsoft could argue their entire operating system business, app store, and update infrastructure are intentionally negligent, and so not covered.
I’d think a reasonable court would say that it’s working as designed, and therefore not covered by the carve out.
We could easily go back to installing firmware on-disc or in-download and only calling it at runtime. We won't because devs are in a desperate and futile campaign to outrun console modding (and to some extent piracy) they can't control. With consoles moving to common PC hardware rather than custom hardware like Flipper or Cell they're just going to get broken into faster and faster, so the only bet is harsher and harsher DRM on the software side. AMD straight up sold PlayStation 5 defects as the AMD 4700S "all in one" board.
6.61 from January 2015[1].
[1] https://www.psdevwiki.com/psp/index.php?title=Official_Firmw...
I want to be the only cheater in my lobby.
Can you manually modify the system clock? If so you could roll the calendar back every 3-6 months.
If it's working right now, an update can only cause it to break. The best case scenario is that it still works. Why would your roll the dice?
There's a timing argument - that unless you're at risk of zero days (like you're the DOD) - that you probably don't need to upgrade immediately. But it seems unarguable to me that the longer you wait, the greater the risk from a security perspective.
As always, security is a trade off. Risk of breaking from an update has to be balanced against risk of exploit. I'd argue the latter is going up more quickly than the former.
on a more serious note though I don't think machines with ipv6 enabled that are behind a NAT are likely to be vulnerable to this, i suppose maybe wormable if you can natpunch through some p2p voip or gaming service, it's the sort of patch i would probably install if i were made aware of it (if i had ipv6 enabled), but being made aware of it doesn't like, leave me worried, and i don't consider it to be likely to affect me unpatched
Would you be interested in educate yourself about IPv6?
I suspect it's because I don't use many common software packages so the attack surface is small-ish.
Agree in general that people wildly overestimate the risk leaving things alone. e.g. nginx hasn't had a security advisory affecting basic http 1.1 serving static content without TLS in many years. And of course desktops are behind stateful firewalls.
I only let my browser autoupdate (somewhat reluctantly) since I view that as the most likely security issue on my winpc but when I used to let win10 autoupdate (and other garbage dell drivers), things would start breaking after each update
this also applies to phone app updates - I only update if there's a reason to, not just for the sake of updating...
and people wonder why I have the best working phone and pc at the office...
Boxes get popped all the time. Why are you painting such a dishonest picture?
> and people wonder why I have the best working phone and pc at the office...
Probably because you know about computers. Nothing to do with your poor security practice.
And this still doesn’t say anything about the explicitly absolutist advice in the parent comment. “No matter the circumstance, turn auto-update off! Just in case you want to partake in some piracy!”
IME knowing about computers is what causes auto-update to break things. Because you actually rely on the kind of things that it would break.
[1]: Borrowing syntax from Markdown.
Is that a common usage /auf Deutsch/? Such use is listed on the Wikipedia page, but it's a use I don't ever recall having seen before.
§ is a bit less common but iirc used in some legal texts. It's also easy to use on ANSI German keyboards with shift+3.
Especially on sites like this one, which have no previews.