HNHacker News
TopNewBestAskShowJobs

Harvesterify

846 karma · joined March 21, 2020

Infosec engineer.
submissionscomments
Harvesterify··on Waymo CEO explains why Tesla’s camera-only self-driving falls short
He did not say that Tesla made the LiDAR afforadable though.
Harvesterify··on Infomaniak transitions to a foundation model to protect user data privacy
Migrated my email servers in 20 minutes yesterday from OVH (their MXs does not support IPv6, and Infomaniak was less expensive for basic email hosting), I found the documentation and the diagnostic tools of the DNS zone very clear, was a no brainer to add DKIM, SPF and DMARC (hey generate the records for you, just have to cpy paste in your zone manager and refresh the diagnostic to get a status after propagation), and autodiscovery and autoconfiguration of email clients are a nice bonus !

Overall a great experience, can recommend !

Harvesterify··on IBM Plunges After Anthropic's Latest Update Takes on COBOL
Did you read the last sentence ?
Harvesterify··on Linux Capabilities Revisited
That's totally true, you actually have examples of unsafe capabilities delegation in the other article mentioned in the References: https://juggernaut-sec.com/capabilities/
Harvesterify··on Dns0.eu private DNS service shuts down over sustainability issues
DNS0 was launched at a time when no other EU public DNS resolver was available. Today, you have DNS4EU that is actively funded and pushed throughout the EU administration (and critical infrastructures), so I believe that the DNS0/NextDNS founders saw that there was very little differenciating factors to their proposal, and decided to shut it down.

Had they "captured" a larger marketshare in the EU while they were ahead, situation might have been different today, but in my opinion it never happened.

Harvesterify··on Dns0.eu private DNS service shuts down over sustainability issues
Which public funds ? DNS0.eu was a private initiative, from the NextDNS founders. DNS4EU is a public initiative, as mentioned in the news, and this one is still supported and actively developed.
Harvesterify··on Anssi: Technical Position Paper on Confidential Computing
Highlight:

"However, Confidential Computing is not secure enough to protect data integrity and confidentiality against a hostile administrator performing targeted, active attacks. Under such a threat model, users must avoid running on shared infrastructure operated by providers they cannot trust, and are rather encouraged to leverage Confidential Computing to increase their security posture on dedicated hardware instead."

Harvesterify··on Battering RAM – Low-cost interposer attacks on confidential computing
In their current form, AMD and Intel proposals never fulfilled the Confidential Computing promises, one can hope they will do better in their next iteration of SGX/TDX/SEV, but they were always broken, by design.
Harvesterify··on Battering RAM – Low-cost interposer attacks on confidential computing
Security theater, mostly.
Harvesterify··on Inflammation now predicts heart disease more strongly than cholesterol
Unrelated to the topic, but does anyone know if an equivalent service (à-la-carte blood testing with online booking) is available in Europe, specifically the Netherlands (or France) ?
Harvesterify··on Rethinking the Linux cloud stack for confidential VMs
Exploited in the wild, difficult to say, but there has been numerous vulnerabilities reported on underlying technologies used for confidential computing (Intel SGX, AMD SEV, Intel TDX, for example) and quite a good amount of external research and publications on the topic.

The threat model for these technologies can also sometimes be sketchy (lack of side channel protection for Intel SGX, lack of integrity verification for AMD SEV, for example)

Harvesterify··on Rethinking the Linux cloud stack for confidential VMs
I'd recommend anyone interested in Confidential Computing to read the work from Rodrigo Branco (@BSDaemon) to understand why it's mostly a failure and a PR stunt from cloud providers to give the illusion that the customer stays in control, while at the same time the hardware capabilities CC is built upon are unsecure (and can't be fixed by firmware or microcode update, most of the time).

For example, a direct link to his keynote slides from ESA 3S conference last year (PDF): https://indico.esa.int/event/528/attachments/5988/10212/Keyn...

Harvesterify··on Control shopping cart wheels with your phone (2021)
As a french living in the Netherlands, the first time I saw this behavior was in the US (SF and LA), it just never happens here, or very marginally.
Harvesterify··on Passkeys are just passwords that require a password manager
Push notifications are vulnerable to MFA fatigue/"bombing" attacks, that are used in the real world, cf. this breach on Uber:

https://www.darkreading.com/cyberattacks-data-breaches/uber-...

Harvesterify··on Secure boot certificate rollover is real but probably won't hurt you
The rotation is not related to the UEFI capability to check/enforce the expiration, but the capability to sign future shim/OpROMs/drivers/bootloaders.
Harvesterify··on Graphene OS: a security-enhanced Android build
For those who don't want to root the phone, you can still avoid most of the ads by using a filtering DNS server with the Private DNS functionality on stock Android ROMs (or only at browser level if your favorite browser support DNS over HTTPS).

It comes with some minor usability issues with captive Wifi portals sometimes, but the trade-off of not having ads in app or while browsing is way worth it IMHO.

Harvesterify··on Building JetClock – a clock that shows the passing planes
This is incredibly cool!
Harvesterify··on EU gives staff 'burner phones, laptops' for US visits
The initial report was denied though: https://x.com/lorenzofb/status/1911829523659653137
Harvesterify··on Microsoft reports several bootloader vulnerabilities
Did you read the OP link ? They go in far more details than just presenting what they did with AI, and they actually found several exploitable vulnerabilities, not just with AI, but with other techniques such as code analyzing or fuzzing.

AI is in he title, but the content is not entirely revolving around it.

Harvesterify··on Xiaofeng Wang
This is related to Trusted Computing on ARM platforms, i.e. what is cited related to Distributed Confidential Computing.

https://chromium.googlesource.com/chromiumos/third_party/arm...

Harvesterify··on Colorful cars are becoming a thing of the past
Posted right at the time of the release of the Renault 5, sold with the default color Iconic Yellow, and available in Green Pop (also very flashy)... :)
Harvesterify··on How fast should you accelerate your kid in math?
Read it the same way.
Harvesterify··on Project Everest: Probably secure communication software
"Probably" ! You did that on purpose, right ? :)
Harvesterify··on Breaking BIOS: enabling VT-x virtualization support on Acer Aspire One netbook
I'm guessing Intel Boot Guard is enabled and provisionned with Dell keys, but it's just a guess.
Harvesterify··on CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
Without more infos on the initial infection vector, it's difficult to assess the impact of those mitigations (Secure Boot, Secure Launch and Trusted Boot). Qutoing from the report:

"Looking at the various firmware images we were able to obtain, we assess that the modifications may have been performed with an automated patcher. If so, it would follow that the attackers had prior access to the victim’s computer in order to extract, modify and overwrite the motherboard’s firmware. This could be achieved through a precursor malware implant already deployed on the computer or physical access"

While Secure Boot + BitLocker with TPM and PIN would have prevented an Evil Maid attack (at least would have triggered a PCR change and a Windows Recovery prompt), a preliminary infection (I understand by it a supply chain attack before it reaches the user for the first time, but maybe I'm extrapolating a bit what the report is saying) would have stayed undetected in most scenarios (depending on how Intel Boot Guard is configured).

Regarding the Linux part, ANSSI did a pretty great job with their CLIP OS implementation: https://docs.clip-os.org/clipos/boot_integrity.html, but it's really "for the masses" :(

Harvesterify··on The Dangers of Microsoft Pluton
For now (and I haven't seen an annoucement of a coming change about it), only trustlets signed by Microsoft can be executed in the VSM (Virtual Secure Mode), so you won't be able to write a malware or a rootkit that leverages it to hide the execution flow.
Harvesterify··on CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
You can use the Dell Trusted Agent to to do just that:

https://www.dell.com/support/kbdoc/en-us/000126098/what-is-d...

Harvesterify··on DNS-over-HTTP/3 in Android
But in that case, you will not benefit of DoH3, it's limited to Cloudflare and Google servers right now.
Harvesterify··on DNS-over-HTTP/3 in Android
Apparently it is not possible for the moment to specify a custom suffix to the complete URL of a DoH server (for example, with a AdGuard server, I cannot append a client identifier such as dns.contoso.com/dns-query/my-client, while dns.contoso.com is working fine).

Will stick to DoT for the moment :)

EDIT : ok so only 'dns.google' or 'cloudflare-dns.com' are supported right now, other domains are still using DoT. Pretty useless feature then :(

Harvesterify··on Responsible stewardship of the UEFI Secure Boot ecosystem
Previous discussion: https://news.ycombinator.com/item?id=32023868
Page 1 of 2Next →