353 karma · joined December 15, 2023
That said, this is absolutely going to be changing now. We obviously can't keep relying on tarballs anymore. We'll find a new normal that will work for a very long time until some other critical issue arises and the cycle repeats.
I'm a tad reminded of https://xkcd.com/705/
We got so lucky here. We won't get lucky every time. We will have a massive breach one of these days.
I would bet dollars to donuts that they lost a lot more than the replacement cost would have been.
Wow, the drive manufacturer's warranty most certainly wouldn't apply. There was no fault with the drives at all.
Very poor look for EVGA.
Plus all the secrets in the Secure Enclave are immune to this attack, so your FileVault keys and your Apple Pay cards and all that jazz are completely safe.
It sucks that it exists, and crypto libraries that run on the platform outside of the Secure Enclave will get slightly slower, but no one will notice.
https://support.apple.com/guide/security/secure-enclave-sec5...
Take for example a program that attempts to calculate the https://en.m.wikipedia.org/wiki/Collatz_conjecture
Some inputs would rapidly get answered. Most won’t. If you can prove it’s halt-able for all inputs, you’ve won a Nobel and will be well off for life.
Good luck.
https://old.reddit.com/r/openSUSE/comments/1biunsl/hacked_in... has the smoking gun
> That all said, this is a plasmoid that was written for KDE 5. Maybe some interaction with KDE6 lead to the issue? One issue that could have happened is that property string configPath <SNIP> now uses another StandardPaths.standardLocations due to KDE6. This could lead to configPath looking like somepath / (note the space), which expands to sh save.sh somepath / ..., which will happily remove everything. The whole situation reminds me of the Steam uninstaller, where a single space had some remarkable results.
Spot usage could make a decent profit in addition to training anything they want.
I’m gonna email them asking to reconsider the projects name.