HNHacker News
TopNewBestAskShowJobs

OneLessThing

176 karma · joined December 8, 2014

submissionscomments
OneLessThing··on Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
1) ASLR: address space layout randomization 2) Yeah libc is commonly ropped against (though you'd need to check with a linux guy) 3) Yes ASLR is a compiler option (/DYANMICBASE for windows). For windows a flag exists in the PE header, probably something similar in ELFs. When loaded the modules are fixed up so pointers and such are correct.
OneLessThing··on Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
Total facepalm to this comment.

Does modern ASLR increase costs (time, difficulty, money, skill, etc.) necessary for exploitation and decrease benefits (privs, chances of success, etc.)? If yes, then it's a protection. Any security engineer will tell you unequivocally ASLR is a protection. And one of the most successful ones to date.

OneLessThing··on Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
I did security research on VLC on Windows a year or two ago. I may be remembering incorrectly, but last I recall every module was protected by ASLR. Which means that remote code execution is not likely because there is no scripting or network comms to dynamically create a valid ROP chain.

I also didn't check for executable heaps at the time but given that all heaps are non executable (which they really shouldn't be executable in VLC) again I don't see how RCE is possible. Maybe there is some way to validate and therefore brute force addresses? I don't know. But there was no VLC POC and I'm sure they would have made one if they could have.

Use VLC it's the most secure media player I've seen.

OneLessThing··on Ableton Live Developers at Work [video]
News organizations already do this, they're called ads. You have (in theory) a clearly defined content section that is (in theory) honest, and not biased or bribed. This section earns consumers trust in the news organizations brand and keeps eyeballs returning to their content. Then you have the advertising section that is 100% biased to those buying the space. News organizations have always been primarily an advertising business, getting eyes to ads.

The danger is letting companies influence sections that are believed to be objective and honest. One example of this is Michael Arrington the founder and former editor-in-chief of TechCrunch who is famous for investing in start-ups that his blogs would then cover. Not only that but he was partner in two investment funds during his tenure and now has his own fund, CrunchFund. All this to say that he has special interests in dozens of companies at any one time. When AOL bought TechCrunch they eventually let him go because in part of his conflicts of interest.

OneLessThing··on Please don't denigrate what a beginner is currently learning
That's the thing about teaching, it depends on the student.

For example, I wish someone told me to stay away from php when I began learning. My motivation was to become as effective as quickly as possible not just a casual learner or hobbyist. I wanted to hear the harsh criticisms and realities as quickly as possible because that's where the growth is. Of course feedback should not "denigrate" the beginner as the title says but giving the complicated, multifaceted truth early on may be desired rather than compartmentalizing and simplifying the reality.

See work on "expertise" by Ericsson and Hoffman (and others) for support of my argument.

← PreviousPage 2 of 2