The author is a physicist. Looks like he just decided to publish about his C++ code.
292 karma · joined March 20, 2019
The author is a physicist. Looks like he just decided to publish about his C++ code.
How have you been? Are you still in the Bellevue/Redmond area?
Thanks for the laugh! :)
About a week ago this topic was widely in the news under variations of the title:
"DARPA and NASA Scientists Accidentally Create Warp Bubble"
That's the context of my response here in this thread. I am not sure if everyone reading this thread knows that. The new title "No, we didn't accidentally create a warp bubble" was the NASA engineer attempting to fix the misinformation generated by the journalists.
Absolutely agree with you about physics journalism. I enjoy science fiction books too, I have no problem with the theoretical FTL topic.
It makes me sad to think that I contribute to this process. I have to admit... that I probably do read alot of those clickbait articles giving them more views.
It makes me even more sad when I think about the platforms that are removing the ability to downvote incorrect/misleading information.
I think journalism is getting worse as the years go by. Like everybody else I noticed the title and clicked on it a few days ago. Reading the paper revealed that the team was simply interpreting/speculating what the math was showing about some hypothetical energy density structures.
Of course the sensationalized title propagated all over the net ignoring the facts.
Small world, I worked with you on the Windows Update team. Hope you are doing well. Good to see you here on the HN forum. I also remember the notepad incident!
Actually you can use the Windows Projected File System to project the registry into the file system, making registry keys and values appear as files and directories.
https://github.com/Microsoft/Windows-classic-samples/tree/ma...
That's not the only discrepancy.
https://pubs.opengroup.org/onlinepubs/9699919799/functions/m...
Note the following: "The memccpy() function does not check for the overflow of the receiving memory area." "If copying takes place between objects that overlap, the behavior is undefined."
The strxcpy he provides at the bottom doesn't look better at all. I'm not sure where the author got that function. I found some better variants of the proposed strxcpy function with bounds checks and that provides overflow detection.
I looked at both patches and didn't like either one of them. The user 'manfred-kaiser' makes a good point and I have confirmed that he is correct. However the fix he is proposing is not a very good fix. So in my opinion both of the proposed fixes are not sufficient.
The proposed fix: https://github.com/openssh/openssh-portable/commit/b3855ff05...
This proposed fix means OpenSSH is not secure 'by default' and would require HostKeyAlgorithms to be set in the config file. Furthermore... there needs to be an existing public key. Also keep in mind that SSHD refuses to use group/world-accessible keys.
So if this patch is accepted CVE-2020-14145 will continue to work on 'misconfigured' servers.
"It's not our fault, your OpenSSH was misconfigured!"
Maybe by forming it as a question he is inviting someone to verify or revise that number.
Yeah, there are newer ROP mitigations coming down the pipeline, I agree verifiable execution flow remains a major problem.
That seems a bit harsh. There is a certain beauty in the geometry equations Weinstein presented. I find it interesting that EFE, Yang-Mills and Dirac emerge from that. He certainly hasn't shown a complete theory of everything but I wouldn't say that it doesn't have any merit.
If I had one criticism of Weinstein it would be that he's never put anything down on paper for anyone to deeply review.
Windows Defender actively interferes with security software development. I've noticed that lots of developers either disable Windows Defender or try to whitelist the development folders. Whitelisting doesn't always work... Windows Defender will block certain behaviors such as token stealing and in-memory attacks.
Also... software developers often have 'test-signing' enabled and all kinds of other security risks that are unique to software development.
It's amusing that you actually believe that you can 'check the logs' to detect all DoH being performed on the machine. Would you be willing to disclose your employer? "I can check the logs" sounds like something a naive systems administrator would say.
I'm glad that 'security' is your thing. The best thing about the internet is that you never know who you are talking to... Even when you meet people that wrote the parts of the operating system you're currently using.
Why even comment on things that you don't fully understand?
Someone will probably respond with something like: "Just block the IP address ranges of public DoH resolvers" and that would work for the resolvers we know about.
There are dozens of ether-types that are not standardized. There is also 0x8899 which is Realtek Remote Control Protocol (RRCP)
https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protoco...
There are many more but I don't remember them off the top of my head. I probably need more coffee.
Looks like ethertype 0x8300 is covered in this Chinese patent titled "Access-network looped network monitoring method" https://patents.google.com/patent/CN102263658B/en
Chinese version: https://patentimages.storage.googleapis.com/a3/f8/5e/8a9fcd4...
The lens in the human eye is continuously doing Fourier transforms via the lens:
https://en.wikipedia.org/wiki/Fourier_optics#Fourier_transfo...
Does anyone know if those games come with the manual? In the 1980's DRM was implemented something like "What is the third word in paragraph 3 on page 14 of the manual?" I see several games in there that I remember having this type of protection.
Seamus Blackley worked on the hardware team and is primarily remembered for developing the XBox controller. I didn't work with him but I am a former XBox team member.
I am fairly certain that this does exist, I remember almost purchasing a spectroscopy adapter for my iPhone way back around 2014. I didn't buy it and I guess it wasn't too popular.