Black box data (speed, steering+pedal input logs) were invaluable in determining fault in an accident involving one of my family members recently. As long as the data doesn't leave the car under normal circumstances, what's the harm?
809 karma · joined September 1, 2020
Black box data (speed, steering+pedal input logs) were invaluable in determining fault in an accident involving one of my family members recently. As long as the data doesn't leave the car under normal circumstances, what's the harm?
1. https://www.darpa.mil/program/assured-micropatching
2. https://www.iarpa.gov/newsroom/article/annotated-malicious-b...
3. https://www.darpa.mil/program/recovery-of-symbolic-mathemati...
To partially answer GP's question:
Unofficial major kernel updates have happened in the past. OnePlus 6T, for example, shipped with 4.9.x, but supports mainline on pmOS.
".://" is a particularly egregious example. (and, by the same principle, "evil.com://good.com")
- Python 3.6's urllib.parse sees the "." as the URL's scheme, and an empty authority.
- Python 3.11's urllib.parse sees the entire ".://" as the URL's path.
- urllib3.util.parse_urlsees the "." as the URL's hostname, the ":" as the separator for an empty port number, and the "//" as the path. (this is one of the most downloaded packages on PyPI)
- Boost::URL rejects the URL outright.
If you're going by RFC 3986, then only Boost::URL is exhibiting the correct behavior. If you're going by the WHATWG URL standard, then I don't know which one of these behaviors (if any) is correct.
If you're interested in collaborating on this project, please send me email. My address is in the footer at https://kallus.org
Until recently, LiteSpeed parsed Content-Length values using strtoll in the base-0 mode. Thus, by sending Content-Length values prefixed with 0, you can get it to interpret the value in base-8. Most HTTP proxy servers strip leading 0s from Content-Lengths, rendering the bug in LiteSpeed not exploitable. Until recently, HAProxy didn't do this, which made HAProxy + LiteSpeed vulnerable to request smuggling.
I put together a PoC demonstrating how this can be used to bypass any HAProxy ACL with default configurations for HAProxy (except the added ACL) and LiteSpeed.
Clearly, LiteSpeed is more responsible for this problem than HAProxy, but the bug in LiteSpeed violates HAProxy's security model, not its own.
We need (at least)
- A clear policy from the CNAs that describes exactly which bugs should be assigned CVEs.
- A process by which bogus CVEs can be invalidated, and CVE spammers can be banned from further submissions.
- A way to register CVEs for vulnerabilities that span multiple programs.
- e.g. an HTTP proxy has a low-risk bug, and an HTTP server has a low-risk bug, but when the proxy and the server are deployed together, the bugs become exploitable.
- An appeals process for CVE description updates. - e.g. You would not know from the description that CVE-2023-34188 is trivially exploitable and can reliably lock up vulnerable servers because MITRE refuses to update it.I'm still trying to figure out if I'll fly out to Columbus for OLF this year. I went last year and the year before. It's worth the travel to me, but I have a flexible schedule. The talks are good, but the people are the real reason to go. A lot of the people who go to these conferences work on really interesting stuff. There are of course also big names like maddog and Doug McIlroy.
One is through constructs like Clojure's `take-while`. Instead of setting a vairable when you want to exit the loop, you define a predicate that is false when the loop should exit.
Another is through `any` and `all` (aka `some` and `every`), which work in a similar way to `take-while`, except they reduce OR or AND across the returned values from the predicate as they go.
EDIT: grammar and clarity
https://github.com/aio-libs/aiohttp/issues/7312 https://github.com/nodejs/premature-disclosures/issues/4
You might also consider taking a proof-based course in linear algebra.
I don't know who still makes decent printers today -- I see a lot of people recommend Brother -- but why buy new when there are tons of cheap old laser printers from the days before they all became anti-consumer garbage?
Also, I think bath salts is usually synthetic cathinones, i.e. functional analogues of khat, and not derivatives of meth, cocaine, ecstasy, or pcp.
Could be wrong, I'm just some guy on the internet.
See https://www.foxnews.com/us/medical-examiner-rules-out-bath-s... and https://en.m.wikipedia.org/wiki/Miami_cannibal_attack
When I increased the slider that allows you to change the flow of time for the gas in the cube, it really looked like visualizations I've seen of increasing the temperature of a gas. Is there a deeper relationship here? Could an observer tell the difference between a cube $A$ of gas in which the flow rate of time were doubled and a cube $B$ of gas with normal time passage, but a correspondingly increased temperature? If so, what would give it away?
"We will continue to support Manifest v2 to the extent that we can"
"Brave's adblocker (Brave Shields) is not an extension, and is natively implemented. So, it will be totally unaffected."
Source: https://www.reddit.com/r/brave_browser/comments/rdab12/how_w...