239 karma · joined January 9, 2017
It is still shipped locked. Unlocking wipes the device.
It also doesn't work if your device is carrier locked.
For every "feature" provided by the SMM or bios.
Export a UUID ( eg NVME resume implementation1) Have that feature have an enable and disable function. Have each feature have a dependency on each iorange / firmware device it needs access to.
If the kernel know how to implement the feature it can just disable the feature and then as long as it follows the dependency tree and can see nothing else accesses those ranges. It can know that it has exclusive use. If it doesn't have exclusive use it must use the firmware to access those ranges if possible or fall back to no support
If the firmware has a feature without a disable function. The kernel knows it can never access that hardware directly/safely.
You could even have a "lock device" that if you take you know that SMM won't access those io ranges whilst you have the lock.
Obviously this all requires vendor support
Very common = greater than 1 in 10
Common = 1 in 100 to 1 in 10
Uncommon [formerly 'less commonly' in BNF publications] = 1 in 1000 to 1 in 100
Rare = 1 in 10 000 to 1 in 1000
Very rare = less than 1 in 10 000
Frequency not known = frequency is not defined by product literature or the side-effect has been reported from post-marketing surveillance data
[0] https://bnf.nice.org.uk/medicines-guidance/adverse-reactions...
[0] https://www.youtube.com/live/CSOF8RFrihM?feature=share&t=982...
[1] https://www.virginmedia.com/legal/fibre-optic-services-terms...
So all except n (netnod (EU)) and i (WIDE (JP))
The only code that isn't GPLv2 is the alloc crate. Which is basically a copy of upstream with some changes. All the kernel specific stuff is GPL
Most likely you would have to use .get() which returns an Option rather than [] array index which panics.
Quite a few schools have decided to use this warning to close as they are unable to manage heat on their premises [1]
[0] https://www.gov.uk/government/publications/phe-heatwave-mort...
[0] https://www.metoffice.gov.uk/about-us/press-office/news/weat... [1] https://www.metoffice.gov.uk/weather/learn-about/past-uk-wea...
Bad service isn't a reason for a refund. And if the person doesn't say "This debit was in error. I wasn't given notice" or similar the bank will usually say this is a legitimate direct debit [0] https://www.directdebit.co.uk/DirectDebitExplained/pages/dir...
Edit: For the purposes of the Networked Evil Maid Attacks. Mutual Authentication (of device and user) is currently the purpose of research. It has not needed to be implemented yet as the regular Evil Maid is still possible due to the fact that Secure Boot is currently the easier target to circumvent. Once Secure Boot becomes harder to circumvent and old "assumed" buggy kernels are revoked from running. Networked Evil Maid counter measures will need to be implemented as standard
Secure boot means that when you log in you can trust that the disk decryption screen is not a disk encryption key exfiltration screen waiting for you to enter your password so that a disk backup taken earlier can be decrypted.
How?
The disk encryption is based on a key in the TPM which only is decrypted with your password. That TPM gets wiped when you disable secure boot. The result is that when you enter your password either you get a correct decryption key or your disk encryption key has already been wiped. Assuming it's not possible to run untrusted code before the disk encryption key login screen with secure boot enabled.
kernel lockdown is part of the parcel for making sure that untrusted code does not run that can exfiltrate the disk decryption key.
Louis Rossman publicly asking Steve Wozniak to back right to repair because it's faster than finding someone in his social circle etc to pass the message
I do remember having loads of problems with RCS registration failing on the Samsung side, or just disabling itself.
Edit: Specifically I think it won't register whilst on WiFi and requires the correct mobile APN. I used to switch APNs to get a public IP address/ unfiltered internet
But I love that RCS has enabled cross carrier (For carriers supporting RCS) E2E messaging.
And the main benefit over iMessage is that there isn't the messaging blackhole problem when changing device.
Edit: And with HTTP having case-insensitive matching (which is most likely broken in lots of hand written implementations). This is rife with the possibility for errors
Taken from RFC 7230 3.2.4 Field parsing
Historically, HTTP has allowed field content with text in the
ISO-8859-1 charset [ISO-8859-1], supporting other charsets only
through use of [RFC2047] encoding. In practice, most HTTP header
field values use only a subset of the US-ASCII charset [USASCII].
Newly defined header fields SHOULD limit their field values to
US-ASCII octets. A recipient SHOULD treat other octets in field
content (obs-text) as opaque data.Edit: Actually I usually sent emails even when we did have a hard copy but no online access. Just because I couldn't be bothered to find the physical copy
I use acme.sh with dns, it just plonks a certificate in a directory of your choice and runs a reload command of your choice. I actually upload the certificate into a kubernetes cluster. All repeated by cron
The current ones will ignore the remember this site probably due to a stupid group policy.
Possibly forgets on logoff