HNHacker News
TopNewBestAskShowJobs

roastedpeacock

168 karma · joined November 26, 2021

contact: $username @ protonmail.com

575C3ADAB97AD331CA41544ABBDE39538C0FDD59

submissionscomments
roastedpeacock··on Call for Participation to Chaos Computer Club’s 37C3
Wau Holland. Missed by those who never met him.

I too love a good talk on (e.x exploit research) and longingly wonder if in part due to attempts of censorship by companies, also the value of exploits if the 'glory times' of such presentations are over. Ultimately I respect the CCC for providing a platform to discuss difficult problems adjacent to technology as well.

roastedpeacock··on What can we learn from leaked Insyde's BIOS for Intel Alder Lake
> Individuals or organizations that are not eligible to sign CNDA with Intel, such as open source firmware maintainers. Please note that open source firmware projects cannot directly benefit/reuse from leaked content due to legal risks

This has probably occurred in certain communities but 'clean-room' documentation may have been written by third-parties from an understanding of non-public information and as long as the developer(s) nor the writers of said documentation were involved in any malice towards obtaining said information it is probably somewhat ok.

roastedpeacock··on The PS5 Has Been Jailbroken
Certain others can elaborate further but back during the tenure of the PS3 Sony did attempt to prosecute individuals for publishing research into exploiting it. So not entirely a joke/meme.
roastedpeacock··on WhatsApp Remote Code Execution in Video Call
No one remember how Telegram likes to reinvent the wheel with their encryption and raise subtle implications that Signal is magically backdoored?

For starters: https://nitter.net/durov/status/873870658874355713

roastedpeacock··on Patent Trolls Inbound: Our First Lawsuit
In prior history Hotz was targeted by Sony for his independent research into running homebrew applications on the PS3 game-console. Unfortunately Sony objected to this and launched legal action[1] against Hotz and others which sadly ended in Hotz settling to not research Sony products again and did not set a good precedent towards such work.

Different situation but hopefully better outcome this time...

[1] https://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Am...

roastedpeacock··on The hacking of Starlink terminals has begun
Repository is live now. Commit cbde04c9bc45ea54cc509a65247c62a82f64bca9

From README

> We are not providing exact glitch parameters. The presentation slides contain various hints and the parameters will vary depending on how you patch the firmware.

Some may see this as capitulation towards Starlink business interests but a more benign reason could involve the glitch parameters varying based on various hardware factors and as stated the execution of firmware as well.

roastedpeacock··on The hacking of Starlink terminals has begun
:-)

Might be better to encourage placeholder repository to avoid concerns from the public such as this but as long as the presenter ultimately controls the namespace it is not really at issue.

roastedpeacock··on The hacking of Starlink terminals has begun
Wondered that too but the presentation slides make no mention of anything related to SimpleLink. Than again there could be more under the hood than just what the slides themselves describe. Close but probably not a match.
roastedpeacock··on The hacking of Starlink terminals has begun
> looks like Starlinks legal dept got to the github repo first :(

If true than it was not through the normal DMCA process of GitHub that would result in a public[1] take-down notice being filed for transparency.

[1] https://github.com/github/dmca

roastedpeacock··on The hacking of Starlink terminals has begun
This WIRED article[1] references a release of tools and information about the research on GitHub[2] however it 404s. Hope that is not being censored.

[1] https://www.wired.com/story/starlink-internet-dish-hack/

[2] https://github.com/KULeuven-COSIC/Starlink-FI

roastedpeacock··on GitHub deleted accounts of people who contributed to Tornado Cash repos
DMCA and similar nonsense got forced to the rest of the world :-(
roastedpeacock··on Cory Doctorow on 20 years of Copyright Wars
In my opinion we took heavy causalities in 'the war' after WIPO and their friends manged to twist the arms of other countries in attempt to pass DMCA style laws with little public debate and minimal fair-use exemptions.
roastedpeacock··on Oracle Suspended My Account
Glad to see I am not the only one who gives pause to the recent aggressive marketing of Oracle Cloud services.

Oracle is the epitome of rug-pulls.

roastedpeacock··on Ask HN: Where have all the forums gone?
For an advocate for maintaining ones own 'sovereignty' by relying less on centralised services I think forums have been assimilated by modern social media (Facebook Groups, subreddits) and crude attempts by IM apps to emulate forum threads (Discord, Slack).

Fondly remember when those ad-filled 'free forum hosts' were shunned by anyone serious who would get a domain and private server instead. In some ways it feels like we are potentially back at the same situation but in reverse.

Considering traditional forum software like phpBB, vbulletin and similar largely look and work the same as they did 15 years ago not hard to see why some change is desired particularly with accessibility by mobile-users.

roastedpeacock··on Big Bird: killing SQL injection with graph homomorphisms
Also does PDO not fall back to 'emulating' prepared-statements by ultimately sending an interpolated query in certain circumstances with unknown implications?
roastedpeacock··on Playstation confirms chain of 5 vulnerabilities on PS4/PS5
Not saying public bug-bounty programs such as this are perfect. Those around a certain date in the past remember strongly when the situation with public research was more precarious and Sony attempting lawsuits, prosecutions and other utterly horrible attempts at 'damage-control' with the PS3. In that light and with the researcher being able to disclose his research after public security-patch it does appear more amicable.
roastedpeacock··on Proposed Freedom to Repair Act Seems Unlikely to Make Streaming Piracy Worse
Particularly interesting how the boogeyman fixate on 'streaming piracy' as a single evil.

IMO this 'design-by-committee' approach allowing individual acts that should already constitute fair-use to be maddening.

roastedpeacock··on Nintendo Nemesis Max Louarn: Hacker, Rebel, and Wanted by the FBI
Sure. Hang on a platform that logs everything to hell and back and can be disclosed at the drop of a hat. Nope.
roastedpeacock··on Nintendo Nemesis Max Louarn: Hacker, Rebel, and Wanted by the FBI
If you have to ask...
roastedpeacock··on Nintendo's big piracy case is a sad story
I said in a previous discussion

> Nintendo have had a conflicted stance about community projects over the years. From threatening UltraHLE (early Nintendo 64 emulator) developers back in the late 90s to largely ignoring the Wii exploits and homebrew scene in the mid-to-late 2000s to attempting to hire private investigators to identify and implicate 3DS homebrew developers in 'illegal' activities.

Ultimately I think if Xecuter did not have their product so closely intertwined with enablement of piracy and distribution of copyrighted content it would leave Nintendo less legal ammo to use against them and potentially make it not worth pursuing.

Important to note the RCM exploit only works for the first revision of Switch units. This does not justify other potential crimes Xecuter may have done but certain previous mod-chips for certain previous consoles have been open-source in a clean-room design not including copyrighted content by the original vendors thus potentially removing issues of copyright infringement. Sad the Switch scene could not be the same.

roastedpeacock··on I cut GTA Online loading times (2021)
Although a bit different rather sad seeing Take Two/Rockstar attempt to censor other fan projects through DMCA or lawsuits.
roastedpeacock··on First triangle ever rendered on an M1 Mac with a fully open-source driver
Exactly - https://github.com/AsahiLinux/m1n1
roastedpeacock··on First triangle ever rendered on an M1 Mac with a fully open-source driver
Perhaps releasing internal code or documentation is a mile of red-tape so some forward-thinking people are trying to do what they can to support the project while avoiding the above-mentioned issues.
roastedpeacock··on First triangle ever rendered on an M1 Mac with a fully open-source driver
Not an attorney but from what I understand in the traditional view of copyright it is often legal to reverse-engineer a proprietary system for integration with third-patty hardware/software if nothing copyrighted from the original product otherwise not licensed to you ends up the final third-party product.

Some people make a big deal out of reverse-engineering blobs through disassembly particularly for certain discrete components (e.g DSP or GPUs) but a) writing a set of clean-room specifications not containing any copyrighted information to use as a reference is a known task and often considered legal and b) m1n1 makes it in some cases easier to understand how the hardware is being used versus manual disassembly of blobs or drivers.

roastedpeacock··on Gitea – a painless self-hosted Git service
I am no Sinophobe but I think the pragmatic concern is by being under P.R.C jurisdiction 'certain parties' could either force abandonment of the project by (some of) the original team or compel certain code changes that may not be in the users interest.

No offense to anyone and do not want to imply anything nefarious is about but from what I remember Gogs was even worse in that only a single maintainer inside P.R.C had merge access to the main branch. Also a concern because I might remember something about known vulnerabilities having been outstanding on the issue-tracker when the maintainer was busy.

roastedpeacock··on Gitea – a painless self-hosted Git service
No fan of Discord but from what I remember the functionality is opt-in and if the webhook is not configured it does nothing.

Among all the possible things to get worked-up about this seems like nothing (unless you are purist that considers including optional functionality to interface with a proprietary-service to be harmful).

roastedpeacock··on Bernstein v. the U.S. Department of State (2014)
This wonders the question, what restrictions on including cryptography in either open-source or commercial products exist in the U.S today?

Bit of a different topic but I hope a landmark case tears down the DMCA nonsense in the U.S and other countries at some point.

roastedpeacock··on Security Vulnerability in Tor Browser
Anyone know how much the Tor Browser 'Safer' security-level mitigates real exploits? Among several things it disables the JavaScript JIT functionality which has been a known mechanism for exploits.
roastedpeacock··on Security Vulnerability in Tor Browser
It is an complex idea but in theory one could produce a live-image that spins up the Whonix 'gateway' and 'workstation' virtual-machines into RAM. Boom, probably better than Tails.

The most obvious concern is the RAM-usage (because of tmpfs and each VM having allocated RAM on top of that) and if disk-usage between the gateway and workstation images could be de-duplicated to save space in the live-image.

roastedpeacock··on The math prodigy whose hack upended DeFi won’t return funds
Am I missing something or did Medjedovic simply use unforeseen actions in the implementation of the contract as arbitrage and did not have an agreement to not attempt such actions?

Do not see any 'unauthorised access' in that case i.e not the classic definition of 'computer hacking'. However if the case does end up progressing I do wonder what form a defense will take.

← PreviousPage 2 of 4Next →