HNHacker News
TopNewBestAskShowJobs

shaded-enmity

149 karma · joined August 20, 2017

submissionscomments
shaded-enmity··on Amsterdam looks incredibly realistic in the new Call of Duty
Yeah, it's much, MUCH different to have those vistas unfold in front of your eyes at smooth 144 fps while you have control over the movement and everything compared to hyperanalizing 1 still frame or a sequence of frames with no real control.
shaded-enmity··on Packed structs in Zig make bit/flag sets trivial
The nice thing about this is that it's simple and works pretty much in any language so there's very little cognitive strain if you work with multiple languages at the same time.
shaded-enmity··on Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild
From your link:

> securelevel may no longer be lowered except by init

> The list of securelevel's effects may not be comprehensive.

So yes, it's a nice sandbox that can help prevent accidents, but doesn't sound like something you should rely on for actual defense.

shaded-enmity··on Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild
Aye, I think what you're describing is "security by obscurity" - i.e. the capability is still there, I'm just counting on the attacker not knowing that it is because I've hidden it so well. It can work really well in combination with actual security practices, but it absolutely shouldn't be considered one.
shaded-enmity··on Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild
> I believe the concern is that the attackers gain root access on system A but hide their presence/activity - even in the presence of logs to remote, more trusted server B.

That's generally called pivoting and has nothing to do with method of persistence of the malicious code.

OP makes a point that certain systems move or have moved away from giving root user the ability to extend/modify kernel code at runtime via kernel modules, my argument is that none of that matters since root user can still extend/modify kernel code at runtime via binary patching.

shaded-enmity··on Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found in the wild
How is the vector of persistence of any significance here? At some point the attackers got root access on your system, game over.
shaded-enmity··on New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
Turns out (1) works:

  #include <stdio.h>
  #include <stdlib.h>

  static void begin() __attribute__((constructor));

  void begin() {
    unsetenv("LD_PRELOAD");
  }
Build with:

  gcc -shared -fpie -o library.so library.c
Test:

  LD_PRELOAD=~/library.so env | grep LD_PRELOAD
shaded-enmity··on New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
This is a nice summary: https://lcamtuf.blogspot.com/2014/10/psa-dont-run-strings-on...
shaded-enmity··on New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
1. Can't the process just scrub LD_PRELOAD from its environment? Linker already done it's job at that point.

2. I'd suggest against using `strings` (let alone with sudo) on attacker controlled inputs

shaded-enmity··on EU reaches deal to make USB-C a common charger for most electronic devices
No it's not fine, this is just another coercion and consolidation of power where it shouldn't belong. Independent entities cannot innovate on their own because now there's a central apparatus that decides what should be innovated and how, with all the inherent political power struggles of big players, good luck.

EU should be there to set goals, not to dictate implementation.

shaded-enmity··on splice() and the ghost of set_fs()
You still need to implement a CI rule so that I don't just call `set_fs()` without using `preferred_syntax(set_fs)`, don't you?
shaded-enmity··on splice() and the ghost of set_fs()
A simple policy that both set_fs() calls need to happen within the same function body with corresponding CI test based on AST/DWARF inspection would have also prevented it. Do you really want to rely on stack unwinding/destructors for security sensitive code when stack is usually the first thing that gets controlled by the attacker? Exception handling (SEH) on Windows is an exploitation vector of it's own.
shaded-enmity··on Puzzling quantum scenario appears not to conserve energy
I'm no physicist either, I just like to ask questions :)

How does the demon attain the knowledge of what is "fast" and "slow" without continuous observation (and thus interaction) with the particles. Velocity is just function of position over time, so the demon needs at least 2 samples to make the most basic approximation. Where is the entropy for doing that coming from? How does the interference of the measuring apparatus factor into the whole process - what if the sole act of measurement changes the state of the particle from "fast" to "slow" or vice versa? Do we need to measure twice? But what if the second measurement causes the transition it was meant to detect?

shaded-enmity··on Puzzling quantum scenario appears not to conserve energy
How do you build a mechanism that has a perfect knowledge about a system while being part of said system?
shaded-enmity··on Software Mise En Place
This all depends how much product are you expected to produce. Your "don't chop things beforehand" works if you're cooking for 1 or 2, but if you need to cook for 4+ you absolutely need to plan your steps and prepare your ingredients so that you merely combine them. This is evermore important if you want to have some sufficiently consistent level of quality, which I suppose is implied.
shaded-enmity··on Persepolis of ancient Persia rendered in WebGL
This looks amazing but I'd appreciate an autoplay button or free walk + look, the scrollwheel monorail handcranking makes the exploration rather frustrating.
shaded-enmity··on Pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)
I haven't touched this in a long time, but isn't the attack vector essentially the same as in Vortex lvl 4? https://overthewire.org/wargames/vortex/vortex4.html
shaded-enmity··on Antigravity.py (2020)
Defense in depth would disagree that it is fine. I'm pretty sure this vulnerability can go much further if you combine it with, for example, the `https_proxy` environment variable.
shaded-enmity··on Plasma Kinetics May Revolutionize Hydrogen Storage for EVs
Probably because you'd need a battery to store the energy generated via braking thus eliminating much of the environmental benefit.
shaded-enmity··on Physicists identify the engine powering black hole energy beams
My crazy pet theory: computational bandwidth is constant for any spacetime coordinate. According to Bekenstein bound the lower the temperature of the system the cheaper it is to flip a bit of information. As time progresses the CMBR gets colder, so it's cheaper to flip a bit, but conversely, as time progresses our Hubble volume gets smaller, limiting our total available energy budget to perform a bit flip.
shaded-enmity··on Show HN: Redbean – Single-file distributable web server
If you want to learn more how these things work I'd highly suggest going through the PoC||GTFO archive (https://github.com/angea/pocorgtfo/blob/master/README.md) and check out entries by Ange Albertini or entries named like "This ZIP is also a PDF".
shaded-enmity··on Podman: A Daemonless Container Engine
In Docker each container process is a child of the Docker daemon process. If you need to apply security patches to the Docker daemon it kills all your running containers.
shaded-enmity··on Python’s tug of war between beginner-friendly and advanced features
Both examples look unreadable to me. Just because you can do a lot on a single line doesn't mean you should.

    all_members = ", ".join(members)
    all_scores = ", ".join(map(str, scores))
    print(f'{id:<5} {all_members:<50} {all_scores:<30}')
shaded-enmity··on CD Projekt Conference Call with the Management Board [pdf] (Dec 14)
Not really, I'm going to give the worst example of all - Star Citizen (aka Scope Creep The Video Game) - which was IIRC crowdfunded, and according to the wiki page below remains the most expensive game in terms of development cost.

https://en.wikipedia.org/wiki/List_of_most_expensive_video_g...

shaded-enmity··on The Black Hole information loss problem is unsolvable
So is this survivorship bias or something else? I don't understand your point. I have a white wall in front of me. If I take a brush and red paint and paint a big red circle on the wall, are you saying that the big red circle "just happens to be there" with no relationship to the brush, red paint and my actions?
shaded-enmity··on The Black Hole information loss problem is unsolvable
I'm confused, isn't the whole schtick around past events being related to future events the basis of causality?
shaded-enmity··on Dockerfile Security Best Practices
If you upgrade your packages during a build then inadvertently if 2 people build your Dockerfile at two distinct times they can end up with 2 different images. So rather than focusing on "we're using base-image:1.0.2" you need to start asking questions like "list all packages and versions and start comparing those".

If there's a security issue you need to rebuild your images anyway and optimally you have a system in place that represents images and their dependencies as some sort of dependency graph structure, so when you upgrade your base image all dependent images get rebuilt automatically.

shaded-enmity··on Room-Temperature Superconductivity Achieved for the First Time
I think you meant "very low resistance" or "very high conductivity", right?
shaded-enmity··on We learn faster when we aren’t told what choices to make
How much are you willing to pay for those answers? What you're describing sounds similar to interactive courses and 1:1 couching.
shaded-enmity··on Postgresqlco.nf: a PostgreSQL configuration guide
Amazing work, I wish every service was covered like this!

Some feedback/things I'd like to see (or not see):

- Make the Comments section collapsible, right now it takes 1/4 of the screen

- Filtering by categories is kinda confusing, since filters affect both the left sidebar as well as the main view I'd expect the filtering UI to sit on top of both

- Better visibility/categorization for parameters that can only be set via command line

Page 1 of 2Next →