588 karma · joined July 7, 2013
https://www.twitter.com/srcmapy
"As a proof-of-concept, JavaScript code was written that, when run in the Google Chrome browser, allows JavaScript to read private memory from the process in which it runs (cf. Listing 2). "
That looks like is the current limit of javascript base attack. It doesn't seem to be able to access system resources nor execute system command script (yet....).
That kind of JS attack vector likely can be mitigated with web browser update.
For home computer, standard office use, there is no impact at this point, right?
I play with Framework 7 https://framework7.io/ and it looks very nice.
Any other suggestions?
Specially if one can capture some of cool Linux KDE GL special effects.
Looks great! 4k video streaming from Youtube works very good.
4 x 1080 Tiled windows - perfect for productivities.
I don't do gaming. The latency is less of an issue for me.
FB definitively know a lot folks' "political leaning" base everyone's "likes" in global scale and has profit from the info in the last elections.
I also wonder how much of the speed up is due to the GPU parallelization vs the DB size seem to fit within the size of DDR4.
" 0.005 0.011 0.103 0.188 BrytlytDB 2.1 & 5-node IBM Minsky cluster" NVME
"1.034 3.058 5.354 12.748 ClickHouse, Intel Core i5 4670K" SSD
The core i5 system only has 16GB of RAM. I love to see what that number would looks like if it also has 512GB or more of DDR4 with NVME drive.Also one can also try increase to data size from 1.1 B -> 1000B and see how it scale on Minsky cluster.
The powershell's syntax is just too esoteric for me. I did tried that a few times.
I still can't run those command under Windows Subsystem for Linux.
Virtual Keyboard Developer Leaked 31M Client Records (mackeepersecurity.com)
Apple is sharing your facial wireframe with apps (washingtonpost.com)In Linux, I can easily monitor how much data, what kind of data are transferred to the remote IP and disable them on per apps base anytime I want.
In IOS, I can't do any of that. At most, I can only disable an app from using cell data. If anyone else know how to do monitor/block network connection on per APP base in IOS, I would love to hear about it.
For me, it is a different between "trust" and "trust and verify".
I use IOS and have some level of trust on Apple/IOS. But I don't trust majorities of the IOS APPs for security/privacy.
Programming Language Advocates love language wars
Most programmers just like to be aware of ALL the PROs and CONs of the languages and choose the right one for the task at hand.
I used to work on embedded systems where I have full control of uboot. With that, I can easily reserve the section of memory in boot uboot and Linux kernel when the keys logging info (such as FTRACE of ISR, sched switches etc) from kernel are kept.
When a kernel panic happens, the system will go thru the warmboot sequence and detected there are logging info in that section of DDR and dump it out before continue to boot.
This "postmortem debugging features" make debugging certain category of very difficult bugs (kernel driver panic) much easier.
With typical close source x86 bios in Linux laptop, it is very hard to enable this kind of debugging.
@jackpot51 system76 folks -
Are your systems currently using opensource boot bios? If not, any plan to do so in near future?
It would be very cool if they can be anonymized and some data scientists graph them out like this page.
If you don't know Calculus, Physics, you can be a very good construction workers but hard to know the fundamental behind why/how the Buildings, Cars, Airplanes, are designed that ways.
Same for C, if you don't know C. You can certainly a very good program Python, java script, web developers, but might not have deep understand of Kernel, Browser, Database, Network, nor why Java, Go and Rust need all those new language features.
Know how the tools are different will help you to choose the best tool for the jobs.
It is very fun to play with a full screen MacOS on a touch screen enable Laptop.
1) Use SystemInternal's process explorer and track all network connections: (As admin: Add column to track the network tx, rx counts)
https://docs.microsoft.com/en-us/sysinternals/downloads/proc...
2) When I see some app, system that connect to network which I think it should not. I just block their network connections with Windows Firewall or uninstall those app.
There is a "netsh advfirewall firewall" command that can do this from command line.
3) BTW this works very well with Windows' own service too. I block svchost.exe, Edge, SerchIndex, etc from accessing internet. svchost.exe is allowed to access local subnet for file, print sharing. When I feel like upgrade to to latest version windows 10. I turn off the firewall rules for a few hours to allow the update to go thru.
4) Only Firefox and Chrome in my windows system are allowed to connect to internet full time. The CPU usage is normally < 15% and most of the time < 10% even when playing youtube @ 1080 resolution.
The latest Firefox Quantum has less CPU usage and faster also. I love it.
5) The WSL (Windows Subsystem for Linux) is getting better - X, xfce4-termnial now working good enough for me. I like accessing the Ubuntu shell in windows environment without the overhead of Virtualbox.It kind of prove Linux kernel is not mono-culture and natural selection and evolution are happening.
I believe the AOSP's kernel patches are also not mainlined - also proof Linux kernel are evolving very healthily.
Need to monitor/hack the computer when the users think it is "power off", Do it in ME.
Need to add other "features" to the system in the future, Do it in ME.
Firefox's servo engine can compose CSS elements/Display List together at 500 frames / second.
Maybe next version of Windows / Linux desktop should use FF's servo engine?
Show Apple why they need to release better Mac Desktop/Laptop HW or risk loss the heart and mind of next generation of developers.
If so, the comparable code base to check against is Android AOSP, Ubuntu, RedHat or FreeBSD.
If that is true, I believe the source code base for Ubuntu/RedHat distribution with all the Apps likely be bigger compare to Windows in term of number files, source repo and number of engineers (open source developers for all the packages such as ff, chrome openoffice.)
Microsoft folks feel free to correct me here.
It seems that the existing git's process, dev model seems to work well for much bigger projects already by using different git repo for each apps.
Still not sure what pain point does the new GVFS solve.....
That would be a fun thing to to do.
Anyone know what kind of potential regulatory/FDA issue will this kind of apps have?
Anyone has estimated the impact of this on crypto currency or crypto wallet system?
It would be interesting to see how many if any of the public keys use n crypto currency systems are potentially impacted by this type of hack.
I recently debugged packet issues after 100gbps port speed change to 25gbps, to 10 gbps issues. Breakdown the issue to sub-system components - check phy, mac loopback, check link status on both side of the QSFP connections before and after speed changes, check counters (A LOT of them), enable debug packet to send to CPU with special command. Check all the VLAN, port settings, configuration commands over and over again. Enable debugging on kernel driver to track down every bytes/bits of every packet. Use tcpudmp on linux socket layer when one gets to that point.
Instead of oscilloscope, today's SOC does have a lot of counters inside that help one identifies issues.
For complex issue, one does get tremendous high when the issue was ID and resolved.