(disclosure: I am the speaker)
193 karma · joined October 16, 2020
(disclosure: I am the speaker)
(but it probably won't ever happen, because banks are lobbying against it with FUD campaigns, they feel like it threatens their existence)
Wero is something completely different. It allows consumers to easily pay merchants, mostly online. The digital euro is not a payment network in the same sense as Visa, Mastercard, iDEAL and others.
We had to limit the scope of the project somewhere unfortunately, but it would have been nice to check Firecracker and Lambda as well.
[1] https://github.com/firecracker-microvm/firecracker/blob/main...
[1] https://media.ccc.de/v/39c3-spectre-in-the-real-world-leakin...
You can annotate your error enum with #[non_exhaustive], then it will not be a breaking change if you add a new variant. Effectively, you enforce that anybody doing a match on the enum must implement the "default" case, i.e. that nothing matches.
We've demonstrated our attack on real-world KVM-based cloud solutions. Both Google Cloud [1] and AWS [2] wrote a blog post in response to this attack, where they describe how they mitigate against L1TF Reloaded and how they harden their systems against unknown transient execution attacks. Google also decided to award us a bug bounty of $151,515, the highest bounty of their Cloud VRP yet.
PoC is available at https://github.com/ThijsRay/l1tf_reloaded
[1] this submission
[2] https://aws.amazon.com/blogs/security/ec2-defenses-against-l...
[1] https://bughunters.google.com/blog/5424842357473280/zen-and-...
The Binary and Malware Analysis course that you mentioned builds on top of the book "Practical Binary Analysis" by Dennis Andriesse, so you could grab a copy of that if you are interested.
> While FLOP has an actionable mitigation, implementing it requires patches from software vendors and cannot be done by users. Apple has communicated to us that they plan to address these issues in an upcoming security update, hence it is important to enable automatic updates and ensure that your devices are running the latest operating system and applications.
> Additionally, organizations may have their own billing information associated with the org itself. They can use this to sponsor the accounts of their members, allowing the billing for a tightly coupled group of users (e.g. staff members at a company or organization) to have access to centralized billing. Through this they can meet the 50% requirement without having individual members pay up.
Organizations can have centralized/simpler billing with this proposal
It currently shows major disruptions.
We chose for a test harness because one of our goals was to make it as easy as possible to run it on existing Rust projects. A lot of projects define tests, but benchmarks are not often not present. But maybe a bench harness would be a better and/or cleaner approach, will look into it!
I wanted to share this project I have been working on for the last year, Project MARCH! Project MARCH is a student team of the TU Delft that is involved in the development of a user-friendly and versatile exoskeleton, a motorized robotic suit, that can be used to get people with a spinal cord injury to stand up and walk again. Our team consists of 26 full-time volunteers that have spent the last year to design, program, and test a powered exoskeleton for our pilot.
After a few months of legal paperwork, we were finally able to make the software available under the GPLv3 open source license. We are investigating options to make the hardware open source as well! One of our goals is to investigate the possibilities of exoskeleton technology. Open sourcing our hard- and software allows others to learn from it and possiblity build their own exoskeleton, without having to spend years doing research.
You can watch a video of the previous iteration of our exoskeleton at https://www.youtube.com/watch?v=YilqnUZQIks&t=2010s This years iteration will be revealed on August 22nd! If you have any questions, don't hesitate to contact us at tech (at) projectmarch.nl