48 karma · joined September 3, 2010
But the bug is real and people should patch :)
For the size: sometimes people will shove in kilobytes of offset tables or something into an exploit, so it'll fingerprint and then look up details to work. This is much smaller because it doesn't need any of that, which is important for severity. (I agree the "golf" nature is a bit of an aside, kind of like pwn2own exploits taking "10 seconds")
I think GEONET (the Japanese data source) might have some NTRIP casters. Also some in Korea and elsewhere. Sometimes you have to pay for access though, so I need to look more.
I'm glad folks are looking at it, and enjoying it! If you have questions or anything let me know! :)
Yeah, we had a detector with some ML stuff, it worked okay, but the main issue is there isn't much training data.
Overall the false positives are quite low (visually, which is hand wavey, of course). I've not really seen a big event that was not real. I ran it for a while 24/7 and while there are "scintillations" there aren't any circular waves. False negatives are a much bigger issue. Something like an IRBM or SRBM doesn't really show up, and those are much more common.
Fwiw, this uses a bandpass filter to look for the ripples, which filters out a ton of noise. Looking at ionospheric depletion would be good and probably more sensitive, but it requires accurate models of what the ionosphere ought to do. I've tried a few things there with mixed results.
Some folks asked, so I also uploaded the source for the challenges in the videos: https://github.com/ForAllSecure/c2c-rapidfire-challenges
There has also recently been a published timing attack regarding elliptic curve signatures, and there are some older papers about AES's vulnerability to timing attacks due to cache misses when using S-boxes. So while this paper specifically isn't a viable attack today, it is still relevant.