Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
osy
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
osy
1y ago
STM32H7 is just an example. Most (all?) STM32 with has hardware SPI slave support. For example the STM32F030C8T6 is on JLCPCB as a basic part (no per-part cost for assembly) at $0.82 while the RP2040 is $1.11. While the RP2040 and RP2350 ha
2.
▲
by
osy
2y ago
Until basic features like cloud backup/restore[1] works on GrapheneOS, they are irrelevant when talking about sophisticated targeted attacks. Your random journalist uncovering corruption in Saudi Arabia doesn't have the time to fi
3.
▲
by
osy
2y ago
> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value fo
4.
▲
by
osy
2y ago
All they did was release technical drawings for a proprietary connector they designed to interface with their products. That's not what "open source" means. They're not releasing any schematics for their products. This i
5.
▲
by
osy
2y ago
I've been shouting at the void for years ( https://gist.github.com/osy/45e612345376a65c56d0678834535166 ) about how TPM doesn't bring any practical security and was originally introduced for DRM then repurposed
6.
▲
ROG Ally Community Rebuilds the Proprietary Asus EGPU
(hackaday.com)
2 points
by
osy
2y ago
|
0 comments
7.
▲
by
osy
2y ago
I use this to stream my ROG Ally to my Vision Pro on long plane rides. The latency is crazy low.
8.
▲
An open source eGPU for the proprietary XGM connector
(github.com)
2 points
by
osy
2y ago
|
0 comments
9.
▲
by
osy
2y ago
It's true that nobody is expected to balance a binary tree as part of the job but the point of these questions is to see how you approach the problem and how you communicate your solution. Given that you can't perfectly predict ho
10.
▲
by
osy
2y ago
Yes, where did you think Meta get their idea from? It's the same as lying down mode and hand gestures...
11.
▲
Apple Vision Pro and ROG Ally: Portable console gaming setup guide
(gist.github.com)
2 points
by
osy
3y ago
|
0 comments
12.
▲
by
osy
3y ago
Yes really. The lack of any working implementation in production systems is an issue (D-RTM + encrypted sessions), something that Apple has done in an equivalent threat model since the iPhone 11. You can argue that "insecure by design&
13.
▲
by
osy
3y ago
TPM is insecure against physical attacks by design: https://gist.github.com/osy/45e612345376a65c56d0678834535166 The only secure implementation is called D-RTM which requires a level of chip, OEM, and OS support that&#
14.
▲
by
osy
3y ago
They are all denial of service bugs. I.e. crashes/hangs. No remote code execution or disclosure of sensitive data. Glad they were able to figure out the branding though.
15.
▲
by
osy
3y ago
The screenshot is (obviously) from a jailbroken phone. Currently nobody with a stock phone can reproduce it (through Console on a Mac with Developer Mode enabled) although you are free to try it and test for yourself. This is just another s
16.
▲
by
osy
3y ago
Yes, when implemented correctly (I've never seen Google's implementation so I can't comment), D-RTM + Secure Boot is good. If Microsoft would give us this before shoving TPM down our throats, it would be good :) But they have
17.
▲
by
osy
3y ago
The exact argument was made in the article > There are a plethora of attacks on TPM in the past but we need to be clear that a system that is widely attacked does not necessarily mean it is fundamentally insecure but only that there are
18.
▲
by
osy
3y ago
This is not the way TPMs are used by most of the industry. For example, Microsoft and now Canonical are advertising it as a way to do FDE which Microsoft has known to be broken since 2006. They are requiring it for Windows 11 because of &qu
19.
▲
by
osy
3y ago
> This sounds like the rant of a typical Linux fanboy Hi, it's me the Linux fanboy whose entire personality is making Hackintosh and VM apps for iOS. Just a friendly reminder that attacks on the author's credentials have no bar
20.
▲
TPM provides zero practical security
(gist.github.com)
76 points
by
osy
3y ago
|
108 comments
21.
▲
by
osy
3y ago
What’s the threat model of TPM? They claim it’s for “physical attacks” but they can only enforce it when there is no software vulnerability or unauthorized privileged access anywhere so it’s a very small area of the Venn diagram where you h
22.
▲
PSA: Cropped/censored images from Pixel phones can leak details from original
(twitter.com)
7 points
by
osy
4y ago
|
0 comments
23.
▲
Show HN: Windows 10 running fully virtualized on M1 iPad Pro
(twitter.com)
2 points
by
osy
4y ago
|
0 comments
24.
▲
Show HN: Content caching for GitHub actions local runner with Squid Proxy
(gist.github.com)
1 points
by
osy
4y ago
|
0 comments
25.
▲
Tell HN: Beware of Uber Eats Scam
11 points
by
osy
4y ago
|
0 comments
26.
▲
by
osy
4y ago
Does it support searching regex expressions in all files in a directory as well as all open files?
27.
▲
by
osy
5y ago
Shameless plug for my soon to be outdated Safari iOS extension https://filepicker.app which implements these APIs through an extension.
28.
▲
iOS Safari Extension Implementation of File System Access API
(filepicker.app)
3 points
by
osy
5y ago
|
0 comments
29.
▲
Show HN: Run VS Code on iOS with Safari Extension
(filepicker.app)
2 points
by
osy
5y ago
|
0 comments
30.
▲
Hades Canyon NUC: The best Mac mini Apple never made
(osy.gitbook.io)
5 points
by
osy
5y ago
|
0 comments
More ›