Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
thudson
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
thudson
5y ago
If you want to play mental poker with an arbitrary number of friends/enemies, I built a prototype with a really basic UI that extends the SRA81 protocol to support more than two players and that also removes the need to reveal the hand
2.
▲
by
thudson
5y ago
Similar higher-than-rated-bandwidth can be achieved on the TRS-80 Model 100, which uses an array of 10 HD44102 controllers. With an FPGA it is possible to draw full motion video on the LCD: https://twitter.com/qrs/statu
3.
▲
by
thudson
5y ago
The WEH001602A is pin compatible to the HD44780, with OLED output instead of LCD. In 8-bit parallel mode with an FPGA you can exceed the recommended clock rate to drive quite a bit of data into the displays: https://twitter.com&#
4.
▲
by
thudson
5y ago
A few years ago I built an adapter to allow classic Mac CRT's to be used with BeagleBone or Raspberry Pi systems ( https://trmm.net/Mac-SE_video ). X11 has supported 1-bit mono displays since forever, so it mostly work
5.
▲
by
thudson
5y ago
12-eights for "microns turnabouts Como migraines": 9a7e6f41875b444851cb19f018cea83e6565762d88888888888813ac47d39ce7 Although I'm also a fan of "Georgetown surfboarded rips nodding", which hashes to the very pleasant
6.
▲
Sleep Attack: Intel Bootguard Vulnerability Waking from S3
(trmm.net)
3 points
by
thudson
6y ago
|
1 comments
7.
▲
by
thudson
6y ago
If you want to more easily configure UEFI Secure Boot on your Linux system, while also registering your own signing keys to eliminate the Microsoft and OEM ones: https://safeboot.dev/
8.
▲
by
thudson
6y ago
The CD-ROM is now on archive.org: https://archive.org/details/hugo_nebula_1993 Brad Templeton wrote about it: "I believe this CD is now a piece of history, as the world's first major eBook project using curre
9.
▲
by
thudson
6y ago
In practice it is a bit of a pain during the initial setup and package installation -- I was probably rebooting to recovery mode once a day or more to install some command line tool that I had forgotten about. Once the machine is configured
10.
▲
by
thudson
6y ago
If you want LUKS encryption with signed policies to prevent brittle PCRs, rollback prevention with monotonic counters, and user pin to prevent dictionary attacks, plus TPM sealed TOTP to attest to the state of the firmware: https:/&
11.
▲
by
thudson
6y ago
The TPM is not a DRM enforcement mechanism if you set it up for your own use. It is a very useful tool for taking control of machine that you own - it provides a way to prove* to yourself that the system booting with the firmware that you&#
12.
▲
by
thudson
6y ago
Some forms of TPM tampering are explicitly addressed in the threat model: > The PCR values in the TPM are not "secret", so an adversary with physical access could directly wire to the TPM and provide it with the correct measure
13.
▲
by
thudson
6y ago
A separate bootloader and key on USB does not protect against many physical attacks, nor ones that involve changing the firmware or nvram configuration through software attacks. Without some sort of sealed keys or attestation of the platfor
14.
▲
by
thudson
6y ago
This NSA report is a wonderfully thorough guide to configuring UEFI Secure Boot, although it is another example of how unusable security tools can be. This conplexity was my motivation for writing the safeboot[1] scripts, which wrap all of
15.
▲
Tpm2-Attest: TPM2 Remote Attestion
(safeboot.dev)
3 points
by
thudson
6y ago
|
0 comments
16.
▲
by
thudson
6y ago
That was exactly my motivation: there are tons of guides for setting up UEFI SecureBoot platform keys, yubikey tokens, TPM disk encryption, dmverity, etc, but all of them seemed to involve "type hundreds of commands with no mistakes an
17.
▲
Safeboot: Booting Linux Safely
(safeboot.dev)
197 points
by
thudson
6y ago
|
54 comments
18.
▲
by
thudson
9y ago
It's pretty typical boot time for most UEFI server platforms with network cards and RAID controllers. The Dell R630 takes about six minutes, the HP DL3x0 is about eight and the Lenovo x3550 takes over ten. Of the ones I've teste
19.
▲
by
thudson
9y ago
The threat model that LinuxBoot is addressing is different form SecureBoot and it can use the well known, normal Linux tools rather than the unconventional UEFI ones. The Heads runtime can do things like use TPMTOTP to attest to the user th
20.
▲
by
thudson
9y ago
The LinuxBoot kernel establishes a hardware root of trust with the TPM and measures the ROM before bringing up any IO devices, so when it connects to the network it is able to perform a remote attestation as to its state. This way the host
21.
▲
by
thudson
9y ago
With LinuxBoot you can use any filesystem that Linux supports, not just FAT. You can update boot entries by editing shell scripts, rather than manipulating opaque NVRAM variables. You can run Linux applications straight from the ROM if you
22.
▲
by
thudson
10y ago
Helen Sharman was Britain's first astronaut -- she spent seven days on the Mir space station in 1991. Peake is the seventh British astronaut[0]. 0: https://en.wikipedia.org/wiki/British_space_programme#Britis...
23.
▲
by
thudson
10y ago
Cool URLs still work in OmniWeb on a NeXT with a decades old bookmarks file: https://www.flickr.com/photos/osr/17082625625/lightbox The Mondo 2000 interview bookmarks, not so much.
24.
▲
by
thudson
11y ago
tl;dr: Xeno Kovah, Corey Kallenberg and I ported several previously disclosed vulnerabilities from Windows UEFI systems to Apple's EFI firmware. Using the 2014 Darth Venamis ("Dark Jedi") vulnerability we were able to unlock
25.
▲
by
thudson
11y ago
Firmware passwords can be bypassed by a local user with a Thunderbolt Option ROM. The 10.10.2 fix for Thunderstrike left that hole open during normal boots: https://trmm.net/Thunderstrike_FAQ#Is_Thunderstrike_fixed_in...
26.
▲
by
thudson
12y ago
Fun! I've been working on a similar free software project to unfold generic STL files for laser cutting: https://github.com/osresearch/papercraft The problem is that most models on thingiverse produce designs tha
27.
▲
by
thudson
12y ago
Most of the disk packs have had the help files deleted to reclaim 100 blocks so HELP results in a "?KMON-F-File not found SY:HELP.SAV". If the files are there, it looks sort of like this: https://www.flickr.com/ph
28.
▲
by
thudson
14y ago
I hear that the WC doors on Swiss trains have a slide-to-unlock feature as well.
29.
▲
by
thudson
15y ago
The T221 is a great monitor for coding -- check out the size of the "fixed" font on the wikipedia image. But with most configurations it only does 12, 24 or 48 Hz depending on how many DVI channels you can use. Also, since it is being driv