Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
umanghere
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
umanghere
1mo ago
They did recently add the iCloud@Work compartment (right before I left), and it seemed like an OK compromise and kosher policy-wise.
2.
▲
by
umanghere
2mo ago
This is bizarre. I used to work in offensive security, doing a lot of vulnerability research and exploit development. Given the nature of the work and the fact that our products were subject to export controls, we used to work in an actual,
3.
▲
by
umanghere
4mo ago
I completely encourage you to write this as a blog post, you’ve articulated all of the concerns I had with Go’s package management wonderfully.
4.
▲
by
umanghere
7mo ago
Fascinating article, and I am surprised how well peer pressure works on LLMs. Somewhat tangential though, but I find the amount of perl clutching from the AI industry about writing malware code a bit ridiculous. Most of the examples cited i
5.
▲
Peer Pressure Works on AI Too
(robkopel.me)
1 points
by
umanghere
7mo ago
|
1 comments
6.
▲
by
umanghere
7mo ago
I started reverse engineering at 13 with an IDA Pro of questionable provenance - at that time, I found it quite difficult. One thing which really helped me (and I wholeheartedly recommend) is to write simple programs, run them through the c
7.
▲
by
umanghere
8mo ago
https://umangis.me Not a lot of content, but enough to be of some interest to a few niches.
8.
▲
by
umanghere
2y ago
> 4) Hacking is Cool Pardon my French, but this is the dumbest thing I have read all week. You simply cannot work on defensive techniques without understanding offensive techniques - plainly put, good luck developing exploit mitigation
9.
▲
by
umanghere
3y ago
I don’t mean to sound argumentative, but that’s a knee jerk response. It’s possible to reverse engineer the OS code to verify that the biometrics indeed end up on the SEP’s encrypted storage, and several people have done this in the past. H
10.
▲
by
umanghere
3y ago
In my opinion, a better submission title would be: Open Source distributions for macOS 13.5 have been released. The current title is a bit misleading, because several parts of macOS, including those covered partially by the OSS releases, ar
11.
▲
by
umanghere
3y ago
https://archive.is/Kxdeh
12.
▲
by
umanghere
3y ago
It took forever to get the document off SFTC’s website, so I mirrored it behind CloudFront for everyone’s convenience. https://blog.umangis.me/static/08539708.pdf
13.
▲
A first look at Rust in the 6.1 kernel
(lwn.net)
6 points
by
umanghere
4y ago
|
0 comments
14.
▲
SQLite: Wal2 Mode Notes
(sqlite.org)
63 points
by
umanghere
4y ago
|
15 comments
15.
▲
by
umanghere
4y ago
Unfortunately it can’t be done even if you target an M1 iPad — virtualization is locked behind an entitlement that’s not publicly available on iOS.
16.
▲
by
umanghere
4y ago
Just allowing kexts to be loaded should not increase the attack surface or expose the author to any currently known exploits. The reason that people avoid doing it anyways is because third party kexts have a history of obvious vulnerabiliti
17.
▲
by
umanghere
5y ago
There are publicly available SecureROM dumps online, see http://securerom.fun The author(s) maintain the site out of personal interest.
18.
▲
by
umanghere
5y ago
__padding replied to you, but unfortunately their comment is dead because of their account being new, so I’ve reposted it as I cannot vouch yet. > __padding 45 minutes ago [dead] [–] > Typically with devices like network cards (that a
19.
▲
by
umanghere
5y ago
iPhones do not use the A1 chip as of quite a few years ago. Besides, the M1 and the A12+ have significant microarchitectural similarities, to the point that the DTK used the A12Z. Furthermore, the keyboard app extension and the keyboard app
20.
▲
by
umanghere
5y ago
While Marcan has written in a very entertaining fashion, there is perhaps one application of this vulnerability that wasn't considered. If this can be reproduced on the iPhone, it can lead to 3rd party keyboards exfiltrating data. By d
21.
▲
On Security Research Devices
(blog.umangis.me)
1 points
by
umanghere
6y ago
|
0 comments
22.
▲
by
umanghere
6y ago
They (Facebook) have done this before too. I recall that they bought full-page ads in all major newspapers to promote their "Free Basics" initiative. There are also other examples, but I consider this level of advertising by them
23.
▲
by
umanghere
6y ago
You can still pull the database from an iOS backup on your Mac or created from `idevicebackup2`. The file is named `1b6b187a1b60b9ae8b720c79e2c67f472bab09c0`, `275ee4a160b7a7d60825a46b0d3ff0dcdb2fbc9d`, or `7c7fba66680ef796b916b067077cc246a
24.
▲
by
umanghere
6y ago
On macOS, these executables can be signed with a detached signature. Surprisingly, the embedded codesignature also works (but the signature is stored in an extended attribute on the filesystem).
25.
▲
by
umanghere
6y ago
Speaking from experience, that's not necessarily true. EU countries accept equivalent experience in lieu of academic qualifications. Assuming that you are offered a position that pays well, and have around 5-ish years of experience, em
26.
▲
by
umanghere
6y ago
This seems to be quite similar to the other unikernel that was posted recently [1]. It would be useful to have an in-depth comparison of these (and other) unikernels, especially with regard to performance and compatibility. I can see that H
27.
▲
by
umanghere
6y ago
Here’s a list of SolarWinds’s customers: https://www.solarwinds.com/company/customers I’m not in favour of having public client lists, especially when you’re a critical software vendor — but this list is just terrifyin