Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
x4132
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
x4132
4mo ago
this is why you don't contact distro mailing list. responsible disclosure is dead.
2.
▲
by
x4132
5mo ago
to which distros? how do you ensure fairness? Do you report this to the maintainer of Red Star OS (north korea)? The kernel security team was given the heads up a month ago. At that point it is their decision.
3.
▲
by
x4132
5mo ago
sorry yeah, I saw not exploitable on Android and thought most SELinux would be ok. Not super sure on this case what the surface is
4.
▲
by
x4132
5mo ago
so what? we should never disclose anything? this will only result in companies suppressing disclosure and leaving vulnerabilities unpatched.
5.
▲
by
x4132
5mo ago
are you sure containerization would be more secure? this is also a rootless podman escape. the lesson here is to not give random people shell access to your systems.
6.
▲
by
x4132
5mo ago
this is because the `su` binary is replaced with x86 shellcode, replace it with aarch64 and it will work just the same.
7.
▲
by
x4132
5mo ago
there is a PoC floating around for Alpine.
8.
▲
by
x4132
5mo ago
it's advertising their AI, not the talents of their humans :D
9.
▲
by
x4132
5mo ago
i mean, it doesn't work on any SELinux, but it's still quite severe anyhow
10.
▲
by
x4132
7mo ago
ctrl + o isn't live - that's not what users want, what users want is the OPTION to choose what we want to see.
11.
▲
by
x4132
7mo ago
not surprised about the chrome part, but pretty shocked at the phone OS part. I know APFS migration was done in this way, but wouldn't storage considerations for this be massive?
12.
▲
by
x4132
8mo ago
goddamn, almost missed out such a cool extra layer, thanks for the tip!
13.
▲
Torching the Modern-Day Library of Alexandria: The Tragedy of Google Books(2017)
(theatlantic.com)
3 points
by
x4132
8mo ago
|
0 comments