Ricardo Carvalho

173 posts

Ricardo Carvalho

Ricardo Carvalho

@crvvdev

Talented programmer

Brazil Katılım Temmuz 2020
59 Takip Edilen228 Takipçiler
Sabitlenmiş Tweet
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
If you're interested about anti-cheat reverse engineering then please checkout my very detailed and rich article about EMACLAB Anti-cheat. This anti-cheat software is used in Counter-Strike 2 league called GamersClub, pretty popular in South America. github.com/crvvdev/emacla…
English
4
18
58
5.6K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
How did Claude gone from: "Ok I will reverse engineer this 20 year old proprietary encrypted protocol for you" to "Sorry I cannot process your request because it violates the..." We enriched your models capabilities for free and now you gatekeep the most important features...
English
46
63
1.7K
55.4K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@Iron_Adamant There's no alternatives once they get rid of Sonnet 4.6, all the comercial models simply refuse to do any security related task, even simple things like DLL injection. We might need to run local models with no guardrails in the near future.
English
2
0
26
2K
Iron_Adamant
Iron_Adamant@Iron_Adamant·
@crvvdev I've been trying to harden one of my projects to get this sorted out. My issue with that is that it switches to Opus 4.8 in the middle of that session, which is going to be a problem. Those overtuned guardrails will not work for long term.
English
2
0
20
2.4K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@Rubix161 Yea they definitely will not sell the fine tuned models for governments and stuff, I trust that they will keep em safe because it is too dangerous lmao
English
0
0
19
1.5K
TotheStars
TotheStars@Rubix161·
@crvvdev Wait till you hear how they used to sell dynamite in hardware stores but then it turned out people could do very dangerous things with it and so it became restricted
English
8
0
8
1.9K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@GlenWilsonIA They know how powerful it has become for tech related stuff, it feels like they wanna move people away from that area and force people to use it for stupid things like creating games or other general normie stuff.
English
3
0
61
2.6K
Glen Wilson
Glen Wilson@GlenWilsonIA·
@crvvdev They stole the data to make the model. They stole our data to make the model better. Now they won't let us use their models because we're too dangerous, stupid, and poor to use the models they built off our stolen works.
English
2
3
165
3.2K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
Agora esta explicado o motivo de eu não estar conseguindo mecher no github direito ontem... que palhaçada
Ayub | Internet propriamente dita@ayubio

Confirmo que há todos os indícios típicos de bloqueio nacional determinado pela Anatel no dia de hoje para api.github.com. Nas quartas-feiras, geralmente em dias de jogos de futebol, a agência de reúne com as maiores operadoras do país e determina o bloqueio de endereços utilizados pelos TV boxes. A lista de endereços bloqueados é mantido em sigilo pela agência, algo que tenho criticado em artigos, entrevistas e palestras. Os indícios são: 1) O fato de ocorrer numa quarta-feira e pelo relato desse internauta que me acionou, ontem o problema não ocorria. 2) O fato do IP 4.228.31.149 para qual aponta o FQDN api.github.com estar bloqueado somente na Claro, Vivo, Nio, Algar e TIM e *NÃO* em ISPs regionais conforme posso testar com o comando globalping. 3) O fato de outros endereços IP contidos no mesmo bloco /24 serem normalmente alcançáveis, o que exclui problemas de roteamento já que todos os IPs entre 4.228.31.1 e 4.228.31.255 necessariamente pertencem a mesma rota (vide exemplo 4.228.31.3). Recomendo que os afetados entrem em contato com seus provedores mostrando evidências coletadas a partir de sua casa ou empresa e exijam uma resposta do porquê não havia rota para 4.228.31.149 na noite de 10/06/26 enquanto para 4.228.31.3 há. Nesse thread a seguir, colocarei algumas informações úteis sobre o problema.

Português
0
0
1
134
OS Dev
OS Dev@OSdev_·
In the windows kernel, at IRQLs you can use Spinlocks but not Mutexes. The reason is Mutex structure holds ownership details meaning they only work with threads. At higher IRQLs >= DISPATCH_LEVEL, there's no concept of threads. When we use KeWaitForSingleObject() on a thread, the scheduler switches this thread on sleep and runs another thread. The scheduler only handles threads not interrupts. That's why there should be no blocking at Higher IRQLs (Mutexes, accessing paged data etc) Btw the Scheduler itself runs at DISPATCH_LEVEL. That's why thread level activity is only restricted to PASSIVE_LEVEL/APC_LEVEL
OS Dev tweet media
English
5
3
106
5.7K
Russian Bot
Russian Bot@russ1anbot·
@HomericWigger @Sosowski I want the best chip possible. I don’t want a dumbed down architecture just so it’s Linux compatible. Linux should adapt and catch up. That’s what open source is all about.
English
3
0
0
124
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
I have been telling everyone that the real plan of big hardware companies is forcing users away from open source solutions and real control over YOUR hardware.
HomericWigger@HomericWigger

@Sosowski I can see the seething in the comments. The issue with ARM platforms is they lack an equivalent of BOIS/UEFI. The real magic of the PC is the BIOS. That allows for a far more open platform than ARM or even RISC-V. If you care about open computing, it's x86 all the way

English
0
0
0
106
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@kernullist Same here, cannot use Claude to reverse engineer anything security related right now. Unfortunately I guess that we should move to weaker unrestricted models
English
1
0
4
837
kernullist
kernullist@kernullist·
Pretty much stopped using Claude for anything anti-cheat related. Their CVP(Cyber Verification Program) is so aggressive now that even simple API call requests get flagged instantly. Funniest part? It blocks me from reviewing code that Claude literally generated back during the Opus 4.6 era. Got tired of constantly wrestling with prompt engineering to bypass it, so I just gave up. Still subscribed, but only using it for non-cybersec stuff now.😞
kernullist tweet media
English
8
4
78
9.6K
Hope 
Hope @hopefullyidont1·
@SheriefFYI The one thing you can say about unreal's source code is that it has very good build instructions.
English
1
0
3
1.7K
Sherief, FYI
Sherief, FYI@SheriefFYI·
uninstalling Unreal Engine, much like every other interaction I have with Epic's code, makes me firmer in my belief that the entire org does not contain even a single systems engineer that understands how computers work.
Sherief, FYI tweet media
English
13
20
398
30.2K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@Reeshasx Melhor apagar isso dai já que aqui no Brasil aparentemente encontrar falhas em sistema (principalmente do governo) é considero um crime mais grave que matar alguém!!
Português
0
0
8
666
Reesha
Reesha@Reeshasx·
que legal eu posso mudar meu nome no Detran KKKKKKKK agora sou reeshasx no serviço do detran outra coisa é que além disso existe um arg chamado "statuscnh" escondido num json, se eu mudar pra true aparentemente eu fico com uma CNH válida ou algo assim (KKKKKJM???) além disso talvez também tenhamos auth takeover, basicamente um openredirect com roubo de sessão é muita falha esquisita de serviço legado aliás acho q perdi no psicotécnico pra tirar a CNH 🔥🔥🔥
Reesha tweet media
Português
20
9
397
40.7K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@NeedlessTrust Warbird goes as far as Windows 7, it is not something new only very obscure and just recently discussed.
English
0
0
0
25
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
Did you literally know that Windows has something called Warbird that literally executes encrypted shellcode on your computer? And that all of its functionality is not really known, we just know that exists and is actively running in everyones computers?
English
32
54
962
88.1K
Asukiko
Asukiko@asukiko_f·
@crvvdev Hey Ricardo, have you seen the Airbus analysis. Of this topic ? I believe they were the first one to talk about it on a public talk.. but not sure. And sometime ago some stuff of warbird get leaked as well on reddit.. github.com/airbus-seclab/…
English
2
2
22
2.3K
kthetrat ⚡
kthetrat ⚡@kthetrat·
@crvvdev Couple that w/ hw accel memory virtualization (VBS/HVCI) locking you out of the kernel. The final step of the plan is the complete deprecation of offline local trust, moving directly to centralized datacenter attestation. Since W8 the hw under Win is not entirely owned by Admin.
English
2
1
9
3.4K
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@pr0gam3rdude @anaisbetts Why the fuck would you need a syscall to invoke encrypted code? This could very well be done in userland. To "protect licensing code" you would say, but you don't need to patch NASA level code to activate Windows
English
1
0
6
472
Ricardo Carvalho
Ricardo Carvalho@crvvdev·
@og_ikypw Some people think that their privacy is violated because anti-cheat software runs in kernel level while the OS itself does sketchy stuff
English
0
1
29
7.6K
kaiu
kaiu@og_ikypw·
@crvvdev You mean you have a problem with security through obscurity?
English
2
0
9
8.4K