David J Anderson

287 posts

David J Anderson banner
David J Anderson

David J Anderson

@f4p_dja

Tea drinker. Co-author of Fit for Purpose! How modern businesses find, satisfy & keep customers. Out now! #f4p

Seattle, WA Katılım Eylül 2016
13 Takip Edilen516 Takipçiler
David J Anderson retweetledi
Andreas Bartel
Andreas Bartel@trichromacy·
Red wine and Fit for Purpose - a perfect fit for a relaxed evening while @SusanneBartel is heading for Cologne, for an on-site KMP I class delivery. #Kanban @f4p_dja @az1
Andreas Bartel tweet media
English
3
2
14
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland The actual machine code required is incredibly delicate/fragile eg “if you can out run the interrupt” where “if” is the key word. Nevertheless hardware will need to be redesigned
English
0
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland Now that I understand the POC was in Javascript I see how it is possible to disrupt the layers between the script and the machine code to make it hard to predict the code that will be produced. Thanks
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland The big issue in today’s hyperconnected world is that only a handful of humans out of ~7 billion are required to have knowledge & expertise for something to have global risk implications 🙁
English
0
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland I rarely met C coders who knew how their code compiled or executed on the processor.
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland That is freakishly impressive given the control required on the assembly instructions. Must have required a lot of knowledge on how the script is compiled & mapped to machine code
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland Can you also explain why vendors are claiming firmware/software patches inoculate against this when it is hard-wired into the processor design?
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland Nevertheless the architectural redesign of processors to eliminate this vulnerability will take a decade to filter across the broad population of equipment.
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland Demo exploit code still requiring a delivery vector which is also quite challenging to create
English
1
0
0
0
David J Anderson
David J Anderson@f4p_dja·
@gsuberland Exceptionally thorough & clear explanation. I,m educated in microprocessor architecture & spent 15 years programming assembly. Your explanation shows how incredibly tricky this is to exploit. Has some build a working demo turning theory into practice?
English
2
0
1
0
David J Anderson
David J Anderson@f4p_dja·
@MMahlberg It’s safer is the team pull it rather than have it pushed on them. Sometimes coaching requires risk taking and pushing. Just outside their comfort zone, or too far?
English
0
0
2
0
David J Anderson
David J Anderson@f4p_dja·
@MMahlberg It’s safe to fail if your org has the maturity to roll it back without destroying anything else of value in the process
English
1
1
1
0
David J Anderson retweetledi
Bruno Baketarić
Bruno Baketarić@__bbak·
Many, perhaps even most companies don't get this: "To understand your customers, you need direct customer interaction. Your frontline staff provide that mechanism." #f4p
English
0
1
1
0