u2usvc

60 posts

u2usvc banner
u2usvc

u2usvc

@u2usvc

Science is Fun

Katılım Şubat 2023
418 Takip Edilen11 Takipçiler
Adam Chester 🏴‍☠️
People bragging on LinkedIn that they got approved for Anthropic's Cyber Verification Program.. poor deluded souls 🤣
GIF
English
5
7
69
5.3K
u2usvc
u2usvc@u2usvc·
@ZackKorman I swear people at anthropic be doing everything to hype their shit up as much as they can
English
0
0
0
3
Zack Korman
Zack Korman@ZackKorman·
If Kimi 3 is actually better than Opus 4.8 then I just want to say it was good knowing you all. Stay strong through the cyber apocalypse.
English
77
59
1.7K
108.1K
u2usvc
u2usvc@u2usvc·
@Shugiie1 @shotgunner101 Even considering the person is dedicated enough to change dtpm everytime, this won't save him from a broader attack surface within a mainboard
English
0
0
0
47
Shugiie
Shugiie@Shugiie1·
@u2usvc @shotgunner101 Why you asking me instead of the guy claiming tpm has to do with privacy? dtpm is interchangeable ftpm isn't (in most cases, yes some mainboards "allow" changing these)
English
1
0
0
150
u2usvc
u2usvc@u2usvc·
@bugler @AnonVendetta2 @dogen_1 @shotgunner101 - AMT needs to be enabled explicitly, because it is off by default - AMT is intended for business - all documented vulns in AMT and IME net capabilities require AMT to be enabled - Presumption of innocence
English
0
0
0
36
u2usvc
u2usvc@u2usvc·
@bugler @AnonVendetta2 @dogen_1 @shotgunner101 I am aware of that. A large portion of chips in consumer mainboards have their own OS/RTOS and have DMA - it doesn't indicate anything. Intel AMT has been around for more than 20 years and is being assessed all the time, so yeah a lot of vulns were found. BUT nothing malicious
English
1
0
0
62
エ
@AnonVendetta2·
@dogen_1 @shotgunner101 Still have hardware level spyware like Intel ME and the AMD equivalent PSP
English
2
0
2
434
Sturpen
Sturpen@5turpen·
@JONEMARROW @shotgunner101 You dont get it, thats ok. It completely changes the id and attestation ive tested on multiple anticheats.
English
1
0
2
375
u2usvc
u2usvc@u2usvc·
@dogen_1 @shotgunner101 Not really, because 1) the TPM is still there and it's persistent EK is still retrievable afaik 2) the motherboard (and its fw) itself has a series of identifiers that are WINAPI-retrievable and persistent across reinstalls
English
0
0
4
324
jc dogen
jc dogen@dogen_1·
@shotgunner101 I disable tpm and secure boot typically. is that not effective?
English
2
0
1
2K
Shugiie
Shugiie@Shugiie1·
@shotgunner101 Thats why any "privacy conscious" person runs dtpm instead of ftpm
English
3
1
4
2.2K
ハセン حسن
ハセン حسن@hasen_95dx·
Fable is AGI At least as a programmer, it's leaps and bounds ahead of me. People talking about hallucinations and token prediction and statistical parrots need to wake the fuck up.
ハセン حسن tweet media
English
45
16
518
60K
u2usvc
u2usvc@u2usvc·
@vxunderground How many TBs (7z ultra compressed) of cat pics do you possess?
English
0
0
0
27
vx-underground
vx-underground@vxunderground·
Hello 1. If you're reading this, that means you live inside my computer. Please leave my computer. You are stinking the place up. 2. I am syncing 150,000+ malwares to the internet. Please download the malware. 3. I now possess 14TB (7z ultra compressed) of malware
vx-underground tweet media
English
57
53
1.6K
30.6K
Lazy Lone Lion
Lazy Lone Lion@lazylonelion·
@Existsindeath @u2usvc @T3chFalcon I did search. There is no proof that ME is spyware. Nor have you provided any. There are/were vulnerabilities that could be exploited... if an attacker has physical access to your computer or at least has some access to your OS (depends on vulnerability).
English
1
0
0
15
IT Guy
IT Guy@T3chFalcon·
Most people who care about privacy focus on their operating system. Linux over Windows. open source over proprietary. That's good. it's also not enough. Here's what's running below your OS on almost every Intel computer made since 2006: The Intel Management Engine is a separate processor inside your chipset running its own closed-source operating system called Minix 3. It has direct access to your RAM, storage, network, and peripherals. it runs at Ring -3 below your kernel, below your hypervisor, below everything your OS can see or control. it stays active even when your computer is powered off as long as it's plugged in. You cannot audit it. you cannot disable it through normal means. You cannot detect what it's doing from inside your OS. The EFF called it a security hazard in 2017. The Libreboot project said it has complete access to and control over your PC, including the ability to track keystrokes, capture screen images, and examine all running applications. Intel confirmed multiple vulnerabilities in ME in 2017 affecting 6th through 8th generation Core processors, Xeon, and Atom chips. Researchers demonstrated it could be used to inject rootkits remotely via the network interface. The only known method to fully disable it was discovered by Positive Technologies. They found a hidden bit in the firmware labeled 'HAP enable' part of an NSA program called High Assurance Platform. The NSA has a switch to disable Intel ME. you don't. if you want hardware that doesn't include ME: AMD processors do not have the same implementation. Purism builds laptops with ME neutralized. The Libreboot project has a list of hardware that can run without proprietary firmware. Your threat model determines how far down this rabbit hole you need to go. But you should know the rabbit hole exists.
𝐇𝐚𝐦𝐳𝐚 | Networking Guy@Hamzaonchain

@T3chFalcon is this true?

English
121
629
4.2K
228.8K
Exist
Exist@Existsindeath·
@lazylonelion @T3chFalcon No. You completely misunderstand. Intel ME is not able to be disabled. You have 0 access. At this point I am convinced you don't understand what you are actually talking about.
English
3
0
0
29
u2usvc
u2usvc@u2usvc·
needless to say if an attacker has last 2, it's gg anyways. and vulns with 1st one are just regular vulns, like in all other hardware and software (4/4)
English
0
0
0
30
u2usvc
u2usvc@u2usvc·
all vulns I've read about targeting IME have one of these prereqs: - AMT capabilities + AMT enabled + host reachable - kernelmode code execution on host - physical access to hardware (3/4)
English
1
0
0
33
u2usvc
u2usvc@u2usvc·
This seems misleading... IME is ancient and there is still no evidence that IME sends out any traffic secretly. IME really does: - have DMA - have PHY access (for AMT) - provide a broad set of RMM functionality called AMT. (similar to BMC) but it (1/4)
IT Guy@T3chFalcon

Most people who care about privacy focus on their operating system. Linux over Windows. open source over proprietary. That's good. it's also not enough. Here's what's running below your OS on almost every Intel computer made since 2006: The Intel Management Engine is a separate processor inside your chipset running its own closed-source operating system called Minix 3. It has direct access to your RAM, storage, network, and peripherals. it runs at Ring -3 below your kernel, below your hypervisor, below everything your OS can see or control. it stays active even when your computer is powered off as long as it's plugged in. You cannot audit it. you cannot disable it through normal means. You cannot detect what it's doing from inside your OS. The EFF called it a security hazard in 2017. The Libreboot project said it has complete access to and control over your PC, including the ability to track keystrokes, capture screen images, and examine all running applications. Intel confirmed multiple vulnerabilities in ME in 2017 affecting 6th through 8th generation Core processors, Xeon, and Atom chips. Researchers demonstrated it could be used to inject rootkits remotely via the network interface. The only known method to fully disable it was discovered by Positive Technologies. They found a hidden bit in the firmware labeled 'HAP enable' part of an NSA program called High Assurance Platform. The NSA has a switch to disable Intel ME. you don't. if you want hardware that doesn't include ME: AMD processors do not have the same implementation. Purism builds laptops with ME neutralized. The Libreboot project has a list of hardware that can run without proprietary firmware. Your threat model determines how far down this rabbit hole you need to go. But you should know the rabbit hole exists.

English
1
0
0
57
Ghost Pepper
Ghost Pepper@ghost_pepper108·
@chompie1337 Well my CVP approval did not really help me reach my goals. Claude started aggressively refusing to cooperate after a while, although starting a new session seems to help but not sure, attempts going on. You are right though. This is getting really annoying.
English
1
0
3
225
u2usvc
u2usvc@u2usvc·
It seems like after my recent break it is effectively impossible to work on any sort of real security-related task (including offensive PoC dev/analysis) with Claude Opus without filling some weird forms
u2usvc tweet media
English
0
0
0
43
u2usvc
u2usvc@u2usvc·
POV: doing my best squishing this 6 hours debugging session into 2 paragraphs, cuz I gotta make content out of it
u2usvc tweet media
English
0
0
0
30