lenish

3.8K posts

lenish banner
lenish

lenish

@lenish

␂ バトルプログラマ ␞ Write tests. ␞ Automate everything. ␞ Free range developer. ␃

インターネット Entrou em Temmuz 2009
218 Seguindo69 Seguidores
lenish retweetou
Edge Security
Edge Security@EdgeSecurity·
There are some nice RNG changes in the pipeline for Linux 5.18, addressing a long standing crypto quasi-vuln in the RNG, going back to Linux 1.3.35. Gory details and some fun PoC code are in this commit: git.kernel.org/pub/scm/linux/… [1/3]
English
1
46
124
0
lenish
lenish@lenish·
Apparently parsing arbitrary HTTP in the kernel is more secure than doing it in userland. #shithnsays
English
0
0
2
0
lenish retweetou
Willy Tarreau
Willy Tarreau@WillyTarreau·
Fred and Amaury just committed an amazing work on #QUIC+HTTP/3 in #HAProxy 2.5! They're far too humble to admit it in part due to many remaining limitations and bugs, but here you can already see curl-7.80 ->HAProxy-cde911231 ->Apache-2.4 at work with H3 translated to H2! Kudos!
Willy Tarreau tweet media
English
6
48
120
0
lenish retweetou
ippsec
ippsec@ippsec·
Ever curious about HTTP Smuggling? Check out HTB's Sink video, it abuses a bug between HAPROXY and GUNICORN to trick the server into writing someone else's HTTP Headers into your POST Request. Allowing you to steal the cookies! youtube.com/watch?v=8gf5Yv…
YouTube video
YouTube
English
1
78
363
0
lenish retweetou
Péter Szilágyi
Péter Szilágyi@peter_szilagyi·
Between the 3 Sept and 10 Sept, secure env vars of *all* public @travisci repositories were injected into PR builds. Signing keys, access creds, API tokens. Anyone could exfiltrate these and gain lateral movement into 1000s of orgs. #security 1/4 travis-ci.community/t/security-bul…
English
32
1.3K
1.8K
0
lenish retweetou
Halvar Flake
Halvar Flake@halvarflake·
It's finally ready: Prodfiler, a continuous profiler that "just works" -- for C/C++/Rust/Go/JVM/Python/Perl/PHP -- no code change required, no symbols on the machine required, no service restart required. Check out: prodfiler.com or the blog post below.
optimyze.cloud@OptimyzeCloud

It is alive! Introducing Prodfiler, the world's first frictionless whole-fleet whole-system continuous profiler: prodfiler.com/blog/introduci… -- profile all your code, everywhere, all the time. Try it today :-)

English
38
224
732
0
lenish retweetou
Steve Weis
Steve Weis@sweis·
I'm glad the @NSAGov "Quantum Computing and Post-Quantum Cryptography" FAQ dismisses quantum key distribution (QKD) as impractical. There are several companies out there trying to push their QKD solutions, which aren't useful for anything. media.defense.gov/2021/Aug/04/20…
Steve Weis tweet media
English
0
21
59
0
lenish
lenish@lenish·
@ezyang valgrind usually does a good job IME, unless it's a rare leak
English
0
0
0
0
Edward Z. Yang
Edward Z. Yang@ezyang·
it still gets my goat how hard it is to debug memory leaks
English
2
0
29
0
lenish
lenish@lenish·
TIL bash namerefs foo() { local -n array=$1 array+=( a ) } bar() { declare -a arr foo arr # note the lack of a $ echo "${arr[@]}" } Prints: a
English
0
0
1
0
lenish
lenish@lenish·
@jjcarett2 my favorites have broken pseudocode and a note from the author on their website asking you to email them for the source. Never have received a reply.
English
0
0
0
0
Jacques Carette
Jacques Carette@jjcarett2·
Wow, so many CS papers from before ~2015 are amazingly non-reproducible! The systems are not available, and the details in the paper are not there at all. Super frustrating to do a lit survey and see many papers that we ought to have learned 'something' from, but can't.
English
12
15
108
0
lenish retweetou
eevee 💨
eevee 💨@eevee·
github copilot has, by their own admission, been trained on mountains of gpl code, so i'm unclear on how it's not a form of laundering open source code into commercial works. the handwave of "it usually doesn't reproduce exact chunks" is not very satisfying
eevee 💨 tweet media
English
117
1.5K
4.8K
0
lenish retweetou
Matthew Green
Matthew Green@matthew_d_green·
This is an amazing paper. It implies (with strong statistical evidence) that the design of a major mobile-data encryption algorithm — used in GPRS data — was deliberately backdoored by its designer. eprint.iacr.org/2021/819
English
27
989
2.3K
0
lenish
lenish@lenish·
Private chatrooms in Slack are engineering culture cancer. Engineering decisions should be a matter of record all engineers can review.
English
0
0
2
0
lenish retweetou
Karl (RIP )
Karl (RIP )@supersat·
This is bonkers: At a large enough scale, you will have CPUs that develop silent corrupt execution errors. Manufacturing and burn-in tests miss these: sigops.org/s/conferences/…
English
23
218
834
0
lenish
lenish@lenish·
Programming is fun. Engineering is work.
English
2
0
2
0