Ammar Askar

93 posts

Ammar Askar

Ammar Askar

@__ammar2__

شامل ہوئے Temmuz 2018
106 فالونگ162 فالوورز
solst/ICE of Astarte
@evelovesolive Interesting, I always imagined this would be extremely difficult and inevitably leave gaps, esp for more complex systems
English
2
0
1
124
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: Another researcher skipped coordinated disclosure entirely and dropped a critical 1-click GitHub token theft in public because he doesn't want to deal with MSRC. In his own words: "I really don't want to deal with MSRC on VSCode bugs." The bug: just clicking a link can hand an attacker a GitHub token that reads AND writes to all your repos, including private ones. It lives in github[.]dev, GitHub's browser-based VSCode editor, which passes the browser an OAuth token that isn't scoped to a single repo. That token can touch everything you can. Researcher Ammar Askar found that VSCode's sandboxed "webviews" leak keyboard events to the main editor. A malicious repo opened via one link can simulate keystrokes, install a local extension that skips VSCode's publisher-trust check, and exfiltrate your token. He published a working proof-of-concept. He says when he reports github[.]dev bugs, GitHub tells him they're out of scope and to go report to MSRC, and a prior VSCode bug he reported was silently fixed with no credit. One commenter summed up the mood: "MSRC has turned into Feedback Hub."
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
58
338
2.2K
278.1K
Ammar Askar
Ammar Askar@__ammar2__·
@zemnmez Oh yeah, your write up was awesome, learned a bunch from it! The twitter thread was also very entertaining.
English
1
0
2
93
Darin Givens
Darin Givens@atlurbanist·
@AngieAsadourian Can you recommend a particular block or two in Midtown were I could observe a lot of pedestrian activity on sidewalks on weekday mornings? I'd like to visit.
English
4
0
3
1.9K
Darin Givens
Darin Givens@atlurbanist·
Question: Is there an Atlanta street or block that's particularly vibrant with pedestrian activity on weekday mornings? I heard form someone that Midtown sidewalks can be creepily quiet in the mornings, given the density. Just wondering if any place has a lot of activity.
English
25
4
73
16.2K
Ammar Askar
Ammar Askar@__ammar2__·
@isidentical Key/value type restrictions? Does it have to work across versions? Quick thought would be to just dump the whole in-memory dictionary and mmap it into place. Looks like mmappickle.readthedocs.io/en/latest/ does something like that for a limited set of values and string keys.
English
0
0
0
44
batuhan the fal guy
batuhan the fal guy@isidentical·
what is the best way to load an immutable python dictionary (~13GB of kv pairs) from a local file. ideally with pre-allocating the memory so we don't loose time on it.
English
1
0
0
650
Nobel Yoo
Nobel Yoo@nobelsucks·
I think we should let twinks vote
English
2
0
6
145
Diogenes Stan
Diogenes Stan@SpraklingTwit·
what the fuck
Diogenes Stan tweet media
English
1
0
7
112
Ammar Askar
Ammar Askar@__ammar2__·
@R1amu__ Good way to support them but I just use Dropbox
English
0
0
1
45
mouse 🐭🇨🇦
mouse 🐭🇨🇦@R1amu__·
Am I about to spend $8/month on Obsidian sync?... Much better value proposition than Twitter Blue 🤔
English
3
0
2
202
Diogenes Stan
Diogenes Stan@SpraklingTwit·
can someone who is good at budgeting help me Food - $50 Cell phone - $100 Transportation - $50 DragonCon costumes - $2,000 Movies - $25 please, my family is starving
English
1
0
6
138
Ammar Askar
Ammar Askar@__ammar2__·
Suffice it to say I'm very dissapointed in @msftsecresponse and @code around their handling of this. Two months to triage an RCE and mark it moderate severity and ineligible for bug bounty is crazy to me.
English
2
0
5
497
Ammar Askar
Ammar Askar@__ammar2__·
I found a remote code execution bug in VSCode that can be triggered from untrusted workspaces. Microsoft fixed it but marked it as moderate severity and ineligible under their bug bounty program.
English
4
3
16
972
Ammar Askar
Ammar Askar@__ammar2__·
@__phantomderp You may already know this but for what it's worth, PSF fellows aren't necessarily developers of the Python language (that's the Python core dev team). Anyone can nominate someone who has had a big impact in the Python ecosystem to be a PSF fellow.
English
1
0
3
699
Björkus 'No time_t to Die' Dorkus
🙃 I didn't know he was a PSF Fellow. I, uh. I use python mostly for scripting so it's not like my life depends on it but this is gonna feel... extra weird. (It's doubly weird because I parasocially know other PSF engineers and they're lovely so WTF!) twitter.com/BajoranEnginee…
mastodon.online/@bajoranengineer@BajoranEngineer

Sending unwavering support to @__phantomderp in the face of only wanting to continue to provide their expertise to their programming community. I condemn the RANCID remarks made publicly about them by a PSF Fellow.

English
1
0
42
10.3K
Ammar Askar
Ammar Askar@__ammar2__·
@R1amu__ Bro they really went out and made a separate app is absurd
English
1
0
1
16