More commonly, voltage glitching does rely on removing capacitors etc., and extremely precise timing (nanosecond resolution, or below).
However, the fun part about this particular attack is that it does not require quite the same level of precision. The voltage is dropped incrementally until the CPU starts to make faulty calculations. It just so happens that AES is one of the most complex operations, and thus, the first to start faulting.
I'd much prefer a slightly dry but genuine personality, than a hyperactive and fake "youtuber personality". The content speaks for itself. He generally takes safety pretty seriously, too.
This requires the assumption that storage will continue to exponentially (or at the very least, linearly) decrease in cost. It also requires a certain amount of good luck. I would hope the IA has a reasonable amount of data resilience, but you never know.
I used to have access to papers via my university, but I never used that access. The UX of scihub is infinitely better. Anything else just added unnecessary friction to my research process.
This post is still getting linked from other places, so I think it's helpful to point out that it's almost certainly fake. (Hence its [flagged] status)
The images shown do appear to be adversarially generated inputs against some NN-based image hash or classifier, but there is no evidence to suggest that this is at all related to Apple's NeuralHash, or that the colliding hashes are from a real CSAM database (the target hashes are not public).
OP claimed they would "release 5 pieces of proof in the next 5 days" [1], and guess what, 11 days later they still haven't.
Look at OP's post and comment history, it's quite clear that they are a troll.
In the mean time, it has been actually proven that hash collisions against NeuralHash are trivially possible, see [2]
Codebases with high levels of abstraction and metaprogramming are often easier to understand in IDA/Ghidra, if your goal is to understand how a specific part of the program works.
"2 minutes setup" is mentioned in various places on the page, as well as on the chrome store page.
Why 2 minutes? I assume this is used as a stand-in for "very short time", because there's no way it actually takes two minutes to install unless your internet is particularly slow, and I don't imagine there's much to configure.
It seems a bit out of place, especially when the extension itself centers around the problem of 5 seconds feeling like an eternity.
Edit: I just installed it as a test, and it was ~instant.
Out of the 45 search results, the most relevant one (the UDP RFC itself) was all the way at the bottom, listed as "RFC0768" and tagged as "legacy". (I'm not sure what legacy actually means here?)
This site does seem genuinely useful, but I think the UX could really use some polishing here, especially since I literally followed through with one of the example queries in the middle of the homepage.
John Carmack is awesome, but I find this level of deification (of any individual) kinda creepy - it just feels unhealthy. Would you like to be treated that way, in Carmack's position?
I realize that your comment was likely made in jest, but it still bugs me.
However, the fun part about this particular attack is that it does not require quite the same level of precision. The voltage is dropped incrementally until the CPU starts to make faulty calculations. It just so happens that AES is one of the most complex operations, and thus, the first to start faulting.