> "After this story published, Apple told [Kim Zetter] they just posted the instruction about the DIT to their web site yesterday [MAR 21], timed to the public release of the researchers' findings, which means that developers were not told to do this fix prior to yesterday's release" [1]
The mitigation for the issue was posted in coordination with the publishing of the vulnerability. Given that the mitigation only applies to the M3 processor, it's reasonable to assume that there is no currently known mitigation for the M1 and M2 processors.
> The cryptographic key itself isn’t placed in cache. But bits of material derived from the key gets placed in the cache, and an attacker can piece these bits together in a way that allows them to reconstruct the key, after causing the processor to do this multiple times. The researchers were able to derive the key for four different cryptographic algorithms: Go, OpenSSL, CRYSTALS-Kyber and CRYSTALS-Dilithium.
> [Green] notes that in theory this attack might be used to break the TLS cryptography that a computer’s browser uses to encrypt communication between their computer and web sites, which could allow attackers to decrypt that communication to extract a user’s session cookie for their Gmail or other web-based email account and use it to log into the account as them.
I distinctly remember IV being big in the patent troll space, but I haven't seen anything recently. It looks like in the past ~8 years they have moved on or stopped for some reason.
I really don't understand how they can make this statement:
> The report states that when the car started, security video shows the owner in the driver's seat, contradicting reports at the time of the April 17 accident that the seat was empty when the car crashed.
Those two things aren't contradictory at all. The car's journey could have started with the driver in the driver's seat, but been empty when the crash occurred. A lot can happen in the time between the start and the end.
I believe the difference here is the temperature. If you look at KSTAR's operating tests you can see that they have run for 72 seconds in the past, so they must be implying 20 seconds at > 100M, or their statement about the 20s runtime would be invalidated by their own operating history.
What's more - the scientific article about the Tore Supra 2003 test is paywalled, but based on the abstract it looks like it was a test of: "simultaneously heat removal capability and particle exhaust in steady-state fully non-inductive current drive discharges" and not a test of maximum sustained temperatures.
This is where I diverge from Jimmy, as he is misinterpreting what the commenter is saying. The commenter is talking about _audit logs_ of changes to Wikipedia being kept in WORM compliant record, which is a good idea - audit logs should be immutable. Jimmy seems to be interpreting the comment as saying the pages of Wikipedia should be immutable, which obviously should not be the case.
Exactly. The case is not alleging that Walmart is engaging in a broad conspiracy, despite what the title of the article seems to suggest. It is simply saying that the plantif was terminated when he brought up to management that there were issues with how they were conducting business - "Walmart did not properly address these issues, its failure to do so could have serious long-term implications for its critically important e-commerce business."
Correct. There were several goals with the launch. The primary was successful payload insertion, the secondary goals were the successful return of the outer two boosters to land, and the central booster to a drone ship down range (success unknown). Additionally the goal was to recover the fairings, but the success of that is not publicly known at this time.
On a related note here is a proposal for a recent update to the animal emoji set. It's interesting to see the factors they consider when choosing whether or not to integrate a new emoji. I didn't know that much thought went into what they chose.
This was a very helpful explanation, thank you! Does using hexagons represent the start of a paradigm shift for mapping applications or is it something that has been used for a while? This is the first I have heard of it, but based on your explanation it makes a lot of sense.
Vitamin D is fat soluble and isn't cleared by the body as quickly as other vitamins such as B. Therefore it can be taken in higher doses, but less frequently. This is often done for convenience sake. A 3000-5000IU pill every week is easier to remember than a 500-600IU pill every day.
The connection between the linked article in this comment and the linked page for this post is that there is a potentially huge bug that will be made public soon and it just affects Intel processors, not AMD - hence the large sale of stock by the Intel CEO.
Take a few minutes to read the blog posts by the creator. Writing aside the general process and motivation around creating a custom hashing algorithm is very strange -
"Curl-P was created by following the idea of simplicity. While de-jure I can say that it was me who created Curl-P, de-facto it was created by a primitive AI created by me. That wasn’t AI of general purpose; an improved version of the AI is working on the final version of Curl now while I’m writing this post. This situation is quite funny because it look unusual, interesting if in the future we’ll see cases similar to https://www.theguardian.com/world/2016/jan/06/monkey-selfie-... but with an AI instead of an animal. By the way, there are a lot of attempts to create a lightweight hashing function, I’d be grateful if someone confirmed or refuted my observation that Curl-P is winning this competition.
IOTA was created to be immune to quantum computer attacks, today I have revealed that it was also created to be immune to attacks from an AI. IOTA was the very first distributed ledger technology to consider imminent threat from technologies which look exotic now. NSA already validated our prediction regarding quantum computers. I think that the both threats (QC and AI) have equal chances to become real in the near future and I’m confident that in few years we’ll see confirmations that the prediction about AI was prophetic too. If someone hasn’t got it yet – IOTA is about the future and it relies only on those paradigms which pass the test of critical thinking."
IOTA's relationship with top-tier companies was more than nebulous it was intentionally deceptive. They stated they had a partnership with Microsoft's Azure, when in fact they were simply using some Azure services. I don't think it's fair to claim I have a partnership with AWS just because I host a website on an EC2 instance.
Those aren't equivalent comparisons. The issues with Ethereum have all been with regards to implementations of applications on top of the ETH layer - parity bug and DAO hack being the two biggest. Neither was due to mistakes in the underlying Ethereum protocol, both had to do with something that someone made using Ethereum.
If I make a vulnerable website it's not nginx/Django/Postgres's fault.
The reason Ethereum hasn't taken over the dominant position yet probably has more to do with Bitcoin's superior brand penetration. Most Bitcoin holders that I know personally have very little actual understanding of how any of the crypto currencies work under the hood, so they follow the general sentiment of the community/press and do not invest based on technical merits.
Absolutely. The 24hr trading volume on gdax.com (connected to Coinbase) is 15,524 BTC (~$93,144,000) and that's just the BTC/USD market on a single exchange.
The mitigation for the issue was posted in coordination with the publishing of the vulnerability. Given that the mitigation only applies to the M3 processor, it's reasonable to assume that there is no currently known mitigation for the M1 and M2 processors.
[1] https://www.zetter-zeroday.com/apple-chips/