>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting of it.
This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?
Yeah, sponsor sections of content is usually done respectfully of the audience. There's no javascript being run on my machine, the sponsor is usually tangentially related to the content, and the creator has an incentive to deliver it in either a humorous or relevant manner.
Yeah, it's an unfortunate titling of the HN post. Defensive means something different in this context - it's meant for people working within the defensive roles of an organization's infosec department.
Kali are a little to blame here for that confusion as well - "We are making enterprise grade security accessible" - is open to misinterpretation of what they are presenting.
Great presentation. Any thoughts on including these tricks directly into wireshark to allow fluid decryption at least on the Linux client where CAP_BPF is present?
Being at the author's talk earlier today, that wasn't really the spirit that it was given in. The author isn't really talking about "defeating" TLS as a technical control more as he is talking about "defeating" it as an annoyance when reverse engineering.
It's meant more as a showcase of how eBPF can be applied to a technical challenge, as opposed to the author claiming they fundamentally broke TLS.
Having been on the receiving end of this as a candidate (not at IBM), everyone was in on the test in the first 15 seconds, and it changed people's behavior instantly.
It's fairly obvious if you're on the receiving end what the purpose of the test is when you're being observed (as with most interview questions, it helps to ask yourself why the interviewer asking me / having me do this?)
Agreed, but also given they initially thought the aircraft itself was deviating from a stable approach (or at least the ATC transcription appears to suggest that?), perhaps the pilots may have thought the feedback was due to autopilot and not the person sitting next to them.
Make sure you're trying to get into the game mode you downloaded when prompted with "Select game data source" - if it was HLDM, only multiplayer is going to work.
Wow, thought I'd be one of the few struggling with this.
Bought the device with the hope that I could register an account for the first time in years, but similar to others, my account was instantly banned with no explanation other than "violating community guidelines."
One of Facebook's arguments against anti-trust accusations has been to point to the lack of consumer harm. This is fairly obvious evidence of material harm to consumers who just bought $500 paperweights.
Musk and JB got asked about this (I think at the 2016 AGM?). Their response was basically "yeah we get asked this a lot; No, because of the make up of the cells makes them inappropriate for the number of cycles."
Data Sovereignty? Could this, for better or for worse, allow Microsoft to completely dictate the terms of how it stores and manages its data in international waters?
My jaw kind of hit the floor after reading Google Security Research's issue 222; very glad someone has built a simplified PoC. With any luck this will get some kind of response out of MS.
Specifically, I've been to a few of the Functional Programming meetups- they've been good so far. UNSW and USYD are hubs for the CS community in general. As a UTS grad, there wasn't much but Business Analysis going on there.
Generally, recommendation would be to pick a few topics that you're interested and find related communities and meetups. You'll find interesting people through osmosis.
This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?