I got to play with a period accurate pentium 4 machine running windows xp the other night, noodled around in control panel and in ableton live 7 and the thing that really shocked me was how *fast* it was. Obviously loading stuff off the hard drive was quite slow, but once the page cache was warmed up it was a very snappy, very responsive experience.
I'd noticed how snappy vintage windows is in a VM on contemporary hardware before, but this was shockingly snappy even on hardware of its own time. Really makes you question what the fuck we're all doing here in computing
In the 90s too many people in Italy were going to raves and then driving home still cooked and crashing their cars and dying so Robert Miles wrote the now iconic track "Children" to play at the end of his rave sets to calm people down before they drove home https://www.youtube.com/watch?v=vbqnTIG8r-I
@dalias it looks like AF_NETLINK is in the critical path of the exploit poc at least? see add_xfrm_sa, it it responsible for actually writing the shellcode and does so via a netlink socket
@dalias hold up, I see the iproute2 shell out. I disagree, I think AF_NETLINK is quite relevant. If you block that address family, you block the exploit. Most programs have no need for that address family, so it's unnecessary exposure. I'll revise my position when I see a poc which does not use AF_NETLINK
The latest (yes another) Linux kernel LPE also relies on an exotic socket type, AF_NETLINK. If you lock down allowed socket types to just internet+unix, you are safe.
Unfortunately even rootless podman relies on AF_NETLINK sockets via pasta (user mode networking), so it's trickier if you're using containers. Good time to reconsider if you really need all the extra complexity containers bring.
With Windows 9x Subsystem for Linux you can run all your favourite Windows and Linux apps side-by-side with a modern Linux kernel running cooperatively with the Windows kernel in ring 0. And unlike modern WSL, no hardware virtualisation is used so even your 486 can run it!
Please enjoy, I think this might be one of my greatest hacks of all time
so it cost anthropic $20k to find this openbsd crash bug which amounts to putting a negative integer in a tcp field where a negative integer was not expected by the c code which does some cavalier int cast bullshit, ie. a vuln which is totally fuzzable, and quite certainly would have been found by the fuzzers of the 2010s had anyone cared to burn that much compute on fuzzing openbsd.
The difference today is not that anybody suddenly cares about investing that much in openbsd (is the build server still a donated machine running in Theo's basement?), but that openbsd's reputation for security makes it really good marketing if you can find a bug, any bug, it doesn't matter; and that marketing value is what makes it worth spending $20k on fuzzing.
I don't mean to throw shade at openbsd here, it's a scrappy project running on the smell of an oily rag and I have a lot of respect for that kind of scrappy resourcefulness, but it's key to understanding why the most salient factor here is big tech deciding to throw lots of money at it. That this is the best they got for $20k really speaks to why nobody bothered previously.
There's a particular strawman response to the concerns that LLMs damage literacy, impair learning, etc that goes like "well people said the same thing about the calculator!" "Socrates said writing would make people dumb!" and the reason it's a shit take is it pretends that pedagogy just doesn't exist. We _do_ study the effect of various technologies and methods used in teaching. We _know_ that certain methods of teaching reading are ineffective and damaging, three-cueing for example.
It is in fact anti-science to believe that all concerns about new technologies and methods being damaging are automatically invalid, especially in the face of mounting evidence supporting those concerns.
@moses_izumi@bojidar_bg doslinux just boots a linux kernel from dos while taking care to preserve dos memory so that it can be resumed in vm86 mode later (just like how win9x worked) It's a real linux kernel so you can do anything you could normally do under linux. The project is more of a fun hack than anything serious though, it's really crashy in practice
@moses_izumi@bojidar_bg yep heaps crashier. It doesn't attempt to virtualise much hardware like win9x does with VxDs - only really the BIOS keyboard service. DOS retains full hardware control otherwise and both OSes are sharing the hardware with basically no coordination. It's enough to make the demo video in the readme work and not much more :)
woof! I am a computer tinkerer, polyglot hacker, music enjoyer, and bike rider. Also a huge nerd. Trans and queer 🏳️⚧️ 🏳️🌈 ΘΔ pfp by https://bsky.app/profile/jankapnoc.bsky.social