In other news I keep getting Linkedin spam trying to get me to join an expenses paid trip to tour China's technology companies and I can't tell if this is a scam or merely espionage so has anyone else (1) got these *and* (2) done it? I want to emphasise that I am not looking for people to hypothesise on this issue.
Microsoft has been a reasonable steward of the third party UEFI signing key and handling revocation, but I think it's reasonable to question the conflict of interest around the Windows signing key and the huge amount of time between Windows bootloader vulnerabilities being identified and Microsoft revoking them. Ideally this would be delegated to a third party, but an alternative would be for Microsoft to issue a signed (but optional) dbx update that revoked trust in the Windows signing key
Hey Google, write me a security solution. No, not that one. I don't like that one either. Can you make one that doesn't delete all my data please. Try harder.
Good morning Europe I have written about the bewildering array of mechanisms available to prevent authentication token theft and also explained why we still basically have none of them available and so the authentication tokens are still being stolen and used. It is here: https://www.codon.org.uk/~mjg59/blog/p/preventing-token-theft/
Conflicted over how much of the future understanding of the PC and Apple industry ok the 80s is going to be poisoned by AI and how much is going to be poisoned by @NanoRaptor
It's been over 6 years since I moved in here and I've only just realised that the reason the lights in the extractor hood don't work is that nobody had ever installed any bulbs in it
The El Toroito specification for bootable CDs was named because it was originally sketched out on the back of a napkin at an El Torito restaurant. If you had to name a spec you'd written after the bar or restaurant you came up with the idea in, what would its name be and what was the actual name?
People on the "LLMs mean all bugs need to be patched immediately" train: are you replacing your ops teams with LLMs as well or have you just forgotten why Patch Tuesday is Good, Actually
It is very funny that there is a guy who spends a lot of time talking about his commitment to facts, and who also keeps making references to me swearing on a bible in court despite (a) that not happening and (b) the transcripts making it clear that didn't happen
DRM is pretty obviously something that inherently removes user freedom without benefit, and decrying it is entirely reasonable. Hardware identity and state attestation *can* be used for DRM, but can also be used for other purposes that improve things for users (like Signal verifying that it's communicating with a genuine enclave before disclosing any sensitive data), and attacking the technology rather than the ways it's used seems short-sighted
People will complain that a technology can be used to oppress user freedom while contributing to free software that gets used in literal weapons of war
I do entirely understand the idea that functionality that can be used against users (even if it can also be used to enhance user security) is bad, I just don't understand why people will simultaneously make that argument and support the idea that a software license that says "You may not use this software to murder people" is incompatible with the ideals of free software
The downside of full-on self-hosting is, of course, that your server will inevitably choose to have weird hardware issues while you're in another country
A bunch of time trying to figure out why I was getting 500 errors any time I tried to type a username into Mastodon and it turns out Elasticsearch believed the index was corrupt but on validating it it seems like it wasn't and just deleting the "corrupt" tag in the index was enough for things to start working again? I'm sure this will all be fine
Speaking of Unicode, I think many people would be surprised just how strong the pushback against it was even in the early to mid 2000s. UTF-8 adoption in Linux was a fight.
Former biologist. Actual PhD in genetics. Security at Nvidia, OS security teaching at https://www.ischool.berkeley.edu. Blog: https://codon.org.uk/~mjg59/blog . He/him.