Only previous time I've had to switch aircraft was when the ground crew accidentally unplugged a 777 from ground power before the APU was running, and apparently cold booting a 777-200 involves a large stack of floppies and is not a rapid task, anyway, was fun getting to see what the emergency floor level lighting actually looks like in the dark
If your vulnerability description is AI written I'm going to assume that you don't actually understand the issue and I am going to accord you no credit
Supposedly the reason there isn't a codified spec for UEFI audio is that there were concerns it would be seen as actually trying to offer a gaming environment that would remove the need for Windows anyway that is all that stands between us and being able to boot directly into an MP3 player
The problem with the OAuth Device Authorization Grant is that you can initiate a request and send the URL to someone else and if they complete the login you get their token. With additional user friction you can mitigate this with a flow that reverses things (generate a unique login link, send that to the machine that completes the login, provide a code, require that that code be entered on the device that initiated the request), but is there any way to do that within the spec?
Going to be real and sentimental for a moment: this weekend I spent time with a number of people who I've known for decades but get to spend time with rarely and the amount of spontaneous support for me and what I've been dealing with for the past couple of years was incredible and let nobody ever tell you that free software is inherently antisocial
I ended up rereading the GNU manifesto when writing my FOSSY talk this week and goodness all the sections about how programmers should make money are very "Some of you may die, but that's a sacrifice I'm willing to make" meme anyway this is an allegory about how LLMs and free software interact: https://www.gnu.org/gnu/manifesto.html
In other news I keep getting Linkedin spam trying to get me to join an expenses paid trip to tour China's technology companies and I can't tell if this is a scam or merely espionage so has anyone else (1) got these *and* (2) done it? I want to emphasise that I am not looking for people to hypothesise on this issue.
Microsoft has been a reasonable steward of the third party UEFI signing key and handling revocation, but I think it's reasonable to question the conflict of interest around the Windows signing key and the huge amount of time between Windows bootloader vulnerabilities being identified and Microsoft revoking them. Ideally this would be delegated to a third party, but an alternative would be for Microsoft to issue a signed (but optional) dbx update that revoked trust in the Windows signing key
Former biologist. Actual PhD in genetics. Security at Nvidia, OS security teaching at https://www.ischool.berkeley.edu. Blog: https://codon.org.uk/~mjg59/blog . He/him.