Hacker Newsnew | past | comments | ask | show | jobs | submit | MattSteelblade's commentslogin

But it's not literally byte comparison; it's case-insensitive ASCII comparison.


I cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his:

- Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc

- The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk

- Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g


My introduction to his work was "The future of RE Dynamic Binary Visualization"[0] which completely blew me away. It still feels futuristic today, 13 years later. Novel UI/UX paradigms like this are slow to find widespread adoption, even when they're so clearly demonstrated to be such an ideal fit for their purpose.

0: https://www.youtube.com/watch?v=4bM3Gut1hIk&pp=ygURY2hyaXN0b...


I love digraphs. I learned about them from that talk's associated paper... but only about 2 years ago. I've been dumping my system and GPU RAM raw and visualizing via digraphs and it's amazing how such a simple algorithm operating on arbitrary bytes leads to such distinct and consistent image.


TBH with the DDD debugger you had a graph with the C structures right away.


If this is the same dude I am thinking of, his wife is also the CISO of Mozilla and do security research together, afair they have a whole book on x86 reverse engineering.

Very cool!


x86 Software Reverse‐Engineering, Cracking, and Counter‐Measures By Stephanie Domas and Christopher Domas

https://onlinelibrary.wiley.com/doi/book/10.1002/97813942771...


> He does such a fantastic job of explaining his work.

He did a fantastic job of explaining his work.


What do you mean? Did he pass away?


The explanation that appears in this repo seems largely LLM-generated. It's punchy, to be sure, but I wouldn't call it CLEAR

I had to look at the comments here to understand what was going on

So maybe he USED to explain things well, but that's not on display


His talks are pretty good, I think that’s what people meant. But yeah, the readmes are really hard to follow and feel very ai generated too


His way of explaining things clearly seems to have done so


I saw a recent video and I was shocked that he had hair:

https://www.youtube.com/watch?v=iOq8O_phwbA

He looks so different.


His stuff is something else.


Alright, a new series to binge now.


In this case, the rm -rf before that does. The rmdir is the Windows command in this example and with /s /q, it will quietly delete everything.


Not at all; standard IR procedure is scope -> containment -> eradication -> recovery. There is a fog right now; we don't know all the details. It seems to me that it's just as likely they weren't fully kicked out before or that the initial vulnerability wasn't remediated. You can't recover until the threat actor has been removed.


There is a lot of love in my group from years of MtG for drafting games, so 7 Wonders and Dune Imperium are consistent favorites. When we have the time, we'll do Twilight Imperium. We've enjoyed all three Nemesis games. We are currently also really enjoying Spirit Island. We've completed Gloomhaven: Jaws of the Lion and put in some serious time with regular Gloomhave as well. As LotR fans, we've also enjoyed the LotR LCG and War of the Ring.


A Technology Connections video recently changed my opinion on this. The land required to power the entire U.S. would be less than the farmland we currently use for ethanol production.


Alec presented it well- but we don't even need to take his word for it.

The Department of Energy has all the data available, so do a dozen different other private and public institutions. It didn't click for me till I ran some napkin math.


Per the article, the issue is with recalled batteries that are going to take 18-24 months to be replaced that won't allow the bus to charge pas 75% or below 41 degrees and because of the risk of fire and lack of suitable fire mitigation equipment, can no longer be charged in garages. Not seeing any mention of an issue with the underlying technology.


It's a double whammy, because at cold temperatures the total capacity of the battery is reduced, and now they're only using 75% of that.

Also, recalls in lithium cobalt batteries are much, much more common than they are with other battery technologies, which is an issue inherent to the specific technology used for those batteries.


Google is hardly betting on it; they are exploring the feasibility of it and are frank about the engineering challenges: > significant engineering challenges remain, such as thermal management, high-bandwidth ground communications, and on-orbit system reliability.[1]

[1] https://research.google/blog/exploring-a-space-based-scalabl...


why do you think this changes what i said? I know it has constraints but the fact is that Google is serious about it. Enough to publicly speak about it many times and invest enormous amounts of R&D.

You are saying they are "hardly betting on it". This is grossly false and I wonder why you would write that? Its clearly a serious bet, with lots of people working on it.

> Google CEO Sundar Pichai says we’re just a decade away from a new normal of extraterrestrial data centers

Its surely a high risk bet but that's how Google has been operating for a while. But why would you say they are hardly betting on it?

As a counter question: do you think Google is not serious about it?


I never said Google wasn't serious; I said they are hardly betting on it relative to their other capital expenditures. Google rightfully describes this as a "moonshot." To date, the only public hardware commitment is two prototype satellites in 2027 for a feasibility study. Compared to the billions pouring into Waymo, DeepMind, and terrestrial data centers, this doesn't yet qualify as an "enormous" financial bet, even if the engineering intent is serious.


i agree with you then. lets agree that the intent is serious.


Not even a little; doesn’t pass napkin math. It doesn’t solve any problems while adding a litany of new ones: massive radiators for heat rejection, radiation hardening, and enormous launch + repair costs (assuming repairs are even possible). The idea exists to separate investors from their money; the product is the funding round.


I haven't done the actual math and I might be a few orders of magnitude off but shouldn't electrical resistance drop quite significantly in space, too? (Of course there's the other issue that information processing is an inherently dissipative process because entropy etc.)


How would electrical resistance drop in space? If you're thinking "because it's cold" that's actually the biggest issue. The vacuum means you can't dispose of heat easily, so you need giant radiators, which are expensive, heavy, etc.


there's no repair involved. imagine a series of throwaway satellites on an orbit that essentially leaves them close enough together for effective mesh networking, and probably on an orbit that slowly takes them away from earth.

the compute is used for training, not inference. the redundancy and mesh networking means that if any of them die, it is no big deal.

and an orbit that takes them away from earth means they avoid cluttering up earth's orbital field.


It sounds like you're describing Google's proposal, which I believe is at least feasible (though likely uneconomic) unlike, say, Starcloud's. I don't think you are correct about the orbit, though; Google's proposal lists the satellites at 650 km, which would give them approximately 20 years in orbit without boosts. They list estimated life at 5 years given radiation concerns, so they almost certainly would purposely deorbit them earlier.


Based on the comments in the thread, I sense I will be in the minority, but for most consumers this is a reasonable default. Broadly speaking, the threat model most users are concerned with doesn't account for their government. The previous default is no encryption at rest, which doesn't protect from the most common threats, like theft or tampering. With BitLocker on, a new risk for users is created: loss of access to their data because they don't have their recovery key. You are never forced to keep your recovery keys in Microsoft's servers and it's not a default for corporate users.


It's certainly a reasonable default. People lose or have their laptops stolen much more often than they get targeted by their governments.

Though that doesn't mean Microsoft couldn't implement a way of storing these keys so that they can't be accessed by Microsoft. Still better than nothing though.


I think it’s a reasonable default if Microsoft weren’t able to access your encryption keys.

Apple has that figured out. Your keys can be stored in your cloud synced keychain but only you can decrypt that keychain.

That’s why they couldn’t help the FBI to decrypt devices even when compelled.

Microsoft should have done the same. They should never find themselves in a place where they can be compromised like this.


I'll always remember - when I was first learning about it, one of the interesting counter-arguments to ignoring privacy was "what if the Nazis come back, would you want them to have your data?". I suppose there's some debate these days, but hostile governments seem a lot closer than they were 10-15 years ago.

Will this make people care? Probably not, but you never know.


"Closer"? They're already here. Trusting corporations or governments is inherently moronic.


Even in the best of times. Why widen your attack surface unnecessarily? Do you tell people your passwords and PINs at parties?

What governments and corporations (and plenty of bad actors in the FOSS world) have done is make this the default; made it easy to mindlessly hand people your privacy without even knowing. Opt-out, if you know the setting exists, and can find it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: