Matthew Garrett
mjg59@nondeterministic.computer
<p>Former biologist. Actual PhD in genetics. Security, OS security teaching at <a href="https://www.ischool.berkeley.edu" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="">ischool.berkeley.edu</span><span class="invisible"></span></a>. Blog: <a href="https://codon.org.uk/~mjg59/blog" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">codon.org.uk/~mjg59/blog</span><span class="invisible"></span></a> . He/him. Opinions do not reflect those of my employer.</p>
Posts
-
Post #4508486
Vivid dream last night where @jwz@mastodon.social's blog was actually a webcomic and the most recent entry was extremely critical of me personally and I learned about this because Scruffy from Killer Net showed up and provided his role-defining line: "He's flamed yer, called yer a wanker in all the newsgroups". Anyway. I am well adjusted.
-
Post #4482471
I ended up rereading the GNU manifesto when writing my FOSSY talk this week and goodness all the sections about how programmers should make money are very "Some of you may die, but that's a sacrifice I'm willing to make" meme anyway this is an allegory about how LLMs and free software interact: https://www.gnu.org/gnu/manifesto.html
-
Post #4310511
Meanwhile Roy has taken to referring to me as "Desperado" in what appears to be a pejorative manner so: Antinio Banderas as Desperado:
-
Post #4309505
Casually hooking ExitBootServices() as a convenient point to transition the kernel into a hypervisor guest because why not
-
Post #4263986
Wanted: chart of chartreuse price Vs ram price
-
Post #4209168
It's the kind of day where I both have to look closely at someone's security model and also deal with the cat deciding to eat the butter
-
Post #4196436
Last year, Roy and Rianne Schestowitz were found to have defamed me and were ordered to remove that defamatory content and avoid any further defamation. They chose not to follow the whole of this order, and I sought to have them held in contempt of court. Today this was upheld: https://www.brettwilson.co.uk/wp-content/uploads/2026/07/Garrett-v-Schestowitz-and-anor-No-2-2026-EWHC-1948-KB.pdf
-
Post #4196177
Roy was held to have provided misleading evidence in both oral and written evidence. Rianne was held to have provided both oral and written evidence that was not correct. My understanding is that this is generally considered to not be a good thing.
-
Post #4158191
Huh. This seems like an odd choice (from https://learn.microsoft.com/en-us/windows/security/hardware-security/pluton/pluton-as-tpm)
-
Post #3942396
Everyone at #emfcamp gathering around the lake as word of mouth spreads that there's potentially a burning of an Elon Musk effigy
-
Post #3933876
Microsoft has been a reasonable steward of the third party UEFI signing key and handling revocation, but I think it's reasonable to question the conflict of interest around the Windows signing key and the huge amount of time between Windows bootloader vulnerabilities being identified and Microsoft revoking them. Ideally this would be delegated to a third party, but an alternative would be for Microsoft to issue a signed (but optional) dbx update that revoked trust in the Windows signing key
-
Post #3920676
Sudden furry parade #emfcamp
-
Post #3919113
The #emfcamp dalek is dispensing whisky while shouting "Inebriate"
-
Post #3918201
Of course there's an actual Teletype for playing Collosal Cave #emfcamp
-
Post #3896326
There's chiptunes and lasers
-
Post #3870396
Hello #emfcamp I failed to validate my pillow in staging before travelling and it is failing in production (ie it had a puncture) anyone have a spare?
-
Post #3858571
Blahaj density in Paddington is visibly increasing #emfcamp
-
Post #3743930
Has anyone built something that lets you plug a VIC-II into modern hardware?
-
Post #3743390
TPMs are single threaded and can't sign more than about 10 queries per second so we simply put all dynamic content behind a proxy that requires a TPM backed client cert and solve the scraper problem that way
-
Post #3713403
It is 2006. I am debugging why a laptop isn't generating ACPI events on lid close. It is 2026. I am debugging why a laptop isn't generating ACPI events on lid close.
-
Post #3696228
Solving the "Can LLM models ever be free software" problem by burning one into ROM so the FSF can ignore it
-
Post #3670616
Flying into the UK on a foreign passport and a somewhat bizarre selection of luggage and still enjoying no longer having to play the "Matthew doesn't get arrested" challenge
-
Post #3652088
Can anyone think why it would be a bad reason for ssh-agent to support being configured to pass specific extensions off to something else that speaks the SSH agent protocol, making it possible to implement custom extensions without needing to either upstream them or front the upstream SSH agent? (cc: @damienmiller@hachyderm.io I guess)
-
Post #3644159
Look I really don't think this needs to be said, but: please don't try to sequence your DNA at home unless you have a shitload of experience, and also please don't ask an LLM to analyse your DNA sequence unless you have ready access to professionals who are in a position to review it
-
Post #3553821
Oh Good Lord https://storage.courtlistener.com/recap/gov.uscourts.nysd.642223/gov.uscourts.nysd.642223.16.0.pdf
-
Post #3552708
And after yesterday's post, here's one on the state of things in agentic identity: https://www.codon.org.uk/~mjg59/blog/p/securing-agentic-identity/
-
Post #3539526
I spent a long time looking at what I think is about every standard for reducing risk around bearer tokens theft and why we still don't have nice things: https://www.codon.org.uk/~mjg59/blog/p/preventing-token-theft/
-
Post #3530785
RE: https://fediverse.zachleat.com/@zachleat/116845291090365543 Obviously everyone knows that Vic Gundotra killed Reader, but he didn't succeed immediately. He could destaff the project, but people could still spend 20% time maintaining it. It was inevitable that it would die, but what the final blow was a standard Google outcome - load bearing infrastructure was going to be turned off, and everyone had to port their project to the replacement that didn't really work yet. Reader just di...
-
Post #3530483
Liberal: *through sobs* you can't just say everything is a bearer token.... Please.... Me: *points at Kerberos flying past* bearer token
-
Post #3528505
Good morning Europe I have written about the bewildering array of mechanisms available to prevent authentication token theft and also explained why we still basically have none of them available and so the authentication tokens are still being stolen and used. It is here: https://www.codon.org.uk/~mjg59/blog/p/preventing-token-theft/