human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs).
works at Google Project Zero.
The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
Posts
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
this sounds exciting, nice that AMD found it:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
[...]
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
aah, the reason why the in-app kindle purchase flow in german has a button labeled "Bitte lesen" (which translates to "Please read") for opening the purchased ebook is that someone mistranslated "Read now" as if it was meant in imperative form?
My favorite out-of-context translation fail was some internal status page in Chrome years ago, which described sandboxing status as (translated back to English) "you have trained sufficiently".
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
I'm currently learning British English slang from a british isekai, no way this could go wrong
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
oh, this sounds like an exciting Xen >=4.17 bug affecting HVM/PVH modes:
"Use after free of paging structures in EPT"
https://xenbits.xen.org/xsa/advisory-480.html
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
from the Security Cryptography Whatever podcast, talking about openssl API design choices: https://youtu.be/jhdLja5mWbU
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
I find stack overflow security bugs fascinating; and on Linux, compilers still don't protect against stack overflows by default when stack frames are bigger than stack guard pages.
So I went looking around in Android, and thanks to how Android's RPC mechanism allows recursive synchronous callbacks in some cases, I managed to find a way to jump a thread guard page in system_server from shell context and (with very low success rate) get instruction pointer control:
https://project-zero.issues.chromium.org/issues/465827985
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
The Linux kernel "every subsystem has its own git tree" thing is so annoying.
Especially when one file is plausibly associated with multiple subsystems and patches get routed through more than one.
I guess it probably works reasonably well for people who only ever touch stuff in the one subsystem they specialize in, but for anything else...
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.
human borrow checker (but logic bugs are best bugs). works at Google Project Zero. The density of logic bugs (compared to memory corruption bugs) goes down as the privilege differential between attacker context and target context goes up.