everything i touch breaks. (mostly by accident)
Posts
The term "Universal Linux Vulnerability" used in the disclosure of the recent Kernel LPEs is incredibly misleading and shouldn't be used.
There is no such thing, as a bug that can be exploited in virtual all setups. The world of
Linux systems is tremendously heterogeneous. Different kernel configs, user spaces, MACs, privilege systems.
Kernel/Userspace isn't even necessarily a trust boundary.
In linux-adjacent vuln research you need to be especially precise what your actual target is.
The joys of ICS security:
"Is that Firmware version deployed somewhere?"
"$Customer"
"What do they do?"
"Cooling systems for nuclear reactors."
I just hate how models are increasingly becoming better with the fun parts of my job, like finding vulnerabilities and not at all becoming better with the boring parts on my job like writing compliance documents.
Something I would like to say more often is "We shouldn't do this, because we do not understand the consequences well enough." But it's hard to defend against folks who, in my opinion, overestimate their understanding and press for it's implementation.
I don't think this will happen btw. I guess that there will be 10x more unpatched vulns in shiny dashboards.
But maybe this is my IACS-perspective speaking :P
In some company the hoops you have to jump through to get access to their shitty source as a contractor
vs.
the willingness of the same company adding their complete company data including source code, crypto keys, financial reports and PII of employees to the training data of $AI_company is astonishing.
Die Squareroots sind zurück! Was im April mit einer Nachricht im @RaumZeitLabor@chaos.social Matrix-Channel begann, hat mittlerweile zur Wiederbelebung des alten, aber einige Jahre mehr oder weniger inaktiven CTF-Teams squareroots geführt.
Nach den letzten Monaten mit regelmäßigen Treffen um die basics zu üben wurde mit dem FAUST CTF jetzt der erste A/D Wettbewerb zusammen gespielt. Weitere werden dieses Jahr noch folgen.
https://raumzeitlabor.de/blog/Die-Squareroots-sind-zurueck/