Show newer

Right now it is 25F. That is cold. In a few days it will be -25F. That is the difference between an 80F beach day and freezing. Again. On top of today.

@QuestForTori i got really excited for a second and went googling to build a vm :(

This first-person vaporwave adventure game about weird internet culture is my favorite thing I saw at Indiecade. Two days left in the Kickstarter!

kickstarter.com/projects/44584

Spend more time looking at the intel bug. It is def a sidechannel timing attack as expected, probably they are looking at a different issue than the MMU cache table walk presented at CCC, but still a known attack.

Had a good TF dream that i woke up during again >.<

@rysiek it seems like they are mistaking an attack that tells you only if a page happens to be mapped or not at a given virtual memory address with an arbitrary kernel memory peek. The attack is the former and not very severe or useful.

We’re using the MMU page tables to rebuild the native mosquito population which need remind you is an endanger species!

Here! Educate yourself!
cs.vu.nl/~giuffrida/papers/anc

*shakes old kernel hacker fist at stupid internet cloud*

Stop fucking freaking out about this.

@rysiek The patches look like they are protecting against the mmu attack only for kaslr when it is useless anyhow and not user space aslr where it is useful.

It is NOT paging out the kernel. This attack is present in amd but not across rings.

The entire article is a fuck. git.kernel.org/pub/scm/linux/k

@rysiek I’m implying they have no idea what the consequences and probable fixes are of the bug not that they are lying. If they are referencing the MMU timing attack which much of it makes me think they are, then the misleading parts are all of it.

They way they portray it is nonsensical. They dont understand when kaslr is and is not useful....

@rysiek that article is so misleading and ambiguous that i literally cant even. I assume their talking about the MMU timing attack from CCC? That affects EVERY architecture tested. Table look up timing attacks are a thing

Show older
Awoo Space

Awoo.space is a Mastodon instance where members can rely on a team of moderators to help resolve conflict, and limits federation with other instances using a specific access list to minimize abuse.

While mature content is allowed here, we strongly believe in being able to choose to engage with content on your own terms, so please make sure to put mature and potentially sensitive content behind the CW feature with enough description that people know what it's about.

Before signing up, please read our community guidelines. While it's a very broad swath of topics it covers, please do your best! We believe that as long as you're putting forth genuine effort to limit harm you might cause – even if you haven't read the document – you'll be okay!