@eligaultney@0xsee4@LiveOverflow The issue is fixed afaik. But sure, malware has access to the things you are looking at right.
But this does not invalidate the fact that Recalls has the capability to make something persistent which wouldve been lost the next day. At least this is my understanding of it.
@eligaultney@0xsee4@LiveOverflow Can you explain how credit card information would get stored persistently on my PC for an attacker to exfiltrate it?
(Assuming that I dont just store them in a text file on my own)
Im not in the hype either but I can see how Recall "permanently" stores data which would 1/2
@h0mbre_ What does `fc` mean here?:)
Is `fc/s` equivalent to executions/second? This would confuse me since I remember from a past of your tweets that Lucid was sadly slow due to Bochs. (Atleast thats what I remember!)
Or have there been any greater improvements I've missed?:)
Always remember to take into account how the binary was built. I was trying to exploit a simple format string bug using positional parameters but this was not working, until @KampetL remember me this. GLIBC doesn´t care about this rule, while MUSL does.
@VespGames@Crexpain Ich weiß nicht, auf welchem Planeten du bisher gelebt hast, aber eklige Männer liefen auch schon vorher in Frauenumkleiden, um sie dort zu belästigen. Dafür muss kein Mann seinen Geschlechtseintrag umändern lassen.
@ballsplate @compux72 @__Manu_War__ @lyq_sqsp Can you elaborate how "making exploitation harder" is not a security measure? Would you consider a lock also not a security measure since "it takes more time to steal the bike"?
@compux72 @ballsplate @__Manu_War__ @lyq_sqsp It is a problem since preventing unprivileged users from knowing these addresses cuts attack surface for kernel exploits which requires knowledge about the memory layout.
But there are still other ways to bypass this randomization besides the stated technique.