@deteccphilippe@daaximus Oh uhm I guess on second thought since you guys run in the hypervisor you can probably prevent this in a few different ways because you can own IOMMU
@deteccphilippe@daaximus Hey I’m not exactly from the (anti-)cheat/windows space but if assuming IOMMU works the same way as in other platforms (which I believe it should), can’t the kernel simply map the entire RAM to the device’s IOMMU address space?
We had a blast this weekend at @offensive_con 🔥- thank you to @Binary_Gecko for the awesome conference!
Congrats to our teammates @caueobici for his pwn2own success and @ryaagard for his talk on a 1-click Minecraft 0day😎
Security researchers become trapped into an identity that they can’t escape, life seems purposeless, reality shifts and they realize they can’t bend like a tree in the wind. It turns out that intelligence isn’t the key to happiness.
For those that know. Chop wood, carry water.
The https://t.co/NSdktUM8QC CFP is officially OPEN! If you are doing cool stuff with AI in offense, defense, or working on core AI tech (from frontier models to open source LLMs), we'd love to hear from you! Submit here: https://t.co/d9C6yxxZbi
@XenonOracle All of that just to say that the game isn’t over. It only changed, again. Probably the biggest shift in a while but a lot of the symmetries will be maintained
@XenonOracle Add that to the fact that the search space is really large, there is attack surfaces that defenders don’t know of or neglect, defenders need to kill all bugs (which is something that can’t even be proven) and attackers only need one or a few bugs per component …
@ippsec The exploit dev improvement of mythos seems substantial, but the findings shared (stack overflow with no KASLR, shallow UAF in a syscall not downstream almost anywhere, etc) were a bit underwhelming.
Maybe once they unrestrict their other findings we’ll se something meaningful 🤷🏻♂️
@S1r1u5_ Basically, because defenders only win if attackers can’t find any bugs but attackers only need to win once the game becomes discovering hidden corners in the search space and directing your effort (even if mostly AI) to those corners
@S1r1u5_ I agree that the workforce could be reduced but what I meant is that since the search space is near infinite, clever harnessing and non-public knowledge can make it touch different parts of the search space as whatever vendors will be running …