@AIatAMD building an agent in minutes, reinforcement learning on an AMD AI laptop, and meeting smart people... a fun day so far #AMDevs#AIDevDay#ROCmClaw
Putting twitter to serious use the first time😂. Just want to share our incoming UsenixSec'24 paper. We managed to make concolic executing firmware even faster than PC program, also utilizing the real hardware. code: https://t.co/aj761RDLCb preprint paper: https://t.co/mT0w05wCPX
Time for an Arm-twist! CVE-2023-4039
Tom Hebb (Meta red team) and I discovered an 0day in GCC (for AArch64 targets) during my Arm exploitation training.
It renders stack canaries against overflows of dynamically-sized variables useless.
https://t.co/q0vX86e9gK
Overwhelmed by all the support I’m receiving from the community. 🥹🙏🏼
As a small thank you, I made all my high-resolution Arm assembly cheat sheets available for free 💙
Get them here:
@AndreasZeller That looks like a classic boilerplate for a meaningless R2 that usually says nice things but ultimately is a strong rejection because reviewer has no clue about what he is reviewing or maybe did not read the paper at all.
If you are a user of the #Amazon#FreeRTOS, check their latest security update https://t.co/Xja1a7bThS. It includes important security patches solving the issues described in my D-Box paper (https://t.co/VT8vgd2bHP) presented at @NDSSSymposium 2022.
@_dr_bea @dasaptaerwin @AcademicChatter That works also practice pronunciation of key words then you get use to present in public, even with tiny errors it is fine as long as you deliver the message and have eye catching slides
A critical reflection on the reviewing culture in computer science (not only computer security, but I agree with many of the raised points): "The Toxic Culture of Rejection in Computer Science" - https://t.co/cWJF8XuBR9
About our @USENIXSecurity paper:
HTTP/2-to-HTTP/1 conversion anomalies were first looked at by @albinowax and @emil_lerner in
the context of Request Smuggling. To take an in-depth look at the conversion anomalies and their security implications, we developed an HTTP/2 (1/3)
@AldoCassola No te das cuenta que hablas o usas palabras del Quechua hasta que sales al extranjero y no te entienden, y viceversa no entiendes cuando usan palabras de otras lenguas nativas, o escuchan mucho a Bad Bunny y hablan como tal, pero ese es otro tema...
@mboehme_ This is true, the novelty factor will be higher, and the bar set by the state of the art will be lower so you can beat comparable (if existing) solutions and push the envelope forward.
@moyix That is true, but MCU vendors may share one single hardware interrupt line with multiple peripheral interrupts. In this case, it is still necessary to evaluate more MMIO registers to dispatch the right function. These MMIO registers may not be part of the snapshot yet.