@KQEDnews “CREDO receives funding from the pro-charter Walton Family Foundation, which provided support for the new research.” Seems like useful background context for this article.
Curious about exploiting VMs or memory bugs in a safe language? Read my new blog post, where I attack Firecracker, AWS' VMM written in Rust. Learn about the various layers of virtualization + the attack surface, and how design decisions impact security.
https://t.co/FNN7JjeRce
I will never find it anything less than hilarious that Ramanujan noclipped through numbers like no one else who came before him to the point where he felt a need to add a 1/30 to his factorial approximation algo for precision
And there's no proof for it
It just fucking works
@ECCTLS@sans_isc@johullrich Yeah, turns out CA issuance portals error out when you try to submit a request with tons and tons of SANs. We had these custom issued (a support tech manually processed them for us) but that isn't really sustainable. They'll probably get marked "defunct" (or local-only) sometime.
our PETS 2022 SoK on Certificate Transparency log auditing is up! https://t.co/DoWRXKBM1U
covers why SCT auditing is hard & how it looks similar (or not) to other tricky privacy-preserving reporting in browsers. w/ Sarah Meiklejohn, @deblasioj, @notyetsecure, @modyoloN, Kevin Yeo
This is cool! Reminds me of how in Chrome we still err on the side of punycoding hostnames that mix strong RTL characters to avoid similarly confusing directionality changes in URL displays. (Also nice to see the Rust folks continue to have good, developer friendly warnings.)
The Trojan Source vulnerability allows supply-chain attacks on software written in C, C++, Go, Java, Javascript, Python and Rust. We're releasing details after a 99-day coordinated disclosure period, and some of these compilers will be patched quickly. See https://t.co/tO4xIU5Ncw