Isn't biggest attack surface in drivers? I expect distros to split less popular kernel modules into many separate opt-in packages at cost of default hardware support, and kernel developers to purge everything without active development team. The good old "lets leave it in tree, someone might find it useful" was nice idea but that is the part that is definitely not sustainable.
That would be my guess too, the current batch however is all over the place: Bluetooth, file systems, etc. (the network layer ones are probably the most interesting ones). And the severity is mixed as well, some are 'just' vulnerabilities to potential DOS attacks.
> I expect distros to split less popular kernel modules into many separate opt-in packages
In the past questionable modules were blacklisted rather than removed.
ASMLs machines can easily be "one of the most sophisticated" without stepping on LHC or ITERs toes. I'm not sure ISS qualifies anymore. I would have went with JWST.
neither of the observations gp made is dependent upon the definition of machine, nor is it dependent on the inclusion of the examples you brought up in that definition.
You are wrong. Just idea of having to use to remotes is unacceptable level of friction to most people. We should not hail separate device as excuse to allow this shitty behaviour by TV manufacturers.
I guess the lawmakers won't move a finger and we have wait for consumer network equipment manufacturers[1] to advertise build in pi-hole and ACR/TV ads blocking on firewall level.
[1] Let's just forget for a second they are famous for low quality software full of security bugs
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.
I think the issue is that for now people are actually amused, not shocked. At least that was the reaction to news about agent accessing root files by abusing docker group membership. The general sentiment is still "cool trick bro" not "some agent is going to do something we all are going to regret, and it is going to happen soon"
Well, at least this one looks like custom made: https://shop.tesla.com/product/cybertruck-for-kids?sku=19856... . I dare to say, most products in that shop make sense. Well besides the entire "why would I want anything related to this toxic brand" issue.
I am sure finding holes in existing proofs is what counts as "another little annoying detail". Some people are probably relieved when they have failed to prove a hypothesis and someone finds a counterexample.