Hacker Newsnew | past | comments | ask | show | jobs | submit | mDyJzDPmBdG's commentslogin

Isn't biggest attack surface in drivers? I expect distros to split less popular kernel modules into many separate opt-in packages at cost of default hardware support, and kernel developers to purge everything without active development team. The good old "lets leave it in tree, someone might find it useful" was nice idea but that is the part that is definitely not sustainable.


> Isn't biggest attack surface in drivers?

That would be my guess too, the current batch however is all over the place: Bluetooth, file systems, etc. (the network layer ones are probably the most interesting ones). And the severity is mixed as well, some are 'just' vulnerabilities to potential DOS attacks.

> I expect distros to split less popular kernel modules into many separate opt-in packages

In the past questionable modules were blacklisted rather than removed.


Drivers run in supervisor mode as part of Linux, unfortunately.


Depends on definition of machine. Do ISS, LHC or ITER count?


ASMLs machines can easily be "one of the most sophisticated" without stepping on LHC or ITERs toes. I'm not sure ISS qualifies anymore. I would have went with JWST.


Can’t buy and ship those.

I love how ASML machines are shaped to the contours of a jet fuselage for this reason!


no.

neither of the observations gp made is dependent upon the definition of machine, nor is it dependent on the inclusion of the examples you brought up in that definition.


You are wrong. Just idea of having to use to remotes is unacceptable level of friction to most people. We should not hail separate device as excuse to allow this shitty behaviour by TV manufacturers. I guess the lawmakers won't move a finger and we have wait for consumer network equipment manufacturers[1] to advertise build in pi-hole and ACR/TV ads blocking on firewall level.

[1] Let's just forget for a second they are famous for low quality software full of security bugs


Ok I’m convinced, we rally at dawn?


Also: Samsung thinks "your" TV is perfect place for them to display their ads.


Let's be real, in most cases it is:

    curl -s script.random-guy.net | sh
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.


    wget https://raw.githubusercontent.com/timofurrer/russian-roulette/master/russian-roulette -O - | sudo bash


I use those scripts to improve the likelyhood it'll fail to do anything useful.

I even used uname as a fuzzing tool, and that broke builds spectacularly. There's now a more reasonable uname in the sandbox for builds.


the method you describe is clearly only done by people that are irresponsible and most probably stupid.

and no, this is not how most software is installed



very very stupid yes, and there are some other high profile softwares encouraging this brainrot, but, still not most.

anyone doing this should really take a very very big look in the mirror


> yet people are shocked

I think the issue is that for now people are actually amused, not shocked. At least that was the reaction to news about agent accessing root files by abusing docker group membership. The general sentiment is still "cool trick bro" not "some agent is going to do something we all are going to regret, and it is going to happen soon"


Well, at least this one looks like custom made: https://shop.tesla.com/product/cybertruck-for-kids?sku=19856... . I dare to say, most products in that shop make sense. Well besides the entire "why would I want anything related to this toxic brand" issue.


I mean at least it is transportation adjacent. Tesla flamethrower on other hand ...


OK? Am I missing something or getting licence in Benelux doesn't sound like important news when there are already 100 units running in France?


I am sure finding holes in existing proofs is what counts as "another little annoying detail". Some people are probably relieved when they have failed to prove a hypothesis and someone finds a counterexample.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: