greateric's blog

By greateric, history, 5 months ago, In English

Might wanna update your computer if you run linux. (and probably also codeforces servers)

https://copy.fail/

Also maybe I don't fully understand the kernel and am complaining too much but still who decided it was a good idea to let page cache be overwritten

  • Vote: I like it
  • +6
  • Vote: I do not like it

»
5 months ago, hide # |
 
Vote: I like it 0 Vote: I do not like it

Auto comment: topic has been updated by greateric (previous revision, new revision, compare).

»
5 months ago, hide # |
 
Vote: I like it 0 Vote: I do not like it

dang if I'm not mistaken an $$$AI$$$ model heavily assisted in finding this bug right?

  • »
    »
    5 months ago, hide # ^ |
     
    Vote: I like it 0 Vote: I do not like it

    Codebase scanning I believe, yeah, it seems pretty insane how skilled it was

    • »
      »
      »
      5 months ago, hide # ^ |
       
      Vote: I like it +6 Vote: I do not like it

      It's pretty crazy isn't it? One of anthropic's models also found a really old bug in openbsd apparently, so it could be that systems are either going to be very secure or very insecure in the near future. But I wonder if any of these bugs have already been discovered by the $$$CIA$$$ / $$$NSA$$$ (like eternalblue) or if some of them were put there intentionally. Like this privesc didn't exist before $$$2017$$$, why is that?

      • »
        »
        »
        »
        5 months ago, hide # ^ |
         
        Vote: I like it 0 Vote: I do not like it

        Yeah. Personally I feel like there should be more focus on safety in things like Linux, especially given how many exploits rely on memory issues. Like lots of fortify everything, put canaries everywhere and check if they get overwritten lol

»
5 months ago, hide # |
 
Vote: I like it 0 Vote: I do not like it

and probably also codeforces servers

They use Windows. Yeah, it's not great, but anyways.