the grugq's newsletter

Subscribe
Archives
November 25, 2022

November 25, 2022

I spent some time yesterday running #sudo through Facebook's Infer static analyzer. It seems much more strict about dead stores than other analyzers and there were a _lot_ of uninitialized value false positives

Most of those false positives fall into two categories: the value was set inside a for() loop which was guaranteed to run for at least one iteration, or the value being set was dependent on another variable. This last case used to cause problems for gcc but they improved their checker to deal with that years ago.

I quieted the dead store warnings (hopefully introducing no new bugs in the process) but at this stage, I can't really recommend using Infer for C code if you have Coverity or even the clang analyzer available.


Todd C. Miller: "I spent some time yesterday running #sudo through…" - BSD Network

I spent some time yesterday running #sudo through Facebook's Infer static analyzer. It seems much more strict about dead stores than other analyzers and there were a lot of uninitialized value false positives Most of those false positives fall into two categories: the value was set inside a for() loop which was guaranteed to run for at least one iteration, or the value being set was dependent on another variable. This last case used to cause problems for gcc but they improved their checker to deal with that years ago. I quieted the dead store warnings (hopefully introducing no new bugs in the process) but at this stage, I can't really recommend using Infer for C code if you have Coverity or even the clang analyzer available.

-

Subscribe now

-

Twitter avatar for @BrettCallow
Brett Callow @BrettCallow
A poster at a Russian-language cybercrime forum is concerned that the #Medibank hackers may have killed the market for #ransomware in Australia, and possibly in other countries too.
Image
6:28 PM ∙ Nov 23, 2022
241Likes46Retweets

-

Twitter avatar for @videolan
VideoLAN @videolan
As usual, @Google refuses to take down or unlist domains with tons of malware, impersonating normal software. How are those things a grey area?!?
Twitter avatar for @fcartegnie
François @fcartegnie
If you see a fake @VideoLAN / #VLC download page here, @Google legal thinks it is legitimate enough to refuse to take it offline... https://t.co/NlhDgn5R0b
9:08 PM ∙ Nov 23, 2022
704Likes197Retweets

-

Twitter avatar for @ericgeller
Eric Geller @ericgeller
NATO allies are developing plans to offer cyber services each other in crises. Fick said they could include digital forensics and counter-drone tech.

The pledges will be "concrete and "actually deployable today," he said. "It's not just, 'Oh, we're gonna stand with you.'"

4:38 PM ∙ Nov 23, 2022
11Likes4Retweets

-

Twitter avatar for @mccrabb_will
Will McCrabb @mccrabb_will
I will think about how they did this shot from The Empire Strikes Back on my death bed.
9:33 PM ∙ Nov 22, 2022
83,301Likes8,788Retweets

-

Twitter avatar for @bonehugsnirony
serg @bonehugsnirony
[thanksgiving dinner] mom: no politics tonight everyone: absolutely me: this casserole reminds me of the bolshevik revolution
1:34 AM ∙ Nov 28, 2019
154,260Likes19,669Retweets

-

BBC documentary used face-swapping AI to hide protesters' identities


BBC documentary used face-swapping AI to hide protesters' identities | New Scientist

Filmmakers used an AI to swap the faces of anti-government protesters in Hong Kong for those of actors to protect the protestors' identities while maintaining their facial movements and emotional expressions

-

Twitter avatar for @gf_256
cts @gf_256
Image
3:51 AM ∙ Nov 24, 2021
1,301Likes160Retweets

-

Twitter avatar for @gf_256
cts @gf_256
pick your poison
Image
5:51 AM ∙ Mar 19, 2022
1,394Likes151Retweets

-

Twitter avatar for @AndrewMohawk
AndrewMohawkᴵ'ᵐ ᶠᶦⁿᵉ ᵗʰᵃⁿᵏˢ, ᴬⁿᵈʳᵉʷˀ @AndrewMohawk
Hilarious!
ycamper.medium.comWe Asked 5 Celebrities What Their Favorite Internet-Exposed Dashboard Was, And You’re Not Going To…Where I ask a bunch of celebrities how they find targets to pwn.
5:58 AM ∙ Nov 25, 2022
6Likes2Retweets

-

This is what happens when Katie joins us on Glasshouse. Europe backs down.

The final version of the preliminary draft report concerning spyware/Pegasus/etc is completely cut out of details, previous details about curbs on vulnerability research/trade are purged.

It now says that "the discovery, sharing and exploitation of vulnerabilities have to be regulated".

Unclear how - would they suggest an "EU-approved" seal for zero-day vulns or such products? Obligatory on the box - not made of plastic of course! We have to protect the environment. https://www.europarl.europa.eu/doceo/document/PEGA-PR-738492_EN.pdf


Lukasz Olejnik: "The final version of the preliminary draft report…" - Mastodon

Attached: 1 image The final version of the preliminary draft report concerning spyware/Pegasus/etc is completely cut out of details, previous details about curbs on vulnerability research/trade are purged. It now says that "the discovery, sharing and exploitation of vulnerabilities have to be regulated". Unclear how - would they suggest an "EU-approved" seal for zero-day vulns or such products? Obligatory on the box - not made of plastic of course! We have to protect the environment. https://www.europarl.europa.eu/doceo/document/PEGA-PR-738492_EN.pdf

-

Russian spies have been the theme of the week, been commenting to the media about activity targeting Finland. Overall, there are tens of foreign intelligence officers posted in Finland, and espionage attempts targeting Finland are constant. (Correct English name for our service is Finnish Security and Intelligence Service, bit wrong in the article.) https://yle.fi/a/3-12680851

https://infosec.exchange/@vpk/109403188484005378

-

Don't miss what's next. Subscribe to the grugq's newsletter:
X