Power usage is also very reasonable! 400GE switches and routers pull a ridiculous amount of power.
"there was a correction issue" is downplaying it. Etcd is truly the worst example of Raft. Etcd corruption and loss of quorum is extremely common in practice and the GitHub issues sit for years. The design is simple,…
Not speaking to their code, but to start GoBGP has the worst performance of any BGP daemon by a large margin [1]. [1] https://elegantnetwork.github.io/posts/comparing-open-source...
I don't think iPhone Upgrade Program was ever the best deal to be honest. It's just convenient.
I stand corrected! This doesn't look too bad then.
The Apple Upgrade lease model isn't even a replacement as you have to wait 24 months before upgrading. The entire point of the iPhone Upgrade Program was to make it painless to swap to the newest iPhone every year.…
You'd be surprised to know that this strategy works quite well! Pixel bots require a hardware fake display when faced with kernel anti-cheat. They also depend on color/pattern recognition, as AI is not yet capable of…
Aimbot is actually very solvable! 1) When DMA is fully blocked, Aimbot resorts to being a pixel bot. 2) Once you're relying on a pixel bot, all the anti-cheat has to do is "bait" the bot. After you click the bait a few…
> "How come replay analysis doesn’t catch more cheaters?" 1) There's too many players. 2) Closet cheaters are extremely subjective: automated & manual moderation would be full of false positives. In these cases,…
I feel someone doesn't need to play competitive games to be able to give an honest assessment of the privacy & security risks. I'm sad I'm not seeing that honesty elsewhere in this thread.
At least in Valorant, DMA is becoming impossible due to IOMMU / Memory Integrity enforcement. The only option is becoming pixel bots. As for faking the input device: I'm sure it's possible, but I'm also sure that…
In my opinion, the debate about kernel anti-cheat on Windows is disingenuous fear-mongering. I'm confused why Hacker News of all places misrepresents the technical details. You can already completely compromise the…
That's a different type of game entirely. Private/community servers cannot be competitive at the scale of modern competitive games.
This isn't possible in Valorant. Their kernel module is extremely particular about input devices: 1) only allows a single mouse input device at a time 2) completely ignores virtual mouse input 3) flags…
I don't disagree. Clarifying, I personally don't think this exploit is a backdoor, but rather that the negligence is enough to appear malicious. Just for fun (not saying I believe this!): Did you ever consider that a…
If the device does not have BitLocker, WinRE already by default provides full Administrator access to the unencrypted disk via Command Prompt. > I think that level of pushback against the claims is a valid (and small)…
If the device doesn't have BitLocker, this exploit is pointless because you can already boot any OS USB and immediately have full access to the unencrypted disk. This exploit is only ever relevant with BitLocker enabled…
1) Except that the entire premise behind BitLocker TPM's security relies on the login screen as a hard security boundary, and thus any attack on the login screen is an attack on BitLocker. It is semantics to dispute…
Considering the researcher had already reported these to Microsoft, and delayed releasing them publicly until Microsoft "pulled every childish game possible" (quote) instead of patching them, it's not unreasonable for…
What's with all the replies on these threads downplaying this? Why is it mainly brand new accounts? What's going on here? I've seen every variant of: 1) "this is an authentication/privilege escalation bug, not a…
That’s quite a stretch, to say the least.
But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happens. Microsoft goes beyond that: they've…
I knew there was another incident that I was forgetting, insanity... I don't understand how Microsoft keeps getting away with this and everyone just forgets.
Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for…
I'd use WireGuard in that case. The main reason WireGuard is popular at all is because it is approachable. IPsec is much more complicated and is designed for network engineers, not users.
Power usage is also very reasonable! 400GE switches and routers pull a ridiculous amount of power.
"there was a correction issue" is downplaying it. Etcd is truly the worst example of Raft. Etcd corruption and loss of quorum is extremely common in practice and the GitHub issues sit for years. The design is simple,…
Not speaking to their code, but to start GoBGP has the worst performance of any BGP daemon by a large margin [1]. [1] https://elegantnetwork.github.io/posts/comparing-open-source...
I don't think iPhone Upgrade Program was ever the best deal to be honest. It's just convenient.
I stand corrected! This doesn't look too bad then.
The Apple Upgrade lease model isn't even a replacement as you have to wait 24 months before upgrading. The entire point of the iPhone Upgrade Program was to make it painless to swap to the newest iPhone every year.…
You'd be surprised to know that this strategy works quite well! Pixel bots require a hardware fake display when faced with kernel anti-cheat. They also depend on color/pattern recognition, as AI is not yet capable of…
Aimbot is actually very solvable! 1) When DMA is fully blocked, Aimbot resorts to being a pixel bot. 2) Once you're relying on a pixel bot, all the anti-cheat has to do is "bait" the bot. After you click the bait a few…
> "How come replay analysis doesn’t catch more cheaters?" 1) There's too many players. 2) Closet cheaters are extremely subjective: automated & manual moderation would be full of false positives. In these cases,…
I feel someone doesn't need to play competitive games to be able to give an honest assessment of the privacy & security risks. I'm sad I'm not seeing that honesty elsewhere in this thread.
At least in Valorant, DMA is becoming impossible due to IOMMU / Memory Integrity enforcement. The only option is becoming pixel bots. As for faking the input device: I'm sure it's possible, but I'm also sure that…
In my opinion, the debate about kernel anti-cheat on Windows is disingenuous fear-mongering. I'm confused why Hacker News of all places misrepresents the technical details. You can already completely compromise the…
That's a different type of game entirely. Private/community servers cannot be competitive at the scale of modern competitive games.
This isn't possible in Valorant. Their kernel module is extremely particular about input devices: 1) only allows a single mouse input device at a time 2) completely ignores virtual mouse input 3) flags…
I don't disagree. Clarifying, I personally don't think this exploit is a backdoor, but rather that the negligence is enough to appear malicious. Just for fun (not saying I believe this!): Did you ever consider that a…
If the device does not have BitLocker, WinRE already by default provides full Administrator access to the unencrypted disk via Command Prompt. > I think that level of pushback against the claims is a valid (and small)…
If the device doesn't have BitLocker, this exploit is pointless because you can already boot any OS USB and immediately have full access to the unencrypted disk. This exploit is only ever relevant with BitLocker enabled…
1) Except that the entire premise behind BitLocker TPM's security relies on the login screen as a hard security boundary, and thus any attack on the login screen is an attack on BitLocker. It is semantics to dispute…
Considering the researcher had already reported these to Microsoft, and delayed releasing them publicly until Microsoft "pulled every childish game possible" (quote) instead of patching them, it's not unreasonable for…
What's with all the replies on these threads downplaying this? Why is it mainly brand new accounts? What's going on here? I've seen every variant of: 1) "this is an authentication/privilege escalation bug, not a…
That’s quite a stretch, to say the least.
But it doesn't. Full authentication bypass exploits are extremely rare and unheard of among tech giants. Maybe account takeover/recovery, sure, but full bypass? It just never happens. Microsoft goes beyond that: they've…
I knew there was another incident that I was forgetting, insanity... I don't understand how Microsoft keeps getting away with this and everyone just forgets.
Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for…
I'd use WireGuard in that case. The main reason WireGuard is popular at all is because it is approachable. IPsec is much more complicated and is designed for network engineers, not users.