Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

:nsavince:

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



more of a lomarf than secfuck but still good

quote:

5. Within the port range, enter the starting port and the ending port to forward. For the Nintendo Switch console, this is port 1 through 65535.
6. Set the protocol as UDP.

Bulgogi Hoagie
Jun 1, 2012

We
group messaging with strong security guarantees is coming

https://twitter.com/sweis/status/950523137468153857

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

...wat.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).


Nintendo official help site is telling you to configure your home router to forward every single udp packet directly to the switch. just really let yourself bathe in the filth of the internet.

SO DEMANDING
Dec 27, 2003

mrmcd posted:

Nintendo official help site is telling you to configure your home router to forward every single udp packet directly to the switch. just really let yourself bathe in the filth of the internet.

ok so raw water but internet instead

Schadenboner
Aug 15, 2011

by Shine

SO DEMANDING posted:

ok so raw water but internet instead

dsyp

Linguica
Jul 13, 2000
You're already dead

eschaton posted:

seems like at very least they’re incurring some amount of civil liability: if Alice discloses a 0-day and Bob gets compromised by it, I expect Bob would prevail when suing Alice for negligence, if he can show a connection between Alice’s publication and his subsequent compromise (such as comments in exploit code referencing her publication)

one could even say that at the scale at which these things affect us, Alice could conceivably be charged criminally: a security researcher should be reasonably expected to know that publishing a flaw will result in quite rapid exploit development and use, so publishing a 0-day could be construed as criminal negligence

am I off base here?
I think so, maybe. The rules of negligence almost never extend to instances when a third party is committing an unlawful act (e.g. hacking your poo poo). The times when they do are considered exceptional and don't really follow a strict pattern.

pseudorandom name
May 6, 2007

Carbon dioxide posted:

They loving changed the result by measuring it.
Bugfix by applied quantum mechanics.

The more I read about Spectre, the more I am getting convinced that real life quantum mechanics are just a result of the universe speculatively executing potential parallel realities.

I appreciate the sentiment, but they didn't change the result by measuring it, they changed the result by changing ever broken prefetch instruction into a breakpoint instruction.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

why would GPU drivers need to be updated with fixes for Meltdown and Spectre?

pseudorandom name
May 6, 2007

do they JIT untrusted bytecode to x86?

because that's a really easy way to do Spectre variant 1.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

oh, probably, yeah

I wonder about Meltdown though

pseudorandom name
May 6, 2007

which GPU driver is this?

Evis
Feb 28, 2007
Flying Spaghetti Monster

I’d guess it would be the kernel running on the GPU needing an update?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

pseudorandom name posted:

which GPU driver is this?

NVIDIA’s latest, I believe

pseudorandom name
May 6, 2007

well, Linux is breaking the driver ABI as per usual, but I have no idea why they'd do a Windows release

Shifty Pony
Dec 28, 2004

Up ta somethin'


Subjunctive posted:

why would GPU drivers need to be updated with fixes for Meltdown and Spectre?

perhaps it might be less a Meltdown/Spectre fix and more a fix to prevent the MS fix from causing performance drops or errors?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shifty Pony posted:

perhaps it might be less a Meltdown/Spectre fix and more a fix to prevent the MS fix from causing performance drops or errors?

what could they do to change the performance characteristics? they’re already designed to minimize kernel transitions, AFAIK

pseudorandom name
May 6, 2007

unrelated, but talking about Windows reminded me -- does Microsoft have any kind of pure software mitigation for Spectre variant 2 or are they just relying on Intel's microcode update?

Shifty Pony
Dec 28, 2004

Up ta somethin'


Subjunctive posted:

what could they do to change the performance characteristics? they’re already designed to minimize kernel transitions, AFAIK

an edge case perhaps?

I'm really just guessing here. it is also possible they didn't change a drat thing and this driver set had just been run through tests on updates systems.

Trabisnikof
Dec 24, 2005

pseudorandom name posted:

do they JIT untrusted bytecode to x86?

because that's a really easy way to do Spectre variant 1.


Subjunctive posted:

oh, probably, yeah

I wonder about Meltdown though

My guess is it fixes spectre and they didn't want to say it didn't fix meltdown because people would assume the meltdown patch was still incoming and freak

pseudorandom name
May 6, 2007

device drivers aren't involved with Meltdown at all

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Could be some kind of protections to prevent cuda/opencl from being used as a vector for a meltdown attack similar to the browser-based mitigations

Potato Salad
Oct 23, 2014

nobody cares


SO DEMANDING posted:

ok so raw water but internet instead

This is raw sewage

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

mrmcd posted:

Nintendo official help site is telling you to configure your home router to forward every single udp packet directly to the switch. just really let yourself bathe in the filth of the internet.

Yeah, I get that

but it just stunned me I wasn’t really expecting "port forward loving everything "

my networking knowledge is still nascent, would doing that gently caress up other port forwards you might require for other equipment?

Shame Boy
Mar 2, 2010

Avenging_Mikon posted:

Yeah, I get that

but it just stunned me I wasn’t really expecting "port forward loving everything "

my networking knowledge is still nascent, would doing that gently caress up other port forwards you might require for other equipment?

it would gently caress up quite a lot more than that but yes

cinci zoo sniper
Mar 15, 2013




what was thread consensus on telegram? im trying it out as a whatsapp replacement for sending cat photos to relatives and stupid jokes to friends and it seems ok + im happy to share less with facebook even if that means sharing more with less overreaching vk/kgb/whatever

suffix
Jul 27, 2013

Wheeee!

mrmcd posted:

Basically the embargo was lifted early because people were repro-ing the exploit and posting about it publicly on Twitter. Well... https://arstechnica.com/gadgets/2018/01/meltdown-and-spectre-heres-what-intel-apple-microsoft-others-are-doing-about-it/


Granted, almost all I know is from that ars article but no one's really pushing back against that assertion.

were they really expecting amd to take a knife for intel and accept the meltdown performance hit on unaffected systems though

Progressive JPEG
Feb 19, 2003

cinci zoo sniper posted:

what was thread consensus on telegram? im trying it out as a whatsapp replacement for sending cat photos to relatives and stupid jokes to friends and it seems ok + im happy to share less with facebook even if that means sharing more with less overreaching vk/kgb/whatever

just use signal

Wiggly Wayne DDS
Sep 11, 2010



Progressive JPEG posted:

just use signal

cinci zoo sniper
Mar 15, 2013




Progressive JPEG posted:

just use signal

i wont get anyone there and dont care that much i think, but yeah ive heard of signal and tox, especially of signal itt. i wouldnt care much more than whatsapp either, but i really dont like that they were acquired by facebook

on that note, apparently russian linux community has some homegrown messenger that needs in-person meeting with mutual qr code scanning to add someone to your contacts. :eyepop:

Cybernetic Vermin
Apr 18, 2005

cinci zoo sniper posted:

i wont get anyone there and dont care that much i think, but yeah ive heard of signal and tox, especially of signal itt. i wouldnt care much more than whatsapp either, but i really dont like that they were acquired by facebook

on that note, apparently russian linux community has some homegrown messenger that needs in-person meeting with mutual qr code scanning to add someone to your contacts. :eyepop:

this sort of thing has been a lug staple as long as long as there has been lugs

it is clearly very tricky for people to inhabit the middle ground between "does not know or care about security at all" and "i need a stronger quantum guarantee on the randomness of my otps in case there exists a parallel dimension where a mustachioed version of me may have rolled these dice in the same way i did and now wants to read my spam email through a wormhole"

cinci zoo sniper
Mar 15, 2013




Cybernetic Vermin posted:

this sort of thing has been a lug staple as long as long as there has been lugs

it is clearly very tricky for people to inhabit the middle ground between "does not know or care about security at all" and "i need a stronger quantum guarantee on the randomness of my otps in case there exists a parallel dimension where a mustachioed version of me may have rolled these dice in the same way i did and now wants to read my spam email through a wormhole"

i completely don't get the first line

Truga
May 4, 2014
Lipstick Apathy
linux user group

cinci zoo sniper
Mar 15, 2013




Truga posted:

linux user group

ah, i was thinking of verb "lug" and completely overthinking this :cripes:

Truga
May 4, 2014
Lipstick Apathy
yeah, it took me a moment too.

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

Progressive JPEG posted:

just use signal

Shame Boy
Mar 2, 2010

i use telegram because nobody else in the world seems to use signal and it works "fine" but i don't trust the security or anything

the answer is to use whatever your friends are already using because you're not going to get them to switch to your special snowflake messenger just cuz

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"
i've gotten people to use whatsapp, which they had at least heard of before even if they hadn't used it. signal, though, they "don't know anybody on."

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

whatsapp suits needs but its stubborn insistence on not working if it doesn't think my phone's online is annoying

  • Locked thread