back
user profile

dmitrygr

13,816karma·4,955submissions·March 28, 2012
about
I make things and I break things for fun.

me@dmitry.gr

https://dmitry.gr/ long ago: http://palmpowerups.com/

Places we might have crossed paths: VMWare, Google, Apple

recent activity (4,955 total)
comment
In so far as I cook myself? Yes
4mo ago·view thread
comment
We are in violent agreement. And precisely because there is no simple solution to it, half-measures like what is proposed here do absolutely no good, and often times do harm.
4mo ago·view thread
comment
If only somebody could make a firmware that claims to have accepted the update, but then proceeds to not actually update itself. Read out the version string from the update and save it. Show that when…
4mo ago·view thread
comment
Yes. But a lot of people still got cars that were not as represented. So if we follow the same pattern, somebody will go to jail, but most routers will not be running verified or safe code.
4mo ago·view thread
comment
One word for you: dieselgate https://en.wikipedia.org/wiki/Volkswagen_emissions_scandal …
4mo ago·view thread
comment
That proves that the one they checked, had the correct firmware. It does not prove that the one from the next batch that you bought did. We are all technical people here we and understand that there …
4mo ago·view thread
comment
> They have complained that they are paid far less than their colleagues who are on track for tenure. Well, yeah… Lower standard for hiring (try getting a tenure-track position) -> lower pay.
4mo ago·view thread
comment
Self-Funding Bug Bounties strike again.
4mo ago·view thread
comment
problem is: how do you prove the firmware in the flash chip matches source? And I do not mean me, with a disassembler and a pi pico to read out the flash chip. I mean the 70-yaer-old corner shop owner…
4mo ago·view thread
comment
It is the "potentially" that is the problem. Remove that and i am 100% onboard
4mo ago·view thread
comment
I had "PUSH EAX" and "BX LR" :)
4mo ago·view thread
comment
Dropping google for .... > Titan OS operates on a Chromium browser, Google....
4mo ago·view thread
comment
I specified slave specifically because slave is a LOT harder. Master is always easy. Waiting for someone else’s clock and then capturing and replying asap is the hard part. Especially if as a slave yo…
4mo ago·view thread
comment
What are your thoughts on efficiency? BIO vs PIO implementing, say, 68k 16-bit-wide bus slave. I know i can support 66MHz 68K bus clock with PIO at 300MHz. How much clock speed would BIO need?
4mo ago·view thread
comment
You think USA punishes criminals too much?!?! You mean like this? https://komonews.com/news/nation-world/minnesota-judge-sarah... Or like that?? https://www.kiro7…
4mo ago·view thread
comment
very cool. tiny processors everywhere. but be nice to PIO. PIO is good :)
4mo ago·view thread
comment
Yes, my point is that the article throws a lot of shade at PIO while the real issue is that the author is trying to shove a third-party FPGA reimpl of it into a place it never belonged. PIO itself is …
4mo ago·view thread
comment
> Above is the logic path isolated as one of the longest combination paths in the design, and below is a detailed report of what the cells are. which is an argument that "fpga_pio" is bad…
4mo ago·view thread
comment
I am curious how long the approval process in some large corp or the military would be for either of those options... Hand over our private keys to a third party or run this binary written by some vol…
4mo ago·view thread
comment
And the original article shows you how that is going
4mo ago·view thread
comment
This was the predictable outcome of shortening certificate length validity to appoint where they are now.
4mo ago·view thread
comment
It did until it got so short that it created a new potential attack surface — the scripts everyone is using to auto update them.
4mo ago·view thread
comment
No. The sister comment gave the correct answer. It is because nobody checks revocation lists. I promise you there’s nobody out there who can factor a private key out of your certificate in 10, 40, 100…
4mo ago·view thread
comment
Which would make sense if they were valid for 10 years and somebody forgot about them. Not when they’re valid for, what is it now, 40 days?
4mo ago·view thread
comment
Which is yet another chore. And it doesn’t add any security. A certificate expired yesterday proves I am who I am just as much as it did yesterday. As long as the validity length is shorter than how l…
4mo ago·view thread
comment
So what? They keep shortening the validity length of these certificates, making them more and more of a pain to deal with.
4mo ago·view thread
comment
they will do it for unsigned. for signed they will do a bit more to do the same rounding as C promises
4mo ago·view thread
comment
> The new system will have a positive impact both for the EU budget as well as for national public finances Will it though...?
4mo ago·view thread
comment
Yes! Now do the same on beaches, busses, streets. Same punishment: banishment from the area.
4mo ago·view thread
comment
This is too little and too late, but you must give them credit for having the introspection ability to even go this far. Yes, the bar for microsoft is so low as to be handicap-accessible.
4mo ago·view thread