Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)PA
Posts
0
Comments
204
Joined
2 yr. ago

  • Already fixed, in software that's existed for years and is used by millions. But Oh no, memory issues, let's rewrite that in

    <language of the month>

    ! will surely result in a better outcome.

    Rsync is great software, but the C language fates it to keep having memory issues in spite of its skilled developers.

    Preventing a bug from being possible > fixing a bug.

  • I fear moving away from GPL that moving to Rust seems to bring, but Rust does fix real memory issues.

    Take the recent rsync vulnerabilities for example.

    https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/#more-2215

    At least this one in a Rust implementation of rsync would have very likely been avoided:

    CVE-2024-12085 – A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. Info Leak via uninitialized Stack contents defeats ASLR.

  • Sadly I found out yesterday:

    Matrix is not a community-based software, it was born [00] in Amdocs [01], a multinational corporation founded in Israel.

    https://hackea.org/notas/matrix.html

    Many were claiming its impossible to get contributions merged as well.

    I would be happy to find out this information is wrong or outdated.

  • I wouldn't be surprised to find out its true.

    The problem is it shouldn't be a blight because its impossible to prevent bad actors from using an actually private and secure messaging app.

    So the act of reporting on it is a smear because most don't understand or acknowledge the impossibility of preventing those bad actors.