Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)WA
Posts
8
Comments
177
Joined
2 yr. ago

  • Well the pixel 8 will be supported for quite a while, for now you've tried all the things you can but if you prevent it from updating maybe they'll publically patch an exploit you can use to gain root. I think Verizon in particular does this because they eat a lot of the cost for the phone and lock you into using their network, they want that cost recouped but since they're not legally required to unlock it after they recoup their cost they will do nothing. They should legally be required to allow bootloader unlocking after they stop supporting it but regulators are too busy inventing reasons for us poors to hate eachother.

  • So, the supply chain affected wasn't wordpress source but git repos of other malicious tools used to attack stuff, like wordpress. They stole from people stealing stuff. The headline makes it seem like the wordpress source was compromised.

  • Here's microsoft's info: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49071

    MS says they mitigated it without user intervention. Allegedly someone with privileges for Windows Defender could access an index file and send file contents over a network. I couldn't tell if the file contents were just the index itself or file contents from elsewhere on the machine but I think it's the former.

    Anyway, MS says it's fixed and pay no attention to the man behind the curtain.

  • Looks like AMD has already patched it, also appears to affect older Intel versions of the same tech concept but not current generations.

    Only really affects guests in multi tenant hypervisor environments, requires physical access to the hypervisor, requires external physical hardware, requires booting the host with said hardware attached, at some point this level of compromise is already absurd. This kind of research is important and shows that we still need to limit out level of trust with host providers but I don't think anyone needs to panic.

  • Permanently Deleted

    Jump
  • You're right, the thing that would work is if governments held them accountable, but governments have sided with the CEOs instead. These CEOs should beg the government to hold them accountable so that they don't have to fear the masses.