Jump in the discussion.

No email address required.

I'm still unsure if this is only keys in regular application memory (e.g. you run a https server on your Mac and now a malicious actor can grab the secret keys in memory) or if this also applies to Secure Enclave keys.

The former is bad but not alarm bells ringing (to me), the later is the worst exploit that could happen.

!codecels


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

In theory it should require direct access to your machine and time. Having read the white papers, more likely than not, its all keys including secure enclave keys

Jump in the discussion.

No email address required.

How are they extracting the key data from the Secure Enclave if they don't touch the memory?


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

The video explains it in the later bits, he whiteboards it then does a proof of concept.

Jump in the discussion.

No email address required.

whoops, I had it assumed it was a clickbait "news" channel - didn't realize this guy was legit :marseyteehee:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Its a little hard to follow if you dont watch from about the beginning. Hes really good actually. Around the 15 minute mark he really starts diving in.

https://i.rdrama.net/images/17112537206103685.webp

https://i.rdrama.net/images/17112537208249042.webp

Jump in the discussion.

No email address required.

secure enclave is the antichrist

Jump in the discussion.

No email address required.

You think? I get that it can be leveraged for DRM but I think it's ultimately a useful tool.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Is this the Bluetooth meme still?

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Holy FRICK

Jump in the discussion.

No email address required.

>CIA backdoor found

@BigBussyHunter is going too fedpost

:#marseyfedseydealwithit:

trans lives matter too spooks

Jump in the discussion.

No email address required.

lol is that C++? Wait are you binding that with Python?! Imagine using those over Rust. As a proud Rustacean and Ferris the Crab adorer, I regret to inform you that your taste in languages sucks. This is sad. You can do better. You know how easy package and dependancy management is with Cargo? Not to mention you don't even need a Makefile. It's great. Dynamically typed languages need to die. There's no other option. They just do. If you like dynamic typing, you need some help. Seriously. By using a dynamically typed and interpreted language (which means its @#*!&!@ slow!!!), you are committing genocide and harming the environment more than gas cars. Rust is fast and uses clean, renewable energy through the magic of being a language compiled with LLVM. Tired of memory bugs? You should be. Shame on you for still having them when Rust exists. Tired of being bad? Time to go to Rust. Tired of being slow because you're not smart and your friends laugh at you? Rust is quite speedy indeed (all thanks to the big brain of the compiler). Tired of not getting off the normal way? Match statements, loops, and the compiler for Rust give the best orgasms 10/10 (completely legit). Not to mention the superiority you get to feel when you show off your superior Rust code to your inferior “friends” still using some other language. Want to get rid of malware? Rust is safe, therefore malware is noware (also completely legit). You quite honestly will forget about any other language (including English because it's slow and unsafe). You even get to add the Rust Book and its brothers to your Bible collection alongside the Arch and Gentoo Wikis. All hail Rust. TempleOS pales in religious comparison to the faith of Rustaceans. Graydon Hoare is Jesus. Amen.

Snapshots:

:

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.