topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Saturday June 21, 2025, 9:28 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Recent Posts

Pages: prev1 ... 28 29 30 31 32 [33] 34 35 36 37 38 ... 403next
801
Living Room / Re: Looking for audio merger Y-cable
« Last post by wraith808 on March 13, 2020, 01:41 PM »
Yeah, that first one wouldn't.  You're trying to combine Stereo into mono, so just reversing the cables won't work. That second one is what I've used in the past.
802
Living Room / Re: Interesting "stuff"
« Last post by wraith808 on March 11, 2020, 07:10 PM »
Wash your Lyrics

https://washyourlyrics.com/

Generate hand washing infographics based on your favourite song lyrics
803
dc_post.jpg

'Unfixable' boot ROM security flaw in millions of Intel chips could spell 'utter chaos' for DRM, file encryption, etc
from The Register

The short version here:
A new vulnerability has been discovered in Intel's Converged Security and Manageability Engine (CSME), the embedded system that oversees management of Intel system chipsets (not processors, this time). The vulnerability is a DMA race that potentially allows hostile code to overwrite memory in the embedded management engine before the management engine enables memory protection on its own memory space. Key to the vulnerability is the fact that this memory protection is disabled by default until and unless the management engine enables it — i.e, it is unsafe by default, and fails unsafe.

During that timing gap, other hardware – physically attached or present on the motherboard – that is able to fire off a DMA transfer into the CSME's private RAM may do so, overwriting variables and pointers and hijacking its execution. At that point, the CSME can be commandeered for malicious purposes, all out of view of the software running above it.

The vulnerability is exploitable whenever the chipset is starting up. The chipset is vulnerable from the time the CSME boot ROM first initializes the memory page direvctory, up until the IOMMU (Input/Output Memory Management Unit) is turned on. Critically, this occurs not only at system boot time, but every time the CSME or the IOMMU resets.

What this means is that every time the CSME comes out of sleep mode, or any time the CSME is reset, it is briefly vulnerable to attack.

The CSME provides, among other things, something called Enhanced Privacy ID, or EPID. This is used for things like providing anti-piracy DRM protections, and Internet-of-Things attestation. The engine also provides TPM functions, which allow applications and operating system software to securely store and manage digital keys for things like file-system encryption. At the heart of this cryptography is a Chipset Key that is encrypted by another key baked into the silicon, and you can't do too much damage, it seems, until you can decrypt the Chipset Key.

If someone manages to extract that hardware key, though, they can unlock the Chipset Key, and, with code execution within the CSME, they can undo Intel's root of trust on large swathes of products at once, we're told.

"To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov.

"However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key generation mechanism in the SKS is locked, and the ROM vulnerability cannot be fixed, we believe that extracting this key is only a matter of time.

"When this happens, utter chaos will reign. Hardware IDs will be forged, digital content will be extracted, and data from encrypted hard disks will be decrypted."
804
So close enough to a Bot that it might as well be one.  ;D :huh: :-\ :down:
805
Is there no content because your browser removed it?  I've seen that happen before.  On the site, it's showing as 4.8MB so there definitely should be something inside it.  I downloaded it, and there's something there.  I'm scanning it now.

UPDATE: Nothing found in it, and mine definitely had the files for the portable AHK in it.

UPDATE2: So apparently the owners of the Autohotkey site have to report it for google to fix it according to https://developers.g...acked/request_review.  I was thinking about reporting it at https://safebrowsing...eport_badware/?hl=en and putting in the comments that it's not malicious, but not sure if that would get in the way of the process.
806
I didn't think it was a twitter client from looking at it, but rather an automated way to post to different social media.
808
A new option to take a look at: https://casual-effects.com/markdeep/
809
Post New Requests Here / Re: Windows Launcher by Only One Key
« Last post by wraith808 on February 25, 2020, 05:02 PM »
It's funny- malwarebytes blocks that Qsel site, but virustotal shows it as clean from malwarebytes
810
I wonder what would happen if that errant piece that the hash is different on was just excluded?
811
What hasn't been looked it is do both clips restore correctly when pasted somewhere that is supposed to be able to interpret the data?
812
Living Room / Re: Thread on 3d Printing Cody Model
« Last post by wraith808 on February 20, 2020, 11:29 AM »
Very nice!

cody1.jpg

cody2.jpg
813
General Software Discussion / Re: Windows 10 Announced
« Last post by wraith808 on February 20, 2020, 10:46 AM »
Yes, you can customize the pinned tiles, but the actual menu, you can only remove sub-sections.  If I actually ever used the start menu, it would be a bit lackluster.  But I think that they're trying to get people to use search more, as when I do use the start menu, I just start typing the name of the item that I want, and it works.
814
Post New Requests Here / Re: Windows Launcher by Only One Key
« Last post by wraith808 on February 16, 2020, 01:59 PM »
I think in the implementation that he's showing you remember the key for the item.  Still seems like a lot to me.
815
Living Room / Re: Interesting "stuff"
« Last post by wraith808 on February 15, 2020, 04:03 PM »
UK police deny responsibility for poster urging parents to report kids for using Kali Linux

Even worse is that Discord is on there. Discord is very popular amongst the gaming community for chat, voice chat, and similar gaming related activities.

And writing groups, TTRPG/Board Game Groups, Mechanical Keyboard groups, etc, etc.  To say that a platform for chat, etc, is a symptom that your child may be into hacking is incredibly irresponsible.
816
General Software Discussion / Re: Windows 10 Announced
« Last post by wraith808 on February 15, 2020, 01:52 PM »
Just the shell that comes with Windows.  It's capable enough.  For my programs, I use True Launch Bar and Fences.
817
Living Room / Re: Thread on 3d Printing Cody Model
« Last post by wraith808 on February 14, 2020, 11:36 PM »
Mine did today!  I'll try to get a picture up tomorrow!
818
Living Room / Re: Do good mice still exist? Looking for recommendations.
« Last post by wraith808 on February 14, 2020, 11:35 PM »
Ouch. :P


My Logitech G900 Chaos is holding up pretty well, though to be honest, I haven't had an problems with any of their mice.
819
Living Room / Re: Do good mice still exist? Looking for recommendations.
« Last post by wraith808 on February 13, 2020, 10:37 PM »
And I liked it well enough until a couple years later I started having issues which indicate that the microswitch is failing in the mouse button(s).

1. Sometimes a click doesn't register at all.
2. Sometimes a single click registers as a double click.
3. Sometimes a click & drag registers as a single click & release.

I think that's the problem statement.
820
General Software Discussion / Re: Annoying Brave browser 'brave rewards' pop-ups
« Last post by wraith808 on February 13, 2020, 10:35 PM »
The BAT is one of the reason that a lot of people are drawn to the browser and one of the features, so I guess it depends on their focus.
821
General Software Discussion / Re: Annoying Brave browser 'brave rewards' pop-ups
« Last post by wraith808 on February 13, 2020, 02:00 PM »
I found Brave Rewards Settings and turned off the pop-up; but now my 'new' home page has a purple nag-tag picture that begs me to turn it back on. Why do companies of great products insist on ripping off or otherwise annoying their loyal patrons? This is getting old fast. I wonder how popular (as in 'un-') the obnoxious Sales staff is with the rest of Brave's crew.


Glad that Deo got it for you... but Patron?  Sales?  Last I checked, the browser was free...
822
Funny comic. :P

But it's gotten me curious: How come it's so trendy to hate on PHP so much? Is there a succinct explanation on what's wrong with PHP? Seems like a walk in the park next to something like the nightmare working in JavaScript has become.

To me Javascript and PHP have the same downside- it's a pain debugging it.  It's gotten better, but that's the only real difference to me- I hate working in both of them.
823
Now that was funny!
824
Living Room / Re: Animal Friends thread
« Last post by wraith808 on February 08, 2020, 12:52 PM »
Poor doggy legs.  Though I guess the same can be said for any athletic activity by anyone.
825
Skwire Empire / Re: SigcheckGUI
« Last post by wraith808 on February 08, 2020, 12:51 PM »
Probably the real question being that should be asked here is whether or not SigCheckGUI works with the 64-bit version of SigCheck. :P


Deo asking the real question.  Though I altered it a bit  :Thmbsup:
Pages: prev1 ... 28 29 30 31 32 [33] 34 35 36 37 38 ... 403next