Principal Engineer at Amazon. QEMU enthusiast. Enjoys working on KVM/Virtualization, Emulation, RE, Booting, Security, s390x, PowerPC, ARM. @agraf@fosstodon.org
auth bypass confirmed!
> INFO:paramiko.transport:Authentication (password) successful!
mm_keyallowed_backdoor cmd 1 allows to override the response for mm_answer_authpassword with a custom one. if you set it to { u32(9), u8(13), u32(1), u32(0) } you can login with any pass 🤓
Amazon EC2 now supports AMD SEV-SNP
Amazon EC2 now supports AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP), a feature on AMD EPYC™ processors, on M6a, C6a, and R6a instance types. The availability of AMD SEV-SNP in EC2 furth... aws.amazon.com/about-aws/wha…
Spot on by @joshuaseattle. Out of AWS, GCP and Azure, only AWS guarantees that their zones are 3 (or more) physically separate DCs. Turns out for Google, even a region isn’t physically separate!
On paper both GCP and Azure have more zones & regions than AWS: but in practice…
TLDR: Both Google and Microsoft don't guarantee that all zones are physically separate buildings or separated by at least <x> km/miles. Many of their "zones" in smaller regions are just separate buildings by the same DC facility
A process is a purposeful bottleneck.
It directly limits ownership by moving decision-making from the individual, to the organization. It limits the ownership and actions of great hires, and limits the downside of poor hires.
scarletink.com/creating-proc…
If you're a software engineer, your main job is maintaining legacy code.
Why? Because building a system doesn't take long, in comparison to how long code will last, assuming the code/business are successful.
Here are the 10 commandments of maintaining legacy code.
🧵
Wheee. QEMU 8.0 will support hosting Xen guests, but under Linux/KVM instead of actual Xen.
qemu-project.gitlab.io/qemu/…
We've already used it to find and fix guest kernel regressions that would otherwise have needed a full Xen setup to test and reproduce.
We recently found a vulnerability affecting Hyundai and Genesis vehicles where we could remotely control the locks, engine, horn, headlights, and trunk of vehicles made after 2012.
To explain how it worked and how we found it, we have @_specters_ as our mock car thief:
Same offer here: I have an extra bed in the Hilton Garden Inn Dublin from 11th until 15th that I'm happy to share with anyone who didn't manage to snatch one yet 😀. Please DM me if you're interested.
And if someone now suddenly needs a hotel bed in Dublin for @linuxplumbers or has one to offer, see the "Hotel room sharing" page (editable by anyone with an account) lpc.events/event/16/contribu…
Russian soldiers make ~6k€ per year. Ukraine gets 500M€ from the EU for this war. Can't UA just send push messages to every Russian phone logged into UA mobile networks saying "We give you 10k€ and a new passport if you desert. Reply to this number for instructions"?