Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

pfSense / Wireguard / Bad Code / Close Call

By itss | 26/03/2021
0 Comment

A nice write-up of how a whole bunch of bad code very nearly ended up in FreeBSD 13 due to several bad calls on the part of pfSense. https://arstechnica.com/gadgets/2021/03/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call/

Category: Technology
Post navigation
← Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur) A Nice Little Cryptography Primer →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide
    by EditorDavid on 21/09/2026 at 5:34 am

    "I would like to verify your technical abilities, so please download the specified file and complete the assigned task..." Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage... The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said. The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said. The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.." Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible." The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities." Read more of this story at Slashdot.

  • Lawsuit Says Anthropic, OpenAI, SpaceXAI And Google Made Illegal Agreement On AI Slowdown
    by EditorDavid on 21/09/2026 at 1:04 am

    Tom's Hardware reports: Four plaintiffs subscribed to ChatGPT, Claude, Grok, or Gemini filed a proposed class-action lawsuit alleging that the developers of these AI models violated antitrust laws when they agreed to slow AI development. According to the Associated Press, the lawsuit argues that this agreement would "reduce the value consumers get for paid AI subscriptions" and that this coordination started in July 2026 after the leading AI labs signed a statement admitting there is "intense competitive pressure not to unilaterally slow" development. The plaintiffs recognize the need for AI development to slow for the sake of safety, but they say that Anthropic founder Dario Amodei's cooperation proposal is a "shortcut" that "substitutes collective restraint for individual accountability." Attorney Nick Rowley, the lead counsel for the plaintiffs, says, "AI will quickly spin out of human control and could kill us all if we allow AI safety and protocol ... to be controlled by private self-serving agreements between the world's most powerful 'for profit' technology companies." "Representatives for Anthropic, OpenAI, Google and SpaceXAI did not immediately respond..." reports the Associated Press: The coordination largely took place on Sept. 12, the lawsuit argues, when Anthropic CEO Dario Amodei published an essay urging for industrywide cooperation on decelerating advancements in favor of enhanced safety measures. That same day, OpenAI CEO Sam Altman, SpaceXAI CEO Elon Musk and Google DeepMind's co-founder and chair Demis Hassabis each publicly responded to Amodei's proposals in agreement. But the lawsuit also alleges that the coordination began to take shape months earlier. It points to a statement from July 2026 that high-ranking employees from several of the leading AI labs signed that acknowledged the "intense competitive pressure not to unilaterally slow" development. That statement called on the government to support a global effort to slow automated AI development. Sam Altman even specificially said "we do not believe we need to wait for an antitrust exemption or legislation to begin the work of providing this confidence," notes Tom's Hardware. However, the Trump administration shot down this idea... Chinese state media also criticized this announcement, saying that the call to put the brakes on AI development is nothing but a response to Chinese competition, especially as Amodei's essay explicitly mentioned the desire to slow China's progress and widen the U.S.'s gap over Beijing Read more of this story at Slashdot.

  • Democracy vs Digital Infrastructure: Pulitzer-Winning Journalist Charts 'The Rise and Fall of the Artificial State'
    by EditorDavid on 20/09/2026 at 8:34 pm

    The Rise and Fall of the Artificial State ultimately asks the question, "How did we cede control of our democracy to the machines, and can we get it back?" according to the Harvard's Arts and Sciences site, FAS Current: The new title finds Lepore, who used to teach a course at the College titled "The Rise and Fall of the Machine," charting the ascent of what she calls the artificial state: the digital communication infrastructure by which governments and private corporations automate and ultimately control public discourse. Following her Pulitzer Prize win for "We the People: A History of the U.S. Constitution" (2025), "I wanted to think about whether liberal constitutional democracies can survive this moment in time," Lepore shared in a phone interview... [In the "current ChatGPT moment"] Lepore found herself asking: "Who are the people who are clamoring to be replaced by machines, to have movies made by machines, and novels written by machines?" And who, she continued, is pushing for our government to be determined by these machines? In the book, Lepore notes that technological tools are increasingly influencing elections around the world... However, she sees the 2026 U.S. midterms as an inflection point. In a recent piece in the Financial Times, Lepore wrote, "This year marks the first AI election. Voters are asking chatbots how they should vote. Campaigns and activists are using AI to analyze the electorate, send micro-targeted messages, produce tailored ads and even deepfakes...." Lepore stresses in the book that "nobody should trust historians to make predictions," but she believes it's possible for democratic citizens to wrest back control. Referencing proposals such as New York's data center moratorium law, Lepore ends by describing a "growing and increasingly noisy tech backlash." "It's not foreordained. This isn't inevitable," she said during the interview. "In the book's epilogue Lepore predicts, as her title suggests, a fall of the Artificial State," writes the California Review of Books. "That argument turns out to be speculative, much more of a hope than a certainty." [Lepore] does support her prediction by positing that the Artificial State is "poorly designed and badly built," that it has not given people safety and happiness but rather a prison of glowing screens, and that a majority of Americans want more control over AI. To escape the Artificial State we will have to imagine a different future by gaining more knowledge of the past in a search for meaning. Of course, powerful forces want to deny that and turn us into servile automatons. The Guardian adds that "While Lepore interprets much classic sci-fi, such as Isaac Asimov, as cautionary, she observes that "the architects of the Artificial State seem to have read these stories, unironically, as instruction manuals, guides for how to build robots that would one day rule the world". (The Atlantic writes that "What one gathers from these misreadings is not so much that science fiction itself is nefarious, but that arrested development might be...") But The Indian Express writes that despite the author's bleak conclusion, "Lepore is not a pessimist. Because the Artificial State is a construct, neither alive, nor truly indestructible, she argues it is still possible to take it apart... [T]his is a clear-eyed reckoning rather than a doomsday tract. It is not an easy read, but an essential one for anyone unsettled by the pace of the AI wave." Read more of this story at Slashdot.

  • The Brain Is Actually Two Completely Separate Organs
    by EditorDavid on 20/09/2026 at 4:04 pm

    "New research led by Stanford Medicine reveals that what we call the brain is two distinct organs that evolved independently over hundreds of millions of years," Stanford Medicine announced this week: The new research finding shows that the human brain consists of two ancient nervous systems cleverly packaged together — a more primitive part that regulates our hearts' beating, our breathing and other functions, and another that makes us distinctly human, capable of poetry, mathematics and wondering about our own origins. The discovery could help explain why scientists have struggled for decades to grow certain types of brain cells in the laboratory — and it opens new avenues for studying devastating diseases that affect the brain stem... [S]cientists have struggled for decades to generate human hindbrain neurons in the laboratory. This gap has hampered research into devastating diseases affecting the brain stem, including spinal muscular atrophy and amyotrophic lateral sclerosis... The researchers' breakthrough came from studying the earliest moments of embryonic development... [Study co-authors Carolyn Dundes and Rayyan Jokhai] discovered that the hindbrain follows a separate developmental path, running in parallel to — rather than branching off from — the pathway that creates the forebrain and midbrain... This revelation explained decades of frustration in the field — scientists had been trying to turn one type of progenitor cell into another that it is fundamentally incapable of becoming... Armed with this knowledge, the researchers for the first time successfully coaxed human pluripotent stem cells (a kind of cell that can create any cell in the human body) to become functional hindbrain motor neurons in the laboratory... Finally, the researchers looked back over 550 million years of evolutionary time. They found the same two-origin brain pattern in chickens; zebrafish; and, remarkably, in acorn worms, tiny creatures living on the ocean floor that share a distant common ancestor with humans. Jellyfish, which diverged from humans about 600 to 700 million years ago, have two nervous systems at different ends of their body. "Our research suggests that evolution took two existing neural systems and pushed them together spatially," Loh said. "Having the brain as one organ would probably be more efficient, but we rely on this primordial way to make the brain as two separate pieces." Thanks to Slashdot reader Beeftopia for sharing the article. Read more of this story at Slashdot.

  • To Enforce Its Proposed Social Media Ban for 450 Million Pre-Teens, EU Builds an Open Source App
    by EditorDavid on 20/09/2026 at 11:34 am

    The European Commission "proposed on Thursday banning children under 13 from social media, with parent-supervised accounts until 15," reports Reuters. "Enforcement would rely on a tool Brussels built itself" — a free, open-source age verification smartphone app "that tells a platform whether a user meets an age threshold without revealing their identity..." If passed, the proposed Kids Act would create the world's largest social media access restriction, covering 450 million people across 27 countries... [The EU-built age-verification app] is being rolled out through member states, with seven pilot countries: Cyprus, Denmark, France, Greece, Ireland, Italy and Spain. The Commission expects EU-wide availability by the end of 2026. It will also be used to prove users are over 18 when accessing adult sites, a restriction already implemented under the Digital Services Act... [T]he system itself is decentralised. Member states run it through issuers they designate, and the proofs live on the user's phone. There is no central EU database of ages or of who verified whom... A user proves their age once to a nationally designated issuer — a body vetted by the member state, which can be a digital ID provider, a bank or a post office. At a restricted site, the app certifies that the user is above the required age threshold. The platform receives only a yes-or-no response. Issuance and verification are handled by separate entities. The proof provider is not told which service the proof was used for. Each proof works only once, preventing cross-service tracking. No identity documents or biometric data are retained. The code is open-source, allowing independent scrutiny. The significance of the EU approach is that it provides a common age-verification mechanism rather than leaving individual platforms to develop and enforce their own systems. "Online platforms can easily rely on our age verification app. So there are no more excuses," [EU Commission President Ursula] von der Leyen said... The proposal must be approved by EU member states and the European Parliament before becoming law. Non-compliance would risk fines of up to 6% of a tech company's global annual sales, plus supervisory fees, Reuters reported earlier. The EU's plan follows similar initiatives in Australia, Britain, China, India, Turkey and several European Union countries. Read more of this story at Slashdot.

  • Tech Industry Scratches Its Head Over Trump's 'AI Force' Proposal
    by EditorDavid on 20/09/2026 at 7:04 am

    Saturday morning President Trump announced he's creating an AI task force and appointing an AI czar, reports Politico. "I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS," Trump wrote Saturday in what Politico earlier described as "a lengthy Truth Social post on Saturday morning." TRUMP: Over the years, there have been many Hoaxes, all generated by the Radical Left Dumocrats, for purposes of destroying our Country. RUSSIA, RUSSIA, RUSSIA, UKRAINE, UKRAINE, UKRAINE, Global Warming, Impeachment Hoax #1, Impeachment Hoax #2 [...] and now, the decimation, or destruction, of AI, commonly known as Artificial Intelligence — And I, as President of the United States, will not stand by and let this happen. It all began with an attack on our Data Centers, until people realized how wealthy and prestigious they were for the Communities in which they were built. Higher Salaries, Lower Taxes, and Safer Streets, was the result, and the crazed Data Center attack has largely failed, so now [...] they are going straight at AI. We will not in any way hinder or stifle the Growth of this incredible Industry. Rather, we will cherish it, help it, and watch over it, as it grows! However, we will also be looking for BAD, and we can do that, very easily, with our already existing Criminal and Civil Justice System. For this purpose, I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS, in my First Term. To that end, I will be announcing, in the near future, the AI "Czar" — Only High I.Q. individuals need apply! Trump concluded by saying AI "is the next Industrial Revolution, or Internet, but will be even larger and more impactful... We are leading China, and the rest of the World, and I intend to keep it that way!" But what exactly is AI Force? "The White House did not immediately respond to a request to clarify whether the agency would be military or civilian," notes the Washington Post. So now "The tech industry is struggling to make sense of President Donald Trump's surprise announcement," Politico reported Saturday afternoon: Four representatives for the sector, who were granted anonymity because they were not authorized to speak publicly, told POLITICO that the industry was not widely informed of Trump's decision prior to the Truth Social post. "Nobody knows what the idea even is," one of the people said. Another said that feedback on the idea was not widely solicited within the industry. The White House did not immediately respond to a request for comment... "I think that he clearly feels pressure to say something, but he's torn because he's just spent the last few days saying that the whole thing is a hoax," Adam Kovacevich, CEO of the progressive tech industry coalition Chamber of Progress, said of Trump and his prior dismissal of AI doomsday scenarios. Since the departure of David Sacks, who stepped down as the Trump administration's previous AI czar earlier this year, the White House has been "making up AI policy as it goes," Kovacevich added. "I think it's clear they've really missed the presence of an organized leader like David Sacks was." One of the tech industry representatives said they were confused about whether the task force would be charged with formulating more AI regulations or recommending policies that would further stimulate the tech's development. Taylor Barkley, director of federal government affairs at the industry-aligned Abundance Institute, is eyeing it as a way to solidify a light-touch government approach to the technology he says will foster innovation. "Any AI Force or AI Czar should have one job: keep the field open so entrepreneurs at every scale can compete, free from onerous regulation," he told POLITICO. "Existing criminal and civil law can handle bad actors. New permission regimes will stifle the very activity America needs most." It's worth noting that the day before, California's governor made an announcement. "With Donald Trump and Congress asleep at the wheel, Governor Gavin Newsom is once again taking the lead to strengthen AI safety for all Americans," the governor's office announced Friday. Newsom issued a strong executive order convening experts to help California create new AI safety laws and reporting rules, possibly even requiring safety auditors embedded in labs and emergency "kill switches" in frontier models. Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress