Hacker News new | past | comments | ask | show | jobs | submit login

Are there any real CTF's done against OpenBSD to present this evidence?



Not that I'm aware of, but as someone who works in security, I've exploited a bunch of bugs against real world, hard targets both for my own educational purposes and also as part of my job with client engagements. I'm not going to pretend I'm the best in the world, but I'm decent. More importantly, I know a lot of folks with hats of many colors who are a lot better than I am.

When Luca Todesco (the person who wrote that toot) tells you your exploit mitigations are trash, you listen.

Like I said, I'm not going to make any claims to being an elite hacker. I have a cool job that I love, and I enjoy doing this stuff for fun too to keep my skills sharp. But reading through that presentation, there's nothing that made me pause and think "This is a game over scenario." If you have a moderately powerful bug with halfway decent primitives these mitigations aren't really going to stop anyone.

An elite team like NSO group? This isn't going to effect them one bit.


If you think Theo and co. are newcomers to security, y'all gonna have a bad time. You and the NSO group.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: