Advertisement · 728 × 90

Posts by Joachim Schipper

In particular: if you think implementing RSA was really quite easy, don’t use the code you just wrote.

10 months ago 1 0 0 0

Consider something like “just because you get the right answer doesn’t mean your implementation is secure” (because carry bugs and other hard-to-trigger corner cases in mostly asymmetric algorithms, because side channels, or just because your parser accepts all valid messages and many invalid ones.)

10 months ago 0 0 1 0

I agree, and I’d put enforced autoformatting in the same list: it takes a text-based language at least some way to a token-based language.

(Autoformatting really isn’t new - GNU Indent is ancient and was itself not the first system - but it seems to have gotten a lot more popular lately.)

11 months ago 0 0 0 0

I don’t want to compare, but e.g. Qualys’ research into local privilege escalation on Linux - e.g. needsrestart, Baron Samedit - also finds bad stuff. For Windows, consider e.g. James Forshaw’s work. In 2024, unfortunately, (some) VM boundaries are much stronger than process boundaries…

1 year ago 2 0 0 0

Well, it really does seem to be time to leave Twitter. Let's see what a blue sky brings...

1 year ago 6 0 3 0