28c3: The Science of Insecurity

  Рет қаралды 40,636

28c3

28c3

Күн бұрын

Пікірлер: 30
@MasonTVTheOG
@MasonTVTheOG 4 жыл бұрын
Here from LiveOverflow :)
@alexanderheld2200
@alexanderheld2200 4 жыл бұрын
Same, I'm really wondering why this talk just got 415 likes.. Tbh, this was one of the best talks I ever saw ..
@hikingpete
@hikingpete 13 жыл бұрын
Thank you. This has really opened my eyes. I'll never look at a parser the same way again.
@dustinronin3262
@dustinronin3262 3 жыл бұрын
Sorry to be off topic but does any of you know of a trick to get back into an Instagram account..? I was stupid lost the account password. I would love any assistance you can give me.
@kierancain8016
@kierancain8016 3 жыл бұрын
@Dustin Ronin Instablaster =)
@VaShthestampede2
@VaShthestampede2 2 жыл бұрын
@@dustinronin3262 Yeah. Change the password.
@il2626
@il2626 4 жыл бұрын
who else here from live overflow xD
@amirhoseini3563
@amirhoseini3563 11 ай бұрын
me
@ecosta
@ecosta Сағат бұрын
19:32 "If you are into that kind of type theory" - where do I sign?
@jsmuskrat
@jsmuskrat 9 ай бұрын
This is a fantastic talk. ( I heard it when it came out and couldn't find it again until recently.)
@aromanstuff
@aromanstuff 13 жыл бұрын
Totally phenomenal talk. The presenter is awesome.
@richtourist
@richtourist 10 ай бұрын
I can't quite see the problem with length fields. Suppose the sender wants to send 42 and 69 bytes of arbitrary data: Using delimiters they have to escape any bytes that look like delimiters; and any that look like escapes..? or use something like Rust's r## technique. Using length fields the first byte is how many length fields, then the length fields, which describe the data fields that follow in order. What's the problem? Or are they talking about streams which can't have prior knowledge of their field lengths?
@jjones7837
@jjones7837 3 жыл бұрын
RIP Len.
@KurtisRainboltGreene
@KurtisRainboltGreene 12 жыл бұрын
S-expressions don't need to use brackets. She specifically suggests using wrapping characters *that wont exist in the sub-language of the value*.
@sydnius
@sydnius 13 жыл бұрын
Superb talk. Spot on.
@capability-snob
@capability-snob 3 ай бұрын
6:25 not capabilities issues? Just lost my coffee! 2012 may have been before many of the Java deserialisation issues that plagued the decade, but 8 of the OWASP top 10 that year are capabilities issues, that is, they go away or become obvious the moment you phrase them in ocap terms. Not that parsing isn't a deeply interesting field, but it seems a stretch to speak of it as the most foundational security discipline.
@MaestroAlvis
@MaestroAlvis 13 жыл бұрын
@Shorttail Did I miss an MLP reference?
@tcsiwula
@tcsiwula 5 жыл бұрын
break all the things for all the things are broken
@MasonTVTheOG
@MasonTVTheOG 4 жыл бұрын
Glad I’m learning rust
@vytemagic
@vytemagic 11 жыл бұрын
i came here about being insecure in public.
@t9h3m
@t9h3m 4 жыл бұрын
Did anyone catch what was going on with the lab coat in the end? I can't really make out anything :)
@maverickwoo
@maverickwoo 2 жыл бұрын
I think it is en.wikipedia.org/wiki/Len_Sassaman#/media/File:LenSassaman-Bitcoin-Tribute.png from the speech.
@samposyreeni
@samposyreeni 13 жыл бұрын
Uhm, a fixed width length field most certainly does not make a protocol context sensitive, but only blows up the (D)FA needed to recognize it. On the other hand I'm reasonably sure context sensitive grammars won't cut something like Elias codes. Otherwise, Patterson's ideas are a beautiful formalization of what I've been saying for the longest time: validate first, then compute with minimal checks. Kudos!
@MasonTVTheOG
@MasonTVTheOG 4 жыл бұрын
No cap rustlang mitigates a lot of this... hell yeah
@Jibes
@Jibes 13 жыл бұрын
Link to the blackhat conference talk full of lulz is where?
@slimjim1520
@slimjim1520 8 жыл бұрын
Anyone else here because they wanted extra credit for Dr. Winter's class?
@Shorttail
@Shorttail 13 жыл бұрын
This is fucking awesome. Rainbow Dash agrees.
@Lethn
@Lethn 13 жыл бұрын
@GIMBLUTAXT LOL Me too!
@sTL45oUw
@sTL45oUw 13 жыл бұрын
"Blackhat 2010 Exploiting the forest with trees" Same BS talk just from last year and at blackhat Who let this academic talk at a hacker con ? She doesn't get it
28c3: The coming war on general computation
54:35
28c3
Рет қаралды 259 М.
28c3: Reverse Engineering USB Devices
26:03
28c3
Рет қаралды 22 М.
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН
To Brawl AND BEYOND!
00:51
Brawl Stars
Рет қаралды 17 МЛН
Ange Albertini: Funky File Formats
51:13
media.ccc.de
Рет қаралды 25 М.
Bret Victor - Inventing on Principle
54:20
Rui Oliveira
Рет қаралды 300 М.
28c3: Geeks and depression panel
40:51
28c3
Рет қаралды 14 М.
Why TIME Feels Faster As We AGE | Philosophy of Time
9:55
PhiloNautica
Рет қаралды 7 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
28c3: Black Ops of TCP/IP 2011
1:06:11
28c3
Рет қаралды 14 М.
"The Mess We're In" by Joe Armstrong
45:50
Strange Loop Conference
Рет қаралды 383 М.
Google I/O 2009 - The Myth of the Genius Programmer
55:17
Google for Developers
Рет қаралды 1,1 МЛН
НИКОГДА не иди на сделку с сестрой!
0:11
Даша Боровик
Рет қаралды 729 М.
BIP HOUSE  .бип хаус 🥰🏡  #shorts
0:13
bip_house
Рет қаралды 1,2 МЛН
BIP HOUSE  .бип хаус 🥰🏡  #shorts
0:13
bip_house
Рет қаралды 1,2 МЛН
для всей семьи
0:56
Стакановец
Рет қаралды 191 М.
Абзал неге келді? 4.10.22
3:53
QosLike fan club
Рет қаралды 31 М.
BIP HOUSE / БИП ХАУС #SHORTS
1:00
bip_house
Рет қаралды 3 МЛН