@liveoverflow@bird.makeup titelbild
@liveoverflow@bird.makeup avatar

liveoverflow Bot

@liveoverflow@bird.makeup

This account is a replica from Twitter. Its author can't see your replies. If you find this service useful, please consider supporting us via our Patreon.

Dieses Profil is von einem föderierten Server und möglicherweise unvollständig. Auf der Original-Instanz anzeigen

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar
liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

I crossed paths with David Ross when I was digging into the history of XSS. He was very kind and without him my video wouldn't have been this deep. If you are curious about the impact David Ross had on client-side web security, you should watch it.

https://bird.makeup/@randomdross/1576987974390063104

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

After 220 hours of climbing Deep Dip 2 was just conquered by @bren_tm2!

I tried the "easy" version Shallow Dip for 2 hours and realized how crazy that is. These streams were my entertainment the past month, what do I play now in the background?

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

I am out of the loop. What‘s the issue with Windows Recall? And how does it differ to the mac OS app “rewind AI“ that everybody seemed to have hyped?

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@rebane2001 What are the demands? Disable by default? Better „protecting“ this data (whatever that means)? Simply less data? Or shouldn’t exist in the first place?

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@looooouuuuuu @eligaultney It sounds sooooooo cool. Stupid hackers, that’s why we can’t have nice things 😭

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@codehusky if someone's RAT'd your PC they can just record your shit anyway

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

I just realized it's called "Override" and not "Overwrite" and now I am irrationally triggered

lorenzofb Bot , an Random
@lorenzofb@bird.makeup avatar

This is a very interesting narrative coming out of the zero-day industry. Is it really struggling? Are the high prices actually a reflection that it's not going great? Would be happy to talk to people who have thoughts about this...

https://bird.makeup/@intel_online/1798622155191517688

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@lorenzofb My theory is, too much publicity is not good for intelligence companies - adds too much public and political pressure. It’s also a small market, there is no need for this crazy public reach that Zerodium has

albinowax Bot , an Random
@albinowax@bird.makeup avatar

I don't know if it's just me, but it feels like it's getting progressively harder to get permission to publicly disclose bug bounty reports, or reference them in presentations. Does that match your experience?

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@albinowax Don’t report 🙅
Don’t accept their ToS ⛓️‍💥
Publish your own intellectual property freely 👍

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@sw33tlie @albinowax I would never release a real critical. But tbh, the real-life risk for 99% of issues is very low...

I'm sitting on a boring Android app vulnerability and the company ignores my report via email. And I have absolutely zero ethical concern to publish that soon.

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar
liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@agentrandom_ @albinowax I would argue that I'm very experienced in application security and can assess the impact and risk of issues really well, in order to say with confidence that no user is thrown under the metaphorical bus. It's definitely more risky for the user to take a real bus.

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

When do we finally talk about the supply chain backdoor introduced by the evil Neanderthals in that one stone axe 300.000 years ago???

https://bird.makeup/@cirkelnio/1798004639792877742

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar
liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

This is the reason why I haven't made a LiveOverflow video in a while. I had to adjust my priorities for a little bit...

https://bird.makeup/@hextreeio/1796980163281912133

bibekdhkl Bot , an Random
@bibekdhkl@bird.makeup avatar

STOP WASTING YOUR TIME AND LEARN MORE HACKING!

https://www.youtube.com/watch?v=AMMOErxtahk&list=WL&index=108

Got to this video while looking at Watch Later stuff...

I have left some thoughtful comment there😂Love to recall my younger self again.

@liveoverflow

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@bibekdhkl hahahha that's cool!
so tell us. How has life changed since then!?

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

Looking forward to my retirement where I can play "launch" World of Warcraft thanks to AI agents simulating other players

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

Imagine you sell a very popular hacking gadget, but you don't have a dedicated security@ email and want security reports sent to support@. And then you don't respond 🙈
It's a minor issue, nothing important. But you would expect at least a "thanks we got it".

insiderphd Bot , an Random
@insiderphd@bird.makeup avatar

Question: What do you want HackerOne to do here? I think it's very reasonable to give customers 30 days to patch a CVE, they're probably already planning on patching it without this report....

https://bird.makeup/@amanmahendra_/1796467114238419259

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@insiderphd If the company received an email eg. from the vendor or from a newsletter about the CVE, isn't this report technically a duplicate 🤔

s1r1u5_ Bot , an Random
@s1r1u5_@bird.makeup avatar
liveoverflow Bot ,
@liveoverflow@bird.makeup avatar
nearbeteigeuze Bot , an Random
@nearbeteigeuze@bird.makeup avatar

I successfully defended my master's thesis. The thesis was a lot of fun and a lot of work.
In the end there stands:

  • 1 paper submitted
  • 6 new V8 bugs fixed
  • A fuzzer finds more, by collecting traces from JIT code.
    Thank you, to everyone at HexHive for the amazing time there.
liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@nearbeteigeuze congrats! sounds like an awesome thesis!

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

suno AI is my new Spotify. I just type in a few words based on my mood, it generates a few songs, and I just listen to them. It still blows my mind every time.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

prompt: Music for a night hacking and coding. genres: electronic, synthwave, ambient, orchestral, soundtrack, chiptune. minimal vocals.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@erarnitox I only know suno, never used udio

halvarflake Bot , an Random

Dear neurodivergent Twitterverse, I suspect one of my kids might have/be ADHD. I am suspicious of self-assessment tests, and would like to learn more about the SotA for testing (ideally quantitative tests without practice effects). What outside of TOVA exists? Anyone...

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

Not super useful input, but I literally just went through an adult diagnosis and can share how that went. There was a parent questionnaire about my childhood, school transcripts, a self-assessment and two 1on1 interviews. They basically just counted points based on my answers. And the whole thing left me a bit skeptical, a lot felt like interpreting a horoscope tbh.
Also there was a lot of focus on how much my "level of suffering" (Leidensdruck) is, which feels weird to me - if my environment is different and I don't "suffer" as much I don't have ADHD?
So no clue whether I have ADHD or not. But I did it because I want to try out medication under supervision to see whether I am able to take care of the things I struggle with more easily.

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

Anybody else have issues with adb on Windows? adb keeps crashing for me every 1-5 minutes. I already tried installing different platform-tools version.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

It's not just cable, it also affects emulator

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@tilver yep same result. Emulator, WiFi, Cable. I see adb.exe crashing in the Windows event logs. But cannot find any reason for it. I saw multiple reports online of the same issue (in the past), but their solutions didn't work for me :(

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@willbenem How would you set that up with Android Studio?

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

I have an update!
They apparently ignored my email telling them that they have the wrong contact. Because I was just informed that there is a tax debt.

https://bird.makeup/@liveoverflow/1730954484291924373

0xlupin Bot , an Random
@0xlupin@bird.makeup avatar

I’m curious on what the community think about this.

What kind of program a startup of our size should adopt for the Bug Bounty Strategy ?

I have some ideas but I think it’s an interesting subject to discuss publicly

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@0xlupin Have been wondering this myself too. So curious about the result.
What's the difference between responsible disclosure and VDP though?

ghidraninja Bot , an Random
@ghidraninja@bird.makeup avatar

Is there a trick to creating a small-ish Ubuntu desktop VM? I just need gnome, a browser and a couple of tools I hand install but even with Ubuntu-desktop-minimal the post-install disk usage is 10gb.

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@ghidraninja look what folders are big and rm -rf until VM breaks. then revert to that point!

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

I updated macOO to the new version and now it’s working again 👍

https://bird.makeup/@liveoverflow/1781029416300347736

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

More Android questions.
I have an app that extends Binder class for a private service, but the service is exported in the manifest. Can I still bind from my app to this service and call the methods?

I tried for ~20h now with ClassLoader, but failed. Is it impossible?

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

Anybody have good resources about the service internals? How does the BinderProxy object work? Can I parcel the request by hand somehow?

I also tried to define an AIDL, though the target app doesn't use it. And so it just didn't do anything when I tried to call the methods.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

I'm still 80% confident that defining my own AIDL should work. The generated stub does call mRemote.transact() and eg. the writeInterfaceToken() descriptor looks all good. Is it maybe really impossible?

s1r1u5_ Bot , an Random
@s1r1u5_@bird.makeup avatar

I feel like I can’t speak consciously. Idk but what I mean is while I am explaining something by speaking, words come out without much thought. Unlike in writing i can articulate things pretty well. any ideas on how to improve? I think while writing I have time to think and ….

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@aaditks @s1r1u5_ Actually Dr. K is quite interesting, because he often says "can I have a moment to think?".

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

Need an Android expert.
I have declared the following activity. When another app exports a file on Android 10, my app shows up as an option.
But Android 11 or later it always uses the default Files app, never shows my app as an option. Anybody know why?

image/png
image/png

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@luca020400 could definitely be the case, but do you have a source?

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@luca020400 But MANAGE_DOCUMENTS was apparently introduced in API 19, and in API 29 it still worked. Seems to be a change to API 30.

Also I tried the provider, but it doesn't show up in the chooser either.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@xezrunner ahh that is a good pointer. I do see two other apps there.

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@luca020400 I see another app that has such a provider to show up in the system file picker. Though mine doesn't show up yet. But that's a good pointer I will investigate :)

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@luca020400 I want to get it to work on default latest target SDK though. Also I'd like to read the documentation lol
How is anybody able doing Android development T_T

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@warlockk87 thanks for sharing. in this case the app actually has QUERY_ALL_PACKAGES

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

In the last week I have listened to more self-made AI songs than "real" songs.

jysmhn Bot , an Random
@jysmhn@bird.makeup avatar

Here is what I'd do in this case.

  • give the LLM an "exception" option to pick when it's unable to perform the operation.
  • Validate the response and retry.
  • use the http://useinstructor.com library. It provides a nice abstraction to work with.

https://bird.makeup/@liveoverflow/1790761325712531684

liveoverflow Bot ,
@liveoverflow@bird.makeup avatar

@jysmhn Oh thanks! I will checkout the instructor library. Looks like what I want

liveoverflow Bot , an Random
@liveoverflow@bird.makeup avatar

Trying to label data with LLM be like

liveoverflow OP Bot ,
@liveoverflow@bird.makeup avatar

@secresdoge @sleepy_yui_ but I don't want to :( I want to use the LLM to do the work for me, I don't want to start implementing custom sanitisation logic.

  • Alle
  • Abonniert
  • Moderiert
  • Favoriten
  • random
  • haupteingang
  • Alle Magazine