Как системщику остаться в живых: харденинг, который не убьет ваш перфоманс

Здравствуйте, меня зовут Анна Мелехова. Я старший архитектор в отделе развития архитектуры KasperskyOS. В статье я хочу поделиться практическим опытом системной разработки, которой я занималась сначала в проекте по виртуализации, а теперь в «Лаборатории Касперского», где мы делаем микроядерную операционную систему с повышенными требованиями к безопасности – KasperskyOS . Когда вы работаете в такой среде, быстро понимаете: харденинг – это не красивые галочки в чек-листе, а набор очень конкретных, очень практических решений, которые должны и защищать, и минимально снижать производительность. О них я и расскажу, а в конце дам личный топ самых полезных харденингов, которые бустят security и не снижают performance.

https://habr.com/ru/companies/kaspersky/articles/968388/

#kasperskyos #системное_программирование #харденинг #canary #aslr #cfi

Как системщику остаться в живых: харденинг, который не убьет ваш перфоманс

Здравствуйте, меня зовут Анна Мелехова. Я старший архитектор в отделе развития архитектуры KasperskyOS. В статье я хочу поделиться практическим опытом системной разработки, которой я занималась...

Хабр

Last article from issue 7, stay tuned for 8!

'There is a clear link between the expansion of Zijin in China and Central Asia, in South America, in DR Congo, and the increased world demand for minerals required by the so-called energy transition, which needs lithium but also copper. […] The phase out of fossil fuels in terms of percentage of the energy mix is taking place but there is no phase out in absolute terms.'

Read the article on https://journal.commodityfrontiers.com/journal-issues/issue-7/zijin-a-growing-metal-mining-chinese-transnational-firm/ #CFI

Sony PS5 Pro 新修訂版本泄露 減少熱量及噪音或於 9 月底歐洲發售
Sony 準備推出 PS5 Pro 新修訂版本,型號為 CFI-7121,將於 9 月 30 日在歐洲發售。新 […]
#遊戲情報 #科技新聞 #CFI-7121 #playstation
https://unwire.hk/2025/09/27/ps5-pro-cfi-7121-new-model-release/game-channel/?utm_source=rss&utm_medium=rss&utm_campaign=ps5-pro-cfi-7121-new-model-release

New article from Marjolijn Dijkman and Oliver Ressler.

‘[...] it’s nothing new to inject gas into oil fields. The process is known as “enhanced oil recovery”: CO2 is injected into almost exhausted low-pressure oil fields to force out the remaining oil. The main difference is that this time, the industry wants the technology subsidized by states as “climate technology” – a purported solution for a problem caused by the same industry itself [...]'

Read the article on https://journal.commodityfrontiers.com/journal-issues/issue-7/carbon-capture-let-there-be-cracks/ #CFI

New article from Pepe Roswaldy.

'To what degree do carbon trading and offsetting serve as a form of externalization that exploits workers in the Global South, considering plantation workers will become the ones held responsible for the Global North’s attempt to reduce the majority of its carbon emissions?'

Read the article on https://journal.commodityfrontiers.com/journal-issues/issue-7/palm-oil-workers-and-decarbonization-in-indonesia/ #CFI

New article from Evelyne Owino.

'The carbon project poses the risk of dispossession of pastoralists from their ancestral lands, amplifying resource competition by creating scarcity in fragile ecologies prone to climate variabilities. Several communities had to alter traditional grazing patterns due to climate variability and newly imposed land management policies under the carbon sequestration project promoted by NRT.'

Read the article on
https://journal.commodityfrontiers.com/journal-issues/issue-7/carbon-profits-or-pastoralist-precarity-the-sale-of-air-in-northern-kenyas-double-edged-climate-financing-frontier/. #CFI

New article from Mehra Gharibian and Jose Cruz.

'There are ghosts who carry the memory of these stories, as well as the memory of forms of being and thinking that were once expressed in the Central Valley. They wander through the dialectic of fields and towns which have come to characterize the ecosystem.'

Read the article on https://journal.commodityfrontiers.com/journal-issues/issue-7/ghost-stories-of-the-central-valley-a-conversation-with-jose-cruz/ #CFI

In our second session, Christian Rossow shared an overview of CFI techniques and developments and showed which areas still need further research to improve the guarantees CFI can provide and the compatibility with language constructs.

#GSW25 #CFI #Cybersecurity

We just significantly improved the explanation of control-flow integrity (CFI) in the Low Level Software Security Book, see https://llsoftsec.github.io/llsoftsecbook/#control-flow-integrity-cfi

The new version offers clearer, more detailed explanations to help readers better understand this important security concept.

We’d love to hear your feedback — share your thoughts here or open an issue on github at https://github.com/llsoftsec/llsoftsecbook

#LLSoftSecBook #CFI

Low-Level Software Security for Compiler Developers