Aspen Mayer

@aspenmayer
154 Followers
881 Following
352 Posts

Memory Integrity Enforcement is the culmination of a truly incredible amount of work :)

While there's so much to love, one of my favorite pieces was getting to bring kalloc_type-style isolation to out-of-bounds accesses on both the architectural and speculative path. This lets us both mitigate a variety of Spectre v1 style attacks and break the reliable exploitation of some of the most powerful first-order memory corruption primitives (arb offset OOB R/W).

https://security.apple.com/blog/memory-integrity-enforcement/

Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research

Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first, always-on memory safety protection across our devices — without compromising our best-in-class device performance. We believe Memory Integrity Enforcement represents the most significant upgrade to memory safety in the history of consumer operating systems.

Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research

🧵So, here's an updated tl;dr on #Puppet as an #OpenSource project: a fork is absolutely coming now. There was a "town hall" today in which Perforce made it quite clear they are going to claim they want to work with the community while not actually doing so. As a result, those of us who have been following this closely reassembled, determined there was no longer hope of really working together, and that it was time to move forward accordingly.

(this thread is my personal take on things)

End of the Road: An AnandTech Farewell

It is with great sadness that I find myself penning the hardest news post I’ve ever needed to write here at AnandTech. After over 27 years of covering the wide – and wild – word of computing hardware, today is AnandTech’s final day of publication.
For better or worse, we’ve reached the end of a long journey – one that started with a review of an AMD processor, and has end…
#hardware
https://www.anandtech.com/show/21542/end-of-the-road-an-anandtech-farewell

End of the Road: An AnandTech Farewell

@Wraithe I think the most concerning part about this is the fact that the terms (which you are essentially forced to accept because who thinks to look for an arbitration clause on a supplement) are linked in a website.

This means they can essentially retroactively change what you agreed to without your knowledge. Include the terms in the packaging or don't have them in the first place.

@Wraithe By offering this product for sale on the open market, you agree to be bound by all the public laws and then go to court whenever you mess up, like a big boy. If you do not agree to these terms, withdraw your product from the market immediately and fuck off forever.

@Wraithe Your Honor, the wrongful death case must be moved to arbitration. His wife once opened a tub of collagen powder in 2024.

--the Costco-Disney-Google Megacorp's lawyers 20 years from now, probably

Holy shit, my wife just found this on the top of a container of collagen that we just bought from #Costco:
“By opening and using this product, you agree to be bound by our terms and conditions fully set forth at vitalproteins.com/tc, which include a mandatory arbitration agreement. If you do not agree to be bound, please return this product immediately.”

What. The. Actual. Fuck.

If you go hunting and your intended prey kills and eats you, that’s vegan. You had consented to one of you killing the other and consuming them, the only thing that’s changed is which role each of you is fulfilling. Objecting is just hypocrisy. In this essay I will…
I got a degree in cinematography but it didn’t pan out.