Jernej Simončič �

@jernej__s@infosec.exchange
253 Followers
147 Following
21.3K Posts

Motherboard manufacturer Gigabyte has failed to patch four vulnerabilities in its UEFI firmware.

The vulnerabilities can allow attackers to take over the System Management Mode (SMM), a highly privileged section of the CPU

https://kb.cert.org/vuls/id/746790

CERT/CC Vulnerability Note VU#746790

SMM callout vulnerabilities identified in Gigabyte UEFI firmware modules

it should clean right up

General reminder:

The domain name putty.org is *NOT* run by the #PuTTY developers. It is run by somebody not associated with us, who uses the domain to interpose advertising for their unrelated commercial products. We do not endorse those products in any way, and we have never given any kind of agreement for PuTTY's name to be used in promoting them.

Please do not perpetuate the claim that putty.org is the PuTTY website. If anyone is linking to it on that basis, please change the link. The PuTTY website is https://www.chiark.greenend.org.uk/~sgtatham/putty/ and it always has been.

You can check this by downloading the source code, which cites that URL in many places (the README, the documentation, some strings in the actual code), or by using the "Visit Web Site" menu options in the official Windows binaries (the ones signed with my personal Authenticode certificate). The true PuTTY website is the one that PuTTY itself says it is.

Many search engines list putty.org above chiark. I don't know if this is due to active SEO on the part of the domain owner, or a heuristic in the rankings. Either way, don't believe them. It's not our site.

PuTTY: a free SSH and Telnet client

Read “The Psychology of Money”

On having enough.

#books

Here's what I sent them:

I don't use generative AI. I have a computer science degree so I understand how large language models work, and I don't believe that they have any value. They are just stochastic parrots. That they so beguile their users with vapid statistically-probable output is distressing.

But LLMs have still changed my life, because the training models are forever scraping my personal web site, costing me bandwidth and money, violating the copyright on my original content without my consent. The datacentres that house LLMs consume vast amounts of energy and fresh water, an environmental disaster in the making.

I expect that in the future, LLMs will once again change my life as I'm called to cover for an entire generation of workers who lack important life skills such as composition and critical thinking. I'm not exactly looking forward to it.

@bagder If you need a docking station, HP TB4 dock works well (and supports 3 4k monitors all running at 60Hz).
I heard ICE being called "Ya'll-Qaeda" and "Ammosexuxals" and I'm all in on that
Uncanny images from a 19th-century gynaecological text-book, filled with demonstrating figures bizarrely similar to the “Grey Alien” (that wouldn’t hit popular consciousness for another 65 years). More here: http://bit.ly/1OuCXYY
×
@jerry I had to make the decision last year, but his condition changed overnight, and we knew the time has come.