Morgan Hill

@pcwizz@infosec.exchange
37 Followers
271 Following
200 Posts
Hacker of things. Misspent youth in the wilds of Linux and BSD. Reformed DevOps. Worked on a large spherical sound system in Las Vegas.
Bloghttps://pcwizz.net
About mehttps://morganrhill.com

My talk from oxidize has been uploaded: https://youtu.be/5qyuV62nJyM

#rust #appsec

An intro to the world of auditing Rust code

YouTube
Ready to put Rust into action? Oxidize 2025 features five practical workshops plus talks packed with real-world Rust insights and techniques. Learn, connect, and exchange ideas with the Rust community — register now: https://oxidizeconf.com/ #RustLang #Embedded #Conference

Finishing up my slides for "About Time" at #why2025

https://program.why2025.org/why2025/talk/LJ9879/

About Time WHY2025

A shared understanding of what time it is and the rate at which time progresses is essential in many areas of technology from industrial control to broadcast. There are two main ways of synchronizing time between multiple computers, Network Time Protocol (NTP) and Precision Time Protocol (PTP). NTP is sufficient for certificate validation, but when timing is crucial we need PTP. In this talk we will take a deep dive into PTP: what it is, how it works, and various ways to abuse it.

We are finally ready to announce that EMF 2026 will happen on July 16-19, 2026, at Eastnor Castle Deer Park, Herefordshire.

Expect more updates soon as we start spinning up the organisation again.

Extreme reactions to mundane requests:

Can I borrow some string?

Not in your lifetime.

Please stop and have a serious moment of consideration before you write another build system.

Not that I don't enjoy installing 7 different language tool chains and somehow always missing some header files that I need to hunt for. But, it does seem like we still have the old school header hunting problem we just now have several layers of redirection ensuring that you burn more cycles before you get to the failure.

New hobby decompiling with a pencil, paper and hard copy references. It's just like doing a sudoku or a crossword.

#Germany your customer service is not okay. Please improve!

All germans please report to basically any other country to figure out what I mean then come back.

I have been ruined by rust's enums.

I was lucky enough to help another nifty open source utility. The developer has posted a little summary of what I found:
https://whynothugo.nl/journal/2024/10/19/vdirsyncer-status-update-2024-10-security-audit/

If you need something to sync your calendar or contacts give #vdirsyncer a go.

#rust #webdav #codeauditing

Vdirsyncer status update 2024-10: security audit