bk99.de entertain the web since 1997

Blog 2022

32 posts

Projects, Linux, networks, systems, finds and internet standards from 2022.

Why nuclear waste is not shot into space

KG examines the seemingly simple disposal of radioactive waste by rocket and shows why mass, cost and failed launches devalue the concept. Disposal proposals often fail because risk is concentrated during transport. A technically possible solution can be considerably worse than a boring local one.

Read the full post

How BLOOM inference was optimised

The report follows the optimisation of a 176-billion-parameter model from memory planning to distributed execution. It shows that production inference is a systems problem of parallelisation, kernels and communication. BLOOM is too large for the memory of a single common GPU.

Read the full post

TP-Link: smuggling malicious code through a security hole in routers

In 2022 researchers from the Vietnamese telecommunications group Viettel found a buffer overflow in the web-based ping tool of the low-cost TP-Link TL-WR841N Wi-Fi router (CVE-2022-30024). Logged-in attackers could execute their own code via an overlong host address and, for example, install a backdoor. TP-Link delivered updates for revisions V10 to V12 and declared older devices end-of-life.

Read the full post

Web browsers: Google Chrome and Microsoft Edge 104 close security holes

With Chrome 104 in August 2022, Google closed 27 security holes, at least seven of them high-risk; one earned its discoverer a bounty of 15,000 US dollars. Microsoft followed with Edge 104 and additionally fixed three Edge-specific bugs, including a critical sandbox escape (CVE-2022-33649, CVSS 9.6). Also new were Media Queries Level 4 and Web Bundles for faster loading.

Read the full post

Takeover possible: DrayTek routers with critical security hole

In 2022 Trellix found a critical hole (CVE-2022-32548, CVSS 10.0) in numerous DrayTek routers through which unauthenticated attackers could take over the devices. A logic error in the length check on the login page /cgi-bin/wlogin.cgi led to a buffer overflow, exploitable from the LAN or via the internet if management was reachable there. The researchers found more than 200,000 vulnerable devices on the net.

Read the full post

RFC 9114: HTTP/3 over QUIC

RFC 9114 maps HTTP semantics onto QUIC and avoids TCP-induced blocking between independent streams. HTTP/3 ties application and transport development more closely together than earlier versions. UDP reachability becomes an important operational factor again.

Read the full post

RFC 9110: HTTP semantics reorganised

RFC 9110 defines the shared semantics of HTTP independently of the concrete transport versions. Separate semantics allow HTTP/1.1, HTTP/2 and HTTP/3 to share a common basis. Clear terms reduce contradictory implementations.

Read the full post

Linux security monitoring with audit events

Hilko Bengen shows how Linux auditd delivers fine-grained host events and how the unwieldy format can be made usable for attack detection with reasonable effort. Network monitoring only detects many attacks together with context from the affected host. More telemetry only helps if events are reliably correlated and prioritised.

Read the full post

Arduino chip adds Wi-Fi to the hobbyist board

In 2022 Arduino co-founder Gianluca Martino wanted to fund the Jolly module via Kickstarter; it replaces the Arduino Uno’s microcontroller with a variant with Wi-Fi. It combines an ATmega328PB with an ESP8285 including 2 MByte of flash, an integrated antenna and Wi-Fi 4. Because the chip is compatible with the ATmega328P, form factor, GPIO pins and existing Arduino software are meant to keep working.

Read the full post

Millisecond inference on modern CPUs

The case study optimises transformer inference on CPUs with ONNX Runtime, quantisation and dynamic batching. It shows when existing server hardware can be a practical alternative to GPUs. The platform runs optimised transformer models on modern CPUs.

Read the full post

New Chinese x86 CPU in development

Golem’s short news of 5 January 2022 reported that the Chinese manufacturer Zhaoxin was planning new x86 processors for desktop and server for 2022, without giving details. The current state was, for example, the KX-U6780A with eight cores and 16 nm manufacturing. Further topics were a VA-API backend for Nvidia’s NVDEC under Linux and an AR chip from Qualcomm for Microsoft.

Read the full post

Kernel developer wants to escape “dependency hell”

In January 2022 Ingo Molnar presented the “Fast Kernel Headers” project, a comprehensive overhaul of the Linux kernel’s roughly 10,000 header files. With more than 2,200 patches changing more than half of all source files, the “dependency hell” was to be untangled. According to initial benchmarks, build time was reduced by 78 percent, and in some cases considerably more for incremental builds.

Read the full post