Projects, Linux, networks, systems, finds and internet standards from 2023.
oct0xor, kucher1n and bzvr_ reconstruct a multi-stage iOS zero-click chain that combined four zero-days and an undocumented hardware feature. The chain used five vulnerabilities, four of them zero-days. The analysis led to fixes for four previously unknown vulnerabilities.
Read the full post →
Tobias Mueller analyses the Black Basta encryptor and uses a faulty reuse of the keystream to recover files with a known-plaintext attack. Ransomware can undermine strong primitives itself through faulty use. Data recovery benefits from knowledge of file formats, reverse engineering and cryptography together.
Read the full post →
US water utilities were attacked via internet-facing controllers with the unchanged default password 1111.
Read the full post →
Mixtral activates only part of its experts per token and combines high model capacity with limited computation. The article explains the architecture, usage and open availability. Mixtral uses eight experts and activates two of them per token.
Read the full post →
Hackaday presents a script that downloads, configures and builds kernel sources and starts them as a debuggable Debian image under QEMU. It runs as a Python program. The kernels it produces can be built as Debian packages.
Read the full post →
Hackaday checks the claim of an eight-core limit and explains time slices, scheduler domains and scaling assumptions in a nuanced way. The change under discussion was about fifteen years old. Linux runs in production on large systems with many CPUs.
Read the full post →
KG scales the entire history of the Earth to a film in which each second shows roughly one million years of biological and geological change. A continuous presentation conveys duration differently from a list of historical milestones. Complexity emerges over long unspectacular phases and short visible transitions.
Read the full post →
Action Retro installs Red Hat 5.2 on a period Pentium computer and experiences media, drivers and setup without modern aids. Red Hat Linux 5.2 was used. The target computer had a Pentium processor.
Read the full post →
The article compares three model families on classifying disaster tweets with LoRA. It shows that a larger generative model is not automatically the best or most economical classification solution. The study uses the Disaster Tweets data set.
Read the full post →
Gradio-Lite runs Python and Gradio directly in the browser via WebAssembly. Small ML demos therefore need no backend server of their own and process data locally. Demos can be served as static files.
Read the full post →
Attackers exploited a critical Confluence vulnerability weeks before the vendor’s patch was available.
Read the full post →
Manuel Schmitt bids farewell to the admin server admserv, used for almost two decades, and keeps old port 81 bookmarks working. admserv provided the administration interface for web hosting packages. At times the service was known as Siteadmin and Personal.
Read the full post →
The article compares integrated methods such as bitsandbytes, GPTQ and AWQ in terms of memory, hardware and deployment path. It helps to understand quantisation as a trade-off rather than a single switch. Transformers supports several quantisation backends through their own configurations.
Read the full post →
In August 2023 Cisco closed several holes in firewalls and switches. Rated high were an SNMP hole in Firepower 4100 and 9300 through which authenticated attackers could trigger restarts, an IS-IS hole in Nexus 3000 and 9000 without authentication, and a DoS hole in NX-OS. Further medium holes affected, among others, the Application Policy Infrastructure Controller.
Read the full post →
The AutoGPTQ integration quantises already trained language models to a few bits and integrates them directly into Transformers. This considerably lowers the memory requirement for local inference. GPTQ typically quantises weights to four bits after training.
Read the full post →
In August 2023 PaperCut closed two high-rated holes in its print management software. Via CVE-2023-3486, attackers could upload files without logging in and fill up the hard disk; via CVE-2023-39143 they could view and modify files, and according to Horizon3 even execute code. The Windows hole required the External Device Integration function, which was active by default in PaperCut NG Commercial and MF.
Read the full post →
In 2023 network operators and consumer advocates disputed whether the freedom of choice of router, in force since 2016, also applies to GPON fibre connections. The associations Anga, Buglas, Breko, VKU and VATM applied to the Federal Network Agency to move the network termination point behind the operator’s fibre modem (ONT). Customers would then no longer be able to operate their own fibre router directly at the connection socket.
Read the full post →
A fully sealed computer runs under water and gives off its heat directly to a cool pond. The original video has the ID yFswDJPvtPY. Extreme cooling ideas only work if corrosion, condensation and maintenance are planned in.
Read the full post →
Johannes replaces the previous push button of his Passkey project with a touch surface and plans a final enclosure. The project repository was renamed from passkey to Passkey. The new button works by touch.
Read the full post →
The overview classifies open language models, training libraries, inference servers and evaluation tools around the Hub. It makes clear that open LLMs need a chain of compatible components. Models and their associated artefacts are versioned via the Hub.
Read the full post →
RFC 9420 defines MLS for efficient end-to-end encryption in dynamic groups. Group encryption is more than pairwise encryption between many participants. Removed members must lose future access cryptographically.
Read the full post →
The article uses Parquet metadata and DuckDB to evaluate many Hub data sets directly with SQL. Large data sets do not have to be loaded completely onto your own machine for this. DuckDB can query Parquet files directly over HTTP.
Read the full post →
Trail of Bits audited Safetensors as a format for storing tensors without executable deserialisation code. The results strengthened the move away from risky pickle-based weight files. Trail of Bits carried out an independent security audit of Safetensors.
Read the full post →
StackLLaMA combines supervised fine-tuning, a reward model and PPO into a complete RLHF pipeline. The guide shows how PEFT and quantisation lower the hardware requirements. The pipeline first uses instruction data for supervised fine-tuning.
Read the full post →
The article trains transformers via Flower without bringing the participants’ raw data together centrally. Only local model updates are coordinated and aggregated. Flower coordinates federated training rounds between clients and server.
Read the full post →
Alpine Linux provides a small, hardened base for a transparent and maintainable home router.
Read the full post →
PEFT bundles LoRA and related methods that train only a small number of additional parameters. This makes large base models adaptable on limited hardware. PEFT supports several parameter-efficient adaptation methods.
Read the full post →
LoRA trains small additional matrices instead of all the weights of a diffusion model. This lowers memory requirements and produces compact adapters that can be distributed separately. LoRA freezes the original model weights.
Read the full post →
In January 2023 Cisco warned of critical holes in the small business routers RV016, RV042, RV042G and RV082, but announced that it would not deliver any more updates. Manipulated HTTP requests to the web interface could bypass authentication and gain root access (CVE-2023-20025). As the devices had reached end of life, Cisco only pointed to blocking ports 443 and 60443, although proof-of-concept code already existed.
Read the full post →
In early 2023 attackers exploited a critical hole in SugarCRM (CVE-2023-22952) to take over servers and install malware. Authentication could be bypassed via the path /index.php/, after which a POST request uploaded a PNG file containing PHP code that was executed when called up later. By 11 January Censys found 354 compromised servers, just under twelve percent of all 3,059 reachable instances.
Read the full post →
Since April 2020, Linux users had been funding better touchpad gestures under Linux through a Gitclear donation campaign, implemented by Povilas Kanapickas. By early 2023 the core goals had been achieved: gestures worked in many Wayland and X servers, XWayland and in GTK and Qt. The team asked the community in a survey whether it should continue working on support in individual applications.
Read the full post →