Aleks
banner
fuzzyaleks.bsky.social
Aleks
@fuzzyaleks.bsky.social
Utterly disappointing, not at all what i expected by the title! Doesn’t even acknowledge prior works of Discordians!
It’s all about SRE and making complex chaotic systems more resilient to failure. With a bunch of first-hand experience from big corps who have their shit together!
March 28, 2025 at 2:11 PM
Digital vs film X-ray . Film offers higher resolution and better dynamic range with the same settings, but slightly longer exposure time (and more tedious image acquisition). Comes in handy when it comes to tiny electronics. Images of an Abbott Lingo continuous glucose monitor.
February 26, 2025 at 2:40 PM
Not funny in the least , smh
February 24, 2025 at 5:32 AM
I’m RE early boot code of this device. It has a factory testing/debug mode triggered by holding a button combo while powering it on. I see the code, but don’t have an exact memory map to find the correct button sequence! And there's 12 buttons, too much for brute force...
January 25, 2025 at 4:32 PM
I’m a bit of a tall ship nerd and got to see this extraordinary one in Hamburg. Peking is a 4 masted barque. The last of the flying P-liners, immortalized in Irving Johnson’s famed “Around the Cape Horn” film (linked). “The main course sail weights 3 tones when dry. “ youtu.be/gYgl6a-XJ8U?...
December 27, 2024 at 11:15 AM
Cowboy hat unusual for Hamburg? Clearly you haven’t seen Dennis Hopper in Wim Wenders’ “The American Friend”. Say hi if you see me at #38C3 !
December 26, 2024 at 2:33 PM
Regardless, even if a fuzzer tripped over this vulnerable codepath, there are so many other constraints that it likely wouldn’t have been caught. Careful code auditing more likely. Kudos to whoever found it originally.
December 7, 2024 at 12:25 AM
If you were fuzzing TTFs without modifying these, chances are you’d never hit the bytecode interpreter at all. By modifying these two values, you can force it to run.
December 7, 2024 at 12:23 AM
It took a bit of work to figure out the requirements to force the interpreter: units per em > 1024 and Lowest Recommended Pixels Per Em > 19.
December 7, 2024 at 12:23 AM
Without a PoC sample, while reverse engineering, I’ve found a couple of interesting things. First among them is that libFontRenderer tries really really hard to NOT invoke the bytecode interpreter. Because, in most cases, it can do better than hinting.
December 7, 2024 at 12:22 AM
I just wrapped up a talk at #OBTS about ios/macos font renderer vulnerability used in operation triangulation. No PoC was released and I wanted to make one to study the attack surface.
December 7, 2024 at 12:21 AM
Hey @binary.ninja , can we do something about this? I like being on dev but storage on macbooks ain't cheap... :D (i last cleaned it in July, before that I had 3 years of updates )
November 26, 2024 at 5:30 PM
Post a picture you took (no description) to bring some zen to the timeline
November 16, 2024 at 2:38 PM
Hi friends old and new! I’m Aleks and I specialize in obsolete technologies such as typewriters, film cameras and memory corruption exploitation.
November 11, 2024 at 10:59 PM
I've been afk , manning the lines on a square rigged tall ship. If you've tried to reach me but I haven't responded, I'm catching up slowly.
March 18, 2024 at 9:16 PM