Computer programming for fun and profit

The FETT seeks to defeat SSITH defenses as US military goes hard on bug bounties and its Star Wars issues

Two years ago, the US Defense Advanced Research Project Agency introduced a hardware security program called System Security Integration Through Hardware and Firmware, or SSITH.

Having evaded a trademark challenge from Disneyā€™s lawyers, DARPA is ready to test the kit modifications coming out of that program against hackers. On Monday, the exploratory tech arm of the Defense Department said it had partnered with the DoDā€™s Defense Digital Service and private sector vendor Synack to run the Finding Exploits to Thwart Tampering Bug Bounty, or FETT.

Students of Star Wars may recall that Boba Fettā€™s father Jango was hired by Sith Lord Darth Tyranus; for everyone else, the US governmentā€™s nod to Star Wars rather than Star Trek tells you everything you need to know about those running the federal show.

1 Like

sorry. canā€™t ā€œlikeā€ this. :wink:

3 Likes

PHP is like ā€œletā€™s take Perl and make it worse.ā€ Iā€™ve never been a particularly big fan of it. The never ending cavalcade of security bugs doesnā€™t help matters either.

2 Likes

Some gold here.

hundreds of repeat posts of the same error, followed by success.

how did you do that?

I followed the instructions in the README

but not to be outdone:

looks way to complicated for me

1 Like

Not posted to discuss Bandcamps problems with Apple (Spoiler alert: Apple wants their usual cut!), but their take on ā€œfixingā€ email as such.

Hey is trying a new take on email ā€“ but maker complains of ā€˜outrageousā€™ demands after Apple rejects iOS app

Hey claims to fix email, which according to Basecamp has seen little innovation since the launch of Googleā€™s Gmail in 2004. Hey describes itself as a ā€œfull email service providerā€ with a few key features.

Ah lovely, hereā€™s something you can do with those Raspberry Pis, NUC PCs in the bottom of the drawer: Run Ubuntu Appliances on them

Ubuntu has launched its Appliance Portfolio, an initiative designed to enable secure smart devices linked to cloud services. All Ubuntu appliances are ā€œfree to download and installā€ but may include an up-sell to paid-for services.

The idea of the Ubuntu Appliance Portfolio is to ā€œenable secure, self-healing, single-purpose devices,ā€ according to Canonical product manager Rhys Davies. You could probably build this software yourself by hand, though the appliances are supposed to be convenient self-maintaining packages of programs to save you the bother.

2 Likes

I finally decided to use the DHT11 temp/humidity sensor connected to one of my Pis.

Rube Goldberg style!

  • By loading an overlay, the sensor data becomes part of the file system.
  • Using Samba, the file system can be read from my Windows PC.
  • A Lazarus/Free Pascal program serves it as a web page.
  • The web page can be displayed from another Raspberry Pi.
  • Grabbing some gauges from someoneā€™s project, and Star Trek LCARS from someone elseā€™s, it looks pretty good.

Mind you, the CSS needs some tweaking if itā€™s going to fit on a 480x320 screen. (Plus switch the font to the official Swiss911 Ultra Compressed.)

IMG_1214sml

5 Likes

For a while, Iā€™ve had the feeling that there was a lot of unattributed copying of little project articles for the Raspberry Pi and similar types of things. When one person did a project, up would pop a bunch of very similar articles. Sometimes perhaps it was just ā€œrailroad timeā€, where it was a natural next step that different people worked on at the same time. Other times it seemed like barely disguised copying for brownie points (I donā€™t see how thereā€™s any cash incentive).

This morning one hit my feeds thatā€™s so dumb, I wonder if itā€™s automated copy/post?

And that only points to another site:

And that points to:

Read, read, readā€¦

The first thing we will need to do is set up our Pi with raspbian. For this build you will need to download an image of raspbian Jessie

Jessie?! Thatā€™s like at least two years out of date. Scanning down, thereā€™s a link to the project software on GitHub. Which 404s. According to Wayback, it was taken down sometime in 2017.

It seems that someone plagiarized an obsolete project article, and two layers of aggregators picked it up, and not one of them noticed that it was a completely dead project.

Why? The sites will benefit from the clicks and impressions, but whatā€™s the point for the end copier?

Itā€™s a little disheartening, because I wanted to get into the habit of banging off little projects and publishing them. But if itā€™s just going to fuel someoneā€™s click-farmā€¦

2 Likes

Money, I guess. But yeah, I hate this shit too.

IBM job ad calls for 12 yearsā€™ experience with Kubernetes ā€“ which is six years old

3 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.