Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Pirating the Pirates (mubi.com)
    128comments
  2. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    13comments
  3. Joseph Szabo’s pictures of American adolescents (newyorker.com)
    21comments
  4. Hijacking the PS5's RTMP stream (yashgarg.dev)
    37comments
  5. First Steps of the PLC Organization – Independent Public Ledger of Credentials (plcred.org)
    8comments
  6. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    136comments
  7. Sonnet 5.5 (anthropic.com)
    249comments
  8. Launch HN: Vespper (YC F24) – SOTA Docx MCP (vespper.com)
    8comments
  9. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    32comments
  10. SB 923 is Law: CCPA deletion rights now reach third-party data (getprivisy.com)
    10comments
  11. GrapheneOS – When an app is slow (wirelessmoves.com)
    25comments
  12. Who wrote Elizabeth I's most scathing letters? (smithsonianmag.com)
    11comments
  13. What heraldry and Japanese mon can teach about visual-identity generators (benovermyer.com)
    17comments
  14. MongoDB CEO resigns to join Meta (reuters.com)
    219comments
  15. I switched to Brave (kevquirk.com)
    117comments
  16. Windows 11½ (definitelynotwindows.com)
    91comments
  17. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    14comments
  18. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    117comments
  19. I made a visual workspace for AI Automations (biom.dev)
    16comments
  20. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    87comments
  21. So long Google, and thanks for all the nudes (lecaro.me)
    52comments
  22. What would a serious AI product look like? (glyph.im)
    41comments
  23. 37,500 border drawings: a map of the world as people remember it (habibicode.org)
    32comments
  24. Neal Stephenson responds with wit and humor (2004) (slashdot.org)
    5comments
  25. When did Google get so weird? (sancho.bearblog.dev)
    991comments
  26. California Farmers Are Struggling to Sell Grapes as Demand for Wine Drops (kqed.org)
    2comments
  27. Show HN: PaperMono, e-ink fridge magnet shopping list with mobile web page (github.com/seamusc)
    51comments
  28. Footguns with Postgres “at time zone 'UTC'” (bookofrevenue.com)
    92comments
  29. Solving a corn puzzle with CP-SAT (thill.me)
    7comments
  30. Show HN: Free alternative to graphics design giants (scissor.studio)
    39comments

Exploring GrapheneOS secure allocator: Hardened Malloc

106 pointsby 1y agosynacktiv.com
10 comments
1y agoHN ↗

Yeah that work is way more impressive.

I like how they demonstrated exactly how it impacts known exploits for example

1y agoHN ↗

The problem with these kinds of hardened allocators is that:

- They impact performance.

- They don’t prevent the attacker from pivoting a memory safety bug to remote execution.

- They get oversold (like calling it “secure”).

That’s not to say there aren’t allocator mitigations that help. It’s just that this isn’t it. Quarantining for example just means the attacker has to do a bit more acrobatics, but it won’t stop them.

I think what Apple is doing with typed allocations is much more principled and they have data to prove it in their blog posts

1y agoHN ↗

Yes, but it also means you need an Apple device, and hence a locked down system. You also need to take all of Apple's privacy claims at face value. No thanks.

1y agoHN ↗

They don’t prevent the attacker from pivoting a memory safety bug to remote execution.

I'm confused. Isn't this potentially preventing some classes of memory-safety bugs?

1y agoHN ↗

I think what Apple is doing with typed allocations is much more principled and they have data to prove it in their blog posts

This is one of the things that hardened malloc is doing (and is part of the post). Newer pixels are shipping with MTE support and graphene's malloc leverages MTE as much as possible.

1y agoHN ↗

There might be processes that have high privileges, but don't need high performance, for example: sudo utility, new USB device detection daemon, bluetooth communication daemon.

Also idea described in Apple's article (never reuse allocated addresses for other types) cannot be easily implemented for any allocator. Consider a memory pipe (circular buffer), where one process pushes messages and another reads them. How do you implement Apple-style memory safety here? One of the ideas is of course to map the buffer multiple times, so that every allocation returns a new virtual address, but how many syscalls you will need for that and how badly that would impact performance.