Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Pirating the Pirates (mubi.com)
    145comments
  2. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    19comments
  3. World Labs Is Joining AMD (worldlabs.ai)
    3comments
  4. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    —discuss
  5. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    3comments
  6. Hijacking the PS5's RTMP stream (yashgarg.dev)
    39comments
  7. Joseph Szabo’s pictures of American adolescents (newyorker.com)
    22comments
  8. Scientists solve 1840s space weather mystery (arstechnica.com)
    1comments
  9. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    139comments
  10. Palantir founder purchases large swath of forest in Sweden (arctictoday.com)
    —discuss
  11. First Steps of the PLC Organization – Independent Public Ledger of Credentials (plcred.org)
    11comments
  12. Sonnet 5.5 (anthropic.com)
    270comments
  13. Launch HN: Vespper (YC F24) – SOTA Docx MCP (vespper.com)
    8comments
  14. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    34comments
  15. Who wrote Elizabeth I's most scathing letters? (smithsonianmag.com)
    15comments
  16. GrapheneOS – When an app is slow (wirelessmoves.com)
    25comments
  17. Best of British Design (best-of-british-design.vercel.app)
    1comments
  18. SB 923 is Law: CCPA deletion rights now reach third-party data (getprivisy.com)
    11comments
  19. What heraldry and Japanese mon can teach about visual-identity generators (benovermyer.com)
    18comments
  20. MongoDB CEO resigns to join Meta (reuters.com)
    224comments
  21. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    15comments
  22. I made a visual workspace for AI Automations (biom.dev)
    17comments
  23. I switched to Brave (kevquirk.com)
    124comments
  24. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    122comments
  25. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    92comments
  26. Windows 11½ (definitelynotwindows.com)
    99comments
  27. So long Google, and thanks for all the nudes (lecaro.me)
    58comments
  28. It's Time to Investigate the AI Labs (calnewport.com)
    —discuss
  29. California Farmers Are Struggling to Sell Grapes as Demand for Wine Drops (kqed.org)
    17comments
  30. Neal Stephenson responds with wit and humor (2004) (slashdot.org)
    11comments

Exploring GrapheneOS secure allocator: Hardened Malloc

106 pointsby 1y agosynacktiv.com
10 comments
1y agoHN ↗

Yeah that work is way more impressive.

I like how they demonstrated exactly how it impacts known exploits for example

1y agoHN ↗

The problem with these kinds of hardened allocators is that:

- They impact performance.

- They don’t prevent the attacker from pivoting a memory safety bug to remote execution.

- They get oversold (like calling it “secure”).

That’s not to say there aren’t allocator mitigations that help. It’s just that this isn’t it. Quarantining for example just means the attacker has to do a bit more acrobatics, but it won’t stop them.

I think what Apple is doing with typed allocations is much more principled and they have data to prove it in their blog posts

1y agoHN ↗

Yes, but it also means you need an Apple device, and hence a locked down system. You also need to take all of Apple's privacy claims at face value. No thanks.

1y agoHN ↗

They don’t prevent the attacker from pivoting a memory safety bug to remote execution.

I'm confused. Isn't this potentially preventing some classes of memory-safety bugs?

1y agoHN ↗

I think what Apple is doing with typed allocations is much more principled and they have data to prove it in their blog posts

This is one of the things that hardened malloc is doing (and is part of the post). Newer pixels are shipping with MTE support and graphene's malloc leverages MTE as much as possible.

1y agoHN ↗

There might be processes that have high privileges, but don't need high performance, for example: sudo utility, new USB device detection daemon, bluetooth communication daemon.

Also idea described in Apple's article (never reuse allocated addresses for other types) cannot be easily implemented for any allocator. Consider a memory pipe (circular buffer), where one process pushes messages and another reads them. How do you implement Apple-style memory safety here? One of the ideas is of course to map the buffer multiple times, so that every allocation returns a new virtual address, but how many syscalls you will need for that and how badly that would impact performance.