Still wrecked from past Israeli raids, hospitals in northern Gaza come under attack again
They were built to be places of healing. But once again, three hospitals in northern Gaza are encircled by Israeli troops and under fire.
Hasnain says:
Not even keeping up the pretense anymore.
“The Israeli military has never made any claims of a Hamas presence at al-Awda. When asked what intelligence led troops to besiege and raid the hospital last year, the military spokesman’s office did not reply.”
Posted on 2024-11-03T23:28:21+0000
Product Security Bad Practices | CISA
This voluntary guidance provides an overview of product security bad practices that are deemed exceptionally risky, particularly for software manufacturers who produce software used in service of critical infrastructure or national critical functions (NCFs).
Hasnain says:
“The development of new product lines for use in service of critical infrastructure or NCFs in a memory-unsafe language (e.g., C or C++) where there are readily available alternative memory-safe languages that could be used is dangerous and significantly elevates risk to national security, national economic security, and national public health and safety.”
Posted on 2024-11-02T22:54:00+0000
Okta AD/LDAP Delegated Authentication - Username Above 52 Characters Security Advisory
On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was used to generate the cache key where we hash a combined string of userId + username + password. During specific conditions, this could allow users to authenticate....
Hasnain says:
Yikes
“A precondition for this vulnerability is that the username must be or exceed 52 characters any time a cache key is generated for the user.”
Posted on 2024-11-02T04:31:50+0000
From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code
Posted by the Big Sleep team Introduction In our previous post, Project Naptime: Evaluating Offensive Security Capabilities of Large L...
Click to view the original at googleprojectzero.blogspot.com
Hasnain says:
“For the team this is a moment of validation and success - finding a vulnerability in a widely-used and well fuzzed open source project is an exciting result! When provided with the right tools, current LLMs can perform vulnerability research.
However, we want to reiterate that these are highly experimental results. The position of the Big Sleep team is that at present, it's likely that a target-specific fuzzer would be at least as effective (at finding vulnerabilities).
We hope that in the future this effort will lead to a significant advantage to defenders - with the potential not only to find crashing testcases, but also to provide high-quality root-cause analysis, triaging and fixing issues could be much cheaper and more effective in the future. We aim to continue sharing our research in this space, keeping the gap between the public state-of-the-art and private state-of-the-art as small as possible.”
More than 100 BBC staff accuse broadcaster of Israel bias in Gaza coverage
Exclusive: More than 230 media industry professionals sign letter sent to BBC director general Tim Davie
Hasnain says:
“The letter also calls on the broadcaster to implement a series of editorial commitments including “reiterating that Israel does not give external journalists access to Gaza; making it clear when there is insufficient evidence to back up Israeli claims; making clear where Israel is the perpetrator in article headlines; including regular historical context predating October 2023; and robustly challenging Israeli government and military representatives in all interviews”.”
Posted on 2024-11-01T19:36:35+0000
Survivors of north Gaza invasion report Israeli ‘extermination’ campaign
Survivors of the ongoing Israeli extermination campaign in north Gaza describe how the Israeli army is separating mothers from children before forcing them south, executing civilians in ditches, and directly targeting hospitals and medical staff.
Hasnain says:
This is going unquoted because I cannot find a single non horrifying thing to quote.
Posted on 2024-11-01T19:25:32+0000
False citations show Alaska education official relied on generative AI, raising broader questions • Alaska Beacon
Department of Education and Early Development Commissioner Bishop said the false citations were in a draft she used generative AI to create.
Hasnain says:
“The false citations do point to how AI misinformation can influence state policy, however — especially if high-level state officials use the technology as a drafting shorthand that causes mistakes that end up in public documents and official resolutions.”
Posted on 2024-11-01T06:43:59+0000
Australia/Lord_Howe is the weirdest timezone | SSOReady
Timezones are weird. But only finitely so. Here's the exact conceptual model you should have of them.
Hasnain says:
“Also:
Don’t let people bully you into thinking that just because something is complicated, it’s impossible.
This is because almost every standard (except ISO8601, whatever) is just a file, and you can read it. You are smart. You can do it. Embrace the weirdness of Greenland’s daylight savings. Believe in yourself.
If I were UN secretary general, I would kick out any countries that I deem insufficiently considerate of Paul Eggert’s time”
From Sudan to Silicon Valley: Beyond the Resume
“I was so ahead of the curve, the curve became a sphere. Fell behind all my classmates and I ended up here.” — Taylor Swift — This is me…
Hasnain says:
This was inspiring.
“Despite these setbacks, I found other ways to make an impact. During Sudan’s revolution, I ran a social media campaign that raised $10,000 to send top AI students from Sudan to a major AI conference in Africa. Many are now making strides at companies like Google, Meta, and Silicon Valley startups. By my final semesters, though, the struggle caught up with me — I was barely getting through. I left academia with two workshop papers and two Ph.D. offers in hand.”
Posted on 2024-10-31T06:20:59+0000
Super Micro Computer says Ernst & Young resigns as auditor, shares tank
Super Micro Computer said on Wednesday Ernst & Young had resigned as its auditor, sending its shares tumbling more than 30% and deepening investor worries about accounting practices at the artificial intelligence server maker.
Hasnain says:
“"We are resigning due to information that has recently come to our attention which has led us to no longer be able to rely on management's and the Audit Committee's representations and to be unwilling to be associated with the financial statements prepared by management," Super Micro quoted EY as saying in a filing with the Securities and Exchange Commision.”
Posted on 2024-10-31T03:53:03+0000