Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003


I'm not seeing how this is different than the hundred other exploits that allow jailbreaking.

Adbot
ADBOT LOVES YOU

susan b buffering
Nov 14, 2016

rjmccall posted:

okay, so this appears to be the original, four-year-old bug. tl;dr: sqlite has a pair of bugs in its query and database-file parsers

in theory the query parser bug shouldn't be exploitable because nobody would ever be dumb enough to inject user input directly into an sql query string, right?

the file parser bug is only exploitable if you can corrupt the database file that sqlite is working with, but you probably can if there's literally any other bug in the program, because parts of the database file are probably just mmap'ed writably into the address space because that's how databases work. and corruption of the database file will generally persist across reboots, so potentially the exploit can persist, too

i don't know why ios was apparently using an ancient sqlite. probably because the whole clever point of sqlite is that you can just copy it into your project without worrying about adding a dependent project, so people do and then they don't worry about keeping up with security updates

the thing about passwords sounds like bullshit

ios definitely bundles a newer version of sqlite than that so maybe it's something else

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
yeah, i dunno. it's also possible that some projects use their own copy for no good reason

Xarn
Jun 26, 2015
No dep management! Just copy files into your own tree! :suicide:

Shame Boy
Mar 2, 2010

The Fool posted:

I'm not seeing how this is different than the hundred other exploits that allow jailbreaking.

well for one this doesn't allow jailbreaking

Shame Boy
Mar 2, 2010


i went to their website expecting some fun crazy and boy i was not disappointed:

https://www.crownsterling.io/

they're a leader in "data sovereignty and quantum encryption" whatever that means. there's also a press release announcing their black hat talk:

quote:

Crown Sterling, a leading digital cryptography firm, today unveiled TIME AI™, the world’s first dynamic ‘non-factor’ based quantum AI encryption software to protect data privacy for consumers and enterprise systems – https://www.timeai.io. TIME AI™ is based on the recent discovery from Crown Sterling’s Founder and CEO, Robert E. Grant, in which he recently identified the first Infinite Prime Number prediction pattern.

Utilizing multi-dimensional encryption technology, including time, music’s infinite variability, artificial intelligence, and most notably mathematical constancies to generate entangled key pairs, TIME AI™ is designed to wrap around all data and applications to secure the world’s most valuable asset — data. Crown Sterling is demonstrating TIME AI™ this week at Black Hat 2019 in Las Vegas at the Mandalay Bay Convention Center, Booth Number 1304.

the website for TIME AI™ is fun too:

https://timeai.io/



uh... huh.

Shame Boy
Mar 2, 2010

oh boy something falsifiable, thanks!

quote:

In March of 2019, Grant identified the first Infinite Prime Number prediction pattern where the discovery was published on Cornell University’s https://www.arxiv.org titled: “Accurate and Infinite Prime Number Prediction from Novel Quasi-Prime Analytical Methodology.” The paper was co-authored by Physicist and Number Theorist Talal Ghannam PhD. The discovery challenges today’s current encryption framework by enabling the accurate prediction of prime numbers.

i didn't know you could publish things directly to arxiv i thought it was like, a collection of other papers from actual journals, but i guess not!

https://arxiv.org/abs/1903.08570

e: within like two sentences of the introduction they misspelled the word "divisor" so this is already a great paper that i definitely trust to tell me about prime numbers

titaniumone
Jun 10, 2001

Shame Boy posted:

oh boy something falsifiable, thanks!


i didn't know you could publish things directly to arxiv i thought it was like, a collection of other papers from actual journals, but i guess not!

https://arxiv.org/abs/1903.08570

e: within like two sentences of the introduction they misspelled the word "divisor" so this is already a great paper that i definitely trust to tell me about prime numbers

i would love if someone is able to dig into this and tear it apart

Shame Boy
Mar 2, 2010

titaniumone posted:

i would love if someone is able to dig into this and tear it apart

i'm reading through it slowly and so far they basically put all the prime numbers around a 24-sided polygon and observed some patterns that... are kinda obvious patterns that come from primes not being even or ending in 5, etc. but then they put the numbers on a certain side of the polygon into a grid and claim that the grid will show every possible number in a set that is not prime, therefore if you just remove those you can find all the prime numbers! or something, it lost me somewhere after the 24-sided polygon.

e: oh boy and then it gets into digital roots, which are an entire weird thing of their own and often the target of people looking for patterns where there aren't any, great

Shame Boy fucked around with this message at 16:41 on Aug 12, 2019

flakeloaf
Feb 26, 2003

Still better than android clock

so it's time cube but for cryptography

Kazinsal
Dec 13, 2011



that sounds less like a math paper and more like an aggressive arg for the new tool album

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shame Boy posted:

oh boy something falsifiable, thanks!


i didn't know you could publish things directly to arxiv i thought it was like, a collection of other papers from actual journals, but i guess not!

https://arxiv.org/abs/1903.08570

e: within like two sentences of the introduction they misspelled the word "divisor" so this is already a great paper that i definitely trust to tell me about prime numbers

The Nice and Accurate Infinite Prime Numbers of Robert Grant

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
they’re obvious cranks, but they’ve presented an opportunity to re-prove the interesting but ultimately trivial result that the squares of all primes greater than 3 are congruent to 1 mod 24, so, it’s impossible to say if they’re bad or not,

Shame Boy
Mar 2, 2010

actually getting to the "discovery" now, their incredibly fast test for prime numbers / very fast factoring algorithm seems like it's... just a bunch of extra poo poo built up to hide the core idea of "calculate a big table of prime numbers, then look the number in question up on the table", plus a search algorithm for searching the table

congrats on breaking cryptography, guys, can't believe nobody ever thought of that before

Agile Vector
May 21, 2007

scrum bored



infernal machines posted:

The Nice and Accurate Infinite Prime Numbers of Robert Grant

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

infernal machines posted:

The Nice and Accurate Infinite Prime Numbers of Robert Grant

haveblue
Aug 15, 2005



Toilet Rascal

flakeloaf posted:

so it's time cube but for cryptography

primecube

mystes
May 31, 2006

Factoring stuff so it's more like Project Snakeoiler

Phone
Jul 30, 2005

親子丼をほしい。
seems like it wasn’t ready for prime time

burning swine
May 26, 2004



https://mobile.twitter.com/zer0pwn/status/1158433002239746048

0-day for kde disclosed, apparently without any attempt to report it to the devs. lol

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

COACHS SPORT BAR posted:

https://mobile.twitter.com/zer0pwn/status/1158433002239746048

0-day for kde disclosed, apparently without any attempt to report it to the devs. lol

when there are only three users of kde, why not just use twitter?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

primecube

James Baud
May 24, 2015

by LITERALLY AN ADMIN

COACHS SPORT BAR posted:

https://mobile.twitter.com/zer0pwn/status/1158433002239746048

0-day for kde disclosed, apparently without any attempt to report it to the devs. lol

Zero day, but also zero real-world exploitation vector - basically anything that can write a .desktop file can already do much worse. (Maybe a shady game demo from Steam?)

pseudorandom name
May 6, 2007

wouldn’t it be easier to just set the Exec= key to your shell code?

spankmeister
Jun 15, 2008






pseudorandom name posted:

wouldn’t it be easier to just set the Exec= key to your shell code?

That only triggers when you click on it. This does it when trying to render the icon.

Trabisnikof
Dec 24, 2005

https://twitter.com/zer0pwn/status/1159183975103041536

https://twitter.com/zer0pwn/status/1159225058465914882

https://twitter.com/djoghurt/status/1159226243662983168

https://twitter.com/zeroday_exploit/status/1159304730482544641

Raere
Dec 13, 2007

they lost me at quasi-prime. a number is either prime or it isn’t. do or not not, there is no prime

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I have an alternate presentation for them

https://www.youtube.com/watch?v=ZH-cXBhkl-E

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe
iirc there are some quick prime checking algorithms that will tell you if a number is probably prime. Not reading that bullshit, but I'm guessing maybe they found some numbers that fool those into thinking they are prime?

Wiggly Wayne DDS
Sep 11, 2010



i want this framed

spankmeister
Jun 15, 2008






Janitor Prime posted:

iirc there are some quick prime checking algorithms that will tell you if a number is probably prime. Not reading that bullshit, but I'm guessing maybe they found some numbers that fool those into thinking they are prime?

That's what pseudoprimes are. I've never heard of quasi-primes but I'm no mathematician.

[A]sk me about having to patch SAGE's ECM factorization implementation to support pseudoprimes since those work juuust fine when you're doing weird stuff to RSA.

BlankSystemDaemon
Mar 13, 2009



maybe this Robert E. Grant has just read dirk gently’s holistic detective agency one time too many and learned the wrong lesson?

Agile Vector
May 21, 2007

scrum bored



D. Ebdrup posted:

Robert E. Grant’s holistic deception agency

Shame Boy
Mar 2, 2010

Raere posted:

they lost me at quasi-prime. a number is either prime or it isn’t. do or not not, there is no prime

no see the quasi-primes are all the numbers that line up on that polygon-chart but are not prime, which you can use to get the prime numbers by calculating all of them and checking if your number is in that list, or something

like unless i'm really missing something the entire thing breaks down to "if you make a big list of numbers you can check other numbers against that big list of numbers really fast!" with a hell of a lot of hand-wavy bullshit on top to try to get you to tune out before the last like, 3 paragraphs that describe the actual idea near the end.

Shame Boy
Mar 2, 2010

Janitor Prime posted:

iirc there are some quick prime checking algorithms that will tell you if a number is probably prime. Not reading that bullshit, but I'm guessing maybe they found some numbers that fool those into thinking they are prime?

nah it's way dumber than that

Midjack
Dec 24, 2007



haveblue posted:

primecube

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



lol

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe
https://mashable.com/article/dmv-vanity-license-plate-def-con-backfire/

Idiot buys vanity NULL license plate, some system somewhere starts sending him a bunch of unpaid tickets. :owned:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Janitor Prime posted:

https://mashable.com/article/dmv-vanity-license-plate-def-con-backfire/

Idiot buys vanity NULL license plate, some system somewhere starts sending him a bunch of unpaid tickets. :owned:

Droogie is an old friend of mine. I should ask him about this sometime

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

Assbag system can't distinguish between the string null and actual null

Yay lowest bidder

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply