Tag: firmware

  • Hacker News: A brief history of Mac firmware

    Source URL: https://eclecticlight.co/2024/10/26/a-brief-history-of-mac-firmware/ Source: Hacker News Title: A brief history of Mac firmware Feedly Summary: Comments AI Summary and Description: Yes Summary: The text provides an in-depth examination of the evolution of firmware in Apple Macs, focusing on significant architectural changes and associated security implications. It highlights how firmware management has transitioned over years, particularly…

  • Hacker News: When Samsung meets MediaTek: the story of a small bug chain [pdf]

    Source URL: https://www.sstic.org/media/SSTIC2024/SSTIC-actes/when_vendor1_meets_vendor2_the_story_of_a_small_bu/SSTIC2024-Article-when_vendor1_meets_vendor2_the_story_of_a_small_bug_chain-rossi-bellom_neveu.pdf Source: Hacker News Title: When Samsung meets MediaTek: the story of a small bug chain [pdf] Feedly Summary: Comments AI Summary and Description: Yes Summary: The text details a significant security vulnerability found in the boot chain of Samsung mobile devices using MediaTek System-on-Chips. The vulnerability, which can allow an attacker with…

  • The Cloudflare Blog: How we use OpenBMC and ACPI power states to monitor the state of our servers

    Source URL: https://blog.cloudflare.com/how-we-use-openbmc-and-acpi-power-states-to-monitor-the-state-of-our-servers Source: The Cloudflare Blog Title: How we use OpenBMC and ACPI power states to monitor the state of our servers Feedly Summary: Cloudflare’s global fleet benefits from being managed by open source firmware for the Baseboard Management Controller (BMC), OpenBMC. This has come with various challenges, some of which we discuss here…

  • Hacker News: Securing Hardware and Firmware Supply Chains

    Source URL: https://techcommunity.microsoft.com/t5/azure-infrastructure-blog/securing-hardware-and-firmware-supply-chains/ba-p/4268815 Source: Hacker News Title: Securing Hardware and Firmware Supply Chains Feedly Summary: Comments AI Summary and Description: Yes **Summary:** The text discusses critical innovations in hardware and firmware security within cloud data centers, particularly emphasizing Microsoft’s collaboration with the Open Compute Project (OCP) on the Caliptra initiative and the OCP Security Appraisal…

  • Cloud Blog: Sustainable silicon to intelligent clouds: collaborating for the future of computing

    Source URL: https://cloud.google.com/blog/topics/systems/2024-ocp-global-summit-keynote/ Source: Cloud Blog Title: Sustainable silicon to intelligent clouds: collaborating for the future of computing Feedly Summary: Editor’s note: Today, we hear from Parthasarathy Ranganathan, Google VP and Technical Fellow and Amber Huffman, Principal Engineer. Partha delivered a keynote address today at the 2024 OCP Global Summit, an annual conference for leaders,…

  • The Register: Qualcomm urges device makers to push patches after ‘targeted’ exploitation

    Source URL: https://www.theregister.com/2024/10/08/qualcomm_patch_spyware/ Source: The Register Title: Qualcomm urges device makers to push patches after ‘targeted’ exploitation Feedly Summary: Given Amnesty’s involvement, it’s a safe bet spyware is in play Qualcomm has issued 20 patches for its chipsets’ firmware, including one Digital Signal Processor (DSP) software flaw that has been exploited in the wild.… AI…

  • Google Online Security Blog: Google & Arm – Raising The Bar on GPU Security

    Source URL: https://security.googleblog.com/2024/09/google-arm-raising-bar-on-gpu-security.html Source: Google Online Security Blog Title: Google & Arm – Raising The Bar on GPU Security Feedly Summary: AI Summary and Description: Yes Summary: The text discusses the critical importance of GPU security for Android devices, highlighting a collaborative effort between the Android Red Team and Arm to address vulnerabilities in the…

  • Hacker News: 4 Exploits, 1 bug: exploiting cve-2024-20017 4 different ways

    Source URL: https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html Source: Hacker News Title: 4 Exploits, 1 bug: exploiting cve-2024-20017 4 different ways Feedly Summary: Comments AI Summary and Description: Yes **Summary:** The text presents a detailed analysis of a recently discovered vulnerability (CVE-2024-20017) in the wappd service related to MediaTek’s SDK, particularly affecting various embedded devices. It explains how a stack…

  • Hacker News: Ask HN: Assuming any bought laptop is tampered with, what do you do?

    Source URL: https://news.ycombinator.com/item?id=41534858 Source: Hacker News Title: Ask HN: Assuming any bought laptop is tampered with, what do you do? Feedly Summary: Comments AI Summary and Description: Yes Summary: The text highlights a significant concern regarding the physical tampering of laptops, particularly outlining the lack of information related to preventive measures for buyers who suspect…

  • Slashdot: Two Android Engineers Explain How They Extended Rust In Android’s Firmware

    Source URL: https://developers.slashdot.org/story/24/09/08/0455238/two-android-engineers-explain-how-they-extended-rust-in-androids-firmware?utm_source=rss1.0mainlinkanon&utm_medium=feed Source: Slashdot Title: Two Android Engineers Explain How They Extended Rust In Android’s Firmware Feedly Summary: AI Summary and Description: Yes Summary: Google is enhancing the security of its Android Virtualization Framework by rewriting firmware using the Rust programming language, which is known for its memory safety features. The move aims to…