Ryan Castellucci (they/them) 🎃 
Hacker. Cryptography geek. Bureaucramancer. Ex-sysadmin. Nonbinary. Expat (US⮕UK).
By day I'm a Principal Security Engineer at a megacorp, by night I'm an agent of chaos. I post about technology and queer issues, while attempting to be funny along the way.
My continuing mission:
To explore strange new platforms.
To seek out new bugs and new software.
To boldly shitpost where no one has shitposted before!
I'm suing the UK for more gender, please help with my legal bills: https://enby.org.uk
@ryanc@infosec.exchange@justmytoots.com
#hacker #nonbinary #trans #embedded #linux #homelab #hardwareHacking #infosec
This software is a work of fiction. Variable names, character codes, classes, and comments are products of the author's imagination or used ironically. Any resemblance to any actual code, interfaces, or programs, maintained or not, is entirely coincidental.
Reading: Project Hail Mary. No spoilers please.
From HN: my threat model doesn't really include competent .us.gov actors.
On the one hand, props to Kovid Goyal for fixing this quickly, on the other hand I'm a bit salty that he considers it not a security issue to be able to probe for file/directory existence and get back file sizes.
I included a PoC that lists the loaded kernel modules in my report.
https://github.com/kovidgoyal/kitty/commit/87ab3e98f4d399337777e4329960d7cd09101e99
I should have a party at my lair.
Enumerate your loaded kernel modules with shell escape sequences (affects kitty):
https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=1147733;filename=kitty_probe.py;msg=5