Solar Designer Profile
Solar Designer

@solardiz

Followers
13K
Following
31
Statuses
14K

@Openwall founder, @oss_security maintainer, @lkrg_org co-author. RTs don't imply agreement with points of view.

Joined August 2012
Don't wanna be here? Send us removal request.
@solardiz
Solar Designer
15 hours
RT @oss_security: CVE-2025-26519: musl libc: input-controlled out-of-bounds write primitive in iconv() for the vuln…
0
4
0
@solardiz
Solar Designer
8 days
RT @oss_security: CVE-2025-24531: pam_pkcs11: Possible Authentication Bypass in Error Situations PAM_IGNORE strikes…
0
2
0
@solardiz
Solar Designer
9 days
RT @GavinSBaker: Really cool - had not seen the “Accelerator in Memory” and fully agree that compute-in-memory may be the ideal solution to…
0
30
0
@solardiz
Solar Designer
10 days
RT @oss_security: Much info on the AMD Microcode Signature Verification Vulnerability is finally public (with more planned for March) https…
0
3
0
@solardiz
Solar Designer
10 days
RT @_MatteoRizzo: Our newest research project is finally public! We can load malicious microcode on Zen1-Zen4 CPUs!
0
219
0
@solardiz
Solar Designer
11 days
Interview with @Adam_pi3 and me about LKRG, in English and Polish
@adwersarz_pl
Adwersarz.pl
11 days
Czas na wywiad! Rozmawiamy z @Adam_pi3 i @solardiz o LKRG (Linux Runtime Kernel Guard), które może znacznie utrudnić zhackowanie Linuxa. Co słychać i jak przebiega rozwój projektu, czy ktoś próbował skutecznie obejść LKRG? Zapraszamy do lektury!
1
12
28
@solardiz
Solar Designer
12 days
RT @alexobenauer: I have two things to share with you today. First, we're starting a publishing company. Second, I wrote a book about com…
0
49
0
@solardiz
Solar Designer
12 days
@eestokesOSS @mbacarella "impossible to do in CUDA" doesn't imply "had to drop down to PTX". I don't see how PTX would help allocate GPU resources differently. It's intermediate assembly language that compute kernels can be written in, but allocation of SMs is done prior to their invocation. @stratechery
0
0
0
@solardiz
Solar Designer
14 days
@Chick3nman512 @CraigHRowland Sure. In upstream libxcrypt ranking (which is what typical Linux distros use these days), bcrypt is not obsolete and is still listed as STRONG (except for the bug-compatibility-only $2x$ mode).
1
0
1
@solardiz
Solar Designer
15 days
RT @carrigmat: Complete hardware + software setup for running Deepseek-R1 locally. The actual model, no distillations, and Q8 quantization…
0
4K
0
@solardiz
Solar Designer
21 days
RT @sysdig: 🦈 Meet Stratoshark—Wireshark for Cloud☁️ From #OpenSource pioneers @LorisDegio & @GeraldCombs, Stratoshark extends @WiresharkN
0
50
0
@solardiz
Solar Designer
21 days
"The preview of -fbounds-safety is now accessible to the community! -fbounds-safety is a language extension to enforce a strong bounds safety guarantee for C."
@kayseesee
Kostya Serebryany
2 years
RFC: Enforcing Bounds Safety in C (-fbounds-safety). We have enough of important C code that we can't simply rewrite it in Rust, but we have to make it safer. This is the most practical approach I've seen so far to improve spatial memory safety in legacy C code (that won't require new hardware features).
0
5
13
@solardiz
Solar Designer
21 days
RT @oss_security: CVE-2025-23222: dde-api-proxy: Authentication Bypass in Deepin D-Bus Proxy Service is part of the…
0
2
0
@solardiz
Solar Designer
22 days
RT @oss_security: Oracle January 2025 Critical Patch Update - These should be brought to oss-security. - MySQL: 39…
0
1
0
@solardiz
Solar Designer
22 days
RT @oss_security: CVE-2025-0395: glibc: Buffer overflow in the GNU C Library's assert() by @Qualys - the buffer ove…
0
3
0
@solardiz
Solar Designer
22 days
RT @oss_security: AMD Microcode Signature Verification Vulnerability
0
4
0
@solardiz
Solar Designer
23 days
RT @oss_security: CERT/CC VU#199397 - Insecure Implementation of Tunneling Protocols (GRE/IPIP/4in6/6in4) https://t…
0
2
0
@solardiz
Solar Designer
25 days
RT @oss_security: CVE-2024-13176: OpenSSL: Timing side-channel in ECDSA signature computation Could allow recoverin…
0
2
0
@solardiz
Solar Designer
28 days
@MortenLinderud @mjg59 Here's a new blog post describing a closely related attack: I think this answers my question above - yes, the referenced proposal by Lennart Poettering addresses this risk, however "[...] not merged into the systemd main branch yet" (perhaps it is by now).
0
0
0
@solardiz
Solar Designer
29 days
RT @lukOlejnik: We are very, very far from useful quantum computers. It's not even clear how to reliably benchmark the progress. https://t.…
0
5
0