This both real and a decent metaphor, so it is time for me to re-tell a story.
-
This both real and a decent metaphor, so it is time for me to re-tell a story.
Ever heard of The Ping Of Death?
There was a couple of years there - years, hand to god - where you could throw a single malformed or too-large packet across the network at any IP you could see, and if you malformed it just right for its OS, you could crash the machine. You could kill a Windows machine with one line in cmd.exe.
It was bad, but almost nobody knows how bad.
https://mastodon.social/@Natasha_Jay@tech.lgbt/115719291112552201
-
This both real and a decent metaphor, so it is time for me to re-tell a story.
Ever heard of The Ping Of Death?
There was a couple of years there - years, hand to god - where you could throw a single malformed or too-large packet across the network at any IP you could see, and if you malformed it just right for its OS, you could crash the machine. You could kill a Windows machine with one line in cmd.exe.
It was bad, but almost nobody knows how bad.
https://mastodon.social/@Natasha_Jay@tech.lgbt/115719291112552201
Because the Ping Of Death was an RCE. If you sent _just the right_ kind of malformed or too large packet - and you cleaned up after yourself - you suddenly had a system where you could basically ask any computer you could see to do whatever you wanted, and it would do that for you and then quietly go on its way.
I was temping for Global Affairs Canada in the late 90s, then called DFAIT; I got to hang with some old-school-then, semi-retired CSIS sigint guys.
They thought the internet was great.
-
Because the Ping Of Death was an RCE. If you sent _just the right_ kind of malformed or too large packet - and you cleaned up after yourself - you suddenly had a system where you could basically ask any computer you could see to do whatever you wanted, and it would do that for you and then quietly go on its way.
I was temping for Global Affairs Canada in the late 90s, then called DFAIT; I got to hang with some old-school-then, semi-retired CSIS sigint guys.
They thought the internet was great.
I'm sure the situation has improved - I don't think winsock.dll or Wolverine have ever had a proper pentest teardown, even for historical amusement's sake - but I have to assume, given that we live in a world where there are no specialized chips anymore, and everything from the boutique brand-namiest NICs to the dodgiest junk you'd find in a Shenzhenese dumpster is a general-purpose CPU running some tiny OS of questinably determinate provenance, that... well, you have to wonder.
-
I'm sure the situation has improved - I don't think winsock.dll or Wolverine have ever had a proper pentest teardown, even for historical amusement's sake - but I have to assume, given that we live in a world where there are no specialized chips anymore, and everything from the boutique brand-namiest NICs to the dodgiest junk you'd find in a Shenzhenese dumpster is a general-purpose CPU running some tiny OS of questinably determinate provenance, that... well, you have to wonder.
Because you don't have a "network interface card", you have an ARM cpu, maybe even a whole-ass ARM SOC, handling ethernet frames on one side and talking PCI on the other.
You don't even have SD cards, because "memory cards" don't exist. That terabyte of storage the size of your thumbnail you bought? That's an ARM CPU managing the wear levels on its crap-ass flash backing storage while pretending to be a hard drive on the other side.
You don't know how many computers are in your computer.
-
undefined oblomov@sociale.network shared this topic