i'm extremely uncomfortable with the idea of making Big Tech™ the arbiters of truth (especially if it's the same companies selling the poison and the cure), so i appreciate the effort you have put into this display of the obvious -- impressive work, thank you!
(side note: the banner ad at the end made me genuinely lough out loud, and made me realize ublock crashed on my hacked up browser build)
Meta already patched the CVE-2026-43499 LPE on Quest headsets, near the start of the month, to stop people from cheating in VR video games. It's absolutely bonkers to me that Google has not issued a patch for even their flagship Pixel devices yet.
Might it be a revealed preference of megacorps: cheating in VR games is a serious issue, and users' security is not?
Repeating a joke: New lesson for security researchers: when you find a vulnerability, don't use it to steal crypto keys, escalate privilege, or execute shellcode. Just write video game cheats, and the anti-cheat industry will make sure it's patched. DMA attacks were long considered a hypothetical method for FBI/NSA to steal a dissident's laptop disk encryption key in a cafe, yet after a decade of demos, VM and QubesOS users still needed to hunt for motherboards with proper IOMMU. Even after Thunderbolt and USB 4 made these attacks universal, for a long period nobody really cared. It only became the default right now thanks to PCIe cheat hardware. Advancing security and privacy for free software desktops, who cares? Video games losing money? Much better.
The fact I keep hearing about it being pushed is very disheartening. Someone has a business model in mind and doesn't care about the impact on the public.
gir | 8 hours ago
i'm extremely uncomfortable with the idea of making Big Tech™ the arbiters of truth (especially if it's the same companies selling the poison and the cure), so i appreciate the effort you have put into this display of the obvious -- impressive work, thank you!
(side note: the banner ad at the end made me genuinely lough out loud, and made me realize ublock crashed on my hacked up browser build)
k749gtnc9l3w | 10 hours ago
Might it be a revealed preference of megacorps: cheating in VR games is a serious issue, and users' security is not?
ignaloidas | 3 hours ago
Repeating a joke: New lesson for security researchers: when you find a vulnerability, don't use it to steal crypto keys, escalate privilege, or execute shellcode. Just write video game cheats, and the anti-cheat industry will make sure it's patched. DMA attacks were long considered a hypothetical method for FBI/NSA to steal a dissident's laptop disk encryption key in a cafe, yet after a decade of demos, VM and QubesOS users still needed to hunt for motherboards with proper IOMMU. Even after Thunderbolt and USB 4 made these attacks universal, for a long period nobody really cared. It only became the default right now thanks to PCIe cheat hardware. Advancing security and privacy for free software desktops, who cares? Video games losing money? Much better.
k749gtnc9l3w | 30 minutes ago
Optimists thought that rooting a Pixel is already bad for mobile games! Apparently not bad enough to push Google to do something.
Hales | 7 hours ago
Hackerfactor.com has a long line of blog posts about the myriad of ways that C2PA is broken and misleading. Eg https://hackerfactor.com/blog/index.php?/archives/1080-C2PA-in-a-Court-of-Law.html
The fact I keep hearing about it being pushed is very disheartening. Someone has a business model in mind and doesn't care about the impact on the public.
[OP] retr0id | 7 hours ago
He's also written about my findings, here https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html - definitely worth a read for the bigger-picture view