| ▲ | joa- 10 hours ago | |||||||||||||||||||||||||||||||
This showed me that taint analysis is kind of slept on. Maybe we should invest in better tooling that allows us to reverse engineer with taint analysis easier. Do we think it is a UI problem? Of course over tainting is a thing, but maybe we can make it work with better UI. | ||||||||||||||||||||||||||||||||
| ▲ | chuckadams an hour ago | parent | next [-] | |||||||||||||||||||||||||||||||
Taint analysis won't help against memory safety vulnerabilities that directly scribble over untainted data to make it malicious. You need something like a secure enclave to prevent that kind of tampering. | ||||||||||||||||||||||||||||||||
| ▲ | setr 10 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||
Is that really the name for it? It sounds revolting Can’t we just use prim and proper terms like provenance | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| ▲ | ill-ion 10 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||
[dead] | ||||||||||||||||||||||||||||||||