Thursday, November 11


Daily News Stuff 11 November 2021


Top Story

  • Unicode considered harmful: Hiding backdoors in plain sight by, um, making them invisible.  (Bleeping Computer)

    The script in question uses an invisible Unicode character as a JavaScript variable parsed from a URL parameter, and passes it, still invisible, to the command line, where it can do whatever the hell it wants.

    PyCharm flags this as a warning, and Rust quite properly won't compile.  In Notepad++ though, it looks absolutely normal; the only sign of anything odd is a redundant trailing comma in a couple of places.

    Given how frequently Node.js packages are caught misbehaving in obvious ways, it's discomforting to consider that this invisible attack could already be in the wild.
    "It might therefore be a good idea to disallow any non-ASCII characters," advises the researcher.

  • This researcher, if you want to go to the source.  (Certitude)

Tech News

Party Like It's 1979 Video of the Day

When Second Best Is Better Video of the Day

The 12700K backs off a little on clock speeds and removes four of the low power cores.  That brings its power consumption way down compared to the 12900K.  It still runs hotter than the AMD competition but on single-threaded benchmarks it is also noticeably faster.  Plus it's substantially cheaper than the 12900K and - hang on - yes, actually available.

On the other hand, it's priced uncomfortably close to the current retail price of AMD's 5900X, a 12 core part that is 30% faster on multi-threaded workloads.  So for a dedicated workstation I'd probably still recommend AMD.  For mixed work and gaming, the 12700K has the edge.

Of course, there's still the DDR5 problem, which is to say, there isn't any.  You can buy a DDR4 motherboard instead, and it will work fine, but then you're limited to the lower-end motherboards, with only, uh, four M.2 slots (all PCIe 4.0 x4) and five PCIe slots, including a PCIe 5.0 x16.

So, probably just fine.

I'm tempted.  If I survive the next few weeks.

Disclaimer: It's got edge, and it knows how to use it.

Posted by: Pixy Misa at 06:06 PM | Comments (2) | Add Comment | Trackbacks (Suck)
Post contains 476 words, total size 4 kb.

1 ""It might therefore be a good idea to disallow any non-ASCII characters," advises the researcher."

Can't use the pile of poop emoji as a variable?  The horror!!!

Posted by: Rick C at Friday, November 12 2021 12:32 AM (Z0GF0)

2 "More of this, please, harder and faster."
And tack on more zeroes, please.

Posted by: Rick C at Friday, November 12 2021 12:34 AM (Z0GF0)

Hide Comments | Add Comment

Apple pies are delicious. But never mind apple pies. What colour is a green orange?

51kb generated in CPU 0.0928, elapsed 0.9551 seconds.
58 queries taking 0.9248 seconds, 342 records returned.
Powered by Minx 1.1.6c-pink.