[–] 3 points 1 week ago

did your article measure aging? assuming you didn't fry your PC with the excess paste, there is no edge seal on voids when you use too much. over time most paste will dry and crack, creating new voids and hot spots. there is a difference between hour old transfer compound and 2 year old compound.

  • source
  • parent
  • context
  • [–] 4 points 1 week ago

    this has got to be a troll post. right? RIGHT?!

    as you pointed out, just get rid of the air gaps with the absolute minimal amount of paste.

    my back woods methodensure your heat sink does not have pre-applied paste or a pad. apply a small amount of paste. cut the thickness with the short edge of an old credit card at about a 30° angle, using just enough pressure to bend the card slightly so the smooth surface of the card presses paste into voids and the trailing edge of the card removes excess to level the surface - you will likely still be able to make out some chip package markings through the paste. remove all edge excess and spillage. fit your heat sink. done.

  • source
  • parent
  • context
  • [–] 3 points 3 weeks ago

    a security site that (kinda) demands JS shields down? sigh... anyway here is the article for those that prefer to not do silly things...

    cw: OOB writes and race conditions.Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 and 1.4.5, carrying fixes for seven security flaws along with smaller hardening changes.

    Most of the patched bugs sit in the code that unpacks and parses executable formats, the part of a scanner built to handle hostile input. CVE-2026-20213 is an integer overflow in the PE rebuild size calculation that a malformed Aspack-packed file can trigger, leading to a heap buffer overflow write. The related CVE-2026-20214 covers an FSG unpacker loop underflow that can write past the section array during a scan of a crafted PE file. Both reach far back through the codebase, with the FSG issue present in builds dating to 2004.

    CVE-2026-20217 rounds out the PE group. A bug in the PESpin unpacker cleanup path could free pointers into the scanned file buffer and crash the scanner. That flaw has lived in the code since 2005. Archive and image format bugs

    Three more fixes address archive and disk-image handling. CVE-2026-20215 is a 7z parser substream count overflow that can under-allocate parser metadata arrays and then write past them when reading a crafted archive. CVE-2026-20243 covers ALZ parser size handling errors that can make malformed ALZ archives panic, abort the scanner, or skip expected scan-limit handling. CVE-2026-20216 is an InstallShield archive extraction limit bypass that can write far more temporary data than intended and drain temporary storage.

    The last parsing flaw, CVE-2026-20244, sits in the 32-bit DMG parser. A short mish stripe table could pass validation and crash the scanner. This one affects only 32-bit builds, going back to version 0.98.1, and leaves 64-bit builds untouched. Quarantine race condition

    The releases also harden the quarantine actions in clamscan, clamdscan, and clamonacc against time-of-check/time-of-use races. Under unsafe quarantine directory settings, those races could redirect files as the scanner copied, moved, or removed them. Hiroki Imai of Ricerca Security, Inc. reported the issue.

    Version 1.5.3 adds a few items beyond 1.4.5. It upgrades the Rust tar dependency to resolve two RUSTSEC advisories and moves the Rust openssl dependency past CVE-2026-41676. Metadata preclass scans now run before the final scan verdict. A ClamOnAcc fix addresses hash bucket list corruption when two watched paths land in the same bucket. Both releases raise the minimum CMake version to 3.17 to repair Linux builds that link static dependencies against libcurl v8.21.0.

    The release files are available on the GitHub release page, and through Docker Hub in Alpine and Debian containers.

  • source
  • [–] 4 points 4 weeks ago

    an absolutely amazing interview. I spent years of my childhood reading technical documents from this man. he and jay miner were heros of mine and the amiga completely changed my relationship with technology.

  • source
  • [–] 2 points 1 month ago (3 children)

    dont discount the utility of running containers in an abstracted Hardware Virtual Machine (HVM) away from your physical hardware. it expands your testing surfaces and sandboxes immeasurably.

  • source
  • parent
  • context
  •  

    any suggestions on enclosure or room temp/humidity sensors? PoE network connected would be ideal, but USB works as well (cheap, simple). polling/transformation of data will ultimately be done by a raspi 3b.

    open software/hardware is highly desirable and, as long as data is structured, I can transform as needed for insertion into a zabbix backend.

    thanks for any recommendations :-)

     

    We used to think Mimas was a dead world, famous only for the massive crater that gives the moon an uncanny resemblance to the Death Star. But in 2024, scientists discovered a secret hidden beneath its battered shell: a vast, liquid ocean we didn’t know existed.

    Timestamps

    • 0:00 The Death Star Moon
    • 2:00 Herschel Crater
    • 6:36 Pac-Man Boundary
    • 9:24 Splitting Saturn’s Rings
    • 12:08 Mimas vs Enceladus
    • 15:00 Hidden Ocean
    • 18:07 Could Mimas Have Life?
     

    got a call today asking for an obscure file to be restored from a backup thats not particularly important and literally has not been touched (other than OS maint.) in 2+ years.

    poke the web interface and...

    ...urbackup has been faithfully doing its thing all this time. restore the file and walk away. love it when something just works right. thank you urbackup.

    submitted 1 year ago* (last edited 1 year ago) by to c/privacy@lemmy.ml
     

    I have noticed recently (perhaps within the last 6-12 months?) that I can hit many major sites via Tor with JavaScript off. there are a few that reject Tor connections or render illegibly - but, for many mainstream sites, things are actually pretty reasonable. fingerprinting and personal threat models aside, this seems like a positive move and feels different from e.g. 2 years ago.

    am I slowly going insane? has anyone else noticed this? tested over time via orbot and classic Tor nodes with various hardened and non-hardened browsers and DNS resolvers.

    view more: next ›