Matthew Garrett
mjg59@nondeterministic.computer
<p>Former biologist. Actual PhD in genetics. Security, OS security teaching at <a href="https://www.ischool.berkeley.edu" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="">ischool.berkeley.edu</span><span class="invisible"></span></a>. Blog: <a href="https://codon.org.uk/~mjg59/blog" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">codon.org.uk/~mjg59/blog</span><span class="invisible"></span></a> . He/him. Opinions do not reflect those of my employer.</p>
Posts
-
View post
A bit over 15 years ago, a speaker at a tech conference used a couple of slides that were inappropriately sexual given the conference's guidelines. Afterwards the speaker apologised, the organisers apologised, there were process improvements, and it shouldn't have been a big deal. And then people decided that they needed to defend the speaker. Including someone who remains a well known senior Linux kernel developer at a large company.
-
View post
We recognize that the NSDAP is closely associated with its founder, and that raises questions about what our support means. Our contribution is made to the NSDAP, not to an individual, and is not an endorsement of any individual's personal or political views. 1Password does not endorse hateful, dehumanizing, or exclusionary views.
-
View post
Man based on the recruiter mails I get it is *astonishing* how many AI companies are looking for someone to secure their bare metal servers a significant period of time after they started selling product on them
-
View post
So yeah ok I've been clear on my position of "I think my code is uninteresting, it's what my code does that is interesting" and because I do attempt to be honest I am going to present a counterpoint. Amiga UNIX was released in 1990 and supported the 68020 and 68030. Commodore hadn't shipped a 68040 yet, and Motorola didn't adopt the Intel approach of near-absolute backwards compatibility. The 68040 requires different MMU setup that Amiga UNIX never implemented.
-
View post
I would simply not complain about being personally served if my solicitors had explicitly said they were not representing me in this matter
-
View post
"Microscopes are good for biology, not electronics" is a take I had not imagined hearing and yet the internet has blessed me with it (along with the suggestion that I should be using a soldering gun?) Ah yes let me work on these components that are less than a mm across with my bare eyes and a tip several times larger than that
-
View post
Ok, I have perhaps got an idea here? The PD controller is receiving 5V from the charger, but is not receiving 3.3V on its input line. That /should/ be coming from a TCK107AG, which seems to be getting 3.3V on its input and on its control but does *not* appear to be generating 3.3V on its output. This would probably explain the behaviour, but if so I am going to have problems because this fucker is 0.79mmx0.79mm
-
View post
Ok, when plugged in I'm getting 1.8V on the SPI flash power rail, but not when unplugged.
-
View post
Replacement laptop obtained, microscope turning up tomorrow, fun weekend adventure of seeing if I can figure out what's wrong with the broken board (and maybe bringing it back to life) ahead of me
-
View post
I cannot understand the mindset of a (I hope small) subset of the free software community that software-related freedoms can never be impinged upon, but it's fine to remove arbitrary other freedoms that have a greater impact on people's lives
-
View post
If you're invested in there being a Linux distribution that works better with laptops then I will happily make that happen for a mere $1 million a year and you will not be associating your brand with white supremacy in the process please enquire for references and my credentials
-
View post
Things that your app can do that your website can't: 1) gain access to platform cryptography and keystore primitives 2) no that's it If you're not using (1) in ways that makes my security better, fuck off
-
View post
Looking at cryptography in a place that is absolutely fine but satisfies no meaningful threat model whatsoever and deciding that the correct terminology is "emotional support crypto"
-
View post
I am, For Reasons, suddenly very interested in the IBM MWave DSP instruction set and whether anyone has access to any of the apparently lost documentation for that (or whether anyone conveniently already has Ghidra support for it)
-
View post
https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html is both funny and inevitable. Hardware-backed key storage is intended to prevent the private key material being moved to a different system, not prevent the private key material being used in ways you don't like on the system it's stored on. You are not going to stand a good chance of preventing the device owner using that key material however they want (which is why all the fearmongering about TPMs enabling meaningful DRM has alway...
-
View post
I am actually very much in favour of Omarchy because I am very much in favour of all those fuckheads going off and being in one place where they will never bother me
-
View post
Does anyone actually have real-world examples of widescale token theft occurring through compromised middleware boxes or accidental logging of tokens?
-
View post
Vivid dream last night where @jwz@mastodon.social's blog was actually a webcomic and the most recent entry was extremely critical of me personally and I learned about this because Scruffy from Killer Net showed up and provided his role-defining line: "He's flamed yer, called yer a wanker in all the newsgroups". Anyway. I am well adjusted.
-
View post
I ended up rereading the GNU manifesto when writing my FOSSY talk this week and goodness all the sections about how programmers should make money are very "Some of you may die, but that's a sacrifice I'm willing to make" meme anyway this is an allegory about how LLMs and free software interact: https://www.gnu.org/gnu/manifesto.html
-
View post
Meanwhile Roy has taken to referring to me as "Desperado" in what appears to be a pejorative manner so: Antinio Banderas as Desperado:
-
View post
Casually hooking ExitBootServices() as a convenient point to transition the kernel into a hypervisor guest because why not
-
View post
Wanted: chart of chartreuse price Vs ram price
-
View post
It's the kind of day where I both have to look closely at someone's security model and also deal with the cat deciding to eat the butter
-
View post
Last year, Roy and Rianne Schestowitz were found to have defamed me and were ordered to remove that defamatory content and avoid any further defamation. They chose not to follow the whole of this order, and I sought to have them held in contempt of court. Today this was upheld: https://www.brettwilson.co.uk/wp-content/uploads/2026/07/Garrett-v-Schestowitz-and-anor-No-2-2026-EWHC-1948-KB.pdf
-
View post
Roy was held to have provided misleading evidence in both oral and written evidence. Rianne was held to have provided both oral and written evidence that was not correct. My understanding is that this is generally considered to not be a good thing.
-
View post
Huh. This seems like an odd choice (from https://learn.microsoft.com/en-us/windows/security/hardware-security/pluton/pluton-as-tpm)
-
View post
Everyone at #emfcamp gathering around the lake as word of mouth spreads that there's potentially a burning of an Elon Musk effigy
-
View post
Microsoft has been a reasonable steward of the third party UEFI signing key and handling revocation, but I think it's reasonable to question the conflict of interest around the Windows signing key and the huge amount of time between Windows bootloader vulnerabilities being identified and Microsoft revoking them. Ideally this would be delegated to a third party, but an alternative would be for Microsoft to issue a signed (but optional) dbx update that revoked trust in the Windows signing key
-
View post
Sudden furry parade #emfcamp
-
View post
The #emfcamp dalek is dispensing whisky while shouting "Inebriate"