By the way, I think I have to concede defeat in my attempt to audit RAP, because I haven’t been able to get at the private version, and…
2
i must have missed your attempt at the public version, where is it?
1
1
didn’t I identify a weakness in the public version ages and ages ago? turned out it was (supposedly) solved in the private version.
2
1
that is a gcc codegen issue (fixed in RAP) and you never demonstrated anything with it. any other excuses? ;)
1
is it a bug in GCC? if not, it is not an “issue” in GCC but in your implementation. which you apparently worked around, so good for you.
2
but without that workaround (“public version”), it would still be an issue, so.
1
...so do you have an exploit or not? the time you spent on twitter for the past year should have been enough for one... ;)
1
for that issue? it seems like a waste of time to write one if real systems aren’t affected by it, but I could if you want me to
1
Replying to @comex
for anything in RAP, it's more than just retaddr protection after all.

Aug 13, 2017 · 8:18 PM UTC