• Home
  • About

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
By using Twitter’s services you agree to our Cookie Use and Data Transfer outside the EU. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
ageis's profile
K.M. Gallagher
K.M. Gallagher
K.M. Gallagher
@ageis

K.M. Gallagher

@ageis

Site Reliability + DevOps engineer / Linux sysadmin, privacy activist

Joined December 2008
  • © 2016 Twitter
  • About
  • Help
  • Terms
  • Privacy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @

Retweet this to your followers?

Optional comment for Retweet
 
 

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
140

Are you sure you want to delete this Tweet?

Promote this Tweet

Block

  • Add a location to your Tweets

    When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

    Profile summary

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    Preview

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Buy Now

    Hmm... Something went wrong. Please try again.

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Previous Tweet
    K.M. Gallagher ‏@ageis 10 Mar 2015

    downloading Xcode installer from App Store. it came in on plain HTTP port 80 from Akamai. #Strawhorsepic.twitter.com/z5axcyGxZq

    • Retweets 69
    • Likes 32
    • Beau 👁 Kibu 杰 priya joseph Andreas T Sven Welzel Guillaume Ceccarelli Dêfãult Vírüsa Ale⨯aﬡdre Ḡʊédoη
    10:20 AM - 10 Mar 2015
    0 replies 69 retweets 32 likes
      1. K.M. Gallagher ‏@ageis 10 Mar 2015

        K.M. Gallagher Retweeted K.M. Gallagher

        @csoghoian @JZdziarski @mattblaze @micahflee Xcode downloads over plain HTTP. how do I know it's not the CIA?https://twitter.com/ageis/status/575345440356450304 …

        K.M. Gallagher added,

        K.M. Gallagher @ageis
        downloading Xcode installer from App Store. it came in on plain HTTP port 80 from Akamai. #Strawhorse pic.twitter.com/z5axcyGxZq
        0 replies 0 retweets 0 likes
      2. matt blaze ‏@mattblaze 10 Mar 2015

        @ageis @csoghoian @JZdziarski @micahflee The package is signed, no?

        0 replies 0 retweets 1 like
      3. K.M. Gallagher ‏@ageis 10 Mar 2015

        @mattblaze @csoghoian @JZdziarski @micahflee yeah, must be. that's all underneath the surface so I dunno, I don't know much about App Store.

        0 replies 0 retweets 0 likes
      4. matt blaze ‏@mattblaze 10 Mar 2015

        @ageis @csoghoian @JZdziarski @micahflee But if your machine was compromised to accept some additional signatures, who knows...

        0 replies 0 retweets 2 likes
      5. Micah Lee ‏@micahflee 10 Mar 2015

        @mattblaze @ageis @csoghoian @JZdziarski yes the package is signed--all apps from App Store are signed by an Apple key

        0 replies 1 retweet 2 likes
      6. View other replies
      7. Micah Lee ‏@micahflee 10 Mar 2015

        @mattblaze @ageis @csoghoian @JZdziarski downloading over http makes censorship attacks easy tho, preventing a user from downloading an app

        0 replies 1 retweet 3 likes
      8. K.M. Gallagher ‏@ageis 10 Mar 2015

        @micahflee then you could force target to get it from a compromised channel. the developer just wants Xcode, they're not verifying anything

        0 replies 0 retweets 0 likes
      9. View other replies
      10. K.M. Gallagher ‏@ageis 10 Mar 2015

        @micahflee I imagine that a lot of ops that deliver compromised binaries are dirty like that and make use of multiple vectors.

        0 replies 0 retweets 0 likes
      11. Show more
      1. Brian A. Reiter ‏@brian_reiter 10 Mar 2015

        .@ageis @matthew_d_green the binaries are signed, though. Right?

        0 replies 0 retweets 0 likes
      2. Brian A. Reiter ‏@brian_reiter 10 Mar 2015

        .@ageis @matthew_d_green Uh, guys? Should I be worried that Xcode doesn't have a valid signature?pic.twitter.com/naTpVpX3Wa

        0 replies 6 retweets 1 like
      3. View other replies
      4. Bertrand MT ‏@bertrandmt 10 Mar 2015

        @brian_reiter @ageis @matthew_d_green Also:pic.twitter.com/4oPABp0NLc

        0 replies 0 retweets 0 likes
      5. Bertrand MT ‏@bertrandmt 10 Mar 2015

        @brian_reiter @ageis @matthew_d_green To be even more clear:pic.twitter.com/2aGHdpToRb

        0 replies 0 retweets 1 like
      6. Brian A. Reiter ‏@brian_reiter 10 Mar 2015

        @bertrandmt @ageis @matthew_d_green what does `--no-strict` do? It isn't documented in the man page for codesign(1).

        0 replies 0 retweets 1 like
      7. View other replies
      8. Bertrand MT ‏@bertrandmt 10 Mar 2015

        @brian_reiter @ageis @matthew_d_green or it enables the special CIA code path where codesign pretends that your signature is okay…

        0 replies 0 retweets 2 likes
    1. The mach monster ‏@osxreverser 10 Mar 2015

      @ageis @hackerfantastic the binaries are code signed and update packages also. doesn't mean ppl verify them ehehehe

      0 replies 2 retweets 2 likes
    2. comex ‏@comex 10 Mar 2015

      @ageis But is it sigchecked separately? I know this happens on iOS but don't know about Mac.

      0 replies 0 retweets 1 like
      1. Bertrand MT ‏@bertrandmt 10 Mar 2015

        @ageis @matthew_d_green Given the closed garden approach to distribution in the app store, I'm not sure what the big deal is.

        0 replies 0 retweets 0 likes
      2. Bertrand MT ‏@bertrandmt 10 Mar 2015

        @ageis @matthew_d_green Even if an app is modified at the developer's site, it has to go through Apple review before being published.

        0 replies 0 retweets 0 likes
      3. Matthew Green ‏@matthew_d_green 10 Mar 2015

        @bertrandmt @ageis Unless it's an enterprise app.

        0 replies 0 retweets 0 likes
    3. Keyzer ‏@penetrate_io 10 Mar 2015

      @ageis @matthew_d_green dude that’s why God invented sha. Lol

      0 replies 0 retweets 1 like

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2016 Twitter
      • About
      • Help
      • Terms
      • Privacy
      • Cookies
      • Ads info