Skip to content
By using Twitter’s services you agree to our Cookies Use. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
i0n1c's profile
Stefan Esser
Stefan Esser
Stefan Esser
Verified account
@i0n1c

Tweets

Stefan EsserVerified account

@i0n1c

CEO of @Antid0tecom (former CEO of @SektionEins) (contact: twitter@antid0te.com)

Cologne, Germany
antid0te.com
Joined September 2008

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Imprint
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Stefan Esser‏Verified account @i0n1c May 13

    The simple reality is there are so many 0-day exploits for iOS and the only reason why just a few attacks have been caught in the wild is that iOS phones by design hinder defenders to inspect the phones.

    11:06 PM - 13 May 2019
    • 193 Retweets
    • 437 Likes
    • Jah Man TALU carmasec ::: security. done. right. Stean Rishi Andrei Melnikov Flo Honey SaanBhai
    16 replies 193 retweets 437 likes
      1. New conversation
      2. Stefano Zanero‏Verified account @raistolo May 14
        Replying to @i0n1c @matthew_d_green

        I guess the point is also, in part, that for iOS you actually need an exploit, as opposed to it being broken from the ground up 😛

        1 reply 0 retweets 3 likes
      3. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @raistolo @matthew_d_green

        So are you saying on android phones you can just ask whatsapp from remote to execute code?

        1 reply 0 retweets 2 likes
      4. Stefano Zanero‏Verified account @raistolo May 14
        Replying to @i0n1c @matthew_d_green

        No, but I am saying that given a same remote vuln in WA, you are more constrained and need further knowledge on iOS than on Android. YOU are not the average exploiter, my friend :)

        1 reply 1 retweet 2 likes
      5. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @raistolo @matthew_d_green

        of course you need iOS and iDevice knowledge for attacking iOS devices. But for Android you need android knowledge and likely need to know about the myriads of differences between different device vendors.

        2 replies 0 retweets 3 likes
      6. Stefano Zanero‏Verified account @raistolo May 14
        Replying to @i0n1c @matthew_d_green

        Ah yes, heterogeneity is a factor in favor of Android of course.

        1 reply 0 retweets 0 likes
      7. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @raistolo @matthew_d_green

        anyway your opinion on difficulty difference between iOS and (latest) Android exploits is not reflected in e.g. prices entities like @zerodium pay or by what people say who write exploits for both platforms.

        1 reply 1 retweet 3 likes
      8. Stefano Zanero‏Verified account @raistolo May 14
        Replying to @i0n1c @matthew_d_green @Zerodium

        I’d be curious to hear more about that.

        1 reply 0 retweets 0 likes
      9. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @raistolo @matthew_d_green @Zerodium

        Well you can just look into the public @zerodium pricelist. You will see they are willing to pay exactly the same for iOS and Android exploits. And the only thing that they pay premium for is REBOOT PERSISTENCY on iOS because that is much harder.

        1 reply 1 retweet 13 likes
      10. 1 more reply
      1. New conversation
      2. Miguel de la Cruz, Quisqueyano‏ @xchixm May 14
        Replying to @i0n1c @hackerfantastic

        They're both big problems, but which is the bigger threat: inability to investigate 0days in iOS or ability to introduce vulnerabilities relatively easily through the Play store's more permissive process?

        1 reply 0 retweets 0 likes
      3. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @xchixm @hackerfantastic

        without the ability to investigate, how do you get an accurate view on how much malware is really inside the iOS store?

        1 reply 0 retweets 3 likes
      4. Miguel de la Cruz, Quisqueyano‏ @xchixm May 14
        Replying to @i0n1c @hackerfantastic

        That's true. It could be just as bad and we'd have to trust Apple's approval process.

        1 reply 0 retweets 0 likes
      5. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @xchixm @hackerfantastic

        There is no doubt that Android's App permission model is much more open than iOS. But things like the WhatsApp exploit has very little todo with this. Also it would be easily possible for Apple to offer shell access to iOS without compromising app store security.

        1 reply 2 retweets 4 likes
      6. 1 more reply
      1. New conversation
      2. davide‏ @DavideAicardi May 14
        Replying to @i0n1c

        That’s very interesting, i follow you since years but sometimes bring some evidence, it would be easier to understand

        1 reply 0 retweets 1 like
      3. Stefan Esser‏Verified account @i0n1c May 14
        Replying to @DavideAicardi

        Nobody will show you their 0-day just because you ask. But I can see how many players these days built teams/companies around iOS exploitation.

        1 reply 1 retweet 13 likes
      4. 1 more reply
      1. New conversation
      2. Krogoth‏ @le_krogoth May 17
        Replying to @i0n1c

        Interesting thought. Brings me back to the discussion we had a few days ago re obfuscation. How can we proof that there are tons of exploits known. It is difficult to argue in a corporate environment w/o numbers...

        1 reply 0 retweets 0 likes
      3. Stefan Esser‏Verified account @i0n1c May 17
        Replying to @le_krogoth

        In general it is hard to argue about unknowns. Especially when one side very religiously claims things do not exist. However people also didn’t see certain western government pwning everyone left and right like ISPs, etc...

        0 replies 0 retweets 1 like
      4. End of conversation
      1. New conversation
      2. ⓣⓞⓜ‏ @tomtastic May 14
        Replying to @i0n1c @x0rz

        if there are so many exploits, why no public jailbreaks anymore?

        1 reply 0 retweets 3 likes
      3. stuart‏ @42OGHz May 14
        Replying to @tomtastic @i0n1c @x0rz

        This is todo with WhatsApp. Not iOS itself. Unless you can create a jailbreak from WhatsApp, good luck. He’s also saying there are probably more 0days, which means people/teams tend to keep it quiet for either money or personal use in the future.

        1 reply 0 retweets 2 likes
      4. ⓣⓞⓜ‏ @tomtastic May 14
        Replying to @42OGHz @i0n1c @x0rz

        thanks, neither Stefan nor I mentioned WhatsApp here. neither do i believe Stefan was talking about "there are so many 0-day exploits" _for_ Whatsapp...

        0 replies 0 retweets 2 likes
      5. End of conversation

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2019 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Imprint
      • Cookies
      • Ads info