Skip to content
By using Twitter’s services you agree to our Cookies Use. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
marcan42's profile
Hector Martin
Hector Martin
Hector Martin
@marcan42

Tweets

Hector Martin

@marcan42

If it ain't broke, I'll fix it! I'm porting Linux to Apple Silicon Macs at @AsahiLinux. http://patreon.com/marcan  | http://github.com/sponsors/marcan 

Tokyo, Japan
marcan.st
Joined May 2009

Tweets

  • © 2021 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Imprint
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    1. Naomi Wu 机械妖姬‏ @RealSexyCyborg 29 May 2018
      • Report Tweet
      • Report NetzDG Violation

      Naomi Wu 机械妖姬 Retweeted dragosr

      So @bunniestudios & Limor @adafruit, is this bullshit?https://twitter.com/dragosr/status/1001114342958317568 …

      Naomi Wu 机械妖姬 added,

      dragosr @dragosr
      Ever wondered what’s in hw ethernet jack style implants? Notice it has a few more than 8 pins. Parents came from communist country, and defected to avoid their regular bugging of their own staff, so I grew up finding bugs. I think they mistakenly shipped me the wrong Raspi 3b+ pic.twitter.com/GyR9bCb4Ek
      11 replies 3 retweets 26 likes
      Show this thread
    2. tatzelbrumm‏ @Tatzelbrumm 30 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @RealSexyCyborg @bunniestudios @adafruit

      Given where his parents are coming from, @dragosr's concerns are legitimate: https://en.wikipedia.org/wiki/The_Thing_(listening_device) … but can be disproven.

      1 reply 0 retweets 0 likes
    3. dragosr‏ @dragosr 31 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @Tatzelbrumm @RealSexyCyborg and

      Again, compromise is certain (extra consoles on ttyAMA0, new systemd slices that sandbox users and leave some system components unconfigurable, nfs mounts on machines with no net hardware, funny kernel modules you can’t touch, and oh so much more fun), just need to explain how.

      3 replies 0 retweets 1 like
    4. dragosr‏ @dragosr 31 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @dragosr @Tatzelbrumm and

      “Trivial” heh. See earlier posts about flash controllers. This is how advanced malware spreads. IT guy takes his favourite memory stick with his OS install and puts it a compromised machine to reinstall. Instead now it becomes the way every new computer in the company gets owned.

      2 replies 0 retweets 1 like
    5. Hector Martin‏ @marcan42 31 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @dragosr @Tatzelbrumm and

      So... use something else? Dump the filesystem over the network? XMODEM it out the serial port? There are endless ways to gather evidence safely; it's nigh impossible to "cover everything" for the malware. No implant, no matter how sophisticated, magically counters everything.

      1 reply 0 retweets 3 likes
    6. Hector Martin‏ @marcan42 31 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @marcan42 @dragosr and

      If there are as many indicators of compromise as you claim (and it's not just you misinterpreting totally normal stuff), then the malware is shoddy and clearly not designed for stealth. So show us some of them.

      1 reply 0 retweets 3 likes
      Hector Martin‏ @marcan42 31 May 2018
      • Report Tweet
      • Report NetzDG Violation
      Replying to @marcan42 @dragosr and

      FWIW: if I were a three-letter agency designing a Raspberry Pi implant, it would live in the VideoCore firmware blob that rules the system from the shadows and be completely invisible to Linux. And I wouldn't be leaving behind "systemd slices that sandbox users".

      7:43 AM - 31 May 2018
      • 16 Likes
      • Tom Thorogood 🏳️‍🌈 Attie Grande FIPSmode Squad Friedemann Wachsmuth vierito5 Christian Mock hex waxwing :(){ :|: &};: HPH
      4 replies 0 retweets 16 likes
        1. New conversation
        2. modrobert‏ @modrobert 31 May 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @marcan42 @dragosr and

          ...or compromise something like AMD Secure Processor, Intel SGX and ARM TrustZone.

          1 reply 0 retweets 0 likes
        3. Hector Martin‏ @marcan42 31 May 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @modrobert @dragosr and

          I'm pretty sure the VideoCore stuff is higher privileged than TrustZone. Though TrustZone would be more portable to other chips.

          1 reply 0 retweets 2 likes
        4. Show replies
        1. New conversation
        2. dragosr‏ @dragosr 31 May 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @marcan42 @Tatzelbrumm and

          and yet paradoxically, this attacker seems to have dispensed with stealth altogether here. I have so many IOCs it’s not funny, so I get the impression this is more about stopping extraction of the samples I do have.

          1 reply 0 retweets 1 like
        3. Hector Martin‏ @marcan42 31 May 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @dragosr @Tatzelbrumm and

          If you have so many IOCs, why not show them to us? You might get some people excited and less likely to call BS on you. Take a video of what you see that isn't normal. Even the most advanced NSA implant can't plug the analog hole.

          3 replies 0 retweets 3 likes
        4. Show replies
        1. Syler‏ @SylerClayton 31 May 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @marcan42 @dragosr and

          Heh, creating malicious VideoCore firmware would be a fun project xDhttps://github.com/christinaa/rpi-open-firmware …

          0 replies 0 retweets 1 like
          Thanks. Twitter will use this to make your timeline better. Undo
          Undo
        1. dragosr‏ @dragosr 12 Jun 2018
          • Report Tweet
          • Report NetzDG Violation
          Replying to @marcan42 @Tatzelbrumm and

          But the fun thing about the Raspi is that videocore blob isn’t invisible. It lives on the SD card and must be readable for the device to boot.

          0 replies 0 retweets 0 likes
          Thanks. Twitter will use this to make your timeline better. Undo
          Undo

      Loading seems to be taking a while.

      Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

        Promoted Tweet

        false

        • © 2021 Twitter
        • About
        • Help Center
        • Terms
        • Privacy policy
        • Imprint
        • Cookies
        • Ads info