nrv

@nervoir

System explorer, flaw chaser, code twister, funky dancer. Part human, part machine.

1983
Vrijeme pridruživanja: siječanj 2011.

Tweetovi

Blokirali ste korisnika/cu @nervoir

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @nervoir

  1. proslijedio/la je Tweet
    1. velj

    USB 4 specification released. (Highlights: uses USB-C connectors, based on Thunderbolt 3/USB 3.1, backward-compatible with all previous USB specs, carries up to 40Gbps on suitable cables.)

    Poništi
  2. 1. velj
    Poništi
  3. proslijedio/la je Tweet
    28. sij
    Prikaži ovu nit
    Poništi
  4. 23. sij

    Samsung... kmem_cache_zalloc sure helps if you’re going to be writing the allocated structures raw to disk. Rather not have random heap data unencrypted on disk. Thanks.

    Poništi
  5. 23. sij

    And that’s if they’re even still resident on the system. Otherwise you better have some good logging being pushed to a server, which afaik isn’t even widely available on iOS. Because the platform is totally secure as is... 🤷‍♂️ or is there a good solution? Not my area..

    Prikaži ovu nit
    Poništi
  6. 23. sij

    IMHO hunting APT using forensic tooling which is widely available, very commonly used and is known NOT to provide a complete image of all storage, volatile as well as non-volatile, won’t work. Adversary likely have tested the same tool and looked at diff pre and post compromise.

    Prikaži ovu nit
    Poništi
  7. proslijedio/la je Tweet
    16. sij

    Scudo as default Bionic allocator in aosp-master, attempt #2 -- , nothing on fire so far 🤞

    Prikaži ovu nit
    Poništi
  8. 15. sij

    “While commendable, the laws of mathematics do not trump the laws of Australia.” Amazing...

    Poništi
  9. 14. sij
    Poništi
  10. 14. sij

    Tip to some Samsung security engineer.. it’s probably a good idea to use actual random data as a nonce instead of uninitialized kernel stack memory. strncpy is also a terrible way of copying a cryptographic key. 🤭👌🤷‍♂️

    Poništi
  11. 9. sij

    So schemes where a hash of the root CA cert is fused by the OEM would be unaffected.

    Prikaži ovu nit
    Poništi
  12. 9. sij

    The security of such a scheme now depends on any entropy added from CSR to final cert in the form of time stamps and unpredictable identifiers..?

    Prikaži ovu nit
    Poništi
  13. 9. sij

    So.. SHAmbles shows that signature schemes which embed a SOC vendor root CA cert in ROM which uses SHA1 and which in turn signs an OEM cert using a fused customer ID / HWID as differentiation may be tricked such that they’re signing a cert for 1 customer but is actually for 2..?

    Prikaži ovu nit
    Poništi
  14. 3. sij
    Poništi
  15. 1. sij

    I guess it reminds me that people are so much more than their cool security work. The search and rescue, the work on the property are all awesome on their own.

    Prikaži ovu nit
    Poništi
  16. 1. sij

    Wish I would have kept this detailed a record of the goings on in my life. Now it’s all a blur. Particularly once you have kids their needs overshadow everything else and you easily forget all your other achievements. No idea why I found this so interesting 😂

    Prikaži ovu nit
    Poništi
  17. proslijedio/la je Tweet
    Poništi
  18. 26. pro 2019.

    Sounds like something the forensic industry has been doing for a while. Sampling sub pixel burn in to recover histograms which can then get interpolated in 3D matrices, usually evaluated by a convolutional neural network, in order to reproduce historical frame buffer data.

    Poništi
  19. 13. pro 2019.

    God I wish the police would start using more shit plastered with hearts. Always wanted to make surveillance equipment that just says “From China, with love 💕” when discovered.

    Poništi
  20. 11. pro 2019.
    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·