Opens profile photo
Follow
Click to Follow saurik
Jay Freeman (saurik)
@saurik
I developed Cydia for jailbroken iOS devices and am now (theoretically) in charge of technology for ; I am also a local politician in California.
EntrepreneurIsla Vista, CAsaurik.comJoined May 2007

Jay Freeman (saurik)’s Tweets

While it was fun to keep my captive live audience in the dark--I had people asking "what language is that?" and second-guessing their memory of prior years--for here I may as well be clear: with only a single exception, every slide in my talk was generated using #StableDiffusion.
image synthesized by stable diffusion using the text prompt "welcome to the latent dystopia". result is a post-apocalyptic cityscape with a title: "welccmme lalttaint dastiovia" (though in two places one could interpret the letter as an N ligature). at the bottom is written "wecl thea thegoptm" in a smaller font.
image synthesized by stable diffusion using the text prompt "hawaiian speaker with stubble at conference giving an angry lecture wearing a pirate hat and outfit". result is a speaker at a podium, only... he has a long, thick beard and is wearing a hawaiian shirt with a cross between a clown and pirate hat down over his eyes. the speaker does look sufficiently angry.
2
72
Show this thread
The event's organizer--, now a science fiction author--always put me on the schedule with a placeholder title such as "Jay says things", allowing me to present highly-topical and audience-driven content, using callbacks to other talks and nigh unto bait-and-switch twists.
a screenshot of the schedule from 360idev.com, showing the slot 3:15-4:00pm in the colorado ballroom as merely "jay says things" by jay freeman, showing a photo of jay but no abstract.
2
30
Show this thread
As an interesting contrast, released their official postmortem of the bug this morning, along with their understanding of the cause (which I will note is very different from the engineering methodology and process issue I focus on in my talk).
4
43
Show this thread
As an interesting contrast, released their official postmortem of the bug this morning, along with their understanding of the cause (which I will note is very different from the engineering methodology and process issue I focus on in my talk).
3
35
Show this thread
I'd missed the confirmation of this on Thursday, but had decided to additionally extend to me their (maximum) $100k bug bounty payout, making the total reward for my Ethereum L2 bug--"Unbridled Optimism"--$2,100,042! (...I think this might actually set a new record?)
Quote Tweet
Hey #Bobarians! In appreciation for @saurik’s deep detective work on this critical vulnerability, we have offered him the maximum amount in our bug bounty program #WAGMI $BOBA #L222 twitter.com/bobanetwork/st…
12
255
Show this thread
I will be giving a talk about the bug at , Friday, February 18th: 9:40am MST on the Infinity Stage. My talk will be live-streamed, presumably to the #ETHDenver YouTube channel: youtube.com/c/ETHDenver Look out for "Attacking an Ethereum L2 with Unbridled Optimism"!
10
665
Show this thread
Amazingly, the bugs continue: after I gave up and went to sleep, the two transfers I then had "PENDING" were both "CANCELLED" at the same time with the reason "The transaction fee has expired."... but these failed transfers are still counting against my daily withdrawal limit :/.
2
69
Show this thread
Does anyone else find it strange that both Apple and Google not only allow but in fact require privacy policies for apps to be hosted on external websites, meaning that to view an app's privacy policy you must connect to their server and already subject yourself to their logging?
48
949
Cydia just joined the legal battle against Apple: "A new lawsuit brought by one of Apple's oldest foes seeks to force the iPhone maker to allow alternatives to the App Store, the latest in a growing number of cases that aim to curb the tech giant's power."
105
2,899
Show this thread
Regardless, in early September of 2020, I was able to get Facebook to reinstate the Cydia app... though they made it sound tenuous enough that I waited until now--when I'm finally feeling confident-ish--to reactivate the button, in case anyone still has reason to log in to Cydia.
57
931
Show this thread
In June of 2019, Facebook suspended my Cydia app, removing its access to Facebook login and locking users out of their Cydia accounts, which required a slow (on both sides: Facebook and I each were taking months to respond to the other ;P) back and forth of interrogations to fix.
54
1,047
Show this thread
So yeah: I don't know if anyone else will agree with me that security events should not allow companies using USC Section 1201--or similar laws around the world: the US got this included in a WIPO treaty--to speak at their events, but if so: poke a conference organizer for me? ;P
15
291
Show this thread
Companies which wish to speak at security events should be required to sign a non-action pledge on USC Section 1201--which isn't even about infringement: it is a potentially-unconstitutional law about "circumventing" controls and "trafficking" in tools--in order to submit a talk.
1
228
Show this thread
All the while, Apple and its employees show up at conferences like and are welcomed with a speaking platform... even as they out-spend companies like Corellium on lawsuits to push judgements that limit the ability to *do* security research.
3
211
Show this thread
The reality is that Apple has been so hostile to independent security research that they've lost their edge: exploits for Android now cost more than exploits for iOS, a reversal experts generally credit to Google correctly allowing researchers open access.
2
262
Show this thread
Apple claims to "recognize the critical role that members of the security research community play in Apple’s efforts to ensure its devices contain the most secure software and systems available", and yet they routinely ignore advice and downplay issues :(.
2
172
Show this thread
What Apple does is cultivate a "chilling effect" on certain kinds of research: when showed how easy it was to slip exploit code through iOS App Store review, he was banned from the Apple Developer program, so others would be too scared to probe.
7
296
Show this thread
Apple continues to insist they have "never pursued legal action against a security researcher"... but they *have* used the DMCA to take down research and even mere discussion of their platforms; the EFF once had to *file a lawsuit* to get them to back off!
3
190
Show this thread
(This is a place where I take particular issue: I know many people who believe in "responsible disclosure" and I work with many *more* people who believe in "full/simultaneous disclosure"; but I don't actually know any security researchers who consider Apple's model to be moral.)
1
168
Show this thread
It is ridiculous that Apple insists "good-faith security research" "requires" "responsible disclosure"--a specific model that involves release deadlines--when Apple actually disallows security researchers in their program from using responsible disclosure!
Quote Tweet
It looks like we won't be able to use the Apple "Security Research Device" due to the vulnerability disclosure restrictions, which seem specifically designed to exclude Project Zero and other researchers who use a 90 day policy.
Show this thread
2
237
Show this thread
In its most recent complaint, Apple continues to insist that 's usage of Corellium's product to help test and more rapidly develop the Unc0ver jailbreak for iOS 12 was an "unlawful end", entirely ignoring the USC Section 1201(f) interop exemption.
Quote Tweet
Shoutout to @CorelliumHQ for giving me access to their amazing platform. This means that I will now be able to test unc0ver on any device running any firmware with extended debugging capabilities!
3
469
Show this thread
This lawsuit is frankly egregious: after discussions to purchase Corellium broke down, suddenly Apple decided to sue them instead; then, as part of the case, Apple has thrown subpoenas far and wide, including at the parent companies of Corellium customers.
3
188
Show this thread
What makes Epic Games--and its founder, --as "our champion" vs. Apple so exciting is they have the cash and the will to see this through; fighting Apple is almost impossible for most of us, as you need money for lawyers and expert witnesses.
4
244
Show this thread
(Oh, and before anyone tries to claim you can sideload applications using Apple's "free development" profiles, they have consistently worked to limit and cripple these mechanisms; in particular, you can't use this to sideload "network extensions", so Apple can entirely ban VPNs.)
1
214
Show this thread