Posts

This profile is from a federated server and may be incomplete. Browse more on the original instance.

apicultor, to random
@apicultor@hachyderm.io avatar
GrapheneOS,
@GrapheneOS@grapheneos.social avatar

@apicultor Pixels moved away from Snapdragon in 2021 to Tensor. They began using wrapped key encryption support, moved to a custom RISC-V secure element (Titan M2) and an entirely different TEE (TrustZone) implementation (Trusty OS). It's a different platform, not the same one. We've recently posted a lot about this and how we have worked on improving security against recovery of data from After First Unlock devices. Our pinned post is about firmware improvements we got them to add in April.

GrapheneOS,
@GrapheneOS@grapheneos.social avatar

@apicultor Pixel 5a is the only Snapdragon Pixel that's not end-of-life and will be soon. Our device-specific hardening work is being done for Tensor Pixels.

You should read the thread we have pinned: https://grapheneos.social/@GrapheneOS/112204428984003954. It goes into detail about some of our recent improvements and the firmware updates we pushed for.

We have zero-on-free which applies at shutdown/reboot as it does normally, auto-reboot, USB-C port control disabling USB at a low level and our usual exploit protections.

apicultor, to random
@apicultor@hachyderm.io avatar

You're curious. Admit it. @reecemartintransit @jon

apicultor,
@apicultor@hachyderm.io avatar

@jon @reecemartintransit I'm sure you noticed that the track kept going.

You're curious. Admit it.

jon,
@jon@gruene.social avatar

@apicultor @reecemartintransit I’m now wondering when I have a spare hour in Paris soon to have a look 🙂

apicultor, to Matrix
@apicultor@hachyderm.io avatar
dragfyre,
@dragfyre@mastodon.sandwich.net avatar

@apicultor Interestingly enough, @thunderbird now offers Matrix as an option in its Chat tab. But yeah, Element has been a trashfire for a while. :dumpster_fire:

apicultor, to random
@apicultor@hachyderm.io avatar

@AbandonedAmerica I bet you'd get along well with Troy Paiva.

https://lostamerica.com/

AbandonedAmerica,
@AbandonedAmerica@mastodon.social avatar

@apicultor I've never met him but he does great work I've enjoyed for well over ten years at this point!

apicultor, to random
@apicultor@hachyderm.io avatar

Excellent post by @cks regarding how quickly boxes get probed after having their FQDNs included in a Certificate Transparency log (aka having a TLS certificate issued for them):

https://utcc.utoronto.ca/~cks/space/blog/web/WebProbeSpeedNewTLSCertificate

Lively discussion on Hacker News too:
https://news.ycombinator.com/item?id=38620927

This is actually why I use only wildcard certificates when possible — not for security by obscurity, but why stick your head out of the trench and call attention to yourself when you don't have to?

apicultor, to random
@apicultor@hachyderm.io avatar

@ChrisPirillo It's neat to cross paths with you again.

(Disk is cheap, as they say.)

ChrisPirillo,
@ChrisPirillo@mastodon.social avatar

@apicultor ...that takes me back.

apicultor, to random
@apicultor@hachyderm.io avatar
apicultor, to Cybersecurity
@apicultor@hachyderm.io avatar

The third annual ERA/ENISA conference is underway in sunny Athens. Your correspondent is attending in person.

Fingers crossed that UNIFE doesn't get their way! 🤞🏼

https://www.era.europa.eu/content/3rd-era-enisa-conference-cybersecurity-railways

(Pictures courtesy of ERA.)

So many people. Sold out with a waiting list!
ERA/ENISA Collaboration

apicultor,
@apicultor@hachyderm.io avatar

Update: Very glad to be able to report that the UNIFE speaker received a chilly reception from many in the crowd re their bullshit position that the Cyber Resiliency Act should not apply in rail, with special resistance to mandatory supply of patches:

https://www.unife.org/news/joint-statement-raising-concerns-on-unpatched-vulnerability-reporting-in-the-cyber-resilience-act/

Their position seems to not have evolved whatsoever since their position paper from September 2021:

https://www.unife.org/wp-content/uploads/2021/09/UNIFE-Cybersecurity-position-paper.pdf

@jon @PGLux

Heuvinck,

@apicultor @jon @PGLux They're probably not the only sector to need a push. Going the route of regulation is the best way forward, even the US is revising their previous position in favour of regulating.

Tomorrow ENISA will publish a report with a deep dive on the transport sector. Our survey found that more than half of transport entities that have been designated under the NIS directive need 1 month to patch a critical vulnerability. And more than a fifth need between 1 and 6 months to patch

apicultor, to random
@apicultor@hachyderm.io avatar

@jon WTF is up with ÖBB's Nightjet timetable for December?

michael_h,
@michael_h@nrw.social avatar

@jon @sebwilken @apicultor
Called ÖBB‘s customer service yesterday. They admitted some struggle to open online bookings from December, 10.
I couldn‘t book via nightjet.com and was provided advice to book via https://shop.oebbtickets.at as nightjet.com is just a sort of overlay.
But even there: No bookings available for most connections in early 2024.

apicultor,
@apicultor@hachyderm.io avatar

@jon @sebwilken @slateroni Plus ça change, plus c'est la même chose. 😭

apicultor, to Signal
@apicultor@hachyderm.io avatar

@unifiedpush I love the concept of UnifiedPush, and indeed I use it with Element on with no Google anything installed (and thus no Google-powered push notifications).

However, Signal's push notifications work flawlessly on this same device, so clearly they handle their own notifications (and do a good job of it).

So, other than , what's the benefit to the end user of Molly over ?

tcely,
@tcely@fosstodon.org avatar

As Signal itself proved, adding voice and video calls on top of secure text channels is entirely possible.

RCS does already include voice and video calling in the universal profile. I wouldn't be surprised if Google were to announce they are working to encrypt those also in their Messages app in the future.

@apicultor

apicultor,
@apicultor@hachyderm.io avatar

@tcely >The idea that Google controls RCS is only propaganda.

From your own image: "Unlike the RCS messaging servers, the key server is only hosted by Google."

Fucking LOL. And you have contradicted precisely zero of the points I raised, instead resorting to smoke and mirrors and handwaving.

I don't need to "believe" Signal when they have already shown what they collect:
https://signal.org/bigbrother/central-california-grand-jury/

Google, on the other hand? Take your pick:
https://duckduckgo.com/?q=google+geofence+warrant

Trust? Google? No. lol.

apicultor, to random
@apicultor@hachyderm.io avatar

@jon Do you have some time on the afternoon of the 19th? ERA Interop session looks interesting.

https://www.era.europa.eu/content/11th-era-budapest-workshop

jon,
@jon@gruene.social avatar

@apicultor Damn no. Am exploring borders in Slovenia that day... can't login to that!

apicultor, to random
@apicultor@hachyderm.io avatar

@soatok I found this super helpful, thank you!

https://soatok.blog/2022/12/29/what-we-do-in-the-etc-shadow-cryptography-with-passwords

You might want to update it to reflect that Bitwarden now supports Argon2id as of v2023.2.0:
https://bitwarden.com/help/kdf-algorithms/

apicultor, to random
@apicultor@hachyderm.io avatar

Real shit right here. Mad fuckin' props to both you and your wife, @0x00string

https://infosec.exchange/@0x00string/111061491707388395

apicultor, to random
@apicultor@hachyderm.io avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • rosin
  • thenastyranch
  • ethstaker
  • DreamBathrooms
  • osvaldo12
  • magazineikmin
  • tacticalgear
  • Youngstown
  • everett
  • mdbf
  • slotface
  • ngwrru68w68
  • kavyap
  • provamag3
  • Durango
  • InstantRegret
  • GTA5RPClips
  • tester
  • cubers
  • cisconetworking
  • normalnudes
  • khanakhh
  • modclub
  • anitta
  • Leos
  • megavids
  • lostlight
  • All magazines