Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked
Are you sure you want to view these Tweets? Viewing Tweets won't unblock
-
Pinned Tweet
My
@MastodonProject account is now fully setup. If you want to follow me => https://mastodon.social/@fs0c131y From today, I will publish my tweets on both platform. If you want to contact me for sensitive stuff use: - Keybase@fs0c131y - Email fs0c131y[@]protonmail[.]com - Wire@fs0c131yShow this thread -
This thread contains great insights on North Korea and is the best thread I saw on the Virgil casehttps://twitter.com/laurashin/status/1201331530523648001…
-
-
Elliot Alderson Retweeted
-
Elliot Alderson Retweeted
WW2 resistance in Poland was very well organized (awesome name too: ZWZ.) They had a black propaganda organization that was kept completely secret from the rest of the resistance and the Allies. Their security system of cutouts was so effective they were never penetrated.
Show this thread -
Elliot Alderson Retweeted
A problem infosec has - outside of the rampant misogyny - is that people believe that their opinions are facts. Infosec often doesn't have clear answers. We are terrible at science and parrot untruths. To push a valued member of the community out over an *opinion* is bullshithttps://twitter.com/MalwareTechBlog/status/1200679967937351681…
-
Le ministère de l’industrie et des Technologies chinoise a imposé une nouvelle réglementation exigeant que les personnes se fassent scanner leur visage lors de leur enregistrement à un service de téléphonie mobile. https://www.lesechos.fr/monde/chine/en-chine-pas-de-reconnaissance-faciale-pas-de-mobile-1152821 …pic.twitter.com/xYlx0GeAfB
-
Elliot Alderson Retweeted
After the
#ironmarch leak, I was wondering how to find such forums in general. In my new article, I describe how to start#OSINT investigations on right-wing extremists from scratch. Starting in#VKontakte and pivoting to many other platforms and channels.https://keyfindings.blog/2019/12/01/researching-right-wing-extremism-in-central-europe/… -
Elliot Alderson Retweeted
FUN FACT (that I was told while I worked there so it may be entirely false): When the National Climatic Data Center was founded to store weather data, they did a study to find the safest city in the US, and the result was Asheville, NC.
Show this thread -
Elliot Alderson Retweeted
TL;DR: do what you want with your bugs, but don't think you're only "saving the bad guys time". You wouldn't believe how stupid and incompetent the average cybercrime actor is (majority can't even code and only use free tools).
Show this thread -
Elliot Alderson Retweeted
Not really piled into the discussion about vulns & PoCs because it's kinda toxic, but anyway here's my take: 1. That discussions in infosec are toxic *is* symptomatic of infosec toxicity in general, so let's look at that. 2. Attacking people asking it is gatekeeping and shitty.
Show this thread -
4/ It doesn’t mean anything out of context but he has an interest for DPRK, more than an average personpic.twitter.com/n7aXijAU7e
Show this thread -
-
-
1/
@virgilgr, a member of the Etherum foundation, has been arrested after giving a talk in a conference in North Korea. He volunteered to attend this conference.pic.twitter.com/0hGC2LByN1Show this thread -
-
Elliot Alderson Retweeted
-
I found this ticket related to my issue but unfortunately the fix is only available in the internal version of BinDiff at
@Google. Any plans to release BinDiff 6 soon? https://issuetracker.google.com/issues/143198645 …Show this thread -
In BinDiff, I have this error everytime I’m opening a flow graph. Is it a known issue? How can I debug that? I have IDA pro 7.2 and the latest BinDiff version cc
@maddiestonepic.twitter.com/knFqB0L6X3Show this thread -
Protip: Giving a conference in DPRK is rarely a good idea. Protip 2: If the FBI told you not to go, you should probably listen to them Protip 3: if you go, don’t say you want to buy another citizenship publicly
Show this thread -
.
@virgilgr, a member of the etherum foundation, has been arrested. He “provided highly technical information to North Korea, knowing that this information could be used to help North Korea launder money and evade sanctions“https://www.justice.gov/usao-sdny/pr/manhattan-us-attorney-announces-arrest-united-states-citizen-assisting-north-korea…Show this thread -
A hydra is difficult to kill. Hacking Team is back under the name Memento Labs. Business 1 - Ethics 0https://twitter.com/howelloneill/status/1200420611807469570…
-
-
I guess the conclusion of this question: If you are not happy, do it yourself
Show this thread -
Hacking a phone with an unanswered phone call is a fantasy for a majority of people. Being able to show it would be super cool and would help to raise security awareness.
Show this thread -
Don’t get me wrong, I’m convinced that somewhere an exploit dev working for a private company did create an exploit. But why keeping it private? Do you realize how cool a demo of this bug would be? Not only for infosec pros but also for the rest of the world
Show this thread -
Hi
#infosec pro, Why nobody publish publicly an exploit for the NSO WhatsApp vulnerability (CVE-2019-3568)?Show this thread -
Elliot Alderson Retweeted
Happy to announce, I'll be giving the full disclosure talk on
@Boeing &@exostar fought hard against & detailing pressure against@toholdaquill@IDGWorld & myself. Story updates include@fbi &@SEC_News@BlackHatEurope next week in London representing@LHS_LONhttps://twitter.com/SecEvangelism/status/1191671697910517760… -
Elliot Alderson Retweeted
I heard that somewhere on Twitter a discussion about publishing exploit PoCs arose. Good thing information security is so repetitive, and I can field most discussions by referring to previously written long-form blog posts: http://addxorrol.blogspot.com/2019/08/rashomon-of-disclosure.html …
Show this thread -
Elliot Alderson Retweeted
That! I generally don't pitch in on the "responsible PoC disclosure" debate, as I don't actively contribute to the area and rather let
@maddiestone@taviso@AndreaBarisani or@Fox0x01 argue (and enjoy learning the arguments). But here is my defender's point of view: 1/https://twitter.com/idl3r/status/1200223675418468357…Show this thread -
-
I took the control of
@KyoLAB Twitter account, my current client. Follow us!https://twitter.com/kyolab/status/1200389817227468801… -
Elliot Alderson Retweeted
The evolution of the truck is here. Guaranteed shatterproof
pic.twitter.com/RocTEkzzwI
-
It’s funny to see that people, when they see a situation like this, directly think it’s a political thing
Show this thread -
This morning a professional photographer takes photos of me for an upcoming article: A pedestrian stops suddenly, look at us and said « Ah! It’s for the local elections! ». The photographer answered « Yes, but it doesn’t know it yet »
Show this thread -
-
Elliot Alderson Retweeted
So many details in this WSJ investigation i.e: Hewlett Packard owns 49% of a Chinese surveillance/network firm selling to law enforcement. One client is a Chinese city known for “broad surveillance of residents,” & home to “multiple internment camps.”https://www.wsj.com/articles/u-s-tech-companies-prop-up-chinas-vast-surveillance-network-11574786846?mod=searchresults&page=1&pos=1…
Show this thread -
Elliot Alderson Retweeted
Bug bounties and vuln disclosure are trending again. I've found it useful to think of external bug reports as a form of whistleblowing. Someone noticed something wrong with your product/infrastructure and is bringing it to your attention in the hope that you'll address it. 1/n
Show this thread -
Elliot Alderson Retweeted
We downloaded recent content from 151 US city subreddits (Reddit forums), three from each state plus Washington DC, and ran sentiment analysis on the content. This map shows each city colored by the percentage of posts/comments with negative sentiment scores. cc:
@ZellaQuixotepic.twitter.com/JGXqfp3KXwShow this thread -
Is there already a “Mobile Security” newsletter? If not I should create it, do something similar to the excellent
@zackwhittaker’s newsletter. What do you think? Is there a public for that? -
So much choice, thank you all, you are awesome
Show this thread