Fuzz-introspector now automatically lists fuzz blockers! How? Overlay statically extracted fuzzer calltree with runtime coverage data and list exact code locations where largest parts of reachable code is uncovered at runtime Try it yourself: github.com/ossf/fuzz-intr…@theopenssf
As we look back upon the past year, we would like to acknowledge those who have helped us shape our business. We look forward to another great year of technical challenges with the goal of helping you build with security.
Thank you!
In 2021 the Bitcoin network handled ~97 million transactions. This equals roughly 0.012% of the worldwide volume of non-cash transactions.
Bitcoin was responsible for 0.54% of global electricity consumption. On average, that's 1,386 kWh per Bitcoin transaction.
I'm glad the @NSAGov "Quantum Computing and Post-Quantum Cryptography" FAQ dismisses quantum key distribution (QKD) as impractical.
There are several companies out there trying to push their QKD solutions, which aren't useful for anything.
media.defense.gov/2021/Aug/04/20…
github.com/google/binja-h…
This is really awesome! I was trying to do the same for Ghidra and its P-Code but @vector35's Binary Ninja API is so much better.
I've always wondered: where are all the people complaining that Samsung doesn't upstream RKP? blog.longterm.io/samsung_rkp.ht… I thought everyone loved coarse-grained CFI applied post-build via binary patching with a Python script? 🙂
A nice overview of RKP exploitation. Funnily enough, two CVEs I got in RKP are in the same addr validation routine (though not the log bug they mention) and I also used PGT3 to write-what-where but targeted stack to jump to the func to disable s2
x.com/astarasikov/st…
The results of our 2nd #Security#Audit have arrived 📃We are committed to having external audits quarterly to provide the highest standard of quality and security to our users 🔐Thanks @longtermsecbit.ly/2MomFmK
7K Followers 870 FollowingSecurity engineer at https://t.co/027VXUlgOx. Focusing on the Linux kernel. Maintaining @linkersec. Trainings at https://t.co/D5MrxmYimS.
5K Followers 1K Followingsome security stuff, opinions are based on experimental thought patterns resulting in delusional yet fun life choices. @[email protected]
2 Followers 166 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/4HELKOEwKv
10 Followers 125 FollowingMy name is Maxwell Seefeld. I'm currently a double major in electrical and computer engineering at FIU. For work, I'm a cyber security consultant/researcher.
37 Followers 910 FollowingSometimes writes about distributed systems, knows next to nothing about stock market, likes sea a lot, prefers snake_case to camelCase