/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Charlie Miller

@0xcharlie
16 posts
2024-07-12
On the one hand Signal had some bad bugs that are now fixed. On the other hand when a bad guy is running code on your computer, your messenger apps are not going to be able to protect your comms.
2024-07-12 View on X
BleepingComputer

Signal plans to roll out a beta version of its desktop apps that tightens the security of how it stores plain text encryption keys, after downplaying the issue

Signal is finally tightening its desktop client's security by changing how it stores plain text encryption keys for the data store after downplaying the issue since 2018.

2024-04-03
So folks who are wringing their hands over the xz backdoor... What are we going to do differently to stop this in the future? My guess is we will preach and pontificate but not actually do anything useful...just like we always do!
2024-04-03 View on X
research!rsc

A timeline of the attack on open-source project XZ Utils, which began in late 2021 and led to a backdoor with RCE in Linux distros Debian, Red Hat, and others

Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library …

2023-10-29
3) The only interesting (to me) device getting targeted is Samsung Galaxy. 4) Why is pwn2own targeting smart speakers and printers? That's so easy even I could do it and I'm old. 5) When did pwn2own have rules written by lawyers? Used to be a tweet, a blog if you were lucky.
2023-10-29 View on X
BleepingComputer

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

This playlist contains all of the videos recorded at Pwn2Own Toronto 2023. Dustin Childs / Zero Day Initiative : Pwn2Own Toronto 2023 - Day Three Results Alex Ivanovs / Stack Diary...

Interesting data from this week's Pwn2Own. 1) No attempts against Google Pixel or iPhone even though they are worth 4-5x other targets. 2). 15 straight years of hacking Apple products at Pwn2Own ended last year and continues this year. Apple is secure now? 1/n
2023-10-29 View on X
BleepingComputer

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

This playlist contains all of the videos recorded at Pwn2Own Toronto 2023. Dustin Childs / Zero Day Initiative : Pwn2Own Toronto 2023 - Day Three Results Alex Ivanovs / Stack Diary...

2023-10-28
Interesting data from this week's Pwn2Own. 1) No attempts against Google Pixel or iPhone even though they are worth 4-5x other targets. 2). 15 straight years of hacking Apple products at Pwn2Own ended last year and continues this year. Apple is secure now? 1/n
2023-10-28 View on X
BleepingComputer

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

The Pwn2Own Toronto 2023 hacking competition has ended with security researchers earning $1,038,500 for 58 zero-day exploits …

3) The only interesting (to me) device getting targeted is Samsung Galaxy. 4) Why is pwn2own targeting smart speakers and printers? That's so easy even I could do it and I'm old. 5) When did pwn2own have rules written by lawyers? Used to be a tweet, a blog if you were lucky.
2023-10-28 View on X
BleepingComputer

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

The Pwn2Own Toronto 2023 hacking competition has ended with security researchers earning $1,038,500 for 58 zero-day exploits …

2022-01-26
I love me some @joegrand https://twitter.com/...
2022-01-26 View on X
The Verge

How hacker Joe Grand used a fault-injection attack to crack a Trezor One hardware wallet to recover $2M in cryptocurrency for two friends who forgot the PIN

In early 2018, Dan Reich and a friend decided to spend $50,000 in Bitcoin on a batch of Theta tokens, a new cryptocurrency then worth just 21 cents apiece.

2021-04-06
This is really about apple making money, but he is correct. https://twitter.com/...
2021-04-06 View on X
MacRumors

On a podcast, Tim Cook says he's “not focused on Facebook”, Apple is confident in its case against Epic Games, AR is critically important for Apple, and more

Sami Fathi / MacRumors :

2021-01-26
This is why you should use xcode ;) https://twitter.com/...
2021-01-26 View on X
The Keyword

Google Threat Analysis Group details a suspected North Korean specialized campaign targeting infosec researchers with fake profiles, blogs and backdoor software

Over the past several months, the Threat Analysis Group has identified an ongoing campaign targeting security researchers working …

2020-12-30
This is good news but apparently there is still a criminal case pending https://twitter.com/...
2020-12-30 View on X
Washington Post

Federal judge dismisses Apple's claims that mobile device virtualization company Corellium violated copyright law with its software to run iOS on PCs

Corellium helps customers find bugs in Apple's mobile operating system.  Apple aimed to shut it down.  —  Corellium, a security research firm sued …

2020-08-06
This is really stupid and short-sided. I didn't think the free Internet could end so quickly... https://twitter.com/...
2020-08-06 View on X
CNBC

US proposes a five-part “Clean Network” plan to curb potential national security risks from China, including banning “untrusted” Chinese apps from US app stores

- U.S. Secretary of State Mike Pompeo announced a five-pronged “Clean Network” effort aimed at curbing potential national security risks from China.

2020-06-03
Huh I thought for sure @alexstamos would defend zoom e2e policy as a business decision, which i'd disagree with but understand. Instead his argument is the worn out “we only want good people to use e2e encryption, not bad people”. Sigh... https://twitter.com/...
2020-06-03 View on X
The Next Web

Zoom CEO says the app's upcoming end-to-end encryption feature will be available only to paid users in order to comply with law enforcement in case of misuse

If you're a free Zoom user, and waiting for the company to roll out end-to-end encryption for better protection of your calls, you're out of luck.

2020-04-06
This is a decision made by reading scary headlines and not understanding threat models or risk or software security basics. If enough people switch to MS teams, we'll see similar issues reported with that software. https://chalkbeat.org/...
2020-04-06 View on X
Washington Post

Zoom is being banned over security concerns by some US school districts, including NYC, which is directing teachers to switch to Microsoft Teams

Zoom's popularity has taken off … Tweets: Brad Lander / @bradlander : This is a terrible decision @NYCSchools @DOEChancellor. Our teachers, students, and families have put in massi...

2020-04-05
This is a decision made by reading scary headlines and not understanding threat models or risk or software security basics. If enough people switch to MS teams, we'll see similar issues reported with that software. https://chalkbeat.org/...
2020-04-05 View on X
Washington Post

Zoom is being banned over security concerns by some US school districts, including NYC, which is directing teachers to switch to Microsoft Teams

Some school districts around the country have started to ban the use of Zoom for online learning from home during the coronavirus crisis …

2019-09-06
Its easy to criticize security decisions if you don't understand the tradeoffs involved. Let me explain why Twitter made various security decisions, right or wrong. Remember I was Twitter appsec tech lead a while back so I have some insight. https://twitter.com/...
2019-09-06 View on X
The Verge

Twitter says it has “temporarily” turned off the SMS-to-tweet feature, after Jack Dorsey's account was compromised

which is a central way that many orthodox/hassidic jews access this platform—is ultimately being powered down for spreading antisemitic content https://www.adweek.com/... https://t...

2019-09-05
Its easy to criticize security decisions if you don't understand the tradeoffs involved. Let me explain why Twitter made various security decisions, right or wrong. Remember I was Twitter appsec tech lead a while back so I have some insight. https://twitter.com/...
2019-09-05 View on X
The Verge

Twitter says it has “temporarily” turned off the SMS-to-tweet feature, after Jack Dorsey's account was compromised

Twitter has “temporarily” turned off the ability to tweet via text message just days after the feature was misused by hackers to tweet a racial slur, bomb threat …