/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Matthew Garrett

@mjg59
16 posts
2023-05-12
Anyway for full disclosure I emailed @cstanley and the other Twitter people implementing encrypted DMs over a week ago to raise some (not super severe) concerns about the implementation and he never replied, so take any claims about external audits with appropriate salt
2023-05-12 View on X
Engadget

Twitter rolls out encrypted DMs, but both sender and recipient must be Blue subscribers, group messages are not supported, and message metadata is not encrypted

Starting with Verified Users Jay Peters / The Verge : Twitter launches encrypted DMs behind a paywall Geoff Desreumaux / WeRSM : Twitter Launches Encrypted DMs, But Only For Paid S...

https://help.twitter.com/... is refreshingly honest about how poor the Twitter encrypted DM implementation is. What it doesn't cover is how the existing design decisions make it *very* hard to implement some of what they want to add (like group DMs with any meaningful security)
2023-05-12 View on X
Engadget

Twitter rolls out encrypted DMs, but both sender and recipient must be Blue subscribers, group messages are not supported, and message metadata is not encrypted

Starting with Verified Users Jay Peters / The Verge : Twitter launches encrypted DMs behind a paywall Geoff Desreumaux / WeRSM : Twitter Launches Encrypted DMs, But Only For Paid S...

2023-05-11
Anyway for full disclosure I emailed @cstanley and the other Twitter people implementing encrypted DMs over a week ago to raise some (not super severe) concerns about the implementation and he never replied, so take any claims about external audits with appropriate salt
2023-05-11 View on X
Engadget

Twitter rolls out encrypted DMs, but both sender and recipient must be verified users, no support for group messages, and message metadata is not encrypted

There are still some major limitations to the feature.  —  Twitter is beginning to roll out its long-promised encrypted direct messaging feature.

https://help.twitter.com/... is refreshingly honest about how poor the Twitter encrypted DM implementation is. What it doesn't cover is how the existing design decisions make it *very* hard to implement some of what they want to add (like group DMs with any meaningful security)
2023-05-11 View on X
Engadget

Twitter rolls out encrypted DMs, but both sender and recipient must be verified users, no support for group messages, and message metadata is not encrypted

There are still some major limitations to the feature.  —  Twitter is beginning to roll out its long-promised encrypted direct messaging feature.

2023-02-10
But I thought feature development was extremely hardcore https://twitter.com/...
2023-02-10 View on X
9to5Mac

Many Twitter users reported issues on February 8, from outages to not being able to tweet except by scheduling or via an API; the issues seem to be mostly fixed

2023-02-09
But I thought feature development was extremely hardcore https://twitter.com/...
2023-02-09 View on X
9to5Mac

Many Twitter users reported issues on February 8, from outages to not being able to tweet except by scheduling or via an API; the issues seem to be mostly fixed

Shortly after Twitter launched its huge increase in max character count to 4,000 today, many users aren't able to tweet this afternoon.

2023-02-06
This is definitely a man who understands his product before making decisions https://twitter.com/...
2023-02-06 View on X
TechCrunch

After Twitter said free API access would end on February 9, Elon Musk promises “a light, write-only API for bots providing good content that is free”

Last week, Twitter said it is shutting down free access to its APIs starting February 9.  Now, days before the deadline …

2023-02-03
If you want to fuck shit up, you pretend to be the Android or iOS Twitter app in order to make it look like you're human. Doing so allows you to use the API for free even if API access is nominally charged for. This is not something that stops bad things.
2023-02-03 View on X
TechCrunch

Twitter plans to discontinue free access to its API starting on February 9, ending support for both v1.1 and v2, and launch a “paid basic tier” instead

This week I spent too many minutes watching Nothing, Forever, which is a Twitch stream that runs 24/7. Mastodon: Kate Starbird / @katestarbird@mstdn.social : Looks like Twitter is ...

Removing free API access removes a whole bunch of interesting automated accounts and integrations and tooling, and does nothing to stop abuse. Fucking good work.
2023-02-03 View on X
BuzzFeed News

Twitter ending free API access could have the unfortunate side effect of effectively killing off many useful bots like @MakeItAQuote, @BigTechAlert, and more

“I'm not paying a dime to Elon lol.”  —  Pranav Dixit  —  One of the most popular bots on Twitter is @MakeItAQuote, which has more than 565,000 followers.

If you want to fuck shit up, you pretend to be the Android or iOS Twitter app in order to make it look like you're human. Doing so allows you to use the API for free even if API access is nominally charged for. This is not something that stops bad things.
2023-02-03 View on X
BuzzFeed News

Twitter ending free API access could have the unfortunate side effect of effectively killing off many useful bots like @MakeItAQuote, @BigTechAlert, and more

“I'm not paying a dime to Elon lol.”  —  Pranav Dixit  —  One of the most popular bots on Twitter is @MakeItAQuote, which has more than 565,000 followers.

Removing free API access removes a whole bunch of interesting automated accounts and integrations and tooling, and does nothing to stop abuse. Fucking good work.
2023-02-03 View on X
TechCrunch

Twitter plans to discontinue free access to its API starting on February 9, ending support for both v1.1 and v2, and launch a “paid basic tier” instead

This week I spent too many minutes watching Nothing, Forever, which is a Twitch stream that runs 24/7. Mastodon: Kate Starbird / @katestarbird@mstdn.social : Looks like Twitter is ...

2022-03-29
Looking at https://twitter.com/..., it's interesting to think about the degree to which modern security controls would have helped mitigate this attack. It's also important to note that what many people think of as ZTA would have been no help at all.
2022-03-29 View on X
Wired

Leaked Mandiant report: Okta's contractor Sitel first sent a Lapsus$ breach notification to Okta on January 25 and a detailed “Intrusion Timeline” on March 17

Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don't explain the apparent lack of urgency.

2021-08-04
@dangoodin001 @qrs Disk encryption on Windows systems is done on the CPU, using a key that's stored in the TPM. Macs with a T2 do the decryption on the T2 itself, so you can't intercept the key using hardware.
2021-08-04 View on X
Ars Technica

Researchers were able to quickly circumvent security protections of a laptop that followed virtually all NIST recommendations, including TPM and UEFI SecureBoot

2021-06-12
This is a masterpiece in making it sound like the people in question were leaking material externally, without actually making that claim (from https://www.vox.com/...) https://twitter.com/...
2021-06-12 View on X
Vox

NLRB expands its complaint against Google to add three more fired workers who say the company retaliated against them for protesting against its work with CBP

Shirin Ghaffary / Vox :

2019-12-13
The hacks appear to be the result of re-used credentials. Companies who have access to this sort of material should be doing a better job of protecting their customers - at the very least, proactively checking new dumps and forcing password changes if there's a hit. https://twitter.com/...
2019-12-13 View on X
VICE

A recent spate of Ring camera hacks were part of a podcast livestreamed to Discord called “Nulledcast” in which Ring owners were hacked and harassed live on air

@josephfcox @jason_koebler http://bit.ly/2LJeFyn Fred Blankenship / @fblankenshipwsb : No sireeee! “I can see you in the bed! C'mon! Wake the [expletive] up!” This terrified Brookh...

2018-01-04
This (from http://developer.arm.com/...) reads uh pretty badly tbh. If exploitation via Javascript is viable then you can't put the onus on users to avoid malicious Javascript. http://twitter.com/...
2018-01-04 View on X
Google Online Security Blog

Google's Project Zero says it discovered three variants of CPU attack, affecting AMD, ARM, and Intel; Android devices with latest security update are safe

Last year, Google's Project Zero team discovered serious security flaws caused by “speculative execution,” a technique used by most modern processors …