DaKnObCS Profile Banner
DaKnOb Profile
DaKnOb

@DaKnObCS

Followers
946
Following
5
Media
2K
Statuses
43K

I do cool things that matter ;) @[email protected]

Zürich, Switzerland
Joined June 2009
Don't wanna be here? Send us removal request.
@SIGTIM
Tim Geoghegan
3 years
ISRG is hiring an SRE to help keep the world’s largest certificate authority running. Come join our team and help us make the internet safer for all.
abetterinternet.org
Posted: September 29, 2022 Start Date: January 2023 Position Status: Open Location: Remote within US Compensation: $140k USD, 100% 401k Match, Excellent Insurance We’re making HTTPS easier for...
0
6
12
@kennyog
kennyog
3 years
After a constructive engagement with @ThreemaApp during responsible disclosure, this is unexpectedly dismissive. We broke their protocol 6 ways. They updated it, thanks to our work ( https://t.co/XMu8SZBCc3). So of course our work applies to an old version.
@ThreemaApp
Threema
3 years
There’s a new paper on Threema’s old communication protocol. Apparently, today’s academia forces researchers and even students to hopelessly oversell their findings. Here’s some real talk:
5
101
328
@kennyog
kennyog
3 years
We (@winterdeaf @kientuong114 and I) took a deep dive on Threema, a Swiss-made secure messaging app. We found 6 new cryptographic vulnerabilities. Full paper at https://t.co/XMu8SZBCc3; mini-thread follows. #threema
5
121
304
@DougJBalloon
NYTPitchbot
3 years
It takes a good six-year-old with a gun to stop a bad six-year-old with a gun.
102
2K
27K
@FernandoGont
Fernando Gont
3 years
GitHub on finally deploying IPv6.... 😊🤗 ( https://t.co/nsopICqIuL)
2
41
118
@dragosr
dragosr
3 years
Don't dump LastPass because of 7 breaches, dump them for crap crypto: Padding oracle vulns, ECB pass len leaks, switch to CBC for new vaults not old ones, vault key uses AES256 but only 128 bits entropy, key webui leak, silent KDF downgrade, KDF hash log leak, keys left in mem.
6
176
707
@bgptools
BGP.Tools
3 years
🎉 https://t.co/U2xsYhMnN3 has passed 500 Online BGP sessions! Thanks to the networks that have made this possible We now have really quite good routing visibility in EU and a lot of the US, But isn't the whole world! The focus is now Africa, APAC, and LATAM!
0
11
56
@lopp
Jameson Lopp
3 years
This video of cops in Nevada searching a suspect and finding a seed phrase is pretty wild. Imagine having your seed phrase become part of public record due to it being captured by an officer's body camera!
484
792
4K
@jpgoldberg
Jeffrey Goldberg 🌻
3 years
Svaq zr ba Znfgbqba nf wctbyqoret@vbp.rkpunatr
0
1
3
@joncallas
Jon Callas 烏
3 years
1
24
99
@SwiftOnSecurity
SwiftOnSecurity
3 years
POV: You're a security consultant hired to be embedded in a web development team
11
65
460
@bgroothuis
Bart Groothuis
3 years
Europe’s new cyber security legislation NIS2 officially signed! 🥂
38
49
153
@mholt6
🧗‍♂️ Matt Holt
3 years
@DaKnObCS Oh yeah, forgot about that. I'm pretty sure we have the plumbing for this, let me see if we expose it.
0
1
0
@cmwdotme
Chris
3 years
Pulling MikroTik into the Limelight
0
2
23
@mjg59
Matthew Garrett (@[email protected])
3 years
Fine ok you get *another* blog post, this time about why doing on-device WebAuthn (rather than requiring a separate token) is harder in the PC world than on Macs and why Linux just doesn't have a good story here yet:
4
13
40
@DaKnObCS
DaKnOb
3 years
I spoke yesterday about the future of Web Authentication, and you can find the recording online here: https://t.co/TaU3FdmfEv #WebAuthn #Web #WWW #Security #Authentication
0
0
5
@vanschewick
Barbara van Schewick
3 years
The European Commission has been contemplating radical changes to the Internet in Europe that would violate #netneutrality and upend how the internet economy has worked for decades. Its proposal: the long-discredited idea that websites and apps should pay broadband providers.
2
33
68
@DaKnObCS
DaKnOb
3 years
I blogged about using #ACME to automatically, securely, and reliably protect all your workload connections with #mTLS and achieve authenticated End to End Encryption #E2EE: https://t.co/etnzFCbhsP
0
1
2
@DaKnObCS
DaKnOb
3 years
I blogged about how I’m using #ACME to issue #mTLS and #SSH certificates for my personal infrastructure: https://t.co/o6qyRidkKx My end goal is to make sure the devices I’m using don’t have access to my stuff for most of the time. I also move to 100% hardware-backed keys!
0
1
0