ian_roos Profile Banner
Ian Roos Profile
Ian Roos

@ian_roos

Followers
494
Following
876
Media
101
Statuses
651

Hacker | Friend of RPISEC | Cat Advocate | Margin Research | Pwnies

On a couch
Joined November 2011
Don't wanna be here? Send us removal request.
@ian_roos
Ian Roos
6 years
Tweet media one
2
1
13
@ian_roos
Ian Roos
17 days
"The Subtle Art of Not Giving a F*ck"."Everything Is F*cked"."Unfu*k Yourself". Book idea: "Shut the f*ck up." Reject trashy pop sci self help titles.
0
0
3
@ian_roos
Ian Roos
2 months
RT @PwnieAwards: Great news! The Pwnie awards nominations are now open!.
0
26
0
@ian_roos
Ian Roos
3 months
Acid Capital : Shitpost Policy.
0
0
0
@ian_roos
Ian Roos
3 months
"I'm making a massive database of every security bug ever found in software.". "That's a wonderful public service, what information are you including?". "As little as possible!". "Sick!".
0
0
1
@ian_roos
Ian Roos
3 months
Expanding further: The major failure of CVE is the lack of material information contained (or required) within the standard. I can't count the number of times i've had to pivot off platform on a scavenger hunt for a writeup. This can and should be consolidated.
0
0
1
@ian_roos
Ian Roos
3 months
Q: Why is this useful?. A: Hypertaxonimization a la Mitre ATT&CK creates pitfalls where we're chasing order for chaos. Nature is inherently chaotic. If we can catalog that, we can certainly manage it for bugs. A2: Because I like it.
1
0
1
@ian_roos
Ian Roos
3 months
The potential retirement of CVE creates an incredible opportunity for the introduction of a more descriptive and (frankly useful) standard. One thing that would be particularly beautiful would be the implementation of animal kingdom latin naming conventions for bug classes.
3
1
9
@ian_roos
Ian Roos
4 months
I am once again tapping the sign
Tweet media one
0
0
0
@ian_roos
Ian Roos
6 months
You're not supposed to talk about it but in the UK computers all use big endian.
0
1
2
@ian_roos
Ian Roos
7 months
Tweet media one
0
6K
0
@ian_roos
Ian Roos
7 months
UMN was the hero OSS needed, not the one they wanted.
0
0
1
@ian_roos
Ian Roos
9 months
If both parties need the underlying technology to work safely and securely the cost for a valid cyber attack pattern against it increases exponentially. Requires elaborate key'ing a la XZ. Reduces value of deliberate bugdoors which could be easily flipped.
0
0
1
@ian_roos
Ian Roos
9 months
This is actually a good thing. Neoliberal economic globalism is offensive cyber deterrence strategy. Two countries with Windows XP based nuclear launch controls will never go to war with each other.
@committeeonccp
Select Committee on the Chinese Communist Party
9 months
BREAKING: Chinese researchers develop AI model for military use on back of @Meta’s Llama . “Top Chinese research institutions linked to the PLA have used Meta's publicly available Llama model to develop an AI tool for potential military applications.”
2
1
5
@ian_roos
Ian Roos
9 months
Vendor maximalism. Fully randomized attack surface.
0
0
1
@ian_roos
Ian Roos
9 months
The only way to build resiliency is by deploying anti-trust on infosec companies based on their sq footage at black hat conf. Put the entire attack surface in a blender. "Operation gazpacho".
1
0
2
@ian_roos
Ian Roos
10 months
RT @DistrictCon: 🚨The Junkyard Call For Bugs is Open! 🚨We want you to bring your most impactful, creative, or most meme-y bugs in end-of-li….
0
33
0
@ian_roos
Ian Roos
10 months
When Dan Geer said "Hey actually everyone using msoft could be a bad thing" what he meant to say was "if you give everyone the same pager their balls are going to explode at the same time"
Tweet media one
0
7
13
@ian_roos
Ian Roos
11 months
RT @__winn: I’m SO stoked to finally announce @DistrictCon - a new DC hacker conference, bringing together hackers across industries to do….
0
32
0