runasand Profile Banner
Runa Sandvik Profile
Runa Sandvik

@runasand

Followers
72K
Following
0
Media
1K
Statuses
28K

Founder of @GranittHQ, securing journalists and at-risk people around the world.

New York, NY
Joined February 2009
Don't wanna be here? Send us removal request.
@runasand
Runa Sandvik
2 months
Thanks to @odanettverk for inviting me to keynote Inspiration Day yesterday! Really enjoyed being back in Oslo and talking about the importance of end-to-end encryption.
Tweet media one
1
0
12
@runasand
Runa Sandvik
2 months
Had the pleasure of being a guest on the Adventures of Alice & Bob Podcast recently! Check out the interview for stories about my work with journalists and high-risk people — and that one time I hacked a smart-rifle in 2015.
Tweet card summary image
beyondtrust.com
BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen credentials, and misused privileges
0
1
7
@runasand
Runa Sandvik
2 months
The Kaspersky researchers who discovered Careto more than a decade ago privately concluded that the group was run by the Spanish government. Careto relied heavily on phishing emails impersonating Spanish newspapers.
Tweet media one
1
14
31
@runasand
Runa Sandvik
2 months
I’ll be in Stockholm in mid-June! Available for consulting, presentations, workshops for journalists and security folks. Also planning on spending some time in the wind tunnel. 🥳.
1
0
18
@runasand
Runa Sandvik
3 months
A team of journalists in Norway spent a year secretly monitoring a credit card fraud gang to uncover who's behind it and how they operate. Here's the story -- in English -- of how they unmasked Darcula and the crime-as-a-service software Magic Cat.
Tweet card summary image
nrk.no
Who are they and how do they scam us?
4
64
178
@runasand
Runa Sandvik
3 months
I’m really looking forward to speaking at @odanettverk Inspiration Day in Oslo on May 28! I’ll be there a couple of days prior and would love to meet folks for coffee and/or work.
Tweet card summary image
odanettverk.no
Runa Sandvik is the founder of Granitt, a consultancy focused on security for journalists and other at-risk people around the world. We are thrilled to have one of the world's leading experts on...
1
1
12
@runasand
Runa Sandvik
4 months
News articles often focus on spyware victims who had their devices checked and opted to go public. We rarely hear about those who didn’t. New court documents from WhatsApp v. NSO shed some light on the true scale of the targeting in a 2019 campaign.
Tweet card summary image
techcrunch.com
The list of 1,223 victims in 51 countries hints at the “true scale of the spyware problem,” per one researcher.
2
38
58
@runasand
Runa Sandvik
5 months
More of this, please.
@propublica
ProPublica
5 months
Current and former federal workers: We’re here in D.C. sending out our signal 🚨. Contact us confidentially on Signal at 917-512-0201 or go to
Tweet media one
1
2
14
@runasand
Runa Sandvik
5 months
As @AlecMuffett noted yesterday, it looks like the U.K. government has quietly scrubbed all encryption advice from government web pages.
Tweet card summary image
techcrunch.com
The UK is no longer recommending the use of encryption for at-risk groups following its iCloud backdoor demands
0
2
5
@runasand
Runa Sandvik
5 months
Italy’s national union for journalists is demanding answers from the authorities following news that seven phones in the country were targeted with spyware from Paragon — including a journalist.
Tweet card summary image
theguardian.com
Union submits criminal complaint to prosecutors as ministers refuse to answer questions about alleged hacks
1
5
17
@runasand
Runa Sandvik
5 months
All the newsrooms I’ve spoken to say having a confidential tip line is incredibly helpful, even if you do have to deal with some non-tips and other spam.
@SecureDrop
SecureDrop
5 months
We’ve seen significant interest in newsrooms setting up SecureDrop to better protect whistleblowers, so we've put together a quick list of 5 key things you should know before setting it up:.
0
6
17
@runasand
Runa Sandvik
5 months
If you’re interested in aviation security, check out this fantastic 2013 talk from @hteso on leveraging ADS-B, ACARS, and on-board systems to attack virtual airplanes systems.
0
3
11
@runasand
Runa Sandvik
6 months
In September 2018, @citizenlab published a report identifying "45 countries where Pegasus operators may be conducting surveillance operations” – including Libya. Operator BLACKBIRD was active between – at least – September 2016 and September 2018.
Tweet card summary image
citizenlab.ca
In this post, we develop new Internet scanning techniques to identify 45 countries in which operators of NSO Group’s Pegasus spyware may be operating.
0
2
4
@runasand
Runa Sandvik
6 months
In November, Apple told @DavidYambio he was targeted by “a mercenary spyware attack.” Yambio, an activist in Italy, has long criticized Italy’s dealings with Libya. He did not receive a notification from WhatsApp, so unclear what he was targeted with.
Tweet card summary image
theguardian.com
Exclusive: Italy-based David Yambio, a critic of Meloni government, was told of attempt to compromise his phone
1
8
19
@runasand
Runa Sandvik
6 months
In Chasing Shadows, @RonDeibert writes that @NYTBen was the first case “of an American journalist being targeted with Pegasus.” Hubbard was targeted in June 2018, but due to “concerns of New York Times management about going public,” @citizenlab didn’t publish until early 2020.
Tweet media one
0
2
17
@runasand
Runa Sandvik
6 months
In December 2023, the U.K. National Cyber Security Centre published digital security guidance for high-risk people. I always found it odd that the guide made no mention of encrypting data at rest, be it on the device or in the cloud.
Tweet media one
2
1
6
@runasand
Runa Sandvik
6 months
Apple’s Lockdown Mode feature for iOS, iPadOS, macOS, and watchOS remains the best protection we have against sophisticated spyware. Here’s what you should know about the feature, to turn it on: Settings > Privacy & Security.
Tweet card summary image
glitchcat.xyz
Earlier this week, Apple notified a number of individuals that state-sponsored actors may be targeting their iPhones.
2
17
25
@runasand
Runa Sandvik
6 months
The U.K. government doesn't want you to encrypt your iCloud data, which means you should definitely turn on Advanced Data Protection under Settings and iCloud.
Tweet card summary image
freedom.press
By demanding a back door into end-to-end encrypted iCloud data, the U.K. undermines journalist-source confidentiality
5
19
44
@runasand
Runa Sandvik
6 months
Arne Treholt was a journalist, diplomat, and part of Norway's delegation to the UN in 1979. The FBI helped Norway surveil Treholt and his wife in NYC. He was arrested in January 1984, convicted of spying for the Soviets and Iraq, and sentenced to 20 years.
Tweet card summary image
journalistandspy.com
Arne Treholt is a former journalist and Norwegian diplomat who, in June 1985, was convicted of spying for the Soviet Union and Iraq and sentenced to 20 years in prison.
1
1
4
@runasand
Runa Sandvik
6 months
In May 1984, two top officials from the Norwegian Police Surveillance Agency visited FBIHQ and participated “as guest lecturers at an Advanced Techniques In-Service” at Quantico. The two men uncovered several illegal Soviet spies in Norway, including Arne Treholt.
Tweet media one
1
1
12