Sign in

Dino A. Dai Zovi

@ddz.bsky.social
2K followers 108 following 132 posts

I drink amari and I know things. $ddz LMDDGTFY: duckduckgo.com/?q=dino+dai+zovi NYC/BK

PostsRepliesMedia
Reposted by Dino A. Dai Zovi
Kendra Albert @kendraserra.bsky.social · 30/03/2025
New users, on Signal, you can mute chats for a period or permanently. No notifications but you can still see if there are unread messages. On desktop: in that chat, go to Group Settings, then Notifications. On iPhone: in that chat, click on the name at the top, then go to Sounds & Notifications.
46513
Dino A. Dai Zovi @ddz.bsky.social · 30/03/2025
"Life Safety building automation is pretty awesome. 👏"
030
Reposted by Dino A. Dai Zovi
Angie Jones @angiejones.tech · 30/03/2025
Excellent writeup on how MCP future-proofs API integrations ~ @stevemanuel.bsky.social docs.mcp.run/blog/2025/03...
docs.mcp.run
MCP: The Differential for Modern APIs and Systems | 🤖
<div style={{
1218
Reposted by Dino A. Dai Zovi
OffensiveCon @offensivecon.bsky.social · 25/03/2025
Our second keynote for Offensivecon 2025 will be Dino Dai Zovi! @ddz.bsky.social
093
Dino A. Dai Zovi @ddz.bsky.social · 30/03/2025
I'll be doing a speaking!
092
Reposted by Dino A. Dai Zovi
4Dgifts @4dgifts.bsky.social · 17/03/2025
Saw this on the other site but I should comment here: Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991. You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns
096
Reposted by Dino A. Dai Zovi
antirez @antirez.bsky.social · 08/02/2025
We are destroying software: antirez.com/news/145
antirez.com
We are destroying software - <antirez>
1721261
Dino A. Dai Zovi @ddz.bsky.social · 08/02/2025
Exactly this. We should instead be investing that energy into making authentication in our environment unphishable by making it impossible to give away access to an attacker, even if someone actually wanted to.
051
Reposted by Dino A. Dai Zovi
Shell @risu.bsky.social · 08/02/2025
I have never once run a phishing sim. I refuse to use the word. I put it in air quotes and say scam by text or email etc Tech and cyber has been about deflecting blame to anyone else but themselves- which is what sims are. Blaming people when the system they use should protect against issues.
2103
Reposted by Dino A. Dai Zovi
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 31/01/2025
NEW: WhatsApp says it has notified 90 victims, including journalists and members of civil society, that they were targeted with spyware made by Paragon. This is the first time that Paragon is linked to alleged abuse of its products. techcrunch.com/2025/01/31/w...
techcrunch.com
WhatsApp says it disrupted a hacking campaign targeting journalists with spyware | TechCrunch
The Meta-owned company said the campaign was linked to Israeli spyware maker Paragon.
15733
Reposted by Dino A. Dai Zovi
evacide @evacide.bsky.social · 31/01/2025
Meta says almost 100 journalists and activists were targeted with spyware from Israeli company Paragon Solutions using a zero-click vuln in WhatsApp. If you use an iPhone, enabling Lockdown Mode prevents this from working. www.theguardian.com/technology/2...
theguardian.com
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware
7184131
Reposted by Dino A. Dai Zovi
Dennis @dennisf.bsky.social · 22/01/2025
If you're interested in the history of bug bounties, for reasons, this series I did a few years ago with @k8em0.bsky.social @caseyjohnellis.bsky.social @ddz.bsky.social and many others may be of interest. duo.com/decipher/law...
duo.com
Lawyers, Bugs, and Money: When Bug Bounties Went Boom
Bug bounties have grown from a niche idea to encourage independent security research into a massive business and a legitimate career path for bug hunters in less than 15 years. This is the story of th...
53212
Dino A. Dai Zovi @ddz.bsky.social · 19/01/2025
I'm really liking the crisp definitions of and boundaries between product engineering, domain engineering, and infra engineering in this. How much of your security org builds "what any company would need" (infra) vs. "what is unique to this company but shared across the company" (domain) ?
0111
Dino A. Dai Zovi @ddz.bsky.social · 18/01/2025
There are different privacy concerns and approaches for the training phase of AI as well as for the inference phase of using it. It's a good time to be thinking about what the right approaches are for each.
030
Reposted by Dino A. Dai Zovi
Matthew Green @matthewdgreen.bsky.social · 17/01/2025
I wrote a post about how AI will interface with end-to-end encryption. TL;DR maybe not so well! blog.cryptographyengineering.com/2025/01/17/l...
blog.cryptographyengineering.com
Let’s talk about AI and end-to-end encryption
Recently, I came across a fantastic new paper by a group of NYU and Cornell researchers entitled “How to think about end-to-end encryption and AI.” I’m extremely grateful to see t…
1220182
Dino A. Dai Zovi @ddz.bsky.social · 18/01/2025
+1, security product vendors, services companies, *and* internal teams must always operate under the Hippocratic Oath, "First, do no harm."
132
Reposted by Dino A. Dai Zovi
Kevin Collier @kevincollier.bsky.social · 16/01/2025
So phone metadata *is* actually sensitive and important information? So hard to keep this straight.
bloomberg.com
FBI Has Warned Agents It Believes Hackers Stole Their Call Logs
FBI leaders have warned that they believe hackers who broke into AT&amp;T Inc.’s system last year stole months of their agents’ call and text logs, setting off a race within the bureau to protect the ...
742989
Dino A. Dai Zovi @ddz.bsky.social · 16/01/2025
We blogged again! This time about our Data Safety Levels framework, which was inspired by the CDC/WHO Biosafety Levels system and Laboratory Biosafety Manuals. Like biological agents, we also don't want sensitive data to be exposed to humans or escape. code.cash.app/dsl-framework
code.cash.app
Data Safety Levels Framework: The foundation of how we look at data in Block
Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.
053
Dino A. Dai Zovi @ddz.bsky.social · 01/01/2025
The placement of liability for fraudulent credit card charges onto the issuer incentivized the shift to EMV, so we now have smartcards in our wallets and secure elements on our smartphones. Contrast this to the security of authn to way more critical things than buying a coffee.
391
Reposted by Dino A. Dai Zovi
Filippo Valsorda @filippo.abyssdomain.expert · 31/12/2024
Ever wanted to benchmark RSA key generation but found it too slow and variable, like benchmarking a lottery? No? Just me? Well, I nerd-sniped myself into producing average representative inputs that can be used to benchmark, profile, and compare RSA keygen. c2sp.org/CCTV/keygen Happy New Year(?)!
words.filippo.io
Benchmarking RSA Key Generation
RSA key generation is conceptually simple, but extremely tricky. Even benchmarking involves math: we generated a stable but representative “average case” instead of using the ordinary statistical appr...
26613
Reposted by Dino A. Dai Zovi
Matthew Green @matthewdgreen.bsky.social · 29/12/2024
This Salt Typhoon stuff is insane. The entire FISA surveillance infrastructure has been completely owned by China and literally no part of our telecom infrastructure is safe to use without end-to-end encryption.
27892318
Reposted by Dino A. Dai Zovi
Man in Business Suit Levitating @dfeldman.org · 25/12/2024
You’re still arguing about tabs vs. spaces? May I present…
Code written with box characters used on old old software to make fake UIs
15652631267
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
The subtle benefit of *minimal* version selection as a systemic damper on software supply chain attacks: "What’s more, the deeper in your dependency tree the library is, the more explicit approvals are required for the library to propagate to your project." matklad.github.io/2024/12/24/m...
matklad.github.io
Minimal Version Selection Revisited
In this post, I want to highlight one aspect of Go-style minimal version selection that I have missed completely at first. Maybe you missed it too?
071
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
The transition from static long-term "credentials" (PAN + CVV) to EMV cryptograms generated by smartcards and the continuing transition for online payments are good case studies for how to devalue data to the point of making attacks on processing infra no longer worthwhile. Human authn must be next.
041
Reposted by Dino A. Dai Zovi
Mike Masnick @masnick.com · 20/12/2024
Honestly, the Let's Encrypt folks don't get nearly enough credit for basically protecting the entire fucking internet, by making it absolute bog standard to encrypt everything. It happened so fast and so many people were skeptical.
151247277
Reposted by Dino A. Dai Zovi
Stéphane Taillat @staillat.bsky.social · 20/12/2024
An excellent episode on a topic on which I've given some thoughts in my book with similar conclusions: 1️⃣Targeting TikTok in the name of "national security" avoids addressing the structural problems of unregulated personal data and content moderation.
1155
Reposted by Dino A. Dai Zovi
Bob Lord @boblord.bsky.social · 19/12/2024
Directory traversal vulnerabilities have plagued software customers for over two decades. It's time for software companies to step up and eliminate this persistent class of coding error entirely. More info here: buff.ly/3QpbblJ
152
Dino A. Dai Zovi @ddz.bsky.social · 19/12/2024
A bias can form if folks' primary exposure to Signal (or really any other tool) is through observing malicious uses. I've seen it happen with cryptocurrencies as well. A useful tool will often find itself useful for both beneficial and malicious use-cases. It's as old as discovering fire.
080
Reposted by Dino A. Dai Zovi
Meredith Whittaker @meredithmeredith.bsky.social · 19/12/2024
This is disingenuous marketing. Signal chats can't be 'monitored' by anyone not in those chats. Dressing up "joining groups via publicly posted links, then exfiltrating group data" as an offensive 'cybercapability' borders on misinfo, and confuses/scares ppl who rely on Signal for robust privacy.
17530151
Reposted by Dino A. Dai Zovi
Bob Lord @boblord.bsky.social · 18/12/2024
The best Christmas movies are Three Days of the Condor and The Conversation. 🎥 🍿 Thank you for attending my TED talk.
6152
Reposted by Dino A. Dai Zovi
Renee DiResta @noupside.bsky.social · 18/12/2024
🧵New paper out on MIDDLEWARE‼️What is it? 3rd party tools that can interact with, in this case, social media platforms, on behalf of users. Maybe to curate your feed in a particular way. Maybe to moderate, labeling & hiding content or users that you don't want to see. www.thefai.org/posts/shapin...
thefai.org
Shaping the Future of Social Media with Middleware | The Foundation for American Innovation
This paper is co-published by the Foundation for American Innovation and Georgetown University’s McCourt School of Public Policy.
1522244
Reposted by Dino A. Dai Zovi
Hexadecim8 @hexadecim8.com · 15/12/2024
Friends, FBI has responded to my FOIA request for Kevin Mitnick's files, and have made them available to everyone via the FBI public portal here: vault.fbi.gov/kevin-mitnic...
vault.fbi.gov
Kevin Mitnick Part 01 (Final)
821180
Reposted by Dino A. Dai Zovi
Joseph Cox @josephcox.bsky.social · 16/12/2024
New: Cellebrite is being used as doorway to install malware. Amnesty finds multiple cases where police used Cellebrite to unlock phone; cops then used that access to infect with spyware which takes screenshots, turns on mic, etc, give phone back to target. In Serbia www.404media.co/cellebrite-u...
417398
Reposted by Dino A. Dai Zovi
John Scott-Railton @jsrailton.bsky.social · 16/12/2024
NEW: police in #Serbia caught unlocking activists phones with #Cellebrite forensic tool & planting spyware. Investigation by Amnesty Tech shows Serbian authorities mixing a repression brew of homegrown + foreign-purchased surveillance & forensic tech.. 1/ securitylab.amnesty.org/latest/2024/...
27346
Dino A. Dai Zovi @ddz.bsky.social · 14/12/2024
Huh, liars with "flexible" morality lie, as it turns out.
063
Reposted by Dino A. Dai Zovi
Bob Lord @boblord.bsky.social · 13/12/2024
🔒 While we're working to get web traffic to 100% HTTPS, let’s not stop there. What about text messages, calls, and other protocols? It’s time to think bigger and aim for universal encryption—every byte, every pipe, secured. 🌐💬📞 👉 Read more: buff.ly/4iA9i25
0103
Dino A. Dai Zovi @ddz.bsky.social · 12/12/2024
Hot off the presses! Our 2nd blog post on how we do app-layer encryption in our back-end services for Cash App: code.cash.app/encryption-u...
code.cash.app
Encryption using data-specific keys
Associating encryption keys with the data they protect
2178
Reposted by Dino A. Dai Zovi
Working Families Party 🐺 @workingfamilies.org · 12/12/2024
We’d like to live in a world where we never have to choose between affording healthcare or groceries this month. And neither does our neighbor (even if we don’t always agree with them). That’s all.
013316
Reposted by Dino A. Dai Zovi
Whitney Merrill @wbm312.bsky.social · 12/12/2024
Use Signal. Donate to Signal.
29136
Reposted by Dino A. Dai Zovi
North Pole Security @northpolesec.bsky.social · 10/12/2024
Today we're excited to release Santa v2024.11! github.com/northpolesec... Highlights: 1. Our initial beta for standalone mode: This lets you authorize binaries using TouchID. So you can live in lockdown mode. www.youtube.com/watch?v=Hd4t...
youtube.com
Santa Standalone Mode w/Swift UI
YouTube video by Pete Markowsky
112
Reposted by Dino A. Dai Zovi
Maya Kaczorowski @mayakaczorowski.com · 10/12/2024
What keeps security leaders up at night? I interviewed 57 CISOs and security leaders to find out. The answers were surprisingly consistent: access management challenges, vulnerability management complexity, and limited SaaS visibility. Read the post: mayakaczorowski.com/blogs/what-s...
mayakaczorowski.com
What sucks in security? Research findings from 50+ security leaders
I interviewed 57 security leaders and asked them "What sucks in security?" Their top pain points were inconsistent access management, vulnerability prioritization and remediation, and obtaining SaaS l...
23116
Reposted by Dino A. Dai Zovi
Matthew Green @matthewdgreen.bsky.social · 09/12/2024
“Suing Apple To Force It To Scan iCloud For CSAM Is A Catastrophically Bad Idea”, by @riana.bsky.social. Who could have imagined. www.techdirt.com/2024/08/19/s...
techdirt.com
Suing Apple To Force It To Scan iCloud For CSAM Is A Catastrophically Bad Idea
There’s a new lawsuit in Northern California federal court that seeks to improve child safety online but could end up backfiring badly if it gets the remedy it seeks. While the plaintiff’s attorney…
67736
Dino A. Dai Zovi @ddz.bsky.social · 07/12/2024
Pleasantly surprised to see a local news segment like this about consumers using end-to-end encrypted messaging. Make sure to also watch the commentary between newscasters at the end. www.yahoo.com/news/u-urges...
yahoo.com
U.S. Urges Using These Apps for Secure Messaging
Rich DeMuro shares tech headlines on the KTLA 5 Morning News. Topics include secure messaging apps, Walmart buying VIZIO and Cameo opening up it's video greeting platform to smaller creators and influ...
041
Reposted by Dino A. Dai Zovi
Thomas Fuchs 🫯 @thomasfuchs.at · 04/12/2024
My Spotify Wrapped for this year is that I don't use Spotify
810416
Dino A. Dai Zovi @ddz.bsky.social · 05/12/2024
In breaking news, water is wet, the sky is blue, and owning/pwning telco infrastructure is valuable for intelligence gathering. It's been a strategic mistake to keep our society vulnerable by fighting e2e encryption rather than embracing it and promoting democratized use of it.
03816
Reposted by Dino A. Dai Zovi
Angie Jones @angiejones.tech · 03/12/2024
Kendrick x SZA. Pre-sale tickets available for Cash App card holders www.ticketmaster.com/kendrick-lam...
ticketmaster.com
0124
Reposted by Dino A. Dai Zovi
Joseph Lorenzo Hall, PhD @josephhall.org · 03/12/2024
Ahem, [taps the end-to-end encryption sign] "U.S. officials urge Americans to use encrypted apps amid cyberattack that exposed live phone calls"
nbcnews.com
U.S. officials urge Americans to use encrypted apps amid cyberattack that exposed live phone calls
Officials from the FBI and CISA said it was impossible to predict when the telecommunications companies would be fully safe from interlopers.
0105
Reposted by Dino A. Dai Zovi
Lea Kissner @leak.bsky.social · 03/12/2024
The irony, it burns. Yes, there are tradeoffs to end to end encryption, but it's wild for the FBI to start agreeing with basically the entire security community that it's an often-necessary security message. www.nbcnews.com/tech/securit...
nbcnews.com
U.S. officials urge Americans to use encrypted apps amid cyberattack that exposed live phone calls
Officials from the FBI and CISA said it was impossible to predict when the telecommunications companies would be fully safe from interlopers.
26824