Sign in

Pascal Gujer

@evilmaid.bsky.social
63 followers 43 following 59 posts

security researcher | speaker | trainer | lockpicking | evil maid attacks | maker | threema.id/MPK39EB8 | hands-on-security.com

PostsRepliesMedia
Pascal Gujer @evilmaid.bsky.social · 26/09/2026
🔓 Breaking BitLocker at Black Hat Europe still needs a few more early registrations to happen. If TPM sniffing, hardware hacking & BitLocker attacks are on your list: now is the time. There may be no later. Help us get around the workbench! 🔬 👉 hos.direct/bheu26
Black Hat training badge, Because reading the advisor. isn‘t the same as running the drillSoldering to the SPI bus inside a disassembled notebooka notebook standing sideways with a logic analyzer connected to its interior. a second notebook showing the recorded traces in dsview / pulseviewclassroom setup woth desks cluttered with hardware, open notebooks and led magnifier glasses
021
Pascal Gujer @evilmaid.bsky.social · 16/09/2026
🔓 BitLocker enabled. No recovery key. Now what? **Breaking BitLocker** is back in Zürich 🇨🇭 TPM sniffing • DMA • BitPixie + newer attacks • real hardware • fully hands-on. 📅 22–23 Oct 🧰 Hardware kit included 👉 hos.direct/oct26training Also at Black Hat Europe 🇬🇧 👉 hos.direct/bheu26
011
Pascal Gujer @evilmaid.bsky.social · 03/06/2026
Shadow AI rarely starts with malicious intent. It starts with a workflow gap. The question isn't whether employees have access to AI. The question is whether your approved AI can take them all the way to the finished deliverable.
000
Pascal Gujer @evilmaid.bsky.social · 03/06/2026
Recently, someone approached me because their internal AI could generate content, but couldn't produce the DOCX reports required by their workflow. Nobody was using unauthorized AI. But it was obvious how tempting it would be to switch to a public tool that could complete the entire task.
100
Pascal Gujer @evilmaid.bsky.social · 03/06/2026
Shadow AI is the new Shadow IT. Employees don't use ChatGPT or Claude to bypass policy. They use them because there is no useful approved alternative. Every Shadow AI incident is also a review of your AI strategy. 👇 More thoughts and an example in the comments. #ShadowAI #CyberSecurity #AI
210
Pascal Gujer @evilmaid.bsky.social · 23/05/2026
Dad cheat code 🔥 Sous-vide the meat first. Then quick finish on the grill. Almost zero stress. Absolute steakhouse-quality every time 😄 Get yours here 👉 s.click.aliexpress.com/e/_EQNPDai #DadHack #SousVide #LegendDad
000
Pascal Gujer @evilmaid.bsky.social · 21/05/2026
Fighting cybercrime is a team sport. Cybercriminals collaborate globally. Defenders must do the same. Today’s Europol operation is another strong example of what international cooperation can achieve. 👏 Europol: www.europol.europa.eu/media-press/... Operation Saffron: operation-saffron.eu
operation-saffron.eu
First VPN Service — Website Seized by Law Enforcement
⚖ This Service Has Been Seized ⚖
021
Pascal Gujer @evilmaid.bsky.social · 16/05/2026
Dad Hack 🔥 Stop building smoky teepee fires 😄 Stack wood in layers + add a tiny blower = cheat-code campfire. Less smoke. Less wood. Less chemicals. Better fire. (Blower link 👉 s.click.aliexpress.com/e/_EvfC9JU) #DadHack #LegendDad #Camping
020
Pascal Gujer @evilmaid.bsky.social · 11/05/2026
AI gives you great content. Then you spend 20 minutes fixing Word formatting. 😩 So I built Markdown to Word Standalone: Offline tool → AI Markdown → proper corporate .docx No install. No upload. No backend. Src: 👉 github.com/pascal-gujer... Try it out: 👉 pascal-gujer.github.io/markdown-to-...
000
Pascal Gujer @evilmaid.bsky.social · 09/05/2026
After 100+ hours using Codex + Claude in authorized vuln research: -> Codex had cyber research approval, yet steered me away from a high-severity finding. -> Claude, without a special program, immediately flagged it as critical. I wonder whether that cyber research approval was just to get my ID?
000
Pascal Gujer @evilmaid.bsky.social · 06/05/2026
🇨🇭 ÖV-Lifehack für Schweizer: 3 % Rabatt auf SBB-/ZVV-Abos via Coop + Reka 😄 Bei Familien summiert sich das schneller als man denkt. Wie mein Urgrossvater schon sagte: „Wer den Rappen nicht ehrt ist des Frankens nicht wert.“ 💸
000
Pascal Gujer @evilmaid.bsky.social · 04/05/2026
Quick win for parents 💡 Set DNS to 1.1.1.3 / 1.0.0.3 Blocks malware + adult content. Not perfect—but fewer “oops moments”. #LegendDad @pascal_gujer
000
Pascal Gujer @evilmaid.bsky.social · 01/05/2026
“face comparison, fully local — just a browser.” like cyberchef, but for faces. built in ~3h. single HTML, no backend, no network. pascal-gujer.github.io/facetrace-st...
010
Pascal Gujer @evilmaid.bsky.social · 30/04/2026
🚨 Copy Fail (CVE-2026-31431) Linux kernel LPE → page cache corruption → overwrite binaries → root. Public PoC dropped ~24h ago. Tested: ✔ Ubuntu 24.04 / 25.10 (x86_64 + ARM64) If you get code execution → you get root. PoC: github.com/pascal-gujer... #linux #infosec
021
Pascal Gujer @evilmaid.bsky.social · 29/04/2026
Stop typing your password in Terminal. Use Touch ID for sudo 👇 👉 sudo nano /etc/pam.d/sudo Add this line at the very top: auth sufficient pam_tid.so Done. Next time you run sudo, just touch the sensor.✨ Small change — but one of those things you’ll use every single day once it’s there.
000
Pascal Gujer @evilmaid.bsky.social · 28/04/2026
Turned Codex from a kid I had to babysit… into an apprentice that gets work done. Stop babysitting it. → github.com/pascal-gujer...
001
Pascal Gujer @evilmaid.bsky.social · 25/04/2026
🎙️ VoiceInk is a gamechanger. Open source, local/offline AI, no subscription — and finally a voice workflow that lets you structure thoughts before sending them to AI. Way better prompts. Way better output. Go test it:
000
Pascal Gujer @evilmaid.bsky.social · 24/04/2026
Interesting — I checked Apple’s docs and it’s different on iPhone. Apple’s “Stolen Device Protection” mainly protects against someone stealing your iPhone and knowing the passcode: support.apple.com/en-us/120340 Not really a grab/snatch detection lock like Pixel. So I didn‘t reinvent the wheel 😇
support.apple.com
About Stolen Device Protection for iPhone - Apple Support
Stolen Device Protection adds a layer of security when your iPhone is away from familiar locations, such as home or work.
000
Pascal Gujer @evilmaid.bsky.social · 24/04/2026
I honestly haven’t tested how reliably the detection works in practice. One reason I personally don’t rely on Apple’s anti-theft features: while travelling, the added protections/delays became inconvenient when trying to quickly change settings or reset devices at borders or during transit.
110
Pascal Gujer @evilmaid.bsky.social · 24/04/2026
Phone snatching isn’t just about losing hardware anymore. Your banking, passkeys & digital life are on that device. I made a simple iPhone automation: 🔒 Lock screen when Bluetooth disconnects. ➡️ www.icloud.com/shortcuts/23... 🏋 Also great against snatch-and-run theft: ➡️ hos.direct/y8v1n
211
Pascal Gujer @evilmaid.bsky.social · 23/04/2026
Dad Hack 🔋 Loose batteries + kids = bad combo. Fire risk, leaking cells, swallowed button batteries… So I got a proper Inobat battery recycling barrel for home 🇨🇭 And of course a DIY Battery storage solution with a custom laser cut drawer... 😇 🛢️ www.inobat.ch/de/info-verb... #DadHack #legenddad
000
Reposted by Pascal Gujer
Mänu @emanuelduss.ch · 31/01/2026
This was a really cool and awesome course ❤️! I learned so much in these two days and did a lot of stuff I never did and never heard about before. It was cool when (after some nasty debugging 🫠) the encryption key could finally be sniffed 🤘. Thanks a lot for your training, you guys rock!
Open notebook from the backside where the mainboard can be seen, tiny wires are soldered on the SPI flash. These are soldered to a PCB which is connected to a logic analyzer.
062
Pascal Gujer @evilmaid.bsky.social · 29/01/2026
Still on the “wanting to do this stuff” side? Join our mailing list and get alerted when we host the next hands-on training. www.hands-on-security.com/#trainings
000
Pascal Gujer @evilmaid.bsky.social · 29/01/2026
We’re doing it again! No, not the fancy coffee corner — the famous “Breaking BitLocker” training you know from @BlackHatEvents is happening right now in Zurich 🇨🇭 Can’t wait to see the joy in the participants’ eyes when that key pops up tomorrow 🔑
110
Pascal Gujer @evilmaid.bsky.social · 13/11/2025
We just launched our YouTube channel! First Video: 60-seconds on how TPM sniffing breaks BitLocker — one of three real attacks trained at our Breaking BitLocker training Zurich, 29–30 January 2026 More hardware security content is coming soon. Subscribe & stay tuned: 🎥 youtube.com/@hands-on-se...
youtube.com
Hands-On Security
Hands-On Security delivers practical cybersecurity training with a focus on hardware, firmware, and physical access attacks. Our flagship course “Breaking BitLocker” teaches real-world techniques…
000
Pascal Gujer @evilmaid.bsky.social · 20/10/2025
🧠 BREAKING BITLOCKER — Early bird CHF 2999 until Nov 3. Seasoned BHUSA course (3 yrs) back in Zurich, 29–30 Jan 2026. Hands-on: TPM sniffing, DMA, bootloader patching, micro-soldering & RAM key extraction. Open to all professionals — especially valuable for LEA & forensics. hos.direct/jan26training
031
Pascal Gujer @evilmaid.bsky.social · 20/10/2025
“Putting all eggs in one basket and all baskets on the Titanic.” - @stefanfrei.bsky.social 🧺🚢 When AWS goes down and takes half the internet with it, maybe it’s time to rethink our basket strategy. Reuters report: www.reuters.com/business/ret... AWS status page: health.aws.amazon.com #AWSOutage
054
Pascal Gujer @evilmaid.bsky.social · 19/09/2025
✈️ Waiting for a flight → todo list created and stuff done ✅ Used ChatGPT to pull all unfinished projects from our past chats. Clear head & new focus. ➡️ Stop doomscrolling in downtime. Try: 🔥 “Go through our past chats and create a todo list with all the projects and unfinished tasks we discussed”
000
Pascal Gujer @evilmaid.bsky.social · 19/07/2025
🔑 International BitLocker Recovery Key Day – July 19th! One year ago, many learned the hard way: No offline backup = Locked out! Don’t get caught off guard – backup your BitLocker keys now! 💡 Quick tip: manage-bde -protectors -get C: #BitLockerDay #CyberSecurity #Encryption #DataProtection
032
Pascal Gujer @evilmaid.bsky.social · 21/06/2025
Got asked for tick tweezers while out fishing. ✅ My Care Plus kit had everything. 🎯 Remove slow, no twist, disinfect. 💡 Info: zecken-stich.ch/wie-wird-ein... 🎒 Kit: www.careplus-shop.de/first-aid-ki... As a dad, you’re the one they rely on. #DadHack #legendad #legenddad
000
Pascal Gujer @evilmaid.bsky.social · 12/06/2025
Disappointed? Sure. Defeated? Never. Now I’ve got two free days in Vegas. Fishing 🎣? Grand Canyon 🏜️? Hotel room reverse-engineering 🛠️? What would you do? #HackerLife #VegasIdeas
000
Pascal Gujer @evilmaid.bsky.social · 12/06/2025
🚨 Breaking 🚨 Our 2nd Breaking BitLocker session at Black Hat got cut. Only 3 seats left for the Aug 2–3 run. 🔥 Hands-on. Gritty. Soldering scars? likely. 🎟️ hos.direct/bhusa25-23aug 🇨🇭 No Vegas? Zurich pre-run: hos.direct/jun25training #BlackHat #CyberTraining #BitLocker
100
Pascal Gujer @evilmaid.bsky.social · 09/06/2025
Got a flat on the kid trailer. Not just the tube - tyre was toast too. 😬 Swapped it and used my go-to fix: the Xiaomi Portable Compressor. 🛠 Precise ♻️ Reusable 🚗 Lives in the car Way better than CO₂ if you’ve got kids in tow. 🔗 amzn.to/45eSolC #ad #DadHack #BikeLife #Xiaomi #legendad #legenddad
000
Pascal Gujer @evilmaid.bsky.social · 04/06/2025
Lol, ChatGPT struggles a bit with breadboard drawing, but its still pretty impressive… and yes, I use red and green for CAN-H and CAN-L as given by the CANable 2.0 Pro dongle I am using: s.click.aliexpress.com/e/_EvS01ii
s.click.aliexpress.com
US $19.23 | Makerbase CANable 2.0 USB to CAN adapter analyzer CANFD slcan SocketCAN CANdleLight klipper
US $19.23 | Makerbase CANable 2.0 USB to CAN adapter analyzer CANFD slcan SocketCAN CANdleLight klipper
110
Pascal Gujer @evilmaid.bsky.social · 04/06/2025
Spent half a day chasing ghosts on the CAN bus. Logic analyzer showed traffic, but the system was dead silent. Turns out I forgot the termination resistor — the one thing I was told to check first. Lesson: don’t skip the basics. 🧌🔧 #CANbus #DebuggingFails #ElectronicsLife
220
Pascal Gujer @evilmaid.bsky.social · 01/06/2025
Forgot the grill tongs at a Swiss Grillplatz. So I built some — 2 sticks + fishing line = DIY spring-loaded BBQ tongs. Dad Level: 💪 #legendad #legenddad Full story here: www.linkedin.com/posts/pascal... #LifeHack #DadHack #DIY
000
Pascal Gujer @evilmaid.bsky.social · 26/05/2025
Most people wait. For clarity. For courage. For the “right” time. But the truth? You'll rarely feel ready. Movement brings clarity. Not the other way around. That first step changes everything. 🚀 Ready to move? → Vegas Aug 4-5 hos.direct/bhusa25-45aug → Zurich Jun 26-27 hos.direct/jun25training
000
Pascal Gujer @evilmaid.bsky.social · 24/05/2025
🔧 Dad Hack: Fixing Broken Plastic Parts! Unleash the secret combo: super glue + baking soda! 🪄 🛠️ drill, key files 😇, precision drivers, super glue, baking soda, plastic wrap 🔁 glue → sprinkle soda → repeat → file/shape ✅ Done! Hard as stone! What’s your go-to repair trick? 💬 #legendad
032
Pascal Gujer @evilmaid.bsky.social · 22/05/2025
🔐 Break BitLocker with real tools — not slides. Black Hat USA training, >50% booked. Early bird ends May 23, 11:59 PM PDT. You’ll: 🧠 Learn BitLocker internals 📡 Sniff keys 🥾 Attack Bootloader 💻 Take home a hacked test laptop + logic analyzer 👉 hos.direct/bhusa25-23aug 👉 hos.direct/bhusa25-45aug
010
Pascal Gujer @evilmaid.bsky.social · 20/05/2025
Don’t wait for the wind to change – set your sail. 🚩 At 14, I dreamt of attending #BlackHatUSA. Today, I’m not just attending – I’m an invited trainer. Years of passion, perseverance, and hacking led here. Curious about the full story? ;) @blackhatevents.bsky.social hos.direct/kjtyv
hos.direct
#bitlocker #bhusa #third #trainer #goals #attract #like #magnets… | Pascal G.
*Don’t Wait for the Wind to Change – Set Your Sail: My Journey to Becoming a Black Hat Trainer* At 14, I read The Art of Intrusion by Kevin Mitnick and first heard about Black Hat and DEF CON. Fasci...
110
Pascal Gujer @evilmaid.bsky.social · 17/05/2025
“Why do you always carry a knife?” My great-grandfather told my grandfather, who told my dad, who told me: “A real man always carries a knife.” Today, I used mine to turn a normal bottle into a spill-proof straw bottle. Dad Level achieved What’s your best dad hack? #LifeHacks #legenddad #legendad
100
Pascal Gujer @evilmaid.bsky.social · 15/05/2025
🔓 Bitpixie is Back! Bypass BitLocker in under 5 minutes - no screwdriver needed. Thomas Lambertz’s talk at 38C3 showed how. 🚀 Join our Breaking BitLocker trainings: • Zurich: hos.direct/jun25training • BH USA: hos.direct/bhusa25-23aug / hos.direct/bhusa25-45aug ⏰ Early bird ends in 8 days!
031
Pascal Gujer @evilmaid.bsky.social · 14/05/2025
🚀 Cybersecurity Training – Feeling lost? Before every training, I always wonder: 💭“Am I skilled enough?” Turns out, many of us feel the same! With Breaking BitLocker, we make it easy – from 0 to hero with minimal prerequisites. Got a funny training story? Let’s hear it! #CyberSecurity #Training
011
Pascal Gujer @evilmaid.bsky.social · 13/05/2025
@blackhatevents.bsky.social time for a first post on Bsky 😉
000
Pascal Gujer @evilmaid.bsky.social · 13/05/2025
🚀LocalSend: The Open-Source AirDrop Alternative! Transfer files over WiFi without internet! Works on Windows, macOS, Linux, Android & iOS. 💡Perfect for travel, meetings, or quick file swaps at home. No cables needed! localsend.org/de/download github.com/localsend/lo... #OpenSource #FileSharing
040
Pascal Gujer @evilmaid.bsky.social · 12/05/2025
🚨 Our first Breaking BitLocker training at Black Hat USA 2025 is 30% SOLD OUT – weeks before early bird ends! Learn to break TPM-only BitLocker with real hardware & hands-on techniques. Don’t wait – spots are flying! Aug 2&3: hos.direct/bhusa25-23aug Aug 4&5: hos.direct/bhusa25-45aug #BHUSA
001
Pascal Gujer @evilmaid.bsky.social · 25/04/2025
And that’s the difference: you’ve clearly been through Dunning-Kruger more than once - and learnt a lot each time. And you‘re surely more than just acting competent 😉
100
Pascal Gujer @evilmaid.bsky.social · 25/04/2025
“0-day” LPE - but only works if you know the password? That’s not a vuln. That’s literally a feature. Tired of seeing this stuff blindly reposted by folks who can’t tell access control from exploit. We need fewer click-chasers, more professionals.
101
Pascal Gujer @evilmaid.bsky.social · 17/04/2025
Easter food for thought 🐣 What if BitLocker isn’t as secure as you think? We show 3 real-world attacks + mitigations at @blackhatevents.bsky.social #BHUSA 2025. 🧰 TPM sniffing, DMA, BitPixie. 🛠️ All hands-on. Hardware kit included. 🇺🇸 hos.direct/bhusa25-45aug 🇺🇸 hos.direct/bhusa25-23aug
010