Sign in

イヴラド

@kevinreddot.bsky.social
46 followers 135 following 144 posts

Coffee lover. Security nerd. I’ve seen things you would believe (if you do DFIR). APT operators have shitty bosses, annoying in-laws, rising school fees, and teenage kids with questionable music taste. Be kind while burning their C2 infra to the ground.

PostsRepliesMedia
イヴラド @kevinreddot.bsky.social · 22/09/2026
If you have a somewhat modern phone you don’t need IPv4 address to reach IPv4-only sites. It’s going to be either NAT64 or 464XLAT. It’s a pretty common configuration nowadays.
010
Reposted by イヴラド
Emmanuel Thomé @emmanuelthome.bsky.social · 21/09/2026
Forging 1024-bit RSA signatures in nearly SNFS time Hand over your HSM for some time, and we can forge signatures for its key. Arbitrary signatures. Forever. github.com/ucsd-hacc/NS...
github.com
GitHub - ucsd-hacc/NSNFSSSFSFN: Nearly SNFS-Speed Signature Forgery Sans Factoring N
Nearly SNFS-Speed Signature Forgery Sans Factoring N - ucsd-hacc/NSNFSSSFSFN
13013
イヴラド @kevinreddot.bsky.social · 21/09/2026
We are in GitS now, how long until the Neuromancer?
020
Reposted by イヴラド
mechazany @mechamcscringle.bsky.social · 20/09/2026
Ghost in the Shell 1995 garbage man who’s ghost hacked with falsified memories of having a family while lovingly reminiscing on them out loud
3570711865
イヴラド @kevinreddot.bsky.social · 21/09/2026
static.klipy.com
Joke Pointing at You
ALT: Joke Pointing at You
000
イヴラド @kevinreddot.bsky.social · 20/09/2026
Not only were they advertising it, they were *selling* the boxes.
001
イヴラド @kevinreddot.bsky.social · 19/09/2026
… err, I mean European commies, but 1800 years ago
100
イヴラド @kevinreddot.bsky.social · 19/09/2026
There also was the so-called Hadrian wall built by the Roman Empire in the second century CE.
110
イヴラド @kevinreddot.bsky.social · 19/09/2026
Doubt it. It’s a meme by now.
001
Reposted by イヴラド
Micah Lee @micahflee.com · 16/09/2026
I've got a lot of work to do today but I'm getting absolutely nerdsniped by the new Flock dataset. You can download it here. It's all of the Android partitions extracted from a Flock device ddosecrets.org/article/floc...
ddosecrets.org
Flock ALPR camera - Distributed Denial of Secrets
Filesystem images of the partitions on an in-use Flock ALPR camera, including custom Android APK files installed on the device, as well as its recorded media. The data reveals how the devices track bo...
181553567
イヴラド @kevinreddot.bsky.social · 17/09/2026
“Forcibly” here does not mean they should be beaten. People can take advantage of society and not give anything back (or enough, as in “Famine, Affluence, and Morality” by Singer). The question is what are you going to do with them, if they have no incentive to change?
000
イヴラド @kevinreddot.bsky.social · 16/09/2026
I think it boils down to question whether a human can be changed and whether it’s permissible to change humans - sometimes forcefully given that assholes don’t necessarily want to change.
100
Reposted by イヴラド
AFP Fact Check @factcheck.afp.com · 16/09/2026
As scientists investigate the deadly floods that swept through Nepal and Tibet, online posts baselessly claim the disaster was caused by a Chinese dam collapse. We reviewed forensic evidence and spoke to five experts to break down the sequence of events behind the devastation 🧵
Infographic showing the route that the China-Nepal floods took through the Himalayas
176
イヴラド @kevinreddot.bsky.social · 16/09/2026
You obviously have more insight - my takeaway from David Priess’ “The President’s Book of Secrets” was that many presidents did not see a lot of value in PDB. Did I misread him?
000
イヴラド @kevinreddot.bsky.social · 16/09/2026
K9 dogs?
000
Reposted by イヴラド
Internet Archive @archive.org · 15/09/2026
“Fix the Wayback Machine!” We’ve heard you. The Wayback Machine has been dealing with waves of high-volume automated traffic. Mark Graham, director of the Wayback Machine, explains what’s happening and what we’re doing about it. ➡️ blog.archive.org/2026/09/15/a...
Internet Archive Wayback Machine logo.
4583172
イヴラド @kevinreddot.bsky.social · 16/09/2026
If you agree with Sapolsky and others that genetics, environment, and past experiences determine us and that we may not even possess a free will, then yeah, we should compassionately isolate those people.
290
イヴラド @kevinreddot.bsky.social · 15/09/2026
It would be great if SOHO routers were Thread Border Routers but it’s not happening, at least, yet.
110
イヴラド @kevinreddot.bsky.social · 15/09/2026
Given poor stability of a typical Thread mesh it does not look like a benefit.
000
イヴラド @kevinreddot.bsky.social · 15/09/2026
It does. Mine has addresses auto configured via SLAAC and advertises itself with mDNS. No configuration required.
010
イヴラド @kevinreddot.bsky.social · 15/09/2026
Cybercriminals hacking into Berlin federal state network reads as a silly joke but it’s not: www.heise.de/en/news/Berl... Even funnier, the attackers exfiltrated almost 6 terabytes of data. It should have taken days if not weeks, and nobody noticed.
heise.de
Berlin: Passwords exfiltrated, 12,000 systems scanned
The Berlin Senate administration has confirmed that passwords were also stolen in the August cyberattack. All systems are being checked.
000
Reposted by イヴラド
Daniel Gordon @validhorizon.bsky.social · 13/09/2026
Eyal is exactly right. It has long been the case that threat actors would adopt the tools of pentesters. Now adversaries using LLMs are telling them that this is an authorized pentest and the LLM will often leave traces of that.
You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors tell their LLMs they are performing authorized engagements even when using open weight models, or use pentesting harnesses like cyberstrikeAI, PentAGO, Hexstrike.
01613
イヴラド @kevinreddot.bsky.social · 14/09/2026
Harnesses are easy in comparison. Not limited by the constrained GPU supply.
000
Reposted by イヴラド
Zack Whittaker @zackwhittaker.com · 27/08/2026
Australian police say they have arrested two people involved in the TeamPCP hacks, which hit GitHub, OpenAI and others. Brian Krebs has the full back story with one of the hackers, and it's one hell of a read. I audibly gasped at least twice.
krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
12416
イヴラド @kevinreddot.bsky.social · 15/08/2026
It was way too big and bloated. CSS 2.1 could have been trimmed down to good parts and frozen.
000
イヴラド @kevinreddot.bsky.social · 13/08/2026
I turned up to be passkeys hater, lol. And I remember, how fascinated I was with U2F and early FIDO implementations. The future looked so bright! )
000
イヴラド @kevinreddot.bsky.social · 13/08/2026
So, great idea, does not work in practice. Saying from experience.
000
イヴラド @kevinreddot.bsky.social · 13/08/2026
… say, SMM needs a personal and a company’s account, on a social media, this becomes unbearable. In iOS, there could be *multiple* passkey providers, too, and it leads to incredible side effects.
100
イヴラド @kevinreddot.bsky.social · 13/08/2026
… or they could not create a backup key pair on a secondary device because keypair turned up cloud synced and appeared where they did not expect it to be. Or it’s hard with resident keys, which is the most common form of passkeys, to have multiple accounts in the service. If a user needs two …
100
イヴラド @kevinreddot.bsky.social · 13/08/2026
… with a few thousand of employees and implementation quirks are *way* more important than theoretical guarantees. I had multiple situations where people could not tell where a particular key pair ended up, or they could not authenticate because they were locked out of their private account, …
100
イヴラド @kevinreddot.bsky.social · 13/08/2026
Passkeys are no better than “login with Apple” or “login with Google” for all practical risks and reasons. You think public key based authentication is better than passwords, but this is only one aspect and, frankly, a theoretical one. Practically, I managed deployment of passkeys in an org …
100
イヴラド @kevinreddot.bsky.social · 13/08/2026
… person to figure out where the specific passkey ended up if their configuration is at least somewhat non-trivial. Just Chrome on macOS is sufficient to make things confusing. Passkeys don’t remove the need to manage them, especially cross-platform. It’s complicated in fact.
110
イヴラド @kevinreddot.bsky.social · 13/08/2026
… hardware backed. As a result, compromising iCloud compromises all passkeys. Passkeys are also worse than passwords because now every browser and half of password managers want to highjack passkey creation to keep the private key with them. As a result, it’s very hard for a non-technical …
110
イヴラド @kevinreddot.bsky.social · 13/08/2026
Passkeys are also worse than passwords because they lock you into the platform. In modern implementations passkeys are worse than passwords because they are *not* something you have - unless the server jumps through the hoops with key attestation, passkeys will be cloud synced and not …
110
イヴラド @kevinreddot.bsky.social · 13/08/2026
Distribution worked for Microsoft almost every time: it worked with IE, it worked with Azure, it worked with Windows Media Player. There is no reason not to think it will not work for them this time. Only if people will start dropping Office.
000
Reposted by イヴラド
European Space Agency @esa.int · 12/08/2026
Eclipse day! ☀️ Today's total solar eclipse is visible from Greenland, Iceland, northeastern Portugal and Spain. Most of the rest of Europe, northern North America and western Africa will witness a partial solar eclipse. More info: www.esa.int/Science_Expl... #EuropeanSolarEclipse
Map of Earth shown as a globe, with the focus on its northern hemisphere. A red, C-shaped arc marked 'total eclipse' reaches from northeast Russia, past the North Pole, Greenland, Iceland and the Iberian Peninsula. An orange oval surrounds this arc, marked 'partial eclipse', covering most of Europe, Canada and parts of the USA, the western edge of Africa and the northeastern corner of Russia.
1248111
イヴラド @kevinreddot.bsky.social · 12/08/2026
This is totally understandable
110
イヴラド @kevinreddot.bsky.social · 12/08/2026
I hope this clarifies and there is no misunderstanding.
100
イヴラド @kevinreddot.bsky.social · 12/08/2026
… chip isolated from the rest of your computer or phone. It’s not transmitted anywhere.
200
イヴラド @kevinreddot.bsky.social · 12/08/2026
… there. If the comparison is successful, the chip allows to use special cryptographic keys that then used as passkeys or used to unlock real passkeys. The mechanics there is a little complicated, but it’s not important for the main point: your fingerprint is processed locally, by a dedicated …
100
イヴラド @kevinreddot.bsky.social · 12/08/2026
This chip holds a “fingerprint of fingerprint” in a way that even if it’s removed from the computer there is no way to restore the original fingerprint. When you scan your finger, it’s send to this chip, converted to this “fingerprint of fingerprint” representation and compared to what is stored …
100
イヴラド @kevinreddot.bsky.social · 12/08/2026
It’s called Secure Enclave in Apple world and TPM everywhere else. This dedicated chip is not accessible by your operating system, or any program on your computer - this is its main advantage. You can literally open your computer and find it - made by Infineon, STMicroelectronivs, a few others.
100
イヴラド @kevinreddot.bsky.social · 12/08/2026
I read that and I agree with it. To make things clear: touching fingerprint scanner or looking into a camera does not cause transmitting your fingerprint or photo anywhere. The way how it works, is that the fingerprint scanner is connected to a dedicated chip in your phone or computer.
200
イヴラド @kevinreddot.bsky.social · 12/08/2026
This is a funny thread. I manage to upset both sides. )
000
イヴラド @kevinreddot.bsky.social · 12/08/2026
Hmmm. You said this: “just give the door’s bouncer your biometric data to compare to you”. This is NOT how passkeys work. Passkeys have their issues and I don’t recommend them, but biometric data is not transmitted anywhere. You are not giving your biometric data.
200
イヴラド @kevinreddot.bsky.social · 12/08/2026
… algorithms had to be developed, the keys are much longer and this is problematic, they cannot be used to encrypt arbitrary length data, I think I could go on. The real reason why asymmetric crypto exist is because it solved the key distribution problem.
000
イヴラド @kevinreddot.bsky.social · 12/08/2026
This is wrong. Asymmetric encryption in fact is WORSE that symmetric encryption - it’s more fragile (eg, finding good p and n in RSA requires multiple checks and there were bugs when those were not made resulting security issues), it’s orders of magnitude slower, it’s not quantum safe - so new …
110
イヴラド @kevinreddot.bsky.social · 12/08/2026
This is unfounded BS
000
イヴラド @kevinreddot.bsky.social · 12/08/2026
… the technology workings and yes, it’s entirely appropriate to point this out.
000
イヴラド @kevinreddot.bsky.social · 12/08/2026
This is dismissive BS. There is nothing about “authors intent” in that simple fact that passkeys don’t transmit your biometric data anywhere and don’t require it at all. They don’t work like that. Full stop. Bringing biometrics into passkey discussion means someone does not understand …
210