Sign in

jiska

@naehrdine.bsky.social
1.5K followers 581 following 95 posts

ɿɘɘniϱnɘ ɘƨɿɘvɘɿ 🎦 youtube.com/@jiskac 📝 naehrdine.blogspot.com 🐥 twitter.com/naehrdine 🎓 hpi.de/classen 📱 reversing.training

PostsRepliesMedia
Reposted by jiska
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 01/10/2026
NEW: An iPhone hacking company claims it can freeze the iPhone in a state that makes it easier for cops to access data. The iPhone has an automatic reboot feature that reverts the device to a state where data is harder to extract. This would defeat that feature. www.404media.co/cops-can-byp...
404media.co
Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims
Magent Forensics, the owner of the GrayKey phone unlocking tool, says it can bypass an iPhone rebooting feature that was locking cops out.
36043
jiska @naehrdine.bsky.social · 17/09/2026
Are you a PostDoc and want to stay in academia? We just opened 10 tenure track professor positions. HPI is close to Berlin, with the campus located next to a beautiful lake. We have excellent students and friendly colleagues. faculty-search.hpi.de/jobposting/8...
012
jiska @naehrdine.bsky.social · 16/09/2026
With Siri Recap, Apple sends everything people say to Private Cloud Compute. Apple Reference Image extends this and also sends your photos to PCC. security.apple.com/blog/apple-r...
security.apple.com
Apple Reference Image: A New Approach for Verified Photography - Apple Security Research
Introducing Apple Reference Image, a new solution for verifiable photography on iPhone. This new, opt-in camera mode lets a photographer create a securely timestamped reference image that accurately d...
140
jiska @naehrdine.bsky.social · 13/09/2026
Henri Jäger-Menn made huge progress in reverse engineering and reimplementing Apple's proprietary Low-Latency WiFi on Linux. The #mrmcd26 recording is already online: talks.mrmcd.net/2026/talk/3R...
talks.mrmcd.net
Trespassing the Walled Garden: Teaching Linux to Speak Apple's Low-Latency WiFi MRMCD 2026
Some boundaries are not imposed by technology itself, but by what remains undocumented. This talk presents our progress toward freeing Apple's Low-Latency WiFi from its walled garden to the open-sour...
040
jiska @naehrdine.bsky.social · 10/09/2026
Apple shared details on how Siri Recap works, a new feature where your Apple Watch can listen to your surroundings 24/7 and take notes. Source: www.apple.com/privacy/docs...
Your data’s journey for Siri Recap
􀀺 Audio stream during speech detection
Where it’s processed: S11 Always On Processor
Accessible to: No one. Raw audio is processed on-device and discarded in real
time.
􀄩
􀀼 Buffered audio on Apple Watch
Where it’s processed: Secure Exclave on Apple Watch
Accessible to: No one. Raw audio is isolated in secure compartment.
􀄩
􀀾 Buffered audio on iPhone
Where it’s processed: Secure Exclave on iPhone, after being transmitted
encrypted from Apple Watch
Accessible to: No one. Raw audio is isolated in secure compartment.
􀄩
Siri Recap can be turned on and off at
anytime right from Control Center.
􀁀 Condensed text on iPhone
Where it’s processed: Condensed text is encrypted and transferred from
Secure Exclave on iPhone to Private Cloud Compute. If you have optionally
enabled your Apple Intelligence Report in Privacy & Security Settings on your
iPhone, you can verify the Private Cloud Compute request in that report and only
on your device. Depending on your settings, it can be visible to you for 15
minutes or 7 days.
Accessible to: Only you. Your optional Apple Intelligence Report on your device
is only accessible to you after you first authenticate to view it.
􀄩
􀁂 Condensed text on Private Cloud Compute
Where it’s processed: Condensed text is decrypted on Private Cloud Compute
once it is received, where it is processed (subject to daily usage limits).
Accessible to: No one. Condensed text in Private Cloud Compute cannot be
accessed by anyone, not even Apple. Private Cloud Compute creates a
summarization from the condensed text and removes sensitive information. The
summarization is then encrypted and sent back to iPhone. The results are
immediately deleted from Private Cloud Compute.
􀄩
􀁄 Summarization
Where it’s processed: Siri app, and synced across your devices end-to-end
encrypted via iCloud.
Accessible to: Only you.
153
Reposted by jiska
Zack Whittaker @zackwhittaker.com · 09/09/2026
Watching this Apple event tout how iPhones will soon be able to record ambient audio/conversations and transcribe "high level notes" for you. It's billed as private and end-to-end encrypted, but I think the bigger harm is the normalization of always-listening devices. It's creepy and not normal.
a screenshot from an iPhone and Apple Watch showing "recaps" of conversations from ambient audio.
27992353
jiska @naehrdine.bsky.social · 05/09/2026
Du interessierst dich für Anwendungssicherheit und wohnst in Karlsruhe oder der Umgebung? Dann schau doch am 23. September beim OWASP Diversity PreCon Day vorbei, einem Angebot für Frauen und queere Menschen.
Debugging eines Raspberry Pi Picos mit einem anderen Raspberry Pi Pico. Foto Credits: Sandra Cava
120
jiska @naehrdine.bsky.social · 05/09/2026
Did you know macOS binaries can run on iOS? It needs rewriting architecture information and adjusting library paths. I automated this, including DYLD shared cache library extraction and replacement, allowing many macOS command line tools to run on iOS. github.com/mowisec/maco...
github.com
GitHub - mowisec/macos-to-ios
Contribute to mowisec/macos-to-ios development by creating an account on GitHub.
0122
jiska @naehrdine.bsky.social · 31/08/2026
Apple: "We had to work on MTE stability and security improvements for 5 years, but we finally ship it with the iPhone 17 and enable it by default."
170
jiska @naehrdine.bsky.social · 29/08/2026
My hands-on iOS reverse engineering training that covers user space, kernel space, and firmware internals will be at #OBTS on Hawaii in November! Register here: reversing.training/obtsv9/
Running Ghidra on a Mac at the beach in Hawaii with sunset and palm trees.
181
Reposted by jiska
Tagesschau Bot @tagesschau.bsky.social · 27/08/2026
Mobilfunknetze übertrugen Handydaten an Anrufer #Mobilfunknetz #Datenschutz #Sicherheitslücke
tagesschau.de
Mobilfunknetze übertrugen Handydaten an Anrufer
Bei Anrufen übermittelten die Mobilfunknetze sensible Gerätedaten.
43818
jiska @naehrdine.bsky.social · 22/08/2026
Want to learn firmware reverse engineering on an IoT device? I'll be giving a free, women-only workshop with BlackHoodie at Hexacon in Paris on October 15. #reverseengineering blackhoodie.re/Hexacon2026/
Debugging a Raspberry Pi Pico 2W with another Pico. Photo credit: Sandra Cava
0145
jiska @naehrdine.bsky.social · 31/07/2026
First day of #OFTW was a blast. Had fun giving a new workshop where we looked into the iOS permission ecosystem and reverse engineered an app. Looking forward to today's talks!
Photo credits: Nicole KrügerPhoto credits: Nicole KrügerPhoto credits: Nicole KrügerPhoto credits: Nicole Krüger
240
Reposted by jiska
CCC @ccc.de · 16/07/2026
Gesetzentwurf in weiten Teilen ein „Wünsch-dir-was“ der Geheimdienste: #Staatstrojaner & #Hackback und keine Berichte mehr www.lto.de/recht/hinter...
lto.de
Mehr Befugnisse, weniger Kontrolle für die Geheimdienste
Sollte der BMI-Entwurf Wirklichkeit werden, erfüllen sich die Wünsche der Geheimdienstler – zulasten des Datenschutzes. Verfassungsbeschwerden garantiert.
19642
jiska @naehrdine.bsky.social · 11/07/2026
How do the closed-source parts of Apple's Private Cloud Compute work? We had a look at it 🍎👀 Paper: dl.acm.org/doi/abs/10.1... Slides: hpi.de/fileadmin/us...
dl.acm.org
Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence | Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks
0175
Reposted by jiska
pinkflawd.bsky.social @pinkflawd.bsky.social · 07/05/2026
@blackhoodie.bsky.social will be back at @reconmtl.bsky.social this year 😱😻✨ Jane Tangen and Amna K Moon will be teaching an Introduction to x86 Reverse Engineering! We're delighted to be hosted at the Montreal Google offices! blackhoodie.re/Recon2026/
blackhoodie.re
Blackhoodie at Recon 2026
We are looking forward to hosting another Blackhoodie training at Recon for 2026! We will be hosting a free, one day training for women, by women.Join us for an introduction to Ghidra and static analy...
0147
Reposted by jiska
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/04/2026
NEW: Apple fixed the bug that law enforcement, like the FBI, were taking advantage of to extract chat messages that had been deleted or disappeared automatically. Until now the iPhone stored deleted or disappered messages in a database, allowing authorities to access them with forensic tools.
techcrunch.com
Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch
The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.
24817305
Reposted by jiska
Signal @signal.org · 22/04/2026
We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
111789474
Reposted by jiska
dmnk @dmnk.bsky.social · 11/04/2026
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
security.googleblog.com
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
49917
jiska @naehrdine.bsky.social · 27/03/2026
🎉🎉🎉 www.dfg.de/de/aktuelles...
dfg.de
Heinz Maier-Leibnitz-Preise 2026
4120
Reposted by jiska
evacide @evacide.bsky.social · 04/03/2026
I'm reading a bunch of Coruna reports after dinner because I am a cool person who knows how to party. Of particular interest: not only does Coruna not work against iOS in lockdown mode, but if it even detects lockdown mode running, it bails. This is why I talk about lockdown mode so damn much.
213927
Reposted by jiska
Matthew Green @matthewdgreen.bsky.social · 19/02/2026
Here we go again with iCloud photo scanning. www.macrumors.com/2026/02/19/a...
macrumors.com
Apple Sued by West Virginia for Allegedly Allowing CSAM Distribution Through iCloud
West Virginia's Attorney General JB McCuskey today announced a lawsuit against Apple, accusing the company of knowingly allowing iCloud to be used to distribute and store child sexual abuse material (...
13210
Reposted by jiska
jiska @naehrdine.bsky.social · 14/02/2026
Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look! youtu.be/qBsNoa0FOPw
youtu.be
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska
051
jiska @naehrdine.bsky.social · 14/02/2026
Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look! youtu.be/qBsNoa0FOPw
youtu.be
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska
051
jiska @naehrdine.bsky.social · 11/02/2026
Two students I supervised in today's iOS release notes 🎉🎉🎉 support.apple.com/en-us/126346
Call History
Available for: iPhone 11 and later, iPad Pro
12.9-inch 3rd generation and later, iPad Pro
11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions
Description: A logic issue was addressed with improved checks.
CVE-2026-20638: Nils Hanff
(@nils1729@chaos.social) of Hasso Plattner
InstituteWallet
We would like to acknowledge Aaron Schlitt (@aaron_sfn) of Hasso Plattner Institute, Cybersecurity - Mobile & Wireless, Jacob Prezant (prezant.us), Lorenzo Santina (@BigNerd95) and Marco Bartoli (@wsxarcher) for their assistance.
0190
Reposted by jiska
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 09/02/2026
The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)! WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused). Details are available in the Call for Papers: www.usenix.org/conference/w...
usenix.org
WOOT '26 Call for Papers
The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...
001
Reposted by jiska
jiska @naehrdine.bsky.social · 07/02/2026
In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering youtu.be/P7hYg2GpsTk
youtu.be
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska
193
jiska @naehrdine.bsky.social · 07/02/2026
In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering youtu.be/P7hYg2GpsTk
youtu.be
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska
193
jiska @naehrdine.bsky.social · 31/01/2026
Last weekend, Telekom changed their network name from "Telekom.de" to "Im besten Netz." 📶 Curious about how they did this? Will more ad campaigns follow? And what can you do to change it back? More details in this video: youtu.be/-PchHdFhl5M
youtu.be
YouTube
Share your videos with friends, family, and the world
022
Reposted by jiska
stacksmashing @stacksmashing.bsky.social · 28/01/2026
The new AirTags 2 just arrived! Time to take them apart 🧵
414429
Reposted by jiska
OffensiveCon @offensivecon.bsky.social · 20/01/2026
Don't miss out on Jiska Classen's - @naehrdine.bsky.social - training on "Practical iOS Reverse Engineering" at #OffensiveCon26 Find more details here🔗https://buff.ly/psTxdyG
0127
Reposted by jiska
Romain Thomas (@rh0main) @rh0main.bsky.social · 05/01/2026
I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps. From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations. www.romainthomas.fr/post/26-01-d...
romainthomas.fr
A Glimpse Into DexProtector | Romain Thomas
This blog post provides a high-level overview of DexProtector's security features and their limitations
13412
jiska @naehrdine.bsky.social · 28/12/2025
Want to know how Apple's Low Latency WiFi works? Today, 3:40pm CET, Hall 1, #39c3. More details: events.ccc.de/congress/202... Stream: streaming.media.ccc.de/39c3/one
events.ccc.de
[39c3] Cracking open what makes Apple's Low-Latency WiFi so fast
Apple's Continuity features make up a big part of their walled garden. From AirDrop and Handoff to AirPlay, they all connect macOS and iOS devices wirelessly. In recent years, security researchers hav...
1101
Reposted by jiska
OffensiveCon @offensivecon.bsky.social · 17/12/2025
In 2026, Jiska Classen - @naehrdine.bsky.social - returns to OffensiveCon with a training on "Practical iOS Reverse Engineering". More details here🔗https://buff.ly/psTxdyG 🚀 Don't miss this chance to improve your skills—sign up now!
021
jiska @naehrdine.bsky.social · 09/12/2025
WOOT deadline approaching 👀
I LOVE DEADLINES
ESPECIALLY THE WHOOSHING SOUND
THEY MAKE AS THEY PASS BY
060
Reposted by jiska
Victoria Walberg @vickyjo.bsky.social · 03/12/2025
This is Limburg BE, not NL - though they are pretty close. www.bsides-limburg.be/home
bsides-limburg.be
Home
• 13/03/2026 • • CORDA CAMPUS, HASSELT • Friday 13th
064
jiska @naehrdine.bsky.social · 26/11/2025
Using a Pixel with GrapheneOS that features Inactivity Reboot, MTE, and more? — You must be a drug dealer. 🚨
GrapheneOS im Visier der Strafverfolgung
Quelle der Bedenken scheinen Berichte mehrerer französischer Medien zu sein, darunter einer der Tageszeitung Le Parisien.
Darin wird GrapheneOS als "Geheimwaffe" bezeichnet, mit der Drogenhändler und andere Kriminelle ihre Daten vor der Polizei schützten.
Dass sich das Betriebssystem im Vergleich zum Standard-Android besonders schwer knacken lässt, hatte zuletzt eine geleakte Präsentationsfolie des Forensikdienstleisters
Cellebrite gezeigt.
160
Reposted by jiska
Andy Greenberg @agreenberg.bsky.social · 18/11/2025
Researchers tried plugging every possible phone number into WhatsApp's web app. They found they could collect 3.5 billion users' phone numbers, plus photos for half and profile text for more than a third, the biggest personal data exposure ever by some measures. www.wired.com/story/a-simp...
wired.com
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.
615771
Reposted by jiska
Binary Ninja @binary.ninja · 13/11/2025
Binary Ninja 5.2, Io, is live and it's out of this world! binary.ninja/2025/11/13/b... With some of our most requested features of all time including bitfield support, containers, hexagon, Ghidra import, and a huge upgrade to TTD capabilities, plus a ton more, make sure to check out the changelog!
193
Reposted by jiska
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 12/11/2025
USENIX WOOT Conference 2026: two submission deadlines this year! - Cycle 1: December 12, 2025 *only one month away* ! - Cycle 2: March 3, 2026 WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details: www.usenix.org/conference/w...
056
Reposted by jiska
CCC @ccc.de · 09/11/2025
Dein erster Congress und pures Chaos? Die Chaospat:innen sind für dich da. Melde dich bis zum 25. November. Willkommen sind alle, die den #39c3 offener und vielfältiger machen wollen! events.ccc.de/2025/11/10/3...
events.ccc.de
Dein erster Congress? Die Chaospat:innen sind für dich auf dem 39C3 da!
Auch in diesem Jahr sind die Chaospat:innen wieder beim Chaos Communication Congress in Hamburg am Start! Interessierte Mentor:innen und Mentees können sich bis zum 25. November 2025 um 23:59 Uhr…
12610
Reposted by jiska
Lukas Arnold @lukasarnld.bsky.social · 27/10/2025
I just published the slides of my #OBTS v8.0 talk about Apple's #C1 baseband. Our C1 #binja loader is now available on GitHub, and you can find a recording on YouTube. lukasarnold.de/posts/obtsv8...
lukasarnold.de
OBTS v8.0: Diving into C1
Learn more about my talk “What’s at the Bottom of the Sea, One Baseband? - Diving into the C1” at eight edition of the Objective by the Sea conference.
041
Reposted by jiska
CCC @ccc.de · 16/10/2025
Wir freuen uns, den Vorverkauf für den #39c3 anzukündigen. Im Anschluss an die Voucherphase gibt es zwei offene Verkaufstermine. (Fast) alle Engel erhalten heute eine E-Mail mit Voucher events.ccc.de/2025/10/16/3...
events.ccc.de
39C3 Presale: Modus Operandi
Wir freuen uns, euch den Vorverkauf für den diesjährigen Chaos Communication Congress anzukündigen. Der Vorverkauf wird dieses Jahr ziemlich genau ablaufen wie letztes Jahr: Der Vorverkauf wird…
04818
Reposted by jiska
Gabriel Geiger @gabrielgeiger.bsky.social · 14/10/2025
On a Saturday night I stumbled across something on the internet that made me feel like ****** my pants. A giant dataset of real surveillance operations targeting 1000s of people across nearly every country. Unraveling it and the mysterious company behind it has consumed 1.5 years of my life
726996
jiska @naehrdine.bsky.social · 13/10/2025
Want to know more details on Apple's SPTM, TXM, and Exclaves? Read more on this in the paper based on Moritz Steffin's thesis. Lots of low-level details including their security implications are covered. arxiv.org/abs/2510.09272
arxiv.org
Modern iOS Security Features -- A Deep Dive into SPTM, TXM, and Exclaves
The XNU kernel is the basis of Apple's operating systems. Although labeled as a hybrid kernel, it is found to generally operate in a monolithic manner by defining a single privileged trust zone in whi...
0112
Reposted by jiska
CCC @ccc.de · 28/09/2025
Lectures, music, art, punk: Join us at the 39th Chaos Communication Congress and please submit! The deadline for all submissions for the stages is October 24. #39C3 will take place from December 27 to 30 www.ccc.de/en/updates/2...
ccc.de
CCC | Lectures, music, art, punk: Join us at the 39th Chaos Communication Congress!
Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung.
03218
Reposted by jiska
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 11/09/2025
NEW: Apple launched a new security feature specifically to fight against spyware and zero-day exploit makers. We spoke to a researcher who sells zero-days to the U.S. government, who thinks this will make their life much harder and raise the cost of developing and selling hacking tolls for iPhones.
techcrunch.com
Apple's latest iPhone security feature just made life more difficult for spyware makers | TechCrunch
Buried in an ocean of flashy novelties announced by Apple this week, the tech giant also revealed new security technology for its latest iPhone 17 and
24222
Reposted by jiska
The Citizen Lab @citizenlab.ca · 10/09/2025
JOB ALERT: We are recruiting for the newly created role of Information Security Program Manager. Apply by Sept 30. citizenlab.ca/2025/09/job-...
citizenlab.ca
Job Opportunity: Information Security Program Manager - The Citizen Lab
The Information Security Program Manager will be responsible for providing strategic leadership to develop and implement Information Security Programs for the Citizen Lab as well as other units at the...
188
jiska @naehrdine.bsky.social · 10/09/2025
Want to learn reverse engineering? There'll be a free, women*-only BlackHoodie workshop from October 6th to 9th in Paris! Topics: • Linux memory forensics 🕵️‍♀️ (by Sonia) • Web app and mobile app pentesting 🕸️📱 (by Paula) • iOS reversing 🍎 (by me)
12415
Reposted by jiska
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
WOOT 2025 schedule, all papers are now online open access: usenix.org/conference/w... Talks are recorded, and should be online in a few weeks.
usenix.org
WOOT '25 Technical Sessions
All sessions will be held in Room 611-612 unless otherwise noted.
0128