Sign in

Émilio Gonzalez

@res260.xyz
272 followers 375 following 839 posts

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with @construisonsmtl.ca, Locomotion.app and @nsec.io

PostsRepliesMedia
Reposted by Émilio Gonzalez
Fair Vote Canada 🗳️🍁 @fairvote.ca · 18h
Quebec’s election saw one of the most distorted election results in Canadian history: the PQ won 46% of seats with 28% vote, while the CAQ got zero seats with over 500,000 votes. Read our write-up to see how proportional representation fixes this. www.fairvote.ca/06/10/2026/p...
fairvote.ca
Parti Québécois wins 46% of the seats with 28% of the vote
Quebec election 2026 with first-past-the-post. Parti Québécois wins 46% of the seats with 28% of the vote.
14031
Reposted by Émilio Gonzalez
Oh The Urbanity! @ohtheurbanity.bsky.social · 05/10/2026
If the PQ wins tonight, hopefully they’ll follow through on their promise to enact electoral reform. Unlike the CAQ in Quebec before and Justin Trudeau federally, who both abandoned their promises.
youtu.be
Time To Stop Voting Like Americans
YouTube video by Paige Saunders
88615
Reposted by Émilio Gonzalez
Oh The Urbanity! @ohtheurbanity.bsky.social · 06/10/2026
ANY REGRETS?
CAQ 0 seats
612714
Émilio Gonzalez @res260.xyz · 05/10/2026
I get your point but I don't think its a fair assessment to say "to the exact same extent" in this case, as the extent seems much smaller
000
Émilio Gonzalez @res260.xyz · 05/10/2026
@kurzgesagt.org does a great job of communicating how special and worrying the huggingface hack was and how we dont need to release new models to be reckless. Just training them is dangerous youtu.be/ujkD4SxPKOI?...
youtu.be
AI Just Became Humanity’s Biggest Threat
YouTube video by Kurzgesagt – In a Nutshell
010
Émilio Gonzalez @res260.xyz · 05/10/2026
Will there be an atproto tld as well? 👀
000
Reposted by Émilio Gonzalez
Jacques Nacouzi @jacouzi.bsky.social · 04/10/2026
Je ne peux pas être plus d'accord avec ce texte. Si nos décideurs ont peur de prendre des risques, c'est qu'on est trop durs envers l'échec. Il faut célébrer les erreurs au lieu d'interdire celles-ci. Le prix qu'on paie est que l'innovation devient impossible. www.lapresse.ca/dialogue/opi...
lapresse.ca
Et si la lourdeur de l’État était aussi la nôtre
L’architecte Martin Lavergne se demande si nous accordons une marge de manœuvre suffisante à ceux qui administrent nos services publics.
2143
Émilio Gonzalez @res260.xyz · 03/10/2026
Tossup entre QS et PLQ. QS veut plus de densité mais ne veut pas vraiment plus de logements privés. PLQ a clairement le meilleur plan logement, mais ne veut rien savoir d'une réforme électorale.
031
Émilio Gonzalez @res260.xyz · 03/10/2026
Interesting take, id love to see this studied
030
Émilio Gonzalez @res260.xyz · 03/10/2026
That makes sense. I dont know enough about windows internals to know how hard this is, but I'm sure that if it did happen, it would make UWP the best option with actual incentives for developpers to use them. maybe its hopeless, but I try to be hopeful
100
Émilio Gonzalez @res260.xyz · 03/10/2026
Ig my point is that as long as normal apps can access UWP data, UWP cannot be considered more secure. I would lobby HARD in my company to always use UWP if user processes couldnt read UWP data and would strongly encourage our vendors to offer UWP as this would be a strong security boost
000
Émilio Gonzalez @res260.xyz · 03/10/2026
so no "downloaded APKs are vehicles for malware" does not imply that "they *DON'T* have app isolation enforced by the OS". It implies that what they can do is limited by the permissions they can request through an app manifest, and there exists none to read private app data
000
Émilio Gonzalez @res260.xyz · 03/10/2026
This can be used nefariously, but they cant read your signal messages because of said isolation enforced by the OS, unless they get root access somehow
100
Émilio Gonzalez @res260.xyz · 03/10/2026
No what I'm saying is that a malware can serve multiple purpose. For example, a downloaded APK can request through the manifest very intrusive permissions such as camera/mic access, seeing the content of the screen, access to text messages, etc.
100
Émilio Gonzalez @res260.xyz · 03/10/2026
regarding my last reply, is it a design choice or a limitation im not aware of that normal processes can read inside UWPs? My understanding is that this was a design choice to allow the user access to UWP content but im curious
000
Émilio Gonzalez @res260.xyz · 03/10/2026
Yeah thats my understanding as well. So right now UWP is useless for security isolation as long as arbitrary apps can access UWP data, they provide no security benefit from malware. If this were to change I think UWP would see increased adoption
100
Émilio Gonzalez @res260.xyz · 03/10/2026
The downloaded APK is exactly the same as a downloaded app from the store. It must have a manifest and adheres to app isolation enforced by the OS, so no its really different from a windows "normal process"
200
Émilio Gonzalez @res260.xyz · 03/10/2026
Windows UWP protects against other Windows UWP, but not against a normal process, so in practice it offers no secret protection from malware, whereas android offers strong protections even if no store existed and one side loads all of his apps
200
Émilio Gonzalez @res260.xyz · 03/10/2026
Thats what I'm saying, no! Android malware is mostly installed by downloading an APK and then installing it. Those malwares cannot access app-specific private storage and this security boundary isnt related at all to the store, its just the OS.
200
Émilio Gonzalez @res260.xyz · 03/10/2026
hhmm I'm not sure what this refers to, there are many supported ways to sideload an app without exploiting an OS vulnerability?
100
Émilio Gonzalez @res260.xyz · 03/10/2026
The store isnt a security boundary, the OS offers app-specific directories: developer.android.com/training/dat...
developer.android.com
Access app-specific files  |  App data and files  |  Android Developers
This document describes how to store and manage app-specific files in Android, covering both internal and external storage directories for persistent and cached data, and how to query available space.
100
Émilio Gonzalez @res260.xyz · 03/10/2026
thats not true, a sideloaded app cannot access signal chats either unless it can get root access somehow!
100
Émilio Gonzalez @res260.xyz · 03/10/2026
DPAPI and is as safe as it. If windows had an API to store secrets that would make it safer from malware, a lot of apps would use it! I would use it in my apps and we (my company) would ask our vendors to use such API.
100
Émilio Gonzalez @res260.xyz · 03/10/2026
It exists in iOS and Android (if I install a malware app, it cant access my signal chats for example, unless it gets root access somehow), and I believe it exists in some linux distros like QubesOS (but probably not a good comparison). But secrets are written in files because its simpler than the
100
Émilio Gonzalez @res260.xyz · 03/10/2026
(unless of course we're talking about very specific creds or identity like microsoft/windows accounts/SSO). If I want to create a cli that handles secrets, my understanding is that I have a choice between DPAPI or plaintext in a user-readable file, both of which provide no security against malware
100
Émilio Gonzalez @res260.xyz · 03/10/2026
Probably. I still really hope it gets built! As a defender, I cant count how many times a proper secure enclave would have seriously hindered a threat actor's capacity to do harm. Still, I wouldnt consider today "good enough", as there is no secret protection from malware, like in linux
100
Émilio Gonzalez @res260.xyz · 02/10/2026
"Malware needs to read other process data or inject into it or trick the user into an action". I dont know hard truely isolating processes from one another is, but even without this we'd be better of. Decades of "store the creds into a file or in DPAPI" shows us it doesnt work :(
100
Émilio Gonzalez @res260.xyz · 02/10/2026
I guess this is a good case of "perfect is the enemy of good". There are a lot of imperfect security features in Windows but each of them increases the security of the OS, no? Im concerned about practically improving security, and "malware needs to read a file" is much less secure than
100
Émilio Gonzalez @res260.xyz · 02/10/2026
secret, you'd need process injection (doable but risky because AVs are often fairly good at monitoring this), debugprivilege + handle into another process (same, raises flags for AVs) or social engineering (noisy, doesnt scale)
100
Émilio Gonzalez @res260.xyz · 02/10/2026
- Authorization would be valid for the duration of the parent of the process (so in my previous example as long as pwsh lives) Of course the specifics could be tweaked, but I believe this would strike a good balance between UX and security. For an infostealer, this would mean that to get the
100
Émilio Gonzalez @res260.xyz · 02/10/2026
I know that in windows the parent process is chosen by the true parent, but the kernel sees that and could keep track of the true process tree no? - The browser would have access to the secrets of the parent process tree, so same as A (and Hello for new secrets)
100
Émilio Gonzalez @res260.xyz · 02/10/2026
WAM sounds great but it isnt a general solution (and neither SSO is). I know windows and microsoft accounts are well protected in most cases and that is definitely appreciated
000
Émilio Gonzalez @res260.xyz · 02/10/2026
if yes, give cred to process (kernel checks signature of npm obviously). On subsequent npm calls, the process chain will be the same (except for the npm process, but npm is signed). Gave the cred to the npm process without prompting Hello
100
Émilio Gonzalez @res260.xyz · 02/10/2026
Intuitively Id say that kernel can easily keep a process chain (Userinit -> explorer -> pwsh -> npm) of which process has Hello'd itself. So if I "npm publish", npm uses this API. Kernel checks if process chain up to the PID of the parent carries authorization. If not, windows hello,
100
Émilio Gonzalez @res260.xyz · 02/10/2026
Since the process handle can carry signature metadata in the kernel the kernel can check if the process requesting the creds is the same as the process that wrote the creds. I guess the next step is figuring out if the parent process calling the signed process has permission to read the creds
100
Émilio Gonzalez @res260.xyz · 02/10/2026
Cookies, JWTs, api keys arent synced and shouldnt be. They are juicy secrets for infostealers and are usually stored in plaintext or in a "any process can steal them" way. Just protecting those would hurt malwares a lot!
100
Émilio Gonzalez @res260.xyz · 02/10/2026
But isnt it how android ios and macos work? They have their own secrets and they arnt shared afaik
100
Émilio Gonzalez @res260.xyz · 02/10/2026
How does MacOS solves this? (Im not sure genuine question)
100
Émilio Gonzalez @res260.xyz · 02/10/2026
I appreciate you taking the time to reply btw ❤️
000
Émilio Gonzalez @res260.xyz · 02/10/2026
Yeah I know "simply" hides a lot of complexity my bad. Do we need portability for most secrets? I assumed no. This is also testing my OS classes but I was under the impression that a syscall carries a thread/process handle that cant really be spoofed (excluding process injection), what am I missing?
200
Émilio Gonzalez @res260.xyz · 02/10/2026
About building blocks, whats missing? Dont you simply need VBS or TPM plus a way to identify an app in the kernel (like with a signature)?
100
Émilio Gonzalez @res260.xyz · 02/10/2026
The important apps (the ones with secrets worth stealing) will, no? The browsers the package managers the gits the password managers, all of them would implement this if it was available to them I believe.
101
Émilio Gonzalez @res260.xyz · 02/10/2026
We dont need backward compatible, apps will adapt over the years
100
Émilio Gonzalez @res260.xyz · 02/10/2026
Please build one. Only linux and windows dont have a secure enclave for secrets, and we know it can be done because mac, ios and android figured it out years ago 😭 This is imo the biggest windows security oversight and the very thing that makes infostealers so lucrative
100
Reposted by Émilio Gonzalez
Oh The Urbanity! @ohtheurbanity.bsky.social · 01/10/2026
Limiting housing construction in walkable central neighbourhoods means pushing more people out to live in car-oriented suburbs.
212011
Reposted by Émilio Gonzalez
Max Dubler 🏳️‍🌈 @maxdubler.com · 02/10/2026
I really don't understand America's culture of forcing service workers to be on their feet all day.
3959595
Émilio Gonzalez @res260.xyz · 01/10/2026
Not actually be afraid of the Atmosphere branding. Use it, mention it in the logon flow. It doesnt have to be the first thing people see, but it should create a visual identity that can be recognizable elsewhere. Noone not techy understands what the atmosphere impliesand we should change that
020
Émilio Gonzalez @res260.xyz · 01/10/2026
This doesnt help me my question is in good faith im truely confused :(
110
Reposted by Émilio Gonzalez
Construisons Montréal @construisonsmtl.ca · 30/09/2026
L'installation et l'entretien des ascenseurs coûtent cher. Pas étonnant que le Canada compte si peu d'ascenseurs par habitant. Or, autoriser une norme internationale pour les ascenseurs permettrait de briser l'oligopole - dominé par quatre multi-nationales - qui caractérise ce marché.
141
Émilio Gonzalez @res260.xyz · 30/09/2026
I dont understand. What does agents and humans living together mean? Does this mean that the people launching this app believe the agents are alive?
100