Eduardo Vela @sirdarckcat.bsky.social · 15/01/2026We are hiring! CPU security and stuff www.google.com/about/career... 022
Reposted by Eduardo VelaCatalin Cimpanu @campuscodi.risky.biz · 07/08/2025Google security researchers have improved the Retbleed CPU side-channel attack to increase exfiltration speed. The attack can now leak data at 13 KB/s, which is fast enough to be used in modern cloud environments. bughunters.google.com/blog/6243730...bughunters.google.comBlog: Exploiting Retbleed in the real worldCurious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and und... 084
Eduardo Vela @sirdarckcat.bsky.social · 20/05/2025youtu.be/sUFDKTaCQEk?... (slides at entrysign.top)youtu.beOffensiveCon25 - Matteo Rizzo, Kristoffer `spq` Janke, Eduardo Vela Nava and Josh EadsYouTube video by OffensiveCon 064
Reposted by Eduardo VelaCatalin Cimpanu @campuscodi.risky.biz · 06/03/2025Google published details on EntrySign, an AMD Zen microcode signature validation vulnerability (CVE-2024-56161) that can allow threat actors to install malicious firmware: bughunters.google.com/blog/5424842... It also released Zentool, a tool to jailbreak AMD processors: github.com/google/secur... 0298
Eduardo Vela @sirdarckcat.bsky.social · 10/02/2025It's covered by the privacy policy, so similar to Docs/GMail! 010
Eduardo Vela @sirdarckcat.bsky.social · 09/02/2025I am such a big fan of NotebookLM.. The ability to say, hey, here are 20 papers and 3 books from this subject matter, can you please explain this problem to me? and have active in-depth Q&A helps me solve problems in new spaces so much faster. What used to take me multiple weekends now takes hours 120
Reposted by Eduardo VelaChristian Blichmann 🇺🇦 (also on Mastodon) @admvonschneider.bsky.social · 03/02/2025It's out and make for a very interesting read: github.com/google/secur... IMO, AMD should own it and release a microcode SDK.... @sirdarckcat.bsky.socialgithub.comAMD: Microcode Signature Verification Vulnerability### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside... 182
Eduardo Vela @sirdarckcat.bsky.social · 03/02/2025Yes!!! It would be so cool if they open sourced their tools 010
Eduardo Vela @sirdarckcat.bsky.social · 14/01/2025youtu.be/H9K45VkjKvM?... I found a video of c developers 010
Eduardo Vela @sirdarckcat.bsky.social · 02/01/2025LLMs are at least better translators than normal translation tools gemini.google.com/share/68582c... 020
Eduardo Vela @sirdarckcat.bsky.social · 01/01/2025I think the FBI is taking a chaotic good approach to secure coding. No more insecure software or.. right to jail!media.tenor.coma man in a military uniform is standing in front of a group of people and says `` right to jail '' .ALT: a man in a military uniform is standing in front of a group of people and says `` right to jail '' . 000
Eduardo Vela @sirdarckcat.bsky.social · 01/01/2025"Guan Tianfeng's role in the conspiracy was to develop and test the zero-day vulnerability" - yikes, better not develop any more vulnerabilities or fail to do proper testing or the FBI will go after you! www.fbi.gov/wanted/cyber... 111
Eduardo Vela @sirdarckcat.bsky.social · 29/12/2024Today I realized <input type=radio> implements roving tabindex natively.. so you can hack a css-only implementation. Forgive me ARIA, for I will sin. 000
Eduardo Vela @sirdarckcat.bsky.social · 28/12/2024Is this what they call a culture shock in Japan? 010
Eduardo Vela @sirdarckcat.bsky.social · 24/12/2024Made a tiny game with my 6-years old cousin tonight using cursor.com - must say this was way easier than I thought, and I literally wrote zero code. sirdarckcat.github.io/salchichon/sirdarckcat.github.ioPerrito Salchichón 120
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024So with that, I'll update this thread when I make some progress 🙂 000
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024Some I will fix by hiding it from the a11y tree (like the checkboxes), some I will fix by changing divs to buttons (as I should have done since the start). Some I will add aria roles (like for things I styled as links but can't make real links). Some I'm curious what will happen (like dialogs). 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024So, with that, my next step is going to be to look at the *actual* a11y tree of the application and see what's there that shouldn't be there. Some stuff I already know I will find is: 1. I used some divs as buttons instead of using <button> 2. I used some checkboxes for keeping CSS state 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024On an older project of mine, I did this exercise of designing with the accessibility tree, and when making the end-to-end tests, I also serialized the a11y tree to identify regressions (Google also has an internal tool called Rembrandt that does this), you can see it here github.com/google/tampe... 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024Screen readers actually have better keyboard navigation tools than we do (yikes!), as there are a lot more keyboard shortcuts. However, the majority of the interactions work without assistive technologies. As a result, a significant "upside" about caring about a11y is better keyboard UI design. 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024As such, when drafting the a11y tree we can "imagine" what hierarchy is easy to navigate through by landmarks and tabbing. One (surprising?) result is that this makes the webapp extremely keyboard friendly, and in a way, helps users be more productive. 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024Screen readers "navigate" through the accessibility tree, but they also use "landmarks" like headings. And to navigate the hierarchy within the application. Interactive elements (like buttons) also can be sequentially browsed through by tabbing. 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024When we "design", we sometimes let the user assume what certain elements are, based on their looks. For example rounded corners for tabs, or 3d boxes for buttons. This "look and feel" is called an affordance, and for a11y you label these on the a11y tree with aria roles (tablist, button). 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024An interesting exercise is to design the UI of our web app, but instead of doing drawings, draft how the a11y tree of our app would be "seen". Or, in other words, design for a11y first. This actually is a lot easier and faster than drawing boxes. See the screenshots below, for example. 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024Browsers have something similar to the DOM tree but called the Accessibility Tree. developer.chrome.com/blog/full-ac... In many ways it is similar to the DOM tree, but it only contains elements that assistive technologies (like screen readers) find useful, and may have a different hierarchy. 100
Eduardo Vela @sirdarckcat.bsky.social · 23/12/2024So one thing I want to work on the kernel explorer before we keep accumulating tech debt is accessibility. I thought it would be cool to try and describe how I'll approach it, so this will be a 🧵 thread I'll update as I make progress. 100
Eduardo Vela @sirdarckcat.bsky.social · 22/12/2024Writing CSS is so relaxing.. codepen.io/sirdarckcat/... <div class="node"> <h1></h1> <div class="edges"> <div class="left"></div> <div class="right"></div> </div> </div>codepen.ioFunctional HTML/CSS/JavaScript Code BinA Functional Code bin that works like JSBin. It only supports HTML, CSS and JavaScript. No console or JQuery support, unless you modify the mark-up. Cl... 030
Eduardo Vela @sirdarckcat.bsky.social · 21/12/2024I think I would be pretty good at competitive password typing 230
Eduardo Vela @sirdarckcat.bsky.social · 20/12/2024Small preview of our kernel explorer. Still a lot of work to do! kernelctf-dash.storage.googleapis.com/processed/v6...kernelctf-dash.storage.googleapis.com🐧DASHing 172
Eduardo Vela @sirdarckcat.bsky.social · 02/12/2024Oh and there are no 64bit emulators so you have to use a 32bit kernel. 010
Eduardo Vela @sirdarckcat.bsky.social · 02/12/2024I tried to implement this yesterday (kind of). It is too slow to run syz-execprog but running the compiled C reproducer was better. You can't really run ftrace (I was hoping to!) but I probably could get the info from the emulator directly. Promising, but still TBD! 130
Eduardo Vela @sirdarckcat.bsky.social · 24/11/2024It would be cool if there was a way to run Syzkaller on the browser. You just get an IDE for writing Syzkaller programs and you get coverage data, register state (like with kprobes) etc 020
Eduardo Vela @sirdarckcat.bsky.social · 22/11/2024kt.gy/tools.html#c... is pretty cool too!kt.gykt.gy tools 111
Eduardo Vela @sirdarckcat.bsky.social · 21/11/2024blog.wokwi.com/running-gdb-... is pretty cool!blog.wokwi.comRunning GDB in the BrowserGDB inside a Linux in a x86 Virtual Machine using Web Assembly running in the browser. Crazy? 041
Eduardo Vela @sirdarckcat.bsky.social · 21/11/2024media.tenor.coma man in a military uniform has a patch on his jacket that says ' ussr ' on itALT: a man in a military uniform has a patch on his jacket that says ' ussr ' on it 020