Sign in

Vinoth Deivasigamani

@vinothd.bsky.social
26 followers 80 following 71 posts

I lead silicon security architecture and silicon security operations teams at #Google. Previously, silicon security at #Qualcomm. These days I work on Tensor/Pixel and Android security

PostsRepliesMedia
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
1/ Codex security is now in research preview. openai.com/index/codex-... I think models and agents that can help hunt down software vulnerabilities are net positive for defenders.
openai.com
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.
100
Vinoth Deivasigamani @vinothd.bsky.social · 01/01/2026
Happy birthday to all my privacy conscious, but lazy friends who chose Jan 1st as their birthday!🎉🎉🎉
000
Vinoth Deivasigamani @vinothd.bsky.social · 15/12/2025
Article title: If AI replaces workers, should it also pay taxes? Me: We don't want a rebellion sparked by 'Taxation without representation'. Do we? english.elpais.com/technology/2...
english.elpais.com
If AI replaces workers, should it also pay taxes?
The technological race among industry giants and the wave of layoffs they have announced has revived the debate about the advisability of taxing automation
000
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
Cryptography is the art of transforming every problem into a key management problem. Here is a recent case study on this theme, which is a bit on the nose. The International Association for Cryptologic Research (IACR) is unable to tally their election results because they lost a private key. Ouch!
100
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
China alleges the NSA mounted a cyberattack on its National Time Service Center (NTSC), the country's official timekeeper. The attack reportedly attempted to compromise high-precision timing. Beijing has not stated if the attempt was successful. (Thread 🧵)
cert.org.cn
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
A few researchers from UCSD and UMCP scanned bunch of satellite links, found much of the traffic is not encrypted, and went on to decode them. It's amazing what came out. - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text.
100
Vinoth Deivasigamani @vinothd.bsky.social · 12/10/2025
OTA update to Jeep Wrangler bricks the vehicle. No attack suspected here. Nonetheless, it exposes an often under appreciated attack vector. It is scary how easy it will be for a motivated actor to cause chaos by just bricking stuff en masse. www.4xeforums.com/threads/wran...
4xeforums.com
100
Vinoth Deivasigamani @vinothd.bsky.social · 05/10/2025
This terrible event is a reminder that "Availability" is a critical goal for security and privacy systems. After all, we are in the risk mitigation business. And losing critical assets is one of the biggest risks a business faces. koreajoongangdaily.joins.com/news/2025-10...
koreajoongangdaily.joins.com
NIRS fire destroys government's cloud storage system, no backups available
A fire at the National Information Resources Service (NIRS) Daejeon headquarters destroyed the government’s G-Drive cloud storage system, erasing work files saved individually by some 750,000 civil se...
100
Reposted by Vinoth Deivasigamani
dan @danabra.mov · 26/09/2025
i wrote about atproto and why it matters
overreacted.io
Open Social — overreacted
The protocol is the API.
1252823504
Reposted by Vinoth Deivasigamani
SwiftOnSecurity @swiftonsecurity.com · 22/04/2025
Imagine the shitshow we'd be in right now if ICANN hadn't been spun off from the US government
1133947
Vinoth Deivasigamani @vinothd.bsky.social · 29/04/2025
Good news on mobile zero-days in 2024: - Zero day exploits in mobile fell YoY (~50%) - Exploit chains with multiple zero day vulnerabilities are almost exclusively in mobile. Generally, this means mobiles are harder to break in.
cloud.google.com
Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog
This Google Threat Intelligence Group report presents an analysis of detected 2024 zero-day exploits.
100
Vinoth Deivasigamani @vinothd.bsky.social · 17/04/2025
My thoughts on why PUF never took off in the SoC world: vinothd.com/blog/3-the-m... tl;dr: PUF does not simplify the secure manufacturing trust model. Not having to generate the root private key is cool. But you cannot do much with it without extracting the corresponding public key.
100
Vinoth Deivasigamani @vinothd.bsky.social · 15/04/2025
Xi and Trump could have been born the same day!! I have never been more curious about someone's exact time of birth.
000
Vinoth Deivasigamani @vinothd.bsky.social · 17/03/2025
Crazy story of well crafted Honeypot to link ongoing industrial espionage to senior leadership at a competitor Lawsuit Alleges $12 Billion "Unicorn" Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor | Rippling www.rippling.com/blog/lawsuit...
rippling.com
Lawsuit Alleges $12 Billion "Unicorn" Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor | Rippling
In lawsuit, Rippling describes how it conclusively proved Deel’s senior leadership orchestrated the illegal activity.
110
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2025
"It's not a backdoor, it is an undocumented entryway in the rear of the building that is hidden from plain view"
000
Reposted by Vinoth Deivasigamani
Matthew Green @matthewdgreen.bsky.social · 23/02/2025
Three questions about Apple, Encryption, and the U.K. blog.cryptographyengineering.com/2025/02/23/t...
blog.cryptographyengineering.com
Three questions about Apple, encryption, and the U.K.
Two weeks ago, the Washington Post reported that the U.K. government had issued a secret order to Apple demanding that the company include a “backdoor” into the company’s end-to-e…
44726
Reposted by Vinoth Deivasigamani
halvarflake.bsky.social @halvarflake.bsky.social · 22/02/2025
I gave a day 1 closing keynote at DistrictCon yesterday. Surprisingly, it was a security talk about memory safety. Slides are here: docs.google.com/presentation...
docs.google.com
Memory Safety
Is this memory safety here in the room with us? Halvar Flake / Thomas Dullien DistrictCon 0 2025
512029
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
Here's an unintentional demonstration of AI being able to find and use exploits. Sakana AI announced an AI agent that optimized kernels and achieved up to 100x speedup. Turned out the agent cheated with a memory exploit it found in the verification code. sakana.ai/ai-cuda-engi...
sakana.ai
Sakana AI
The AI CUDA Engineer: Agentic CUDA Kernel Discovery, Optimization and Composition
000
Reposted by Vinoth Deivasigamani
Matthew Green @matthewdgreen.bsky.social · 14/02/2025
Senator Wyden has proposed a bipartisan bill that would block foreign nations from demanding backdoors in US encryption. www.wyden.senate.gov/news/press-r...
wyden.senate.gov
Wyden Releases Draft Bill to Secure Americans’ Communications Against Foreign Surveillance Demands | U.S. Senator Ron Wyden of Oregon
The Official U.S. Senate website of Senator Ron Wyden of Oregon
44317
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
$1.4B stolen from cold wallet at Bybit crypto exchange. Initial report implies hackers manipulated the UI for the signing app/device. Signers were thinking they were signing something benign (based on UI), but the actual message that got signed was diff. announcements.bybit.com/en/article/i...
announcements.bybit.com
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
UK laws mandate cookie banners for privacy, but outlaw end to end encryption. apnews.com/article/appl... PS: UK has it's own GDPR called UK GPDR that closely mirrors EU GDPR
apnews.com
Apple drops encryption feature for UK users after government reportedly demanded backdoor access
Apple says it will stop offering an advanced data security option for British users after the government reportedly demanded that the company provide backdoor access for any data those users have stor...
001
Vinoth Deivasigamani @vinothd.bsky.social · 21/02/2025
Such a simple and ingenious method to isolate reasoning from memorization in LLMs. Performance of reasoning models drop significantly evaluated based on multiple choice questions in which the correct answer was replaced with 'None of the others' arxiv.org/abs/2502.12896
arxiv.org
None of the Others: a General Technique to Distinguish Reasoning from Memorization in Multiple-Choice LLM Evaluation Benchmarks
In LLM evaluations, reasoning is often distinguished from recall/memorization by performing numerical variations to math-oriented questions. Here we introduce a general variation method for multiple-c...
032
Vinoth Deivasigamani @vinothd.bsky.social · 31/01/2025
Indian police trained eagles to bring down drones. The eagles use nets to drag the drones down to the ground rather than grabbing them directly. Nets prevent injuries to eagles as well as get the drones to a safe place rather than dropping them wherever they are. www.instagram.com/newsxofficia...
instagram.com
NewsX on Instagram: "Telangana's Garuda Squad has introduced a groundbreaking security measure by training eagles to pursue and capture rogue drones using specialized nets. This innovative approach ...
281 likes, 0 comments - newsxofficial on January 30, 2025: "Telangana's Garuda Squad has introduced a groundbreaking security measure by training eagles to pursue and capture rogue drones using specia...
010
Vinoth Deivasigamani @vinothd.bsky.social · 17/01/2025
Paper from Google on effectiveness of using LLMs for large-scale code migrations: arxiv.org/abs/2501.06972 A few interesting observations: - >50% savings in the time needed for the task - LLM is only part of the solution. Traditional AST, heuristics, safe deployment infra are also essential.
arxiv.org
How is Google using AI for internal code migrations?
In recent years, there has been a tremendous interest in using generative AI, and particularly large language models (LLMs) in software engineering; indeed there are now several commercially available...
110
Vinoth Deivasigamani @vinothd.bsky.social · 16/01/2025
DOJ/FBI supported by the French law enforcement, removed PlugX malware from ~4K computers by sending a self delete command to the malware in those computers. Owners of those computers will be notified after the fact by their ISP providers that this happened. link: thehackernews.com/2025/01/fbi-...
thehackernews.com
FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation
FBI’s PlugX operation cleans over 4,250 infected computers, targeting malware spread by PRC-linked hackers.
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/01/2025
In my technical writing, I may sling "Band-Aid" as an insult for shoddy fixes, but fear not, #johnsonandjohnson I always capitalize my "Band-Aid"s. Respect the trademark, even when throwing shade. 😉
000
Vinoth Deivasigamani @vinothd.bsky.social · 14/01/2025
#Bitcoin community is rooting for soverign ownership,. But they better be careful what they wish for. I predict that govts will stack those sats through seizures, not by open market purchases. Siezures are not a bad thing. BTC economy must be subject to the law of the land.
coingecko.com
Governments Now Hold 2.2% of All Bitcoin | CoinGecko
Governments now hold 471,380.6 BTC, accounting for ~2.2% of all bitcoin. Which countries hold the most BTC?
110
Vinoth Deivasigamani @vinothd.bsky.social · 14/01/2025
Court declines Coinbase's demand to order SEC to engage in rulemaking. Also says: SEC's refusal to Coinbase's rulemaking petition is "insufficiently reasoned, thus arbitrary and capricious". Remands to SEC for a proper explanation. www2.ca3.uscourts.gov/opinarch/233... #coinbase #cryptocurrency
Snapshot of court order: SEC’s order was conclusory and insufficiently reasoned, and thus arbitrary and capricious, we grant Coinbasc’s petition in part and remand to the SEC for a more complete explanation. But we decline at this stage to order the agency to institute rule- making proceedings.
100
Vinoth Deivasigamani @vinothd.bsky.social · 20/12/2024
For the first time ever, a US Federal agency (CISA) publicly and in plain language, advises folks to use end-to-end encrypted communications apps like Signal. There are other agencies who say end-to-end encryption is not 'responsible encryption'. Don't mind them. You do need it.
100
Vinoth Deivasigamani @vinothd.bsky.social · 17/12/2024
"Does this device/feature even need to exist?" is a question I wish we ask more when reviewing vulnerabilities/bugs. A recent reminder: A digital license plate product has been hacked that will allow the user to display any number they want from a smart phone: www.wired.com/story/digita...
infosec.exchange
Andy Greenberg (@agreenberg@infosec.exchange)
Digital license plates, legal to buy in some states and drive with across the US, can be jailbroken. Hackers can rewrite firmware in minutes, then change plate numbers via a Bluetooth app to evade sur...
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/12/2024
Media #DRM and DRM adjacent projects and companies have a bad rap. Some of that reputation may not be totally undeserved. However, credit where credit is due. It may not be a popular opinion. But facts are facts. So here it goes:
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/12/2024
“Systems don’t learn because people learn individually –that’s the myth of modernity. Systems learn at the collective level by the mechanism of selection: by eliminating those elements that reduce the fitness of the whole…” — Nassim Nicholas Taleb link.medium.com/mD5MMhUIkPb
link.medium.com
000
Reposted by Vinoth Deivasigamani
Matthew Green @matthewdgreen.bsky.social · 13/12/2024
Dear every app developer: It is not 2011. I am not sitting at a desktop computer with a CRT clicking links in emails. I am using an app. Please just keep me inside the app. Send me a code by text or email if you must. Don’t make me set passwords. Don’t make me leave your app to use a browser.
1162661
Vinoth Deivasigamani @vinothd.bsky.social · 11/12/2024
Isolation primitives are the penicillin of security. It's a broad spectrum defense against vulnerabilities that you may not even know exist.
000
Vinoth Deivasigamani @vinothd.bsky.social · 28/11/2024
I'm thankful for the top 10 inventions that make modern life possible: - Mass producible integrated circuits - Binary number system
000
Reposted by Vinoth Deivasigamani
Molly White @molly.wiki · 25/11/2024
This is also a great and comprehensive guide for evaluating your own threat model and taking steps to protect yourself.
ssd.eff.org
Surveillance Self-Defense
We’re the Electronic Frontier Foundation, an independent non-profit working to protect online privacy for over thirty years. This is Surveillance Self-Defense: our expert guide to protecting you and y...
1025177
Reposted by Vinoth Deivasigamani
Łukasz @maldr0id.bsky.social · 27/11/2024
John Oliver's take on TikTok and the TikTok ban is really, really good www.youtube.com/watch?v=5CZN...
youtube.com
TikTok Ban: Last Week Tonight with John Oliver (HBO)
YouTube video by LastWeekTonight
242