Sign in

Vinoth Deivasigamani

@vinothd.bsky.social
26 followers 80 following 71 posts

I lead silicon security architecture and silicon security operations teams at #Google. Previously, silicon security at #Qualcomm. These days I work on Tensor/Pixel and Android security

PostsRepliesMedia
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
6/ As a result, defender-side agents will likely be better positioned to identify these harder classes of vulnerabilities. That’s why I think LLM-assisted vulnerability discovery ultimately favors defense.
000
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
5/ Finding these requires deep context: how the system is designed, what assumptions were made, and how different pieces interact across the stack. Defenders naturally have that context. Attackers usually don’t.
100
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
4/ What remains are the harder classes of vulnerabilities: • issues emerging at module boundaries • incorrect assumptions between components • complex system-level behavior rather than a single piece of code
100
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
3/ As that happens, the attack surface shifts. Fewer trivial bugs. More subtle vulnerabilities.
100
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
2/ The era of "stupid bugs" resulting in vulnerabilities is ending. With LLM-assisted analysis, obvious implementation mistakes will get discovered and fixed much faster.
100
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2026
1/ Codex security is now in research preview. openai.com/index/codex-... I think models and agents that can help hunt down software vulnerabilities are net positive for defenders.
openai.com
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.
100
Vinoth Deivasigamani @vinothd.bsky.social · 01/01/2026
Happy birthday to all my privacy conscious, but lazy friends who chose Jan 1st as their birthday!🎉🎉🎉
000
Vinoth Deivasigamani @vinothd.bsky.social · 15/12/2025
Article title: If AI replaces workers, should it also pay taxes? Me: We don't want a rebellion sparked by 'Taxation without representation'. Do we? english.elpais.com/technology/2...
english.elpais.com
If AI replaces workers, should it also pay taxes?
The technological race among industry giants and the wave of layoffs they have announced has revived the debate about the advisability of taxing automation
000
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
Link back to the top of the thread: bsky.app/profile/vino...
000
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
That said, I am glad that IACR is addressing this "human mistake" by making a "system design change" to a 2-of-3 quorum for the re-run. www.iacr.org/news/item/27... #IACR #Cryptography #KeyManagement #InfoSec #OPSEC #Elections
iacr.org
IACR News item: 21 November 2025
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
Devices die. Backups fail. People forget. People die. Anyone who has worked with computers (or people) knows this happens. System design should account for this. I wish IACR took accountability for the design failure rather than blaming the human element.
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
I am disappointed that IACR is framing the root cause as an "unfortunate human mistake," effectively throwing a distinguished member of the community under the bus. This is a system design issue. No critical system should have a 3-of-3 quorum requirement.
120
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
2. Security is more than cryptography. Most secure systems fail or get compromised, not due to sophisticated cryptanalytic attacks, but due to implementation and OPSEC issues.
110
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
Few lessons to relearn here: 1. Availability is a security requirement. It is just as important as Confidentiality. While this seems like a truism, it is not uncommon to come across system designs (or even NSA/NIST specs) that contradict this principle.
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
IACR used #Helios for voting. They configured it such that all 3 trustees need to be present with their share of the private key to tally results. One trustee lost their share. Now the results are mathematically secure—forever. The math worked. The encryption held. The process failed.
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/11/2025
Cryptography is the art of transforming every problem into a key management problem. Here is a recent case study on this theme, which is a bit on the nose. The International Association for Cryptologic Research (IACR) is unable to tally their election results because they lost a private key. Ouch!
100
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
Attack outcome: If you mess with the ground-based time, you mess with GPS. This affects everything from your car's driving directions to the guidance systems for precise missiles. Sources: www.theregister.com/2025/10/20/c... www.cert.org.cn/publish/main...
cert.org.cn
000
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
2. GPS Navigation: GPS satellites need perfectly synchronized clocks. They have onboard atomic clocks but rely on ground stations (like NTSC) to correct for timing drifts. (An interesting source of drift: Relativistic time dilation, because the sats move at ~9,000 mph!)
110
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
1. Telecommunications: Cell phone base stations must share a common clock to hand off calls. This is even more vital for low-latency 5G applications. Attack outcome: If you disrupt the time, you can disrupt the entire communications grid.
100
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
Why target a timekeeper? It sounds mundane, but high-precision time is a critical national security asset. Modern tech relies on nanosecond-level accuracy. If you can mess with time, you can disrupt critical infrastructure. Here are two key examples:
100
Vinoth Deivasigamani @vinothd.bsky.social · 21/10/2025
China alleges the NSA mounted a cyberattack on its National Time Service Center (NTSC), the country's official timekeeper. The attack reportedly attempted to compromise high-precision timing. Beijing has not stated if the attempt was successful. (Thread 🧵)
cert.org.cn
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
Great work, Wenyi Zhang, Annie Dai, Keegan Ryan, Dave Levin, Nadia Heninger and Aaron Schulman! satcom.sysnet.ucsd.edu/docs/dontloo...
satcom.sysnet.ucsd.edu
000
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
While it is important to work on futuristic threats such as Quantum cryptanalysis, backdoors in standardized cryptographic protocols, etc. - the unfortunate reality is that the vast majority of real-world attacks happen because basic protection is not enabled. Lets not take our eyes off the basics.
122
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
- Walmart Mexico: Unencrypted corporate emails, plaintext credentials to inventory management systems, inventory records transferred and updated using FTP
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
- AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic
100
Vinoth Deivasigamani @vinothd.bsky.social · 14/10/2025
A few researchers from UCSD and UMCP scanned bunch of satellite links, found much of the traffic is not encrypted, and went on to decode them. It's amazing what came out. - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text.
100
Vinoth Deivasigamani @vinothd.bsky.social · 12/10/2025
"Almost died on the thruway today when it happened and I’m glad it didn’t cause a bigger accident with an 18-wheeler behind me being able at the last minute to shift lanes because my Jeep died, locked its hand brake and jolted so hard my face almost ended up in the steering wheel at 70mph."
000
Vinoth Deivasigamani @vinothd.bsky.social · 12/10/2025
OTA update to Jeep Wrangler bricks the vehicle. No attack suspected here. Nonetheless, it exposes an often under appreciated attack vector. It is scary how easy it will be for a motivated actor to cause chaos by just bricking stuff en masse. www.4xeforums.com/threads/wran...
4xeforums.com
100
Vinoth Deivasigamani @vinothd.bsky.social · 05/10/2025
Availability is not antithetical to security and privacy. A well designed security system will meet availability needs. "The Interior Ministry explained that... the G-Drive’s structure did not allow for external backups. This vulnerability ultimately left it unprotected."
000
Vinoth Deivasigamani @vinothd.bsky.social · 05/10/2025
This terrible event is a reminder that "Availability" is a critical goal for security and privacy systems. After all, we are in the risk mitigation business. And losing critical assets is one of the biggest risks a business faces. koreajoongangdaily.joins.com/news/2025-10...
koreajoongangdaily.joins.com
NIRS fire destroys government's cloud storage system, no backups available
A fire at the National Information Resources Service (NIRS) Daejeon headquarters destroyed the government’s G-Drive cloud storage system, erasing work files saved individually by some 750,000 civil se...
100
Reposted by Vinoth Deivasigamani
dan @danabra.mov · 26/09/2025
i wrote about atproto and why it matters
overreacted.io
Open Social — overreacted
The protocol is the API.
1252823504
Reposted by Vinoth Deivasigamani
SwiftOnSecurity @swiftonsecurity.com · 22/04/2025
Imagine the shitshow we'd be in right now if ICANN hadn't been spun off from the US government
1133947
Vinoth Deivasigamani @vinothd.bsky.social · 29/04/2025
Google Threat Intelligence Group released their analysis of 2024 0-days that the group tracked: cloud.google.com/blog/topics/...
cloud.google.com
Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog
This Google Threat Intelligence Group report presents an analysis of detected 2024 zero-day exploits.
000
Vinoth Deivasigamani @vinothd.bsky.social · 29/04/2025
The flip side: - % of 0-days in enterprise technologies is increasing (37% ->44%) - Much of that is due to 0-days in *security* and networking products. - Security/networking products generally compromised with a single vulnerability, no exploit chain required. This is scary.
cloud.google.com
Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog
This Google Threat Intelligence Group report presents an analysis of detected 2024 zero-day exploits.
100
Vinoth Deivasigamani @vinothd.bsky.social · 29/04/2025
Good news on mobile zero-days in 2024: - Zero day exploits in mobile fell YoY (~50%) - Exploit chains with multiple zero day vulnerabilities are almost exclusively in mobile. Generally, this means mobiles are harder to break in.
cloud.google.com
Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog
This Google Threat Intelligence Group report presents an analysis of detected 2024 zero-day exploits.
100
Vinoth Deivasigamani @vinothd.bsky.social · 17/04/2025
And that extraction needs to be done securely, which re-introduces the problem of having the trust the manufacturing facilities, and all the complexity needed to minimize that trust.
000
Vinoth Deivasigamani @vinothd.bsky.social · 17/04/2025
My thoughts on why PUF never took off in the SoC world: vinothd.com/blog/3-the-m... tl;dr: PUF does not simplify the secure manufacturing trust model. Not having to generate the root private key is cool. But you cannot do much with it without extracting the corresponding public key.
100
Vinoth Deivasigamani @vinothd.bsky.social · 15/04/2025
Xi and Trump could have been born the same day!! I have never been more curious about someone's exact time of birth.
000
Vinoth Deivasigamani @vinothd.bsky.social · 17/03/2025
"Within hours of sending the letter, Deel’s spy inside of Rippling searched – for the first time – for this empty and never-before-used Slack channel, proving that Deel’s top executives or its legal representatives were running the covert espionage operation."
000
Vinoth Deivasigamani @vinothd.bsky.social · 17/03/2025
"The letter was sent to only three people – Phillipe Bouaziz, the chairman of Deel’s board, CFO, General Counsel, and the father of Deel CEO Alex Bouaziz; Spiros Komis, Deel’s Head of US Legal; and the company’s outside counsel at law firm."
100
Vinoth Deivasigamani @vinothd.bsky.social · 17/03/2025
Crazy story of well crafted Honeypot to link ongoing industrial espionage to senior leadership at a competitor Lawsuit Alleges $12 Billion "Unicorn" Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor | Rippling www.rippling.com/blog/lawsuit...
rippling.com
Lawsuit Alleges $12 Billion "Unicorn" Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor | Rippling
In lawsuit, Rippling describes how it conclusively proved Deel’s senior leadership orchestrated the illegal activity.
110
Vinoth Deivasigamani @vinothd.bsky.social · 09/03/2025
"It's not a backdoor, it is an undocumented entryway in the rear of the building that is hidden from plain view"
000
Reposted by Vinoth Deivasigamani
Matthew Green @matthewdgreen.bsky.social · 23/02/2025
Three questions about Apple, Encryption, and the U.K. blog.cryptographyengineering.com/2025/02/23/t...
blog.cryptographyengineering.com
Three questions about Apple, encryption, and the U.K.
Two weeks ago, the Washington Post reported that the U.K. government had issued a secret order to Apple demanding that the company include a “backdoor” into the company’s end-to-e…
44726
Reposted by Vinoth Deivasigamani
halvarflake.bsky.social @halvarflake.bsky.social · 22/02/2025
I gave a day 1 closing keynote at DistrictCon yesterday. Surprisingly, it was a security talk about memory safety. Slides are here: docs.google.com/presentation...
docs.google.com
Memory Safety
Is this memory safety here in the room with us? Halvar Flake / Thomas Dullien DistrictCon 0 2025
512029
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
Here's an unintentional demonstration of AI being able to find and use exploits. Sakana AI announced an AI agent that optimized kernels and achieved up to 100x speedup. Turned out the agent cheated with a memory exploit it found in the verification code. sakana.ai/ai-cuda-engi...
sakana.ai
Sakana AI
The AI CUDA Engineer: Agentic CUDA Kernel Discovery, Optimization and Composition
000
Reposted by Vinoth Deivasigamani
Matthew Green @matthewdgreen.bsky.social · 14/02/2025
Senator Wyden has proposed a bipartisan bill that would block foreign nations from demanding backdoors in US encryption. www.wyden.senate.gov/news/press-r...
wyden.senate.gov
Wyden Releases Draft Bill to Secure Americans’ Communications Against Foreign Surveillance Demands | U.S. Senator Ron Wyden of Oregon
The Official U.S. Senate website of Senator Ron Wyden of Oregon
44317
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
Holding the keys off-line is great. But for cold wallet with $1.4B, I would've expected the host on which the signing happens to be off-line as well. It appears that might not have been the case here.
000
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
$1.4B stolen from cold wallet at Bybit crypto exchange. Initial report implies hackers manipulated the UI for the signing app/device. Signers were thinking they were signing something benign (based on UI), but the actual message that got signed was diff. announcements.bybit.com/en/article/i...
announcements.bybit.com
100
Vinoth Deivasigamani @vinothd.bsky.social · 22/02/2025
UK laws mandate cookie banners for privacy, but outlaw end to end encryption. apnews.com/article/appl... PS: UK has it's own GDPR called UK GPDR that closely mirrors EU GDPR
apnews.com
Apple drops encryption feature for UK users after government reportedly demanded backdoor access
Apple says it will stop offering an advanced data security option for British users after the government reportedly demanded that the company provide backdoor access for any data those users have stor...
001
Vinoth Deivasigamani @vinothd.bsky.social · 21/02/2025
Such a simple and ingenious method to isolate reasoning from memorization in LLMs. Performance of reasoning models drop significantly evaluated based on multiple choice questions in which the correct answer was replaced with 'None of the others' arxiv.org/abs/2502.12896
arxiv.org
None of the Others: a General Technique to Distinguish Reasoning from Memorization in Multiple-Choice LLM Evaluation Benchmarks
In LLM evaluations, reasoning is often distinguished from recall/memorization by performing numerical variations to math-oriented questions. Here we introduce a general variation method for multiple-c...
032