HN user

dguido

2,454 karma

https://www.trailofbits.com https://www.linkedin.com/in/danguido/

Posts46
Comments479
View on HN
whosecurve.com 6y ago

Whose Curve Is It Anyway?

dguido
11pts0
www.vice.com 6y ago

This App Will Tell You If Your iPhone Gets Hacked

dguido
8pts0
blog.trailofbits.com 6y ago

Tethered Jailbreaks Are Back

dguido
143pts117
blog.trailofbits.com 7y ago

Getting 2FA Right in 2019

dguido
260pts217
blog.trailofbits.com 7y ago

A Guide to Post-Quantum Cryptography

dguido
8pts0
blog.trailofbits.com 7y ago

How smart contract upgrades fail in practice

dguido
59pts15
blog.trailofbits.com 9y ago

Manticore: Symbolic execution for humans

dguido
5pts0
medium.com 9y ago

How Alexsey Belan hacked into more than a dozen tech companies

dguido
1pts0
www.rand.org 9y ago

RAND Study Examines 200 Real-World 'Zero-Day' Software Vulnerabilities

dguido
6pts1
github.com 9y ago

Doorman: an osquery fleet manager

dguido
9pts1
blog.trailofbits.com 9y ago

Look out endpoint vendors, you've got competition in your mirror (osquery/Win32)

dguido
8pts0
fortune.com 10y ago

First startup powered by osquery gets funded

dguido
1pts0
blog.trailofbits.com 10y ago

Tidas: a new service for building password-less apps

dguido
4pts0
medium.com 11y ago

Why startup rules don’t apply to Security Products

dguido
4pts1
www.darpa.mil 11y ago

7 Teams Hack Their Way to the Darpa CGC Final Competition

dguido
2pts0
www.theverge.com 11y ago

DARPA's million-dollar search for software that can defend itself

dguido
2pts1
blog.trailofbits.com 11y ago

Closing the Windows Gap – Practice Windows Exploitation with a new CTF Framework

dguido
3pts0
www.nextgov.com 11y ago

The Smartest Hackers in the Room (Hint: They're Not the Humans)

dguido
1pts0
blog.trailofbits.com 11y ago

Announcing the Speaker Lineup for THREADS 2014: Scaling Security

dguido
1pts0
www.javelinsecurity.com 12y ago

Show HN: We launched Javelin, the product I've been working on

dguido
11pts1
www.builditbreakit.org 12y ago

UMD is hosting a secure-programming contest in January [Build It / Break It]

dguido
1pts0
github.com 12y ago

Encrypted Backups to S3 for GitHub Enterprise

dguido
1pts1
www.poly.edu 12y ago

10,000 people are playing CTF this weekend. Do you want to join them?

dguido
1pts1
www.wired.com 12y ago

Why Everyone Is Pissed Off About Google Chrome’s Sound Security

dguido
9pts0
blog.trailofbits.com 13y ago

iPhone users now have an easy way to ensure their phones are free of malware

dguido
2pts0
www.schneier.com 13y ago

The ODNI Defends NSA Surveillance Programs - Schneier on Security

dguido
3pts0
in.reuters.com 13y ago

India sets up elaborate system to tap phone calls, e-mail. No oversight.

dguido
3pts0
www.pbs.org 13y ago

PBS: What Should Be Up for Public Debate When It Comes to Secret Surveillance?

dguido
1pts0
blog.leafsr.com 13y ago

Comparing ASM.js and NaCl

dguido
3pts0
blog.trailofbits.com 13y ago

Don't get added to the YAML botnet, come to a Ruby Security workshop in NYC!

dguido
3pts0

I use Cape every day on my iPhone. The service is excellent, and the security features haven't ever interfered with my use of the phone. They have a convenient mobile app for setting up extra features like the IMSI rotation and getting support. As a tech savvy user, it matches what I want.

I'm a target for a variety of things, and knowing that no one can SIM swap me is worth the subscription alone. The SS7 protections, encrypted voicemail, secondary numbers, IMSI rotation, etc are all a bonus.

I have a conflict of interest here (I am an advisor to Cape, also a security expert, and my company has done security audits for Cape), you should absolutely look more deeply into what Cape has created. Their service is fundamentally different than other "security-focused cell providers" (mostly snake oil IMHO) because Cape wrote their own mobile core, nearly from scratch. They control the whole software stack and have done really innovative things with it.

Here are a few things you might want to look at more closely:

Encrypted voicemail uses public key crypto: https://www.cape.co/blog/product-feature-encrypted-voicemail

How they use full control of the mobile core to detect SS7 signaling attacks https://www.cape.co/blog/product-feature-network-lock

Swapping SIMs is done via digital signatures, not customer support https://www.cape.co/blog/cape-product-feature-secure-authent...

They're the only provider that can rotate your IMSI, and do it continuously for you https://www.cape.co/blog/product-feature-identifier-rotation

They're also one of very few organizations doing original research on cell network security:

Collaborating with the EFF to release software for detecting cell site simulators (e.g, imsi catchers et al) https://www.cape.co/blog/how-eff-and-cape-collaborated-to-im...

Identifying novel weaknesses for physically tracking people on cell networks https://dl.acm.org/doi/pdf/10.1145/3636534.3690709

We're a bit non-committal about who this affects in the blog, but phew man, there are a lot of agent systems that will fall victim to this general class of attack.

Hi! I'm the author of this PR and the maintainer for Algo. Claude Code has been a tremendous help dealing with a project of this scope and size. This PR to eliminate storing lots of sensitive data on the host was an interest of mine for a while, but Claude Code let me finally make progress on it. I tried to strike a balance between security and privacy (you need logs to investigate issues!). Let me know what you think. Thanks!

Hi all, CEO of Trail of Bits here. PajaMAS includes all our guidance for building multi-agent systems securely, including core design principles, a multi-agent security checklist, and framework selection criteria. Hope it helps!

In case anyone is looking for them, here are the exploits for these EOL devices. I avoided allowing Trail of Bits to release exploits for 13 years, but I decided it was finally time for a policy change. We'll be dropping a lot more as time goes on now.

Here's the exploit for the Netgear WGR614v9: https://github.com/trailofbits/exploits/tree/main/junkyard-2...

Here's the exploit for the BitDefender Box 1: https://github.com/trailofbits/exploits/tree/main/junkyard-2...

There's a lot of included detail so you can learn how to write your own and really understand every decision we made in writing them.

Please stop putting salespeople in charge of highly technical product companies like Sonos. I'm so glad that Tom Conrad is an engineer by training. I hope he can turn this mess around.

The key technical change that broke Sonos was abandoning their reliable UPnP (Universal Plug and Play) system for device discovery in favor of mDNS, while also shifting from direct device communication to a cloud-based API approach. This new architecture made all network traffic encrypted and routed through Sonos cloud servers (even for local operations), adding significant overhead and latency, especially for older Sonos devices with limited processing power. They also switched from native platform-specific UX frameworks to a JavaScript-based interface while moving music service interactions through their cloud instead of direct SMAPI calls, resulting in slower performance and reduced functionality.

For a more extended discussion, see this excellent LinkedIn post from Andy Pennell, a principal engineer at Microsoft with a deep technical understanding of Sonos systems. He created one of the most successful third-party Sonos apps for Windows Phone and worked directly with Sonos on their official Windows Phone 8 app.

https://www.linkedin.com/pulse/what-happened-sonos-app-techn...

As the editor of this blog, I can assure you that AI did not craft the introduction. As a general rule, we include all the most relevant details in the above-the-fold section, allowing readers to quickly determine if the content warrants their time. This is consistent across all our blog posts.

Strong recommend on using meow.com. You can get interest on your primary checking account, and easy access to high yield treasury management services.

I’ve been following the Evolve Bank fallout on the FinTech Weekly newsletter, and the whole situation scares me about Mercury. I used to bank with them, but the sanctions by the Federal Reserve and the continued disclosures about lacking KYC and money laundering controls has me worried there are other problems.

I appreciate how organized the Consensys guide is laid out. It's pretty easy to read. Trail of Bits has a similar guide that is a little more in-the-weeds technically. It also covers, what we think is, essential background about certain automated analysis techniques like static analysis and how fuzzers work. Check it out!

https://secure-contracts.com/

Trail of Bits does this kind of work (https://www.trailofbits.com)!

Tbh there is a much larger market for application of existing technology (e.g., pentests) than development of new technology (e.g., DARPA programs and the 1% of tech firms that need something new). There are a handful of others, but the market doesn't support dozens of other firms like Trail of Bits. There is some innovation that happens in Series A and B security startups but IMHO that quickly gives way to pressures of building an enterprise sales team.

We're using most of the exact same file-based indicators as MVT. It's really refreshing that Amnesty shared so much of what they found -- it made our own process of testing our checks against their discoveries much easier.

Trail of Bits here -- while this is mostly correct, there are also parts of the runtime that dead file forensics won't be able to identify. There's no harm in doing both and, in fact, we'd recommend it if you're concerned.

Ugh, I have been advocating "Solidity--" for years and can't get funding to build it (Trail of Bits).

We use two tools to offer quick turnaround automated testing and verification for Solidity: Echidna (like QuickCheck for Solidity) and Manticore (a symbolic verifier). They each let you write high level properties in the span of 1-2 weeks that cover a large amount of potential use cases.

Here's an example of what that looks like: https://github.com/trailofbits/publications/blob/master/revi...

Here's Echidna: https://github.com/crytic/echidna

and Manticore: https://github.com/trailofbits/manticore

Sometimes we also use custom static analyses built around Slither's IR during projects too: https://github.com/crytic/slither/wiki/SlithIR

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it:

Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees."

https://www.npr.org/2019/11/06/777098293/2-former-twitter-em...

1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." It's news because they misled people about their security, again.

Firefox Send, SendSafely, and Magic Wormhole are all end-to-end encrypted.

https://send.firefox.com/

https://www.sendsafely.com/

https://github.com/warner/magic-wormhole

https://webwormhole.io/ (magic wormhole over WebRTC!)

This seems like table-stakes for a modern file transfer system. Accepting unencrypted files and storing them temporarily in the clear on your own servers seems like it only introduces tons of additional risks without much gain.

The main reason is political: It would let senators stay in their home districts and campaign for their entire time in office, making it easier to neglect their duties to write and pass legislation. Politicians may be more motivated to work together on issues affecting the country in DC together. Staying in their home district could be a distraction because of the competing interests of being re-elected.

In general, I think these remote voting proposals should include a time limitation. That there is some "trigger" when they take effect, and they need re-authorization every 30 days until the incident is over.

Fuckkkkk I think I found the source of my confusion. I am wrong, you are right.

I DID find documents about Moloch floating around my Google Drive from ~2013-ish. I believe I invited your co-author Eion to present at a conference I was running, THREADS, in 2014 and that he was not able to make it. The focus the _year prior_ was exclusively on DARPA CFT. I combined those two events in my head and thought your project got some seed funding from DARPA too. I'm sorry!

Here is the conference:

THREADS 2014 when you were invited: https://github.com/trailofbits/threads/tree/master/2014

THREADS 2013 was a retrospective on DARPA CFT: https://github.com/trailofbits/threads/tree/master/2013