Deleted tweet detection is currently running at reduced capacity due to changes to the Twitter API. Some tweets that have been deleted by the tweet author may not be labeled as deleted in the PolitiTweet interface.

Showing page 43 of 151.

Profile Image

Joanna Rutkowska @rootkovska

RT @matthew_d_green: You can log into a Mac as root/(null)? How does a bug like that even happen? — PolitiTweet.org

Posted Nov. 29, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @wdormann: The Apple High Sierra root issue is bad. If you have exposed "Screen Sharing", you can allow people into your machine with f… — PolitiTweet.org

Posted Nov. 29, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @NielsProvos: Apple MacOS High Sierra Security Flaw Lets Anyone Get Root Access, No Password Required https://t.co/vcrMGQEHW1 — PolitiTweet.org

Posted Nov. 29, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @halvarflake: TIL the term "paperware", as in "vaporware that was only written for an academic paper and fails to generalize outside of… — PolitiTweet.org

Posted Nov. 28, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

Yes, but SCONE seems to be 1) paperware(?), and 2) I don't like its proxing architecture. The authors seems to be c… https://t.co/tIogRf9Cyo — PolitiTweet.org

Vicente Sanchez L @vsanchezl

@rootkovska I guess you already know SCONE ... https://t.co/ZFew4Rwzma https://t.co/8ObETv3NXl

Posted Nov. 28, 2017
Profile Image

Joanna Rutkowska @rootkovska

@alt_kia So, this sounds like a smart solution, which, after more thought, is not so. Consider e.g. the victim went for a walk to the park. — PolitiTweet.org

Posted Nov. 28, 2017
Profile Image

Joanna Rutkowska @rootkovska

A well known attack via proxying of the token. Applies as well to computer tokens. There are only(?) two solutions… https://t.co/v6BnvCHO6A — PolitiTweet.org

ITV News @itvnews

Thieves are now picking up signals from car keys sitting inside people's homes to make off with their vehicles… https://t.co/OAGvpky6di

Posted Nov. 28, 2017
Profile Image

Joanna Rutkowska @rootkovska

A well known attack via proxying of the token. Applies as well to computer tokens. There are only(?) two solutions AFAIK: 1. Fit a button on the token (e.g. Yubikey), 2. Introduce _latency_ limitation for the challenge-response (I heard car manufactures actually use this, no?) https://t.co/tIiSydPLD — PolitiTweet.org

Dan Kaminsky @dakami

Nobody could have possibly seen this coming https://t.co/XJuuY0JTe0

Posted Nov. 28, 2017 Deleted
Profile Image

Joanna Rutkowska @rootkovska

Anyone can recommend a project similar to Graphene-SGX [1] only... with better code quality? So, a libOS-like arch… https://t.co/5IB0LBSRzD — PolitiTweet.org

Posted Nov. 27, 2017
Profile Image

Joanna Rutkowska @rootkovska

RT @QubesOS: Qubes OS 4.0-rc3 has been released! https://t.co/gBynBb2frd — PolitiTweet.org

Posted Nov. 27, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

This! (PED = Pin Entry Device). https://t.co/R9Wvot4OJS — PolitiTweet.org

Ryan Hurst @rmhrisk

@NdK_BO @rootkovska Usability of PEDs and trusted displays have been a total fail. In the real world you end up sig… https://t.co/oSrXT1TFgg

Posted Nov. 27, 2017
Profile Image

Joanna Rutkowska @rootkovska

@whvholst Please stop! :) — PolitiTweet.org

Posted Nov. 26, 2017
Profile Image

Joanna Rutkowska @rootkovska

@whvholst So what? Have the user send the same amount, just to a different account. In a more sophisticated scenari… https://t.co/16LJ59bCTX — PolitiTweet.org

Posted Nov. 26, 2017
Profile Image

Joanna Rutkowska @rootkovska

Valid question. The difference is in the cost of the attack and, even more so, in the PR damage, if they shipped ba… https://t.co/2pyfL5uLod — PolitiTweet.org

Mr. B @4d722e42

@rootkovska @Dell Why worry about the update? How did you verify what it shipped with?

Posted Nov. 26, 2017
Profile Image

Joanna Rutkowska @rootkovska

This is a classic misunderstanding: if the app/software stack is compromised, the hardware token usually helps litt… https://t.co/zvY6xiHuwG — PolitiTweet.org

Franklin Richards was here @io_r_us

@mruef @rootkovska In Europe most banks use a digital token with pin code. This not only adds a signature but also… https://t.co/1VZy5nDWYK

Posted Nov. 26, 2017
Profile Image

Joanna Rutkowska @rootkovska

RT @mruef: German infosec researcher find severe issues in 31 banking apps. They withhold *ALL* the infos until the end of year to announce… — PolitiTweet.org

Posted Nov. 26, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

@letoams I'm afraid somebody else would have to do this... Too busy living my life ;) — PolitiTweet.org

Posted Nov. 26, 2017
Profile Image

Joanna Rutkowska @rootkovska

Some high-level info about Dell BIOS updates in the paper (2013) linked below. Smbdy can please start gathering all… https://t.co/wkpLz2ced4 — PolitiTweet.org

Rick Martinez @rickmartinez06

@kmoragas @Dell @rootkovska Always willing to have the conversation about how our BIOS updates are authenticated an… https://t.co/RwvPjWg8PN

Posted Nov. 25, 2017
Profile Image

Joanna Rutkowska @rootkovska

Thanks! (And they say @QubesOS ISO download & verification is not very user friendly... ;) https://t.co/lO1GhCtjWK — PolitiTweet.org

Rick Martinez @rickmartinez06

@rootkovska @Dell As a user what I would do today is pull .cab here: ftp://ftp.dell.com/catalog/DellSDPCatalogPC.ca… https://t.co/MgQZHUNr2l

Posted Nov. 25, 2017
Profile Image

Joanna Rutkowska @rootkovska

@luizrmgarcia But I am a regular user! ;) — PolitiTweet.org

Posted Nov. 24, 2017
Profile Image

Joanna Rutkowska @rootkovska

I have specifically asked about authenticity & integrity, not about trustworthiness/harmfulness. Please re-read my… https://t.co/YC4N3KTZwI — PolitiTweet.org

Dell @Dell

@rootkovska Hi Joanna, Our engineering team performs multiple levels of stringent tests on any driver/BIOS update… https://t.co/qNX0EOjwY4

Posted Nov. 24, 2017
Profile Image

Joanna Rutkowska @rootkovska

Dear @Dell, how can I verify authenticity & integrity of the BIOS updates for your XPS laptops you publish on your… https://t.co/o97kAfUAJt — PolitiTweet.org

Posted Nov. 24, 2017
Profile Image

Joanna Rutkowska @rootkovska

RT @unixterminal: I am seeking feedback on my Awesome UNIX list on @github: https://t.co/Dq4Sci2Ogg. Please open issues/PRs there. @nixcraf… — PolitiTweet.org

Posted Nov. 24, 2017 Retweet Deleted
Profile Image

Joanna Rutkowska @rootkovska

RT @Lesism: Can you find the circles in this image? Thy are actually VERY obvious, but you're not going to see them so clearly until you'v… — PolitiTweet.org

Posted Nov. 24, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @petertoddbtc: @rootkovska Remind me never to waste time writing an exploit and just focus on making software that's secure by design... — PolitiTweet.org

Posted Nov. 23, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @k8em0: Paying a ransom isn't illegal, not should it be. Evading breach notification laws is illegal because the laws were made to stop… — PolitiTweet.org

Posted Nov. 23, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

#infosec :/ https://t.co/PC1SbcMR5V — PolitiTweet.org

grsecurity @grsecurity

So on the day of Kees' presentation, where he tried to drop a useless 0day on me and talk up how many upstream deve… https://t.co/YtyaJBuz7Y

Posted Nov. 23, 2017
Profile Image

Joanna Rutkowska @rootkovska

"[The hackers] demanded $100,000 to delete their copy of the data." "Uber [paid the ransom]. [Then] pushed them t… https://t.co/yCpuTCwTkS — PolitiTweet.org

The New York Times @nytimes

Uber said a hack last year affecting 57 million accounts was concealed, and the firm fired its top security executi… https://t.co/23FuzSpd6N

Posted Nov. 22, 2017
Profile Image

Joanna Rutkowska @rootkovska

RT @biggzi: Top 100 #Cryptocurrencies described in 4 words or less! Very handy for anyone new to #Crypto #Bitcoin & #Blockchain https://t.c… — PolitiTweet.org

Posted Nov. 22, 2017 Retweet
Profile Image

Joanna Rutkowska @rootkovska

RT @parityzero: @tehjh Intel advisory generator: "Multiple unspecified issues in unspecified component in unspecified platform of unspecifi… — PolitiTweet.org

Posted Nov. 21, 2017 Retweet