the grugq's newsletter

Subscribe
Archives
May 22, 2022

May 22, 2022

Great observation

Twitter avatar for @justintroutman
Justin Troutman @justintroutman
Teaching cryptography to non-cryptographers has been most enlightening for students, and me, when we approach it from purpose: cryptography isn't useful because of what it does; it's useful because of what it makes possible. It's there to bolster what matters.
4:32 PM ∙ May 21, 2022
37Likes8Retweets

-

Phones are very complex devices.

Twitter avatar for @whitequark
Catherine @whitequark
i'm amused by this journalist discovering that the equipment required to reliably repair a modern cellphone is, in fact, complex, heavy, and expensive
theverge.comApple shipped us a 79-pound iPhone repair kit to fix a 1.1-ounce batteryNobody should do it this way.
3:13 PM ∙ May 21, 2022
1,625Likes198Retweets

-

Offensive deception. Always cool

Twitter avatar for @secvalve
Kate Pearce @secvalve
"Gaslighting With Honeypits And Mirages: Destroying Discovery To Deplete Attackers" [Slides] We made a reproducible vulnerability just for you - and nobody else gets it Oh, and i can get attackers to crack hashes for me.
1:14 AM ∙ Aug 6, 2018
153Likes54Retweets

-

The West should make a Marshall Plan for Ukraine when the war is over. Not just restore the country but improve it.

https://foreignpolicy.com/2022/05/20/ukraine-front-line-economy-loans-resources-russia-war/

-

Get your ACM on…

Twitter avatar for @mikko
@mikko @mikko
As a part of ACM’s 75th anniversary celebrations, ACM is opening up a large portion of its archives, making the first 50 years of its published records—more than 117,500 documents dating from 1951 to 2000—accessible to the public without a login: dl.acm.org
Image
8:17 PM ∙ May 21, 2022
149Likes79Retweets

-

This is definitely a Law (h/t @evacide)

Twitter avatar for @EFF
EFF @EFF
We've learned this lesson before. Maybe we should just call it the Amazon Ring Hypothesis: Absent strict protections, any sensors that collect data and footage about people will eventually become a tool of police surveillance--even self-driving cars. 
vice.comSan Francisco Police Are Using Driverless Cars as Mobile Surveillance Cameras“Autonomous vehicles are recording their surroundings continuously and have the potential to help with investigative leads,” an internal training document states.
8:38 PM ∙ May 21, 2022
414Likes230Retweets

-

Twitter avatar for @a13xp0p0v
Alexander Popov @a13xp0p0v
I believe that detecting kernel vuln post-exploitation and illegal privilege escalation is impossible from inside the Linux kernel.
PoC by @wipawel demonstrates that. My PoC exploit for CVE-2021-26708 bypassing LKRG @lkrg_org also demonstrates that: a13xp0p0v.github.io/2021/08/25/lkr…
Twitter avatar for @wipawel
Pawel Wieczorkiewicz @wipawel
@tgraf__ @Fire30_ @paxteam @yuvalavra @_minipli @_fel1x So, I now have a version of that exploit with a small modification (~10 lines) that bypasses and disabled tetragon checks entirely. ¯\_(ツ)_/¯ https://t.co/yPQWCWdZ35
8:51 PM ∙ May 21, 2022
140Likes60Retweets

-

OPSEC!

Twitter avatar for @michaelh992
Michael A. Horowitz @michaelh992
A story in two parts: First part a #Russian reported excitedly reports on the Russian army shelling Ukrainian position using a 2S4 Tyulpan self-propelled mortar, revealing its position
Image
Image
4:28 PM ∙ May 21, 2022
10,007Likes1,908Retweets

-

Job security for life.

Twitter avatar for @grepory
Greg Poirier @grepory
I'm kind of excited about this next paper: On The Relation Between Outdated Docker Containers, Severity Vulnerabilities and Bugs arxiv.org/pdf/1811.12874…
1:53 PM ∙ May 21, 2022
131Likes38Retweets

-

Good coverage of how Ukraine is conducting a sort of total war. They have a lockdown on casualty information. The army has their tank recovery capacity augmented by farmers with tractors. The Russian military is constantly under surveillance by civilians who report everything to the intelligence services. The Ukrainian app for most government functions allows uploading photos and videos. (As I understand anyway)

The problem is that when civilians do military jobs during war they are exposed to new risks such as being unlawful combatants, or spies. Given the dynamics of the conflict it is probably not a huge change, the Russians don’t seem to be adhering to the laws of war anyway. Still. Something to keep in mind

https://warontherocks.com/2022/05/intelligence-and-the-war-in-ukraine-part-2/

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X