the grugq's newsletter

Subscribe
Archives
November 18, 2024

November 18, 2024

November 18, 2024

How does the new iOS inactivity reboot work? What does it protect from?

I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.https://t.co/VbdxhueXtL pic.twitter.com/deA5tBplcX

β€” Jiska (@naehrdine) November 17, 2024

Reverse Engineering iOS 18 Inactivity Reboot

Wireless and firmware hacking, PhD life, Technology


NSO – not government clients – operates its spyware, legal documents reveal https://t.co/UFP0ySHOFN

β€” Dr. Dan Lomas (@Sandbagger_01) November 17, 2024


I wanted to do a side-by-side comparison of my procedural animation to hand-authored animations on some models I bought. This is so I can better study what I need to improve.

When I got my comparison tool running for the first time, this is what I was greeted with! πŸ˜… #ProcGen pic.twitter.com/WQfNK3Tqsy

β€” Rune Skovbo Johansen (πŸ¦‹πŸ˜) (@runevision) November 16, 2024


Let's have a look at some pictures I took at today's Washington DC Area retro meetup. I'll make a thread!

First, a Packard Bell Legend 100CD with some nice expansion, and an IBM PS/1. Also, a Compaq Portable 286, an IBM NetVista and Compaq Deskpro! pic.twitter.com/TAzVUFzYNc

β€” RetroTech Chris (@RetroTechChris) November 18, 2024

Thread by @RetroTechChris on Thread Reader App – Thread Reader App

@RetroTechChris: Let's have a look at some pictures I took at today's Washington DC Area retro meetup. I'll make a thread! First, a Packard Bell Legend 100CD with some nice expansion, and an IBM PS/1. Also,...…


It's a sunday and many friends sent me this paper by Maryam Motallebighomi and Aanjhan Ranganathan delving deep into their security assessment of Shimano's Di2 wireless shifting architecture and hardware pic.twitter.com/hAW7HQUfhT

β€” Daniel Cuthbert (@dcuthbert) November 17, 2024

Thread by @dcuthbert on Thread Reader App – Thread Reader App

@dcuthbert: It's a sunday and many friends sent me this paper by Maryam Motallebighomi and Aanjhan Ranganathan delving deep into their security assessment of Shimano's Di2 wireless shifting architecture and hardware...…

And some needed context.

I see your point, but the context is that this work is by a student and submitted to a workshop the prioritises novelty. Not every paper has to be practical and researchers are human. In all likelihood this started as a fun exercise for the SDRs they had in lying around the lab.

β€” Steven Murdoch (@sjmurdoch) November 17, 2024

Don’t get me wrong, I am not disputing this or the idea behind the research. I like it

β€” Daniel Cuthbert (@dcuthbert) November 17, 2024

This is probably the issue with academic research vs practical security. The systems have different incentives and reward structures which are often incompatible.


Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this..

I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working

Apparently this is built into Chrome/Edge!

edge://net-export/ pic.twitter.com/NG4tZlJh9F

β€” Nathan McNulty (@NathanMcNulty) November 17, 2024

You can just run the app yourself if you want :)https://t.co/TC50okWQrq

β€” chris goblins πŸ‘» @crmullins.bsky.social (@CRMullins) November 17, 2024

In short:

Capture on Chrome/Edge with:

View the logs client side in Chrome/Edge via:

https://netlog-viewer.appspot.com/


@maxwsmeets.bsky.social on Bluesky

Just learned from @biella.bsky.social about this new project documenting hacker history. This map is really cool: wherewarlocksstayuplate.com/map/ https://wherewarlocksstayuplate.com/map/


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X