the grugq's newsletter

Subscribe
Archives
November 27, 2023

November 27, 2023

November 27, 2023

This is an incredibly awesome development.

In the latest release of GrapheneOS, you can now enable hardware memory tagging for all user installed apps on the Pixel 8 and Pixel 8 Pro to make them substantially harder to exploit. This is particularly useful for apps like Signal and WhatsApp.https://t.co/AEExOIk381

β€” GrapheneOS (@GrapheneOS) November 26, 2023


Napoleon at Waterloo. pic.twitter.com/SZ5FstXsDr

β€” Simon Leeson (@SimonLeeson1) November 25, 2023

Some old tech for #StandingStoneSunday - Axe-polishing grooves on one of the entrance Sarsen stones at West Kennet #Neolithic chambered long barrow, #Avebury, Wiltshire

πŸ“· My own, September 2023 pic.twitter.com/Syfc6gExD0

β€” Dr Toby Driver (@Toby_Driver1) November 26, 2023

If the Olympian Gods ever sent each other Christmas cards... https://t.co/b1DzAqWnrL

β€” Classical Studies Memes for Hellenistic Teens (@CSMFHT) November 26, 2023

Welcome to Norfolk. pic.twitter.com/do9Z1whZeV

β€” No Context Brits (@NoContextBrits) November 25, 2023


Today Security researchers Samuel Barnes-Thornton, @TheCyberJoe, and Awais Rashid disclosed a vulnerability in cow tracking collars. They were able to both read and inject animal captivity activity data

They're hackin' the cows 😭😭😭

More info: https://t.co/0wmymRz1QN pic.twitter.com/jI29mnGTkZ

β€” vx-underground (@vxunderground) November 27, 2023


Still laughing about the time a computer scientist who had his bike stolen tried to explain binary search to a cop pic.twitter.com/wqYmlZQmSN

β€” Alec Stapp (@AlecStapp) November 27, 2023


This week on the blog! A look at the rather unusual Roman heavy javelin, the pilum, and its place in Rome's rather unusual infantry tactical system!https://t.co/sl8HotvJ5l

β€” Bret Devereaux (@BretDevereaux) November 27, 2023


Do you think a red teamer / Pentester should go out of scope?

β€” mRr3b00t (@UK_Daniel_Card) November 25, 2023

There are things on the floor that will crash or corrupt from a port scan, if you’re in the right privileged source range. They start calculating losses every 60 seconds. Do NOT fucking go out of scope. https://t.co/VxIXc1PfZv

β€” SwiftOnSecurity (@SwiftOnSecurity) November 26, 2023

As someone who has infamously gone out of scope and accidentally robbed the wrong bank and barely avoided prison time in a foreign country!

NEVER SCREW UP SO BAD THAT YOU GO OUT OF SCOPE!!! ☠️ https://t.co/vGC4mWUKVF

β€” Jayson E. Street πŸ’™ πŸ€—πŸ’› Hacker - Helper - Human (@jaysonstreet) November 27, 2023


Most people today think that the ancient Greeks thought that Persephone was in the underworld during the winter, but the ancient Greek agricultural and religious calendars suggest it was actually the summer.#myths #classics #GreekMythology #Persephonehttps://t.co/O5kyJb7V2P

β€” Spencer McDaniel (@SpenceMcDaniel) November 26, 2023

Yup! Both Greece and Rome are growing 'winter wheat.' I laid out a primer on ancient agriculture back on my blog a while back (https://t.co/lMfzPC5hnp). Fascinating how our distance from agriculture makes it harder to parse the writings of societies that were so agricultural.

β€” Bret Devereaux (@BretDevereaux) November 27, 2023


Main Directorate of Intelligence of Ukrainian MoD obtained documents from Russia's civil aviation agency "as a result of a successful complex special operation in cyberspace"

It's quite rare that a state openly takes credit for an offensive cyber actionhttps://t.co/55tZCrYpbG

β€” Oleg Shakirov (@shakirov2036) November 26, 2023

Yet another potentially big cyber story from Russia

Rosaviatsiya (Federal Air Transport Agency) reportedly got its e-document management system hacked over a weekend losing many files and had to switch to paper-based workflow

Best report so far https://t.co/1HJFLUQ7M9

β€” Oleg Shakirov (@shakirov2036) March 29, 2022

Almost forgot: an uncofirmed and questionable claim that some kind of a virus that transmits information to the United States was delivered on a flash drive to the Russian civial aviation agencyhttps://t.co/lwSWKq7nFm

β€” Oleg Shakirov (@shakirov2036) June 20, 2023


Who says amateur radio is dead? https://t.co/IfAKNMc52K

β€” Accidental CISO (@AccidentalCISO) November 26, 2023

The moment a criminal gang stole the Β£350,000 car in Aveley Essex

(πŸŽ₯East News) pic.twitter.com/zbrvvVkv5n

β€” London & UK Street News (@CrimeLdn) November 26, 2023


This is a 3,200 year old attendance sheet from Ancient Egypt. The limestone ostracon covers 280 days of the year with a list of 40 different names and dates written in black. The notes in red are the reasons for being absent, which include the following:

1. Drinking with Khonsu… pic.twitter.com/MAHHwzzr9b

β€” Historic Vids (@historyinmemes) November 26, 2023


AWS unveils the Amazon WorkSpaces Thin Client, a $195 compact computer resembling a Fire TV Cube that's meant for workers to access cloud-based virtual desktops (Maria Deutscher / SiliconANGLE)https://t.co/JyKM4m5oe6https://t.co/EvFAST9LL6

β€” Techmeme (@Techmeme) November 27, 2023

What's old is new again https://t.co/bbE84O6qm5 pic.twitter.com/taLXu1ShUS

β€” Matt Linton (@0xMatt) November 27, 2023

The network^W cloud is the computer

β€” thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) November 27, 2023


New @ASPI_org work out today - Singing from the CCP’s songsheet: The role of foreign influencers in China’s propaganda system by @fryan @DariImpio & Matt Knight.

The @FT has done a fantastic long piece with their own reporting by @JKynge πŸ‘‡https://t.co/v6uB1OsUcj

β€” Danielle Cave (@DaniellesCave) November 24, 2023


Working in InfoSec watching the rest of IT pic.twitter.com/Kwj8klpqIU

β€” SwiftOnSecurity (@SwiftOnSecurity) September 19, 2023


It seems that every few months, some people discover my SSRF talk from 2015 and learn from it.

So I'll post the links again πŸ˜‡

- slides https://t.co/rpVZzyN17W

- English-speaking video https://t.co/YOWA1uqvwX

- French-speaking video https://t.co/lzbzCbJ2TQ

β€” Nicolas GrΓ©goire (@Agarri_FR) November 27, 2023


Yesterday's interference got repeated in today's pass over Sevastopol.

Sentinel-1 AWS-IW-VVVH
2023-11-24
15:37:02 UTC https://t.co/SI00WU4wId pic.twitter.com/DUCFSE9lpp

β€” Scil (@scil_int) November 24, 2023



bruhhhhhhhhhh

"Google has potentially lost Google Drive user data."https://t.co/3BNhwFUSzP

β€” Killed by Google (@killedbygoogle) November 27, 2023

Bing is badass pic.twitter.com/EIm7Sx6MKS

β€” vx-underground (@vxunderground) November 27, 2023


In many ways the best christmas present for your spouse is getting something for yourself. Seeing you happy is the greatest gift they can receive

β€” Mr. Midwest (@InternetHippo) November 26, 2023


My timeline now: pic.twitter.com/TDXcFXzLLN

β€” Dr. Dan Lomas (@Sandbagger_01) November 26, 2023


Remember when very smart people predicted that just in terms of hardware and electricity-related costs it would eventually be cheaper to use a given amount of compute in the cloud than it would be locally because big providers could buy both so efficiently?

Good times. :)

β€” Brian in Pittsburgh (@arekfurt) November 27, 2023

It turns out that even more than buying hardware and electricity efficiently big tech companies love using those savings to create & maintain remarkably high profit margins. And competition among them has not done as much as expected.

β€” Brian in Pittsburgh (@arekfurt) November 27, 2023

Today, the cost savings promotional calculus for cloud becomes "Well, if you also include A, B, C, D, E, and F costs and presume on-prem hardware needs to be replaced every six months and...."etc. etc..

β€” Brian in Pittsburgh (@arekfurt) November 27, 2023


The Foundation for Information Policy Research has been engaged in the crypto wars, and in policy tussles from medical privacy to AI regulation, for 25 years now. Celebration on November 30! Time to ask: what's changed and what's next?https://t.co/Qt6AEA95pc

β€” Ross Anderson (@rossjanderson) November 23, 2023

Yes, one hour before the meeting starts at 4pm GMT, Nov 30,we will put a streaming URL on the web page: https://t.co/Qt6AEA9DeK https://t.co/XIT3V2F5cj

β€” Ross Anderson (@rossjanderson) November 27, 2023


Succinct, edifying article on the topic of Tagged Pointers and their various uses in the real world:https://t.co/O6mzZTNosz

β€” Mark E. Dawson, Jr. (@medawsonjr) November 26, 2023


The new Australian πŸ‡¦πŸ‡Ί cyber security strategy was launched last week. πŸ‘‡

It's a strong set of measures: congratulations to everyone involved.
Honoured to play a small part in it as chair of the international advisory committee.https://t.co/VXUQHPGTAQ

β€” Ciaran Martin (@ciaranmartinoxf) November 27, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X