Dino A. Dai Zovi

@ddz.bsky.social

I drink amari and I know things. $ddz LMDDGTFY: https://duckduckgo.com/?q=dino+dai+zovi NYC/BK

New users, on Signal, you can mute chats for a period or permanently. No notifications but you can still see if there are unread messages. On desktop: in that chat, go to Group Settings, then Notifications. On iPhone: in that chat, click on the name at the top, then go to Sounds & Notifications.

Saw this on the other site but I should comment here: Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991. You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns

Bild

I have never once run a phishing sim. I refuse to use the word. I put it in air quotes and say scam by text or email etc Tech and cyber has been about deflecting blame to anyone else but themselves- which is what sims are. Blaming people when the system they use should protect against issues.

NEW: WhatsApp says it has notified 90 victims, including journalists and members of civil society, that they were targeted with spyware made by Paragon. This is the first time that Paragon is linked to alleged abuse of its products. techcrunch.com/2025/01/31/w...

WhatsApp says it disrupted a hacking campaign targeting journalists with spyware | TechCrunch

The Meta-owned company said the campaign was linked to Israeli spyware maker Paragon.

techcrunch.com

Meta says almost 100 journalists and activists were targeted with spyware from Israeli company Paragon Solutions using a zero-click vuln in WhatsApp. If you use an iPhone, enabling Lockdown Mode prevents this from working. www.theguardian.com/technology/2...

WhatsApp says journalists and civil society members were targets of Israeli spyware

Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware

theguardian.com

I'm really liking the crisp definitions of and boundaries between product engineering, domain engineering, and infra engineering in this. How much of your security org builds "what any company would need" (infra) vs. "what is unique to this company but shared across the company" (domain) ?

Jack Danger@jackdanger.com · 2y ago

I've extracted the thesis of my new book into a short blog post (with images!). If you've ever seen an engineering team slow down over time this is for you: jackdanger.com/technical-co...

The placement of liability for fraudulent credit card charges onto the issuer incentivized the shift to EMV, so we now have smartcards in our wallets and secure elements on our smartphones. Contrast this to the security of authn to way more critical things than buying a coffee.

Ever wanted to benchmark RSA key generation but found it too slow and variable, like benchmarking a lottery? No? Just me? Well, I nerd-sniped myself into producing average representative inputs that can be used to benchmark, profile, and compare RSA keygen. c2sp.org/CCTV/keygen Happy New Year(?)!

Benchmarking RSA Key Generation

RSA key generation is conceptually simple, but extremely tricky. Even benchmarking involves math: we generated a stable but representative “average case” instead of using the ordinary statistical appr...

words.filippo.io

This Salt Typhoon stuff is insane. The entire FISA surveillance infrastructure has been completely owned by China and literally no part of our telecom infrastructure is safe to use without end-to-end encryption.

The subtle benefit of *minimal* version selection as a systemic damper on software supply chain attacks: "What’s more, the deeper in your dependency tree the library is, the more explicit approvals are required for the library to propagate to your project." matklad.github.io/2024/12/24/m...

Minimal Version Selection Revisited

In this post, I want to highlight one aspect of Go-style minimal version selection that I have missed completely at first. Maybe you missed it too?

matklad.github.io

The transition from static long-term "credentials" (PAN + CVV) to EMV cryptograms generated by smartcards and the continuing transition for online payments are good case studies for how to devalue data to the point of making attacks on processing infra no longer worthwhile. Human authn must be next.

Post nicht verfügbar.

An excellent episode on a topic on which I've given some thoughts in my book with similar conclusions: 1️⃣Targeting TikTok in the name of "national security" avoids addressing the structural problems of unregulated personal data and content moderation.

Knight First Amendment Institute@knightcolumbia.org · 2y ago

Tune in to "Speech & the Border E5: The Free Speech Costs of Banning TikTok" with @ramyakrishnan.bsky.social (@knightcolumbia.org), @anupamchander.bsky.social (Georgetown Law), and @meredithmeredith.bsky.social (@signal.org), for a deep dive on the #TikTok ban. podcasts.apple.com/us/podcast/s...

A bias can form if folks' primary exposure to Signal (or really any other tool) is through observing malicious uses. I've seen it happen with cryptocurrencies as well. A useful tool will often find itself useful for both beneficial and malicious use-cases. It's as old as discovering fire.

Meredith Whittaker @meredithmeredith.bsky.social · 2y ago

This is disingenuous marketing. Signal chats can't be 'monitored' by anyone not in those chats. Dressing up "joining groups via publicly posted links, then exfiltrating group data" as an offensive 'cybercapability' borders on misinfo, and confuses/scares ppl who rely on Signal for robust privacy.