btw me and my friend are still looking for CCC tickets, if you happen to be willing to sell them please message me!! .-. #39c3
jduck
@jduck.me
Continuously learning about computer security through research and development.
It's official. No hacker summer for me due to family health complications. I will miss everyone but hope you have a great (and safe) time!! ❤️
I'm proud to announce that myself and @AtipriyaBajaj have created the Workshop on Software Understanding and Reverse Engineering (SURE), which will be co-located at CCS 2025. sure-workshop.org/ Please follow our workshop account @sureworkshop and RT it for visibility :).
SURE 2025 | The Workshop on Software Understanding and Reverse Engineering
The Workshop on Software Understanding and Reverse Engineering
sure-workshop.org
We're proud to announce the release of Binary Ninja 5.0. Here's some highlights: Union Support, Dyld Share Cache & Kernel Cache, Firmware Ninja, Auto Stack Arrays, Stack Structure Type Propagation, and so much more. Check out the blog post for more information: binary.ninja/2025/04/23/5...
Does using #rustlang really make your software safer? tweedegolf.nl/en/blog/152/...
Does using Rust really make your software safer? - Blog - Tweede golf
We keep saying that Rust is how we make software safer. In this blog, we'll tackle a real-world vulnerability, 'rewrite it in Rust', and show you the results of our empirical research, both as a h ...
tweedegolf.nl
I'm proud to announce that I, through my company @magnetitesec.bsky.social, donated to the Redox OS project! If you're not familiar, Redox OS is a pure Rust Micro kernel based operating system. This donation allows them to sponsor one additional student for their Summer of Code!
I played @defcon.bsky.social CTF quals with @shellphish.bsky.social this year! I'm really impressed with the difficulty levels Nautilus Institute put forth. Making CTF challenges in the AI era has... special considerations... but they nailed it :-) Thanks to everyone involved for a great weekend!
There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jérémy Jourdois explains it here: blog.quarkslab.com/aosp_ota_sig...
A small bug in the signature verification of AOSP OTA packages
A signature verification bypass in a function that verifies the integrity of ZIP archives in the AOSP framework
blog.quarkslab.com
"Building a Linux Kernel Driver using Rust": rust-exercises.ferrous-systems.com/latest/book/...
Building a Linux Kernel Driver using Rust - Rust Exercises
rust-exercises.ferrous-systems.com
Our Call for Presentations & Events is now open! Got cool research, a fresh exploit, or a unique cybersec insight? Submit your talk & be part of Australia’s biggest hacker con! cfp.bsidescbr.com.au/bsides-canbe...
BSides Canberra 2025
Schedule, talks and talk submissions for BSides Canberra 2025
cfp.bsidescbr.com.au
github.com/ariel-os/ari... /via @mattkeeter.com #rustlang
GitHub - ariel-os/ariel-os: Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust
Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust - ariel-os/ariel-os
github.com
Don't forget, the CFP for the 40th anniversary issue of Phrack is open until June 15th 2025. You can be someone's favorite article in the future!! bsky.app/profile/phra...
We heard you needed some more time, so we wanted to let you cook. We decided to push the Phrack 72 CFP deadline back until June 15th. Stay tuned for upcoming Phrack events. Print this flyer out and give it to someone IRL!!
Having some fun with EM measurements today - side-channels are awesome!
Paged Out! #6 has arrived! And it's jam-packed with content! You can download it here: pagedout.institute?page=issues....
Tonight. AHA 0xDE. If it is your first time attending, you will give an “intro talk”. This is an opportunity to share about yourself and allow us to get to know you. This is an important part of the new attendee process. Please take it seriously. If you’ve given an intro talk before, but have […]
Original post on infosec.exchange
infosec.exchange
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too github.com/jduck/bs25-s...
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
github.com
The sedexp Linux malware was disclosed in late 2024. In my talk at @kernelcon.bsky.social, I will present my own deep dive of the malware, including many parts that have not been made public, such as loading of a memory-only rootkit. Be sure to attend for a teardown with @volatilityfoundation.org 3!
Last week I attended Vector35 @re-verse.io RE//verse conference and it was great! Excellent food, high signal to noise (RE/VR), and great people. I scored some amazing schwag including a SIM transposer and a @binaryninja.bsky.social hacky sack! w00t!
On March 29th, I will be speaking at @bsidessd.bsky.social on Volatility 3, including all its new features and plugins. Be sure to attend to catch a sneak peak at the new framework before the major release later this Spring! www.bsidessd.org #DFIR #infosec
Digital vs film X-ray . Film offers higher resolution and better dynamic range with the same settings, but slightly longer exposure time (and more tedious image acquisition). Comes in handy when it comes to tiny electronics. Images of an Abbott Lingo continuous glucose monitor.
BlackHoodie will be back at @ringzer0.bsky.social Bootstrap conference in Austin, TX 🤠 On Friday March 21st I'll be teaching Compiler Internals for Security Engineers, a class for women by women, and it's free. Register here blackhoodie.re/Ringzer0_Boo...
Blackhoodie at Ringzer0 Bootstrap 2025
Compiler Internals for Security Engineers
blackhoodie.re
Tamme is giving a talk at Embedded World 2025! He shows how Rust’s type system and package manager can help to improve development speed and code quality. Also visit us at our booth, or book a time slot for a private chat: https://buff.ly/4308AWE @diondokter.nl #ew25 #embeddedworld #rustlang
Greg KH is a voice of reason downthread: lore.kernel.org/rust-for-lin...
Re: Rust kernel policy - Greg KH
lore.kernel.org
I'm giving a talk at BOOTSTRAP25 in Austin! Hope to see y'all there! ringzer0.training/bootstrap25-...
TALK: Musing from Decades of Linux Kernel Security Research // Joshua J. Drake
The Linux Kernel powers billions of devices across industries, making it critical infrastructure. But is it secure? Josh explores this by comparing its security investments to a typical SDLC, sharing ...
ringzer0.training
It is EXTREMELY cool to me that: * Use of Rust on Embedded platforms is such a high percentage of the ecosystem (16.8% bare metal, 12.9% with an OS) * The usage is increasing year over year Check out the survey results! blog.rust-lang.org/2025/02/13/2...
I'm trying to think of a good way to flex Poststation as a demo for the embedded world booth. Does anyone have ideas of fun, interactive, and maybe mind bending things to have 8-16 independent MCUs do? I plan to fit it all into a eurorack case, as individual cards/modules.
I did the podcast thing! It was great fun chatting with Matthias Endler on his “Rust in Production” podcast. We talked about our little Rust based ECU at Volvo Cars and how it came about. Check it out: corrode.dev/podcast/s03e...
Volvo with Julius Gustavsson - Rust in Production Podcast | corrode Rust Consulting
The car industry is not known for its rapid adoption of new technologies. Therefore, it’s even more exciting to see a company like Volvo Cars embracing Rust for core components of their software stack...
corrode.dev