obilodeau

@obilodeau.bsky.social

Father of two. Hacker. President @NorthSec. Research at Flare. Cofounder of MontréHack. Love to teach and share. BlackHat, Defcon, SecTor speaker.

Learning about color mapping and LUT (cube files) and trying all sorts of ffmpeg tricks to make bland videos look good at 2 am.. Yup, it's about @nsec.io and trying to leverage cool video shots that we were given for free, but they were raw... Then you realize a phone does a lot of work for you...

Bild

Quick analysis of today's chalk / npm supply chain story. It requires the `window` object so it needs to be deployed and run in a browser. It means front-end projects would only be affected if the site itself was a cryptocurrency website. CLI projects unaffected. 1/3

📸 𝗟𝗲𝘀 𝗽𝗵𝗼𝘁𝗼𝘀 𝗼𝗳𝗳𝗶𝗰𝗶𝗲𝗹𝗹𝗲𝘀 𝗱𝗲 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝘀𝗼𝗻𝘁 𝗱𝗶𝘀𝗽𝗼𝗻𝗶𝗯𝗹𝗲𝘀! • 𝗢𝗳𝗳𝗶𝗰𝗶𝗮𝗹 𝗡𝗼𝗿𝘁𝗵𝗦𝗲𝗰 𝟮𝟬𝟮𝟱 𝗣𝗵𝗼𝘁𝗼𝘀 𝗔𝗿𝗲 𝗢𝘂𝘁! Revivez les meilleurs moments de NorthSec avec notre album photo officiel! ⚓️ photos.app.goo.gl/bMCHe366jdP1...

BildBildBild

My advice for people who are applying to big conference for abstracts are: imagine that your reviewer is under a deadline of less than twelve hours and they are deeply deeply angry. Write to impress that person, but write the talk you'd be proud to give.

🔐 This could reshape privacy engineering. Google open-sourced their zero-knowledge proof (ZKPs) age verification libraries on Jul 3 called "Longfellow" letting you prove you're 18+ without revealing birthdate, name, or any PII. blog.google/technology/s... (1/8) 🧵

Opening up ‘Zero-Knowledge Proof’ technology to promote privacy in age assurance

Today, we open sourced our Zero-Knowledge Proof (ZKP) libraries, fulfilling a promise and building on our partnership with Sparkasse to support EU age assurance.

blog.google

Missing the NorthSec community already? We made you a starter pack to help you quickly find us on Bluesky! Saw someone missing from this starter pack? Let us know! go.bsky.app/JZeo2ad

Post nicht verfügbar.

A dream come true: I wrote POC-level code that I thought would be a good addition to our platform, and someone rewrote it and integrated it. We are now protecting more customers automatically with it! Now onto the next POC!

A pop-up that says: Microsoft Entra ID Exposed Credential Verification is now available!

Estelle Ruellan and I were accepted at BlackHat USA!! "Hackers Dropping Mid-Heist Selfies: LLM ldentifies Information Stealer Infection Vector and Extracts loCs" Couldn't be happier sharing what we did on a worldwide stage! p.s.: picture of us celebrating from Botconf after our talk today #BHUSA

Bild

NorthSec is delivered. It was an incredible edition! Great keynotes, our best party so far and our world-class in-person CTF scenario and huge set of diverse and accessible challenges were a great success! I didn't take much photos, I'll report back later. ✈️🇫🇷 to botconf now! 😅

BildBild

On my 4th day in Europe I finally woke up at a normal hour. And unfortunately it is my last full day here 🙃 I'll be in San Francisco Friday. I wonder how I'll hold this weird schedule...

Due to work travel, I had to vote in advance this year. The ballot is in 🗳️☑️ The experience was quite smooth. A 5 minute wait maybe. Now I hope my candidate and his leader don't do anything extremely stupid until the actual vote date 😆

I’m looking for on-demand virtual lab platforms that can spin up full Active Directory environments (8 vCPUs, 64GB RAM, nested virt). It needs to support complex enterprise scenarios to showcase Remote Desktop Manager with other Devolutions products. Any recommendations? 🙏