Peter C

@peterc.ollins.me

Security Engineer https://peterc.ollins.me

I'm very happy to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to DEF CON 34! This research was a huge gamble and the result was glorious, can't wait to share!

Bild

Notifications for deleted shouldn't remain in any OS notification database, and we've asked Apple to address this. In the meantime, you can prevent any preview text from your Signal messages from appearing in your notifications. Signal Settings > Notifications > Show “No Name or Content”

404 Media@404media.co · 4mo ago

NEW: The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database, multiple people present for FBI testimony in a trial told 404 Media.

have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.

Our digital systems reward belonging over accuracy, with people gaining status by aligning with their group, not by checking facts. Once beliefs become tied to identity, more media literacy won’t shift behaviour, the social rewards run against work against it.

my latest investigation for @consumerreports.org is based on months of reporting and 60+ lab tests of leading protein supplements we found that most protein powders and shakes have more lead in one serving than our experts say is safe to have in a day (🧵) www.consumerreports.org/lead/protein...

Protein Powders and Shakes Contain High Levels of Lead - Consumer Reports

CR tests of 23 popular protein powders and shakes found that most contain high levels of lead.

consumerreports.org

New from 404 Media: we spoke to the researcher who found hackers can remotely trigger brakes on American trains. Says was ignored for years, DHS confirmed. "All of the knowledge to generate the exploit already exists on the internet, AI could even build it for you." www.404media.co/hackers-can-...

Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years

“All of the knowledge to generate the exploit already exists on the internet. AI could even build it for you,” the researcher told 404 Media.

404media.co

Just to clear up some misinfo, a BGP hijack was not the cause of Cloudflare DNS going down today. At 21:51 UTC, Cloudflare (AS13335) withdrew both 1.1.1.0/24 and 1.0.0.0/24 for an unknown reason. I suspect AS4755 was always announcing 1.1.1.0/24, when CF went away, it leaked a bit (%2).

Post nicht verfügbar.

Today’s unsigned, unexplained #SCOTUS ruling clearing the way for removals of migrants to third countries without any additional process is a disaster—not just on the merits, but because of the government misbehavior that it not only refuses to punish, but effectively rewards. Me, via “One First”:

161. The Court's Disastrous Ruling in the Third-Country Removal Case

The majority did not just greenlight an especially odious immigration policy without any explanation; it did so in a case in which the government defied the district court—twice—with no consequence.

stevevladeck.com

Here's something I am very excited about: Photosynthesis! 🌱☀️ A proposal to have CAs run transparency logs and make X.509 certificates out of Merkle Tree inclusion proofs. This is similar to how CT would have worked in an ideal world, and it solves the problem of PQC sizes in logs and handshakes.

[TLS] Photosynthesis, an update to Merkle Tree Certificates

Photosynthesis combines the Static CT API with the ideas in Merkle Tree Certificates.

mailarchive.ietf.org

Most engineers aren’t taught how to write secure code or catch threats after deploy. Detection engineering used to be limited to experts. Now anyone can do it with prompts, Goose, and the Panther MCP server. 💪 block.github.io/goose/blog/2...

Democratizing Detection Engineering at Block: Taking Flight with Goose and Panther MCP

A comprehensive overview of how Block leverages Goose and Panther MCP to democratize and accelerate security detection engineering.

block.github.io

SCOOP: In Feb, federal agencies "lost" many #FOIA requests but you probably had no idea. It turns out that the FOIAs disappeared due to an "insider threat attack" by 2 employees at a software company who were previously convicted of hacking into the State Dept 🧵 🎁 www.bloomberg.com/news/article...

Probe Found Security Lapses Led to US Contractor’s Data Breach

Failures in cybersecurity practices at a software company that helps federal agencies manage investigations and FOIA requests allowed two convicted hackers to delete databases, according to internal d...

bloomberg.com