Security: ChromeOS root privilege escalation and android-root persistence (reward: $45000) crbug.com/1166932

Today I make public ALL *recordings* and updated slides (+ FAQ) for my mobile security class, MOBISEC 2020!

Everything is available, for free, at: mobisec.reyammer.io/slides!

Few words about this release in a short thread 👇

This was quite a journey that took multiple rounds of reviews, but the manuscript improved with every iteration. I am tempted to write a more detailed report of the whole process as encouragement to junior researchers not to give up in the face of rejection notices.

Nearly 3 years after starting work on it, our (@ChadBrubaker__ @jeffvanderstoep) paper "The Android Platform Security Model" is now published in ACM Transactions on Privacy and Security (fully open access): dl.acm.org/doi/10.1145/3448609 covers versions up to Android 11.

I want to stress that once these content scanning systems are in place (for child abuse imagery) their usage will expand. They will be retasked by governments all over the world to scan for speech we consider “protected”. This is the infrastructure of authoritarianism. 8/

If want to brush up on some crypto & attacks here is my YouTube channel for "Introduction to Cryptology" youtube.com/channel/UC6crzceua The course page is hyperelliptic.org/tanja/teachi

Also check out our offers @TUeindhoven for cyber security with the IST master track IST.win.tue.nl

„Das Ansinnen, an der Wahrheitspflicht zu rütteln, ist meines Erachtens rein parteipolitisch motiviert und ein frontaler Angriff auf die Demokratie.“ derstandard.at/story/200012652

Hiring/please RT: The @jkulinz /@Dynatrace Co-Innovation Lab at the LIT Open Innovation Center CPS Lab officially started (Details/Press: jku.at/en/news-events/news/det) and we are searching for post-docs (jku.at/fileadmin/gruppen/80/St). @AndreasHametner @Pummex4 @LindingerCh @AloisReitbauer

I am very happy to finally lift the curtain on our paper "undeSErVed trust: Exploiting Permutation-Agnostic Remote Attestation" that will appear at @wootsecurity.
Thanks @JanWichelmann, Florian Sieck and @tomcrypt for the great collaboration.

Intel patched these vulnerabilities in the Management Engine as well.

It's still crazy to me how there's a whole OS that's hidden in the lower layers of your CPU... and that this OS supports Wi-Fi. twitter.com/vanhoefm/status/13

Over the past several years, our Network Health team has built tools to diagnose and reject bad relays. As a result, we have rejected many malicious nodes, and we have started documenting them in monthly reports: gitlab.torproject.org/tpo/netw

If you opt out of having your WhatsApp share data with Facebook, Facebook won't deactivate your account, but they will make WhatsApp largely unusable for you.


I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com

"As with any large project, introducing a new language requires careful consideration. ... This post discusses some of the key design considerations and resulting decisions we made in integrating Rust support into Android’s build system."

Difficult to quantify what an ecological disaster Bitcoin is, but this comes close.

Nice illustrations of hash collisions by @corkami / @angealbertini: github.com/corkami/collisions

”Don’t let the perfect be the enemy of the good.”
Well, I don’t know about you but I don’t consider ”climate targets” putting us on track for 2,4°C and current policies indicating we’re headed for 2,9°C (excluding most tipping points, feedback-loops etc) to be ”good”.

The CIA conducted a supply chain compromise of a phone used by an associate of Soleimani. Got tip Soleimani courier was buying fresh phones from a specific market; got spyware onto phones, one of which ended up in the same room as Soleimani news.yahoo.com/conspiracy-is-h

