GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by James Forshaw :donor: (tiraniddo@infosec.exchange)

  1. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Saturday, 26-Apr-2025 04:44:38 JST James Forshaw :donor: James Forshaw :donor:
    in reply to
    • Kevin Beaumont

    @GossiTheDog "Gone are the days of trying to memorize and remember file names or exact words. With improved Windows search..." we can shove AI generated garbage straight from Bing to your eyeballs with no way of disabling any of it if all you wanted was finding your own files.

    In conversation about 22 days ago from infosec.exchange permalink
  2. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Wednesday, 23-Apr-2025 04:32:23 JST James Forshaw :donor: James Forshaw :donor:
    in reply to
    • Kevin Beaumont

    @GossiTheDog I still can't quite believe _this_ was their fix.

    In conversation about a month ago from infosec.exchange permalink
  3. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Friday, 18-Apr-2025 00:30:29 JST James Forshaw :donor: James Forshaw :donor:
    in reply to
    • Kevin Beaumont

    @GossiTheDog I never managed to the get the updated version working on the ARM CoPilot laptop I bought specifically for that purpose. I don't know of any current write ups other than the puffery from MS.

    I'd certainly focus on the encryption, how it ties into Windows Hello, whether there's any obvious bypasses and also whether you can still hoover up the details _if_ the user has unlocked it first (as in how hard is it to access the database once the key is available).

    In conversation about a month ago from infosec.exchange permalink
  4. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Tuesday, 03-Dec-2024 08:34:07 JST James Forshaw :donor: James Forshaw :donor:
    • Kevin Beaumont

    @GossiTheDog FFS

    In conversation about 6 months ago from gnusocial.jp permalink
  5. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Tuesday, 03-Dec-2024 07:35:03 JST James Forshaw :donor: James Forshaw :donor:
    • Kevin Beaumont

    @GossiTheDog comical :D

    In conversation about 6 months ago from gnusocial.jp permalink
  6. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Friday, 29-Nov-2024 17:34:17 JST James Forshaw :donor: James Forshaw :donor:
    in reply to
    • Kevin Beaumont

    @GossiTheDog as far as I know mine doesn't crash but it's still yet to capture a single snapshot. I did take a look an the enclave binaries though, first (and minimal) pass seems it's "maybe better", at least no obvious bug assuming they're using it correctly.

    In conversation about 6 months ago from infosec.exchange permalink
  7. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Monday, 25-Nov-2024 16:24:11 JST James Forshaw :donor: James Forshaw :donor:

    Awesome that MS are supported and documenting VBS enclaves properly now *apropos of nothing in particular*. https://learn.microsoft.com/en-us/windows/win32/trusted-execution/vbs-enclaves-dev-guide. Also awesome that in the example exported entry point they provide they don't seem to mention how careful you need to be with the input pointer that you don't just read/write enclave memory :)

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: learn.microsoft.com
      VBS Enclaves Development Guide - Secure Enclaves
      from alvinashcraft
      Development guide for Virtualization-based security (VBS) enclaves - Learn how to build a basic VBS enclave.
  8. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Sunday, 24-Nov-2024 19:28:09 JST James Forshaw :donor: James Forshaw :donor:
    • Kevin Beaumont
    • Steve Syfuhs

    @GossiTheDog @SteveSyfuhs well I meant I bought a *urgh* Copilot+ ARM PC for it, sorry.

    In conversation about 6 months ago from gnusocial.jp permalink
  9. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Sunday, 24-Nov-2024 10:28:11 JST James Forshaw :donor: James Forshaw :donor:
    • Kevin Beaumont
    • Steve Syfuhs

    @SteveSyfuhs @GossiTheDog I was able to install it on my ARM device bought almost for this exact purpose (oddly they didn't ship to Canary, I had to full reinstall the OS to move back to the Dev channel). I'll try and take a poke at it now I'm not at work, see if I can get $20k out of MS :D

    In conversation about 6 months ago from infosec.exchange permalink
  10. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Tuesday, 03-Sep-2024 02:51:50 JST James Forshaw :donor: James Forshaw :donor:
    in reply to
    • Kevin Beaumont

    @GossiTheDog from the article "a sentencing hearing was postponed for a 12-year-old boy who admitted taking part in two separate incidents of disorder in Manchester because his mother had gone on holiday to Ibiza". Hmm I wonder what could possibly be the root problem of the boys misdeeds?

    In conversation about 9 months ago from infosec.exchange permalink
  11. Embed this notice
    James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Sunday, 11-Feb-2024 21:55:13 JST James Forshaw :donor: James Forshaw :donor:

    Okay, so I did a quick dive into sudo in Windows and here are my initial findings. https://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html

    The main take away is, writing Rust won't save you from logical bugs :)

    In conversation about a year ago from infosec.exchange permalink

    Attachments


User actions

    James Forshaw :donor:

    James Forshaw :donor:

    Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          241908
          Member since
          11 Feb 2024
          Notices
          11
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.