The new Messaging Layer Security (#MLS) specification provides end-to-end security that makes it easy for apps to provide users the highest level of security, keeping user information safe even if the cloud service they’re using has been breached: https://t.co/yCah3bR1cu
A few weeks after the war has started, we were asked to analyse one suspicious piece of software within state infra, only to find 17 dependencies with easy path to massive breaches if author pushed malicious update. So we've quickly hacked something together to act on it.
Evaluate the risks of #opensource libraries you want to use by learning more about their community.
RepoMetaScore analyzes metadata of #OSS repositories and outputs risk ratings based on location, commit history, and contributors profiles.
➤ https://t.co/2M6SfUDP6E #security
Have you always wanted a SU-34 “Fullback” strike fighter? But $50M is a little bit pricey?
Just donate $1000+ to support Ukrainian army and we’ll send you this tag recycled from a downed russian plane (it’s literally a piece of it with little engraving).
Any recommendation for anything needs to take into account the “system” (structure, bureaucracy, incentives etc.) that will need absorb the recommendation.
Most good ideas simply “bounce off” the systems they need to change.
Event: Starlink ships dishes to Ukraine
Reaction: hundreds of people who can read history but don't understand basic physics are tempted to comment or even instruct others how defenders should use sat comms securely.
Worth remembering in any crisis or major event (economic, security, etc.) that the people who know the most usually can't talk about it, but those that aren't in the middle of things have the freedom to communicate broadly but often don't have particular inside knowledge.
@paulmillr@BearNotesApp 3/ Thank you for bearing with me for this long thread to point it out - if you ever pass by any crypto/security conference and see any of us talking - beers are on me. I'll get someone inside to read this thread.
@paulmillr@BearNotesApp 2/ It is not correct assumption, scheme works differently, based on what I know. Given that you've successfully constructed "the attack", it's fairly trivial to test it yourself and figure it out yourself.
@paulmillr@BearNotesApp Let's try to clarify then - what, in context of the document you've read, you believe to be "main seed" that can be "easily brute-forced"?