LIVE: Apple Security Research, our new blog and website at https://t.co/Ssr3471Pju! We launch with an update on Apple Security Bounty (https://t.co/b7aYxqidka), and a deep dive into some fundamental XNU memory safety improvements with kalloc_type (https://t.co/evVdUYYo5p). Enjoy!
@sleevi_@bradfitz You managed to nerd-snipe me because @rolandshoemaker's explanation did not ring true. Based on the solution and strictness checks I know are in SecCertificateCreate*, I suspect the real problem was an Extensions SEQUENCE of length 0.
Just because a root certificate is in the built-in iOS/macOS trust store doesn't mean that it is trusted. Apple applies additional constraints via configuration updates to maintain a high-level of security. See https://t.co/Lhd9OT2p2N for more detail.
The Security Research Device Program (SRDP) is currently taking applications for its second cohort. This is the last week to apply for an Apple Security Research Device 🔐📲— apply today!: https://t.co/kgzX6JXoMq
I’m hiring secure OS engineers in Sydney, Australia. If designing kernels, hypervisors, and runtimes to be secure and robust is your kind of thing, please get in touch! https://t.co/GApzuVUVoF
@MikhailJennings Generally, SWE at Apple is not remote-friendly; however a substantial portion of Security Engineering is remote. It very much depends on the candidate.
Love TLS, X509, Certificate Transparency, or ASN1? Or hate them and want to make them better? My team is looking for engineers! You can apply at the link. DMs also open. https://t.co/ibySyccFuX
my team work on securing all the new features we ship to our customers. we're recruiting and seeking diverse candidates! check out our job posting or DM me for details! https://t.co/9j93dUSwUG
I’m hiring an engineering manager for the Secure Enclave OS to lead a strong team that sets a higher bar each year for software/hardware security. If you want to help evolve a key security component trusted by a billion users, please reach out! https://t.co/RJkfpDxqyD
Hi folks! The team I manage at Apple, the Authentication Experience team, is hiring a software engineer. We use empathy-driven development to make using apps and websites that have accounts more humane and safe for everyone. Bay Area role; DMs open for Qs. https://t.co/NYTi7RtkxH
Hi folks! My team is recruiting for a Security and Authentication engineer, focused on web-facing features. If you are interested, or know someone who might be, please reach out! https://t.co/gnJdw94Q9f
Reminder to CAs: Apple's CT policy has changed effective 4/21/2021 00:00:00Z. If you're issuing certs with lifetimes greater than 180 days but less than 398 days, you need 3 embedded SCTs, not 2.
https://t.co/WSNGLOT5VO
Ininterested an internship at Apple working on WebKit or related tech?
Some of the areas of opportunity:
- DOM & Web APIs
- Layout & Rendering
- 3D Graphics
- Security & Privacy
- Web dev tools
- Media
- JS VM
- HTTP stack
DM if interested. RTs appreciated.