AI-powered firmwareprotection meets TPM 2.0 device-attestation
We are very happy to announce the partnership with @binarly_io. Professional on AI-based firmware-inspection and protector of cloud using customers infrastructures.
https://t.co/RuCZYEx25d
We hope that all of you have a good start into the week. Due to the #CoronaCrisis a project planned to start in April is postponed and we have some open design and developer slots. Ping us if you want to build something awesome:
https://t.co/sYKuvgHCmB
Stay healthy #StayAtHome
We've found a bug in CSME on-die ROM!💥 Intel says it's already targeted by CVE-2019-0090 (https://t.co/NOUHbb5JwW). Security Fuses can be extracted! 🔥 Mehlow and Cannon Point chipsets are affected. Stay tuned!
Want to make service removal really fun? Create a service with a unicode name. The service will run but won't show in sc.exe, services.msc, or taskmgr.exe and will sometimes cause a critical error while trying to find it with PowerShell/WMI. Unicode wins again.🤦♂️
Bring warm clothing and coat (not so cold now, but might rain and around freezing at night), Belgian power plug type E adapter and your chargers. Cash for purchases at stands and beer-event (cash machine onsite runs out quick), catering accepts cards.
https://t.co/OxTfWdlJZh
@lambdafu I only read the NSA writeup but it sounds like you can trick the crypto API into using arbitrary signing key with an attacker controlled curve. Essentially an invalid curve attack.