Our paper "SIMurai: Slicing Through the Complexity of SIM Card Security Research" just went public!
In this paper, we explore the question: What kind of attacks could a hostile SIM launch against your phone? Surprisingly, a lot.
As it turns out, the secure monitor, Android's most trusted component is full of bugs. @_chli_ and @0ddc0de discovered lots of serious issues @USENIXSecurity though fuzzing. Paper: https://t.co/LBiJF2FXno
Do you want 0days in Android Trusted Applications using the Global Platform API? Use @0ddc0de's binary static analysis @USENIXSecurity to find type confusions resulting in arbitrary writes. Paper: https://t.co/lvH4aB8szX
@spendergrsec Maybe we phrased it a bit strongly, without that context. The usenix security paper makes that a bit clearer. Anyway, not intended as a dig at PaX, but a call to *deploy* defenses that stop such attacks.
@spendergrsec Sorry for late reply - not much X these days. Complexity refers mainly to research that crafts attacks with, say, symbex, and aims for, say, Turing completeness -> neither very practical nor needed. Niche refers to application-specific and requiring much knowledge of application.
A big thank you to the local organizers in Vienna for hosting an outstanding event! Thanks to the outgoing chair @herbertbos and good luck for 2025 to the PC co-chairs @kcotsneb and Anja Lehmann - follow this space for the CfP and changes for the 2025 Venice edition of EuroS&P.
So... Andy won the ACM Software System Award for MINIX!
I feel very proud and privileged to have worked with him (on MINIX 3 and other things)! He is one of the true pioneers of operating systems and one of the reasons i came to @VUamsterdam.
https://t.co/guKgU5JBxG
Zodra de stembussen gesloten zijn, starten de stembureauleden met het tellen van de stemmen. Dit gebeurt in het openbaar en iedereen mag daarbij aanwezig zijn.
Je mag het telproces niet verstoren, dus er gelden enkele regels 👇
Onze Chief Information Security Officer (CISO) Fleur van Leusden @Queen_fennec mocht in de podcast De Technoloog van BNR Nieuwsradio vertellen over hoe we ervoor zorgen dat de verkiezingen veilig, transparant en controleerbaar zijn.
The Belgian presidency has drafted yet another tweaked #chatcontrol proposal. In summary, the proposal remains completely unacceptable. TLDR: All the problems pointed our in our open letters are still there https://t.co/bublijBATW & https://t.co/qb7XIdiB1P 🧵1/6