We ran our first #Bug#Bounty event during the last @BlackHatEvents in Las Vegas. Check out the results and pictures below (White paper is also linked in the blog post).
https://t.co/9qS3U9FTIO
#bugbounty#blackhat#byos
12 factor auth:
Something you know.
Something you have.
Something you are.
Something you were.
Something you've lost.
Something you've forgotten.
Something you seek.
Something you find.
Something you steal.
Something you create.
Something you destroy.
Something you sacrifice.
Official announcement coming via @newaetech newsletter - but the #ChipWhisperer contest form now linked at https://t.co/VaNKp3cdeo points you to https://t.co/u268Qn03ac . Good luck to all entries!
Preview of #ChipWhisperer 5 is now available - virtual box serves to your local browser. See tutorials in https://t.co/600qnxrfwT - release is on github releases page. From this same interface you get firwmare you can edit and rebuild, ChipWhisperer hardware, and Python goodness.
These two gentlemen successfully exploited iPhone, S9, MI6 through browser bugs, NFC, and baseband (!) and were rewarded with $215k of prizes at PacSec PWN2OWN Tokyo winning the overall prize Master of PWN.
Assuming this all works out, the image in this tweet is also a valid ZIP archive, containing a multipart RAR archive, containing the complete works of Shakespeare.
This technique also survives twitter's thumbnailer :P
Rule of thumb - if you do not have any experience in dealing with incident response, forensic, and crisis management in companies that have the scale of data and customers that you are commenting on, please don't.