Months of relentless work finally out: our Bitcoin Core security audit!
Both a bless by the code maturity, security culture -- and a curse by the challenge it represents!
Glad to have crossed paths with such a great dev team, @dergoegge@darosior@fanquake.
Keep up the great job!
Quarkslab engineers @RobinDavid1, @MihailKirov1 and Kaname just completed the first public security audit of Bitcoin Core, led by @OSTIFofficial and funded by @bitcoinbrink. Details on the blog post: https://t.co/xPkDEV7LDy Congrats to developers for such software masterpiece !
The dragon has a VM. Of course it does. Our latest blog walks through the analysis of a complex C++ binary hiding behind a virtual machine, themed as a classic RPG fight. QBDI & TritonDSE are your weapons of choice. The dragon doesn't stand a chance. 🐉
https://t.co/59TX9v5Msq
Join us next Wednesday at 11AM CST for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
Link in 🧵👇
#OSTIF#bitcoin
🎓 New PhD at Quarkslab on: "Analyzing binary programs and obfuscation with
graph-based representations and machine learning". I am overjoyed having supervised Roxane's PhD
and I have rarely seen such a committed, talented PhD researcher congrats 🎉!
Great talk by @JohnLaTwC on ways you can turn security data into graphs: https://t.co/Y9sNNO0i59. Especially the vector part is great: so many tools have built in support for embeddings (e.g. BigQuery ML.GENERATE_EMBEDDING and VECTOR_SEARCH), defenders should be using them more!
It has been a pleasure to be the 2nd talk of 20th Recon edition! Teaming up with Riccardo about EV charger security we show vulnerabilities found and a side step-by-step firmware cryptanalysis.
Outline: https://t.co/M8fw1SCvjR
(slides published soon..)
i wrote a thing about all the different teams in north korea dedicated exclusively to fucking your shit up and how you can know exactly which one just ruined your entire month
https://t.co/KidMTTWlyx
The recording of my talk is online: https://t.co/UZTD1e3nfs
"Streamlining firmware analysis with inter-image call graph and decompilation". Held in Orlando, Florida at @REverseConf!
We were slow with the last video update so we figured we'd do a two for one! Lukas talks about rehosting firmware for fuzzing (https://t.co/fqX8Kuv8Y0) and Robin shows off a fantastic new tool for exploring code relationships beyond single binaries (https://t.co/9DhK6bt9vU)
There are so many great reasons to be on Signal.
Now including the opportunity for the vice president of the United States of America to randomly add you to a group chat for coordination of sensitive military operations.
Don’t sleep on this opportunity…