Daniel Roethlisberger

security & software engineering · operating systems & kernel engineering · cyber defense · civil society

Daniel Roethlisberger boosted:
Frederic Jacobsfj
2025-06-25

📸 ETH Zürich & Empa researchers have developed an image sensor using stacked perovskite layers, capturing full-color images with higher efficiency and accuracy and without the need for traditional color filters.

Goodbye demosaicing, two-thirds more light in the same surface!

nature.com/articles/s41586-025

Daniel Roethlisberger boosted:
2025-06-23

Redox is Hiring!

Check out the job description in our monthly report:

redox-os.org/news/this-month-2

Daniel Roethlisberger boosted:
2025-06-21

Pixels remain the only devices providing a high level of security combined with proper secure support for using another OS. We hope to have more options by the end of 2026 based on contact with an OEM interested in meeting our requirements but there's no specific timeline.

Daniel Roethlisbergerdroe@infosec.exchange
2025-06-21

Looking forward to present some fun NSO exploit archaeology at @recon next week, with Bill Marczak of @citizenlab :

«A Trip to Ancient BABYLON: Unearthing a 2017 Pegasus Persistence Exploit»

cfp.recon.cx/recon-2025/talk/V

Daniel Roethlisberger boosted:
2025-06-20
Daniel Roethlisberger boosted:
2025-06-18

From:

zdnet.com/article/why-sms-two-

Fink Telecom CEO Andreas Fink said: "Our company provides infrastructure and technical services, including signalling and routing capabilities. We do not analyze or interfere with the traffic transmitted by our clients or their downstream partners."

Notice what is conspicuously absent from the list of stuff Fink says they're not doing:

"We do not copy or mirror traffic -- neither all traffic, nor a selected subset of traffic --- for any reason, nor otherwise make traffic available to third parties."

Daniel Roethlisberger boosted:
Julian-Ferdinand Vögelejulianferdinand@infosec.exchange
2025-06-13

Today we’re publishing a new report on Intellexa’s #Predator #spyware, which is still active despite global sanctions, now with a new client and ties to a Czech entity. Check out the full report here: recordedfuture.com/research/pr

Daniel Roethlisbergerdroe@infosec.exchange
2025-06-12

Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted

citizenlab.ca/2025/06/first-fo

Daniel Roethlisberger boosted:
blacktopblacktop
2025-06-09
Daniel Roethlisberger boosted:

End spyware use against civil society! Report confirms that Italy’s intelligence services used #Graphite by #Paragon against NGO founder Casarini & Giuseppe Caccia accessnow.org/press-release/no #Staatstrojaner

Daniel Roethlisberger boosted:
Zack Whittakerzackwhittaker
2025-06-05

NEW: Cellebrite, maker of phone unlocking tech, to buy mobile testing startup Corellium for $170 million.

techcrunch.com/2025/06/05/phon

Daniel Roethlisberger boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-06-02

We have finished going through the court docs and hearing transcripts from the WhatsApp v. NSO lawsuit.

Here's everything we learned, from how NSO's customers use Pegasus, to the spyware's cost.

techcrunch.com/2025/05/30/eigh

Daniel Roethlisberger boosted:
2025-06-02
Daniel Roethlisberger boosted:
2025-05-24

New blog post (about an old exploit): tachy0n.

For iOS 13.0-13.5, dropped as an 0day at the time.

blog.siguza.net/tachy0n/

Daniel Roethlisberger boosted:
Frederic Jacobsfj
2025-05-23

Google quantum researcher Craig Gidney published yesterday a preprint demonstrating that 2048-bit RSA encryption could theoretically be broken by a computer with 1 million noisy qubits running for one week.

This 20x decrease in estimated required ressources for quantum factoring comes from better algorithms and better error correction.

security.googleblog.com/2025/0

Daniel Roethlisberger boosted:
abuse.ch :verified:abuse_ch@ioc.exchange
2025-05-20

The European Council 🇪🇺 has issued sanctions against Stark Industries, a hosting company registered in the UK 🇬🇧, as "they have been acting as enablers of various Russian state-sponsored and affiliated actors to conduct destabilising activities including, information manipulation interference and cyber-attacks against the Union and third countries."

⤵️ ⤵️ ⤵️
consilium.europa.eu/en/press/p

The EU council sanctions UK based hosting company Stark Industries
Daniel Roethlisberger boosted:
daniel:// stenberg://bagder
2025-05-19

Happy inspired Swisscom to add a "disclose your use of AI" to their bug-bounty program:

github.com/swisscom/bugbounty?

Yes, hashtag#AI also affects hashtag#BugBounty. While we could leverage AI to optimize our internal triage processes, we haven't observed any noticeable, positive advances in vulnerability reports (yet). On the contrary, we are rather negatively impacted by opportunistic LLM-generated report submissions that burn our triage resources. Therefore, we followed Daniel Stenberg's example and introduced an AI policy in the Swisscom bug bounty program (link in the comments).
Daniel Roethlisberger boosted:
2025-05-16

I just released a long blog post about using #dtrace on #macOS to debug a thorny bug in the macOS kernel that was breaking #Lix's socket disconnect detection.

It goes through what the fault was, how I found it, where to find information about DTrace on macOS (which is not really well documented), and how the macOS kernel's networking/events system works at a high level. It also explains how one can take an unfamiliar kernel and quickly find relevant code.

jade.fyi/blog/misadventures-in

Daniel Roethlisberger boosted:
2025-05-12

Bumped iometa to version 1.7.0.

This update (finally) merges back the `wip` branch with a complete rewrite of the Mach-O parsing layer, which should resolve many issues. Tested against all kernels that I have between 11.0 and 18.5, and it didn't error out on any of them.

Known issues:
- Fails to find IOService vtable on a bunch of kernels between 12.0 and 14.x, which then cascades to all subclasses.
- Doesn't work on visionOS. This is really cursed stuff that will have to wait for multiple inheritance support.

github.com/Siguza/iometa

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst