Mathias Payer

Securitatis inquisitor and professor at EPFL leading the HexHive 🐝 group, focusing on system/software security (he/him).

Mathias Payer boosted:
Andreas ZellerAndreasZeller
2025-06-24

My team at / : Alexi Turcotte, Marius Smytzek, me, Pepe Zamudio, and Laura Plein. What is ? Watch this space on Thursday for our big 1.0 release announcement and/or attend Pepeβ€˜s presentation on Friday 16:00!

<exchange> ::= <client:request> <server:response>
<request>  ::= 0x1 <length> <payload> <padding>
<response> ::= 0x2 <length> <payload> <padding>
<length>   ::= <uint16>
<payload>  ::= <byte>*
<padding>  ::= <byte>*

where len(<payload>) == uint16(<length>)
where <response>.<payload> == <request>.<payload>
2025-06-23

Well, the proposal has nothing to do with lasers "a priori" but I'm sure some cool laser-related research would fit. A 100W laser is a great place to start, right? πŸ”¦πŸ”¦πŸ”¦

Mathias Payer boosted:
2025-06-09
2025-06-06

@spaf congratulations to this well deserved promotion. Let's see what kind of mischief is next ;)

Mathias Payer boosted:
2025-05-19

The slides for my OffensiveCon talk "Finding and Exploiting 20-year-old bugs in Web Browsers" docs.google.com/presentation/d

2025-05-14

Last week, @epfl hosted LakeCTF, a major academic capture-the-flag competition with amazing challenges. Congrats to @polygl0ts for the flawless organization! I especially enjoyed the retro-challenges on real devices, especially hacking old basic interpreters! πŸ‘ΎπŸ‘ΎπŸ‘Ύ actu.epfl.ch/news/zer0rocketwr

2025-05-14

So many amazing papers at #IEEESSP Oakland'25 this year. Congratulations to all authors on your accepted papers and an amazing program overall.

This year, we had one paper "SoK: Challenges and Paths Toward Memory Safety for eBPF" where Kaiming Huang explores challenges in protecting the Linux kernel against bugs in the eBPF verifier. As it turns out, securing even a simple language is challenging and we need to carefully consider how optimizations are implemented. Check out the full paper for details: nebelwelt.net/files/25Oakland.

Sadly, I could not make it to San Francisco this year. Luckily my alternative program to go hike with the kids was not too bad either!

2025-05-02

Today I received my first spear phishing attempt with a great context and reasonable request. 🀩🀩🀩 Does that mean I'm important now?

2025-05-01

These two selfies are less than 24hrs and less than 50km apart from each other. One of the reasons why I love #EPFL and Switzerland

2025-04-29

@cryxli merci! einen Gruss in die Region um Bern!

2025-04-12

The universe is sending a very clear signal that I should stay TF out of France. Flight cancelled after 3hr delay and we ended up driving all night because no flights or trains were available the next three days. Thanks #easyjet

2025-04-10

@cshentrup a smart car is not necessarily a self driving car. I'm OK with self driving cars but don't want them to be continuously connected to the internet and broadcasting my location.

2025-04-10

@twomikecharlie

Bugs in the hypervisor is a reference to EL3XIR that I introduced with a Gandalf meme
Vulnerable communication APIs is a reference to GlobalConfusion (Global and Confusion)
Forgetting rollback is a reference to Spill the TeA (teapot)
Unsafe allocators... is a reference to books = heap and fire shit is burning
The bread for libraries is a reference to the Elven bread (lemba/scram). In the talk they made sense and hint back at the storyline ;)

2025-04-10

The #THcon organizers suggested that I take a hotel in the city center and commute to the conference. In spite of bad past experiences in every major city in France, I took their advice and learned why Toulouse does not have a problem with transport strikes: they got rid of the conductors!

2025-04-10

What great fun to speak at #THCON2025 in Toulouse and present some of the #HexHive research on Android (in-)security. Find me if you want to nerd out about fuzzing, system mitigations, and any insecure components.

2025-04-08

In Switzerland we take our security and our pocket knives seriously. That's why you can buy pocket knives right before boarding at Geneva airport. πŸ—‘οΈπŸ›«

2025-02-28

What a great time at the #NDSS Symposium in beautiful San Diego. While it is always about meeting friends, catching up on projects, discussing new and exciting research and looking for potential collaborations, the #HexHive lab also had the pleasure to present a total of four research papers at this conference --- and we received two distinguished paper awards!

Check out the blog post with a discussion of the papers and some key takeaways at: nebelwelt.net/blog/2025/0227-n

2025-02-25

@lavados between 6:00 and 6:30 at the waterfront?

2025-02-24

Some life lessons from an amazing researcher after an extensive career across several topics in systems and architecture: family and friendships first, it's about the people; in research follow your passion and pick the important problems! dl.acm.org/doi/10.1145/3637905

2025-02-24

I'm on my way to San Diego for Internet Society's yearly Symposium on Networked and Distributed Systems. If you're around, reach out and ping me if you want to go for a run along the beach in the morning! πŸƒ #NDSS25

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst