#trailofbits — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #trailofbits, aggregated by home.social.
-
#Signal adds new #security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
The new feature is part of a "key transparency" system that uses Cloudflare and #TrailOfBits as trusted third-party independent auditors to verify the integrity of Signal conversations. https://www.bleepingcomputer.com/news/security/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks/ -
#Signal adds new #security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
The new feature is part of a "key transparency" system that uses Cloudflare and #TrailOfBits as trusted third-party independent auditors to verify the integrity of Signal conversations. https://www.bleepingcomputer.com/news/security/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks/ -
source: 404media.co/a-secure-chat-apps…
The #Swisscows CEO confirmed a “technically possible but artificially constructed scenario.” Trail of Bits, for its part, refers to a “misrepresentation” of the #exploit by Swisscows: “The core problem is that Teleguard’s server has all the information needed to decrypt every user’s private key and read every message,” said #DanGuido, co-founder and CEO of #TrailOfBits .
#teleguard #chat #messenger #security #encryption #hack #hacker #software #fail #omg #wtf #news #meme #bug #internet #spy #attack #end2end #rsa
-
👨💻 Wow, an "amazing" discovery: code has bugs 🐞—who would've guessed?! 🎉 Trail of Bits bravely announces they used a tool to find issues, as if highlighting a #zero-day is akin to finding Waldo in a single-page book. 🤦♂️
https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/ #amazingdiscovery #codebugs #TrailofBits #findings #softwareissues #HackerNews #ngated -
👨💻 Wow, an "amazing" discovery: code has bugs 🐞—who would've guessed?! 🎉 Trail of Bits bravely announces they used a tool to find issues, as if highlighting a #zero-day is akin to finding Waldo in a single-page book. 🤦♂️
https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/ #amazingdiscovery #codebugs #TrailofBits #findings #softwareissues #HackerNews #ngated -
We found cryptography bugs in the elliptic library using Wycheproof
#HackerNews #cryptography #bugs #elliptic #library #Wycheproof #cybersecurity #TrailofBits
-
We found cryptography bugs in the elliptic library using Wycheproof
#HackerNews #cryptography #bugs #elliptic #library #Wycheproof #cybersecurity #TrailofBits
-
Hidden Commands in Images Exploit AI Chatbots and Steal Data https://hackread.com/hidden-commands-images-exploit-ai-chatbots-steal-data/ #ArtificialIntelligence #Cybersecurity #Vulnerability #TrailofBits #Security #Chatbot #Gemini #AI
-
Hidden Commands in Images Exploit AI Chatbots and Steal Data https://hackread.com/hidden-commands-images-exploit-ai-chatbots-steal-data/ #ArtificialIntelligence #Cybersecurity #Vulnerability #TrailofBits #Security #Chatbot #Gemini #AI
-
Buttercup: Open-source AI-driven system detects and patches vulnerabilities https://www.helpnetsecurity.com/2025/08/18/buttercup-ai-vulnerability-scanner-open-source/ #TrailofBits #opensource #Don'tmiss #Hotstuff #software #GitHub #DARPA #News
-
Buttercup: Open-source AI-driven system detects and patches vulnerabilities https://www.helpnetsecurity.com/2025/08/18/buttercup-ai-vulnerability-scanner-open-source/ #TrailofBits #opensource #Don'tmiss #Hotstuff #software #GitHub #DARPA #News
-
The Zoom attack you didn’t see coming https://www.helpnetsecurity.com/2025/04/18/zoom-remote-control-attack/ #socialengineering #cryptocurrency #TrailofBits #cybercrime #Don'tmiss #Hotstuff #malware #scams #News #Zoom
-
The Zoom attack you didn’t see coming https://www.helpnetsecurity.com/2025/04/18/zoom-remote-control-attack/ #socialengineering #cryptocurrency #TrailofBits #cybercrime #Don'tmiss #Hotstuff #malware #scams #News #Zoom
-
huh #trailofbits did an audit of #simplex - only the "protocol spec" https://github.com/simplex-chat/simplex-chat/blob/stable/docs/SimpleX_Design_Review_2024_Summary_Report_12_08_2024.pdf
quite limited scope. and last time i looked at the spec i lost my appetite, but apparently there have been updates, like addition of sntrup pq kem. so maybe this has improved? still wouldn't use it the supply chain attack surface is begging for a "soon" not an "if". and the global transcript of group chats was out of scope in this audit. so, meh?
-
White House: Use memory-safe programming languages to protect the nation https://www.helpnetsecurity.com/2024/02/27/memory-safe-programming-languages/ #criticalinfrastructure #softwaredevelopment #Horizon3.ai #programming #TrailofBits #government #Don'tmiss #Honeywell #Hotstuff #News #USA
-
White House: Use memory-safe programming languages to protect the nation https://www.helpnetsecurity.com/2024/02/27/memory-safe-programming-languages/ #criticalinfrastructure #softwaredevelopment #Horizon3.ai #programming #TrailofBits #government #Don'tmiss #Honeywell #Hotstuff #News #USA
-
📬 LeftoverLocals: Apple, AMD und Qualcomm GPUs von Sicherheitslücke betroffen
#ITSicherheit #AMD #Apple #CPUs #HeidyKhlaaf #LeftoverLocals #ProofofConcept #Qualcomm #Sicherheitslücke #TrailofBits https://sc.tarnkappe.info/af0398 -
📬 LeftoverLocals: Apple, AMD und Qualcomm GPUs von Sicherheitslücke betroffen
#ITSicherheit #AMD #Apple #CPUs #HeidyKhlaaf #LeftoverLocals #ProofofConcept #Qualcomm #Sicherheitslücke #TrailofBits https://sc.tarnkappe.info/af0398 -
CFTC adds execs from Circle, Ava Labs and Fireblocks to tech advisory group - The technology advisory committee aims to assist the CFTC in “ide... - https://cointelegraph.com/news/cftc-adds-execs-from-circle-ava-labs-and-fireblocks-to-tech-advisory-group #technologyadvisorycommittee #incadigital #trailofbits #fireblocks #abalanche #avalabs #trmlabs #circle #cftc
-
CFTC adds execs from Circle, Ava Labs and Fireblocks to tech advisory group - The technology advisory committee aims to assist the CFTC in “ide... - https://cointelegraph.com/news/cftc-adds-execs-from-circle-ava-labs-and-fireblocks-to-tech-advisory-group #technologyadvisorycommittee #incadigital #trailofbits #fireblocks #abalanche #avalabs #trmlabs #circle #cftc
-
CFTC adds execs from Circle, Ava Labs and Fireblocks to tech advisory group
https://cointelegraph.com/news/cftc-adds-execs-from-circle-ava-labs-and-fireblocks-to-tech-advisory-group
#TechnologyAdvisoryCommittee #IncaDigital #TrailofBits #FireBlocks #Abalanche #AvaLabs #TRMLabs #Circle #CFTC -
CW: Curl, security audit
I truly enjoyed reading Trail of Bits blog post on their security audit of #curl ( https://blog.trailofbits.com/2022/12/22/curl-security-audit-threat-model/ ) and @bagder answer on his blog ( https://daniel.haxx.se/blog/2022/12/21/the-2022-curl-security-audit/ ).
This is the way security audits should be handled, keeping clarity, addressing critical flaws, and working together towards a common path, software security and reliability. -
The 2022 #Curl Security Audit by #trailofbits was interesting as I've myself done quite a bit of digging into curl internals over the years. While there were many findings, only two of them were considered security vulnerabilities.
2022 security audit: https://daniel.haxx.se/blog/2022/12/21/the-2022-curl-security-audit/
older post about increased CVE activity: https://daniel.haxx.se/blog/2022/08/22/increased-cve-activity-in-curl/
-
The 2022 #Curl Security Audit by #trailofbits was interesting as I've myself quite a bit of digging into curl internals over the years. While there were many findings, only two of them were considered security vulnerabilities.
2022 security audit: https://daniel.haxx.se/blog/2022/12/21/the-2022-curl-security-audit/
older post about increased CVE activity: https://daniel.haxx.se/blog/2022/08/22/increased-cve-activity-in-curl/