home.social

#trailofbits — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trailofbits, aggregated by home.social.

fetched live
  1. #Signal adds new #security feature to thwart man-in-the-middle attacks
    Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
    The new feature is part of a "key transparency" system that uses Cloudflare and #TrailOfBits as trusted third-party independent auditors to verify the integrity of Signal conversations. bleepingcomputer.com/news/secu

  2. #Signal adds new #security feature to thwart man-in-the-middle attacks
    Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
    The new feature is part of a "key transparency" system that uses Cloudflare and #TrailOfBits as trusted third-party independent auditors to verify the integrity of Signal conversations. bleepingcomputer.com/news/secu

  3. source: 404media.co/a-secure-chat-apps…

    The #Swisscows CEO confirmed a “technically possible but artificially constructed scenario.” Trail of Bits, for its part, refers to a “misrepresentation” of the #exploit by Swisscows: “The core problem is that Teleguard’s server has all the information needed to decrypt every user’s private key and read every message,” said #DanGuido, co-founder and CEO of #TrailOfBits .

    #teleguard #chat #messenger #security #encryption #hack #hacker #software #fail #omg #wtf #news #meme #bug #internet #spy #attack #end2end #rsa

  4. 👨‍💻 Wow, an "amazing" discovery: code has bugs 🐞—who would've guessed?! 🎉 Trail of Bits bravely announces they used a tool to find issues, as if highlighting a #zero-day is akin to finding Waldo in a single-page book. 🤦‍♂️
    blog.trailofbits.com/2025/11/1 #amazingdiscovery #codebugs #TrailofBits #findings #softwareissues #HackerNews #ngated

  5. 👨‍💻 Wow, an "amazing" discovery: code has bugs 🐞—who would've guessed?! 🎉 Trail of Bits bravely announces they used a tool to find issues, as if highlighting a #zero-day is akin to finding Waldo in a single-page book. 🤦‍♂️
    blog.trailofbits.com/2025/11/1 #amazingdiscovery #codebugs #TrailofBits #findings #softwareissues #HackerNews #ngated

  6. huh #trailofbits did an audit of #simplex - only the "protocol spec" github.com/simplex-chat/simple

    quite limited scope. and last time i looked at the spec i lost my appetite, but apparently there have been updates, like addition of sntrup pq kem. so maybe this has improved? still wouldn't use it the supply chain attack surface is begging for a "soon" not an "if". and the global transcript of group chats was out of scope in this audit. so, meh?

  7. CW: Curl, security audit

    I truly enjoyed reading Trail of Bits blog post on their security audit of #curl ( blog.trailofbits.com/2022/12/2 ) and @bagder answer on his blog ( daniel.haxx.se/blog/2022/12/21 ).
    This is the way security audits should be handled, keeping clarity, addressing critical flaws, and working together towards a common path, software security and reliability.

    #infosec #trailofbits

  8. The 2022 #Curl Security Audit by #trailofbits was interesting as I've myself done quite a bit of digging into curl internals over the years. While there were many findings, only two of them were considered security vulnerabilities.

    2022 security audit: daniel.haxx.se/blog/2022/12/21

    older post about increased CVE activity: daniel.haxx.se/blog/2022/08/22

  9. The 2022 #Curl Security Audit by #trailofbits was interesting as I've myself quite a bit of digging into curl internals over the years. While there were many findings, only two of them were considered security vulnerabilities.

    2022 security audit: daniel.haxx.se/blog/2022/12/21

    older post about increased CVE activity: daniel.haxx.se/blog/2022/08/22