ivs(@ivansprundel) 's Twitter Profileg
ivs

@ivansprundel

ID:3483496339

calendar_today07-09-2015 16:13:46

408 Tweets

316 Followers

462 Following

ivs(@ivansprundel) 's Twitter Profile Photo

Fucking around with signed int sizes is like playing with a loaded gun. size_t!, learn it, use it, internalize it!

account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

so when I type in 'download chrome' in a freshly installed windows VM, in edge, the actual result to download chrome is the 6th entry down. This doesn't feel like it's a coincidence...

so when I type in 'download chrome' in a freshly installed windows VM, in edge, the actual result to download chrome is the 6th entry down. This doesn't feel like it's a coincidence...
account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

In the 90s when I was an annoying teenager I've done my share of channel takeovers and the occasional server takeover, but in the end you always loose. What Andrews Lee has done is next next level. He took over the largest IRC network in the world and is expecting to keep it.

account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

For those that keep shouting 'gotos, harmful, dijkstra' anytime they see a goto error handler, I suggest you actually go read the paper :)

For those that keep shouting 'gotos, harmful, dijkstra' anytime they see a goto error handler, I suggest you actually go read the paper :)
account_circle
IOActive Labs(@IoaLabs) 's Twitter Profile Photo

IOActive Labs: No buffers harmed: Rooting Sierra Wireless AirLink devices through logic bugs by Ruben Santamarta (reversemode) labs.ioactive.com/2020/09/no-buf…

account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

Having a publicly documented security bug reporting process (e.g. email address) is a sign you care about security. If you don't have that, there's a good chance I won't report security bugs in your product (should I find one).

account_circle
IOActive, Inc(@IOActive) 's Twitter Profile Photo

Mario Ballano, Gabriel Gonzalez, Josep Pi Rodríguez, and Simon Robin, Security Consultants at IOActive, disclosed multiple vulnerabilities to Moog EXO series Cameras on June 18, 2020. Read the advisory: ioac.tv/3hy1xu6

Mario Ballano, Gabriel Gonzalez, Josep Pi Rodríguez, and Simon Robin, Security Consultants at IOActive, disclosed multiple vulnerabilities to Moog EXO series Cameras on June 18, 2020. Read the advisory: ioac.tv/3hy1xu6
account_circle
IOActive, Inc(@IOActive) 's Twitter Profile Photo

Mario Ballano, Gabriel Gonzalez, Josep Pi Rodríguez, and Simon Robin, Security Consultants at IOActive, disclosed multiple vulnerabilities to Verint PTZ Cameras on June 18, 2020. Read the advisory: ioac.tv/2Nbc40h

Mario Ballano, Gabriel Gonzalez, Josep Pi Rodríguez, and Simon Robin, Security Consultants at IOActive, disclosed multiple vulnerabilities to Verint PTZ Cameras on June 18, 2020. Read the advisory: ioac.tv/2Nbc40h
account_circle
CVE(@CVEnew) 's Twitter Profile Photo

CVE-2020-8597 eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. cve.mitre.org/cgi-bin/cvenam…

account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

If you take a moment and think about the TCB in linux/windows/osx you get lightheaded. How did we get here? where did we go wrong?

account_circle
ivs(@ivansprundel) 's Twitter Profile Photo

I always thought Postels robustness principle 'Be liberal in what you accept, and conservative in what you send.' was terrible advise, and has lead to many security bugs. Turns out I wasn't alone, rfc1122 added some much needed clarifications.

I always thought Postels robustness principle 'Be liberal in what you accept, and conservative in what you send.' was terrible advise, and has lead to many security bugs. Turns out I wasn't alone, rfc1122 added some much needed clarifications.
account_circle