Archives
All the posts, in one place.
- post
- puzzles
- security
- Tags
- Types
- Update on August Ping Storms
- infosec
- Ping Storms at GreyNoise
- Funemployment, and Next Steps
- personal
- work
- hardware
- home-automation
- remote-keypad
- Series
- Using an Adafruit NeoTrellis Keypad with MQTT
- Building a remote-control home automation keypad
- code
- Codenames Board Generator
- fun
- 1password
- 1Password - Full Trip from Unlock to Encryption
- cryptography
- BSidesDE - A deep dive into 1Password Security
- Lists
- presentations
- reference
- 1Password - Wrapping up with a few quick topics
- 1Password - Local Vaults
- 1Password - Into the Vaults!
- 1Password - Unlocking Windows Clients
- 1Password - MUKing about on the Mac
- How 1Password Works - Getting under the hood
- Encrypting for Apple's Secure Enclave
- ios
- macos
- crafts
- Infosec Conference Badge Display
- woodworking
- engineering
- rant
- technology
- Technology Sucks
- astronomy
- Eclipse.
- photography
- travel
- iPhone Secure Enclave Firmware Key Found
- New Website Engine
- software
- homestuff
- New Standing Desk
- ShmooCon 2017 Badge (and more) Contest - Solutions
- puzzle-data
- ShmooCon 2017 Badge (and more) Contest - Challenges
- BSidesROC - A (not so quick) Primer on iOS Encryption
- Poem Codes - WWII Crypto Techniques
- Put away the tin-foil: The Apple unlock case is complicated enough
- mobile
- Mobile App Authentication using TouchID and Tidas
- Blizzard of 2016 Time-lapse
- weather
- ShmooCon - My Hash Is My Passport: Understanding Web and Mobile Authentication
- DLP Considered Harmful - A Rant about Reliable Certificate Pinning
- pki
- Thoughts on CyberUL and Infosec Research
- passwords
- Salt as a Service: Interesting approach to hashing passwords
- Nails in the Crypt - White Paper
- papers
- Lenovo, CA Certs, and Trust
- ShmooCon - Knock Knock: A Survey of iOS Authentication Methods
- appletv
- DerbyCon 2013 - Apple TV and Raspberry Pi Slides
- reverse-engineering
- Bypassing the lockout delay on iOS devices
- Why I hate voting.
- What's the deal with keyless entry car thefts?
- link
- MCX - a lousy substitute for proven technology
- privacy
- iPhone SMS forwarding -- cool, but may be risky
- Rebutting FUD and privacy issues surrounding Yosemite Spotlight
- NoVA Hackers - iOS Cryptography Slides
- Even more posts about iOS encryption
- A (not so) quick primer on iOS encryption
- Beacons being deployed in NYC phone booths
- data
- Internet of SCADA, or, why does my HVAC blow?
- Praetorian Crypto Challenge
- Stealing user events from foreground apps on Android
- BSidesLV 2014 Badge Contest
- BSidesLV 2014 Badge Contest - Challenges
- BSLV 2014 - Breaking PRNGs
- Duo Security Bypasses PayPal 2FA for Mobile Apps
- Early look at iOS 8 configuration profile changes
- More Mobile Malware Melodrama
- iOS Malware - Still FUDish, not quite a Real Problem (yet)
- crazy-ideas
- Memory Pressure, Capacity Limits, and Ubiquitous Computing
- Making Tunnelblick + Google Authenticator Easier to Use
- Apple ID Compromise and Device Lockout
- iOS Backups are Still Broken
- How much of your email goes through Google?
- bugs
- Inadvertent OS X Mail Loading of Images in SPAM
- osx
- Dark Reading on the VZ DBIR puzzle
- Referrer considered harmful: Leaking location of obscurely shared docs
- Apple ID Madness
- howto
- blabbering
- It's time to (re)start.
- BSidesROC 2014 - Crypto Puzzle
- About
- crosspost
- Sanitize your outputs: Apple ID Password Logfile Disclosure
- CVE-2014-1279 - Password Disclosure via Apple TV Touch Setup
- More Fun with Apple TV Hacking (and Manual RSA Signature Validation)
- Apple TV Hacking, Counterattacks, and Certificate Pinning
- ShmooCon 2014 - Crypto Puzzle Slides
- Good fun with bad crypto
- Raspberry Pi Media Center on AppleTV - No Jailbreak Required
- iStupid: the indescreet SSID tool
- Hijacking accounts using unicode magic
- Apple's security strategy: make it invisible
- A chameleon for your streams
- iOS 7 and Mavericks: New feature roundup from a security perspective – Intrepidus Group - Insight
- iOS 7 and Mavericks: New feature roundup from a security perspective
- Android Security Overview
- Skout server leaked nearly-exact location information on users
- Auto-updating iOS apps
- Two-factor authentication for Twitter: One account at a time
- Google Hangouts and XMPP
- Recovering iPhone Restrictions Passcode
- Social Share Privacy
- How To Safely Store A Password
- Apple, Forensics, Law Enforcement, and FUD
- iSniff your Wi-Fi and GPS your House
- risk
- tools
- archived-comments
- iSniff your WiFi - Archived Comments
- DBIR Cover Challenge 2013
- 2013 DBIR Puzzle - Archived Comments
- iOS Configuration Profile Ransomware
- phishing
- ShmooCon 2013 - Crypto Puzzle Slides
- conferences
- Getting ready for ShmooCon
- Evading evasi0n: iOS 6 Jailbreak Prevention
- mdm
- Tracking Down the UDID Source - Archived Comments
- breach
- Fidelis Decode This 2012 - Archived Comments
- Tracking Down the UDID Breach Source
- What the flagnog? The Apple / FBI UDID breach, simplified.
- Winning the Decode This! puzzle at Black Hat
- Fidelis Security Systems' Decode This 2012
- FidSecSys Decode This 2012 Ciphertext and Hints
- Apple's iOS Security Overview
- Apple Using Unsalted Hashes Too?
- Verizon 2012 DBIR Challenge
- 2012 DBIR Puzzle - Archived Comments
- 2012 Verizon DBIR Cover Challenge
- Verizon 2012 DBIR Sources
- Quick Look at Apple Configurator
- MDM Hacks - Archived Comments
- iOS MDM: Preventing Disassociation DOS and Potemkin Devices
- Verifying a Detached S/MIME Signature in Python
- BSides Phoenix 2012 Badge Puzzle
- BSidesPHX 2012 Images
- Changes to iOS 5.0 MDM - Archived Comments
- ShmooCon 2008 Puzzle - Archived Comments
- ShmooCon 2008 Badge Puzzle
- ShmooCon 2012 Puzzle - Archived Comments
- ShmooCon 2012 Badge Puzzle
- ShmooCon 2012 Puzzle Data
- ShmooCon 2012 Puzzle Slides
- Changes to Apple MDM for iOS 5.x
- ShmooCon 2012 - Apple MDM Slides
- iOS MDM Command Reference
- Finding Which Root CAs You Actually Use
- BlackHat 2011 Fidelis Puzzle - Archived Comments
- How to Lose $1000 in Vegas Without Even Gambling
- Fidelis Security "Decode This" Black Hat Challenge
- First Anniversary
- BlackHat 2011 Preview - Archived Comments
- Strengths and Weaknesses in Apple's MDM System
- BlackHat 2011 - Apple MDM Paper
- BlackHat 2011 - Apple MDM Slides
- CarolinaCon Flag Puzzle - Archived Comments
- DEF CON 16 Puzzle - Archived Comments
- Inside Apple's MDM Black Box -- Black Hat USA 2011
- Great Googly Moogly! I'm speaking at Black Hat!
- DEF CON 16 Punch Card Puzzle
- Nails in the Crypt - Archvied Comments
- CarolinaCon Flag Puzzle
- Analysis of iOS Location Data from Multiple Devices
- Is the iOS 4 location tracking privacy issue overblown?
- The 2009 Verizon Data Breach Investigation Report
- 2009 Verizon DBIR Ciphertext
- NoVAHackers - Nails in the Crypt slides
- Quantifying the Unknown: Measuring a Theoretical SecurID Attack
- The RSA/SecurID Compromise: What is my risk?
- RSA/SecurID Compromise - Archived Comments
- iOS Overlays - Archived Comments
- VeriFone vs Square - A Draw?
- Crazy idea for multi-user iPads
- Simple Bypass of Safari Restrictions on iOS
- Bypassing MDM Restrictions for Mobile Safari on iOS 4.2
- ShmooCon 2011 Puzzle - Archived Comments
- ShmooCon 2011 Badge Contest
- ShmooCon 7 Ciphertexts
- Breaking a 147-Year-Old Message
- Civil War Code Ciphertext
- Civil War Ciphers Fall!
- Nails in the Crypt
- Rainbow Tables for Unix DES Crypt(3) Hashes
- ToorCon 12 Puzzle - Archived Comments
- ToorCon 12 Badge Puzzle Ciphertexts
- ToorCon 12 Badge Puzzle
- THOTCON Pre-Sale Code Puzzle
- DEF CON 18 Crypto Challenge
- DEF CON 18 Crypto Challenge Ciphertexts
- Puzzles and Contests
- ShmooCon 2010 Badge Puzzle Data
- ShmooCon 2010 Badge Contest
- Quahogcon Flag Puzzle - Archived Comments
- QuahogCon Flag Puzzle
- THOTCON 0x1 - Archived Comments
- THOTCON 0x1 Puzzle
- ShmooCon 2009 Badge Contest
- Crazy Security Con Weekend!
- khanfu
- Belief-vs-Skepticism - Archived Comments
- Blind Belief vs Excessive Skepticism
- Half-Baked Idea: Isolate Browser Security Contexts to Limit XSS Attacks
- It's Time To Start
- Projects
- Publications
- Talks and Presentations
- Topics