-
About

Apr 1, 2014 - 900 Words -
About me, the site, and its content
-
Job Hunt!

Jan 1, 0001 - 100 Words -
-
Publications

Jan 1, 0001 - 200 Words -
Presentations, Papers, other data
-
Topics

Jan 1, 0001 - 300 Words -
General topics and post types
-
Projects

Jan 1, 0001 - 500 Words -
Longer-term special projects and interests
-
Dark Mode, and other site improvements

Apr 23, 2025 - 1700 Words -
On a recent Accidental Tech Podcast member special, John Siracusa unknowingly nerd-sniped me when he mentioned adding Dark Mode to his website. This sent me down a lengthy path of improvements and fixes to this site.
-
Post

Apr 23, 2025 - 100 Words -
-
Programming

Apr 23, 2025 - 100 Words -
-
Software

Apr 23, 2025 - 100 Words -
-
Tags

Apr 23, 2025 - 100 Words -
-
Types

Apr 23, 2025 - 100 Words -
-
Web

Apr 23, 2025 - 100 Words -
-
Latest news on Spotlight Knowledge Events

Apr 18, 2025 - 700 Words -
A couple months ago, I identified a (likely) bug in Intel versions of macOS Sequoia. How's that been going? Though it's faked me out a couple times...the bug is still here, and still just as bad.
-
Macos

Apr 18, 2025 - 100 Words -
-
Troubleshooting

Apr 18, 2025 - 100 Words -
-
Howto

Apr 11, 2025 - 100 Words -
-
Technology

Apr 11, 2025 - 100 Words -
-
Tools

Apr 11, 2025 - 100 Words -
-
Word Salad - Slicing and Dicing with awk and sort

Apr 11, 2025 - 4600 Words -
You've got a big logfile, and something weird is happening, but you don't know what. There's lots of data there, and you're sure there are patterns. How can you make sense of the chaos, quickly, when you really don't even know where to begin? Sometimes, you just need The Old Tools.
-
Managing Sequoia Disk Space

Mar 11, 2025 - 3000 Words -
After a lot of exploration and experimentation, I'm finally closing in on a strategy that, if it won't SOLVE the problems Ive been having, should at least mitigate them.
-
Update on Spotlight and Disk Space Woes

Feb 27, 2025 - 2800 Words -
My Mac's disk has been filling up. I think I figured out where the problem was, but spent a week collecting data to be sure. Now I'm more confident, but also more confused.
-
macOS Sequoia Disk Space...Vanishing!

Feb 19, 2025 - 3500 Words -
My Mac Mini's disk kept filling up. A lot. Even after I got rid of crap, it filled up again. Multiple gigs in just a day. What the hell is going on?
-
Hardware

Jan 28, 2025 - 100 Words -
-
Replacing my Synology DS1515+

Jan 28, 2025 - 2200 Words -
My decade-old NAS finally conked out. Just how easy is it, really, to move the drives to a newer unit? Let's find out.
-
Puzzles

Oct 1, 2024 - 100 Words -
-
Security

Oct 1, 2024 - 100 Words -
-
Update on August Ping Storms

Oct 1, 2024 - 3900 Words -
Still poking around the Noise Storm rabbit hole. I think I've figured out the four main packet types in this storm.
-
Ping Storms at GreyNoise

Sep 27, 2024 - 2600 Words -
GreyNoise has been seeing crazy noise storms full of pings for years. I may have figured out what some of them are.
-
Funemployment, and Next Steps

Jul 9, 2024 - 2100 Words -
A year ago, I got laid off. It's been a weird ride since then...
-
Job-Hunt

Jul 9, 2024 - 100 Words -
-
Personal

Jul 9, 2024 - 100 Words -
-
Series

Jul 9, 2024 - 100 Words -
-
Work

Jul 9, 2024 - 100 Words -
-
Home-Automation

Apr 26, 2021 - 100 Words -
-
Remote-Keypad

Apr 26, 2021 - 100 Words -
-
Using an Adafruit NeoTrellis Keypad with MQTT

Apr 26, 2021 - 2200 Words -
Writing the firmware for a NeoTrellis keypad to allow it to send and receive MQTT controls, and dealing with keypad library read/write conflicts.
-
Building a remote-control home automation keypad

Apr 25, 2021 - 1100 Words -
Introduction to a series about a 16-key remote-control MQTT keypad
-
Code

Mar 11, 2021 - 100 Words -
-
Codenames Board Generator

Mar 11, 2021 - 1500 Words -
Building a board generator for Codenames as a fun diversion
-
Fun

Mar 11, 2021 - 100 Words -
-
1password

Nov 12, 2018 - 100 Words -
-
1Password - Full Trip from Unlock to Encryption

Nov 12, 2018 - 1900 Words -
Pulling the whole series together to demonstrate the 1Password vault system from unlock to item decryption
-
Cryptography

Nov 12, 2018 - 100 Words -
-
BSidesDE - A deep dive into 1Password Security

Nov 9, 2018 - 100 Words -
Slides from my BSidesDE talk, November 9, 2018. A detailed description of how 1Password client unlocking and shared vault encryption works.
-
Lists

Nov 9, 2018 - 100 Words -
-
Presentations

Nov 9, 2018 - 100 Words -
-
Reference

Nov 9, 2018 - 100 Words -
-
1Password - Wrapping up with a few quick topics

Nov 9, 2018 - 1400 Words -
Finishing the Inside 1Password series with some miscellaneous topics
-
1Password - Local Vaults

Nov 9, 2018 - 2400 Words -
Looking at how Local Vaults are encrypted, and how that affects unlocking 1Password clients
-
1Password - Into the Vaults!

Nov 9, 2018 - 1500 Words -
How 1Password's shared vaults work
-
1Password - Unlocking Windows Clients

Nov 9, 2018 - 2100 Words -
How the Encrypted Master Key works to unlock the Windows 1Password client
-
1Password - MUKing about on the Mac

Nov 9, 2018 - 2000 Words -
The Master Unlock Key and unlocking 1Pass on macOS
-
How 1Password Works - Getting under the hood

Nov 9, 2018 - 800 Words -
Beginning of a deep dive into how 1password works
-
Encrypting for Apple's Secure Enclave

May 31, 2018 - 2200 Words -
How to properly encrypt EICES-format messages to be decrypted by the iOS and macOS Secure Enclave system
-
Ios

May 31, 2018 - 100 Words -
-
Crafts

Oct 17, 2017 - 100 Words -
-
Infosec Conference Badge Display

Oct 17, 2017 - 600 Words -
I had way too many conference badges hanging from a stuffed moose head. So I built a nice display for my office.
-
Woodworking

Oct 17, 2017 - 100 Words -
-
Engineering

Sep 12, 2017 - 100 Words -
-
Rant

Sep 12, 2017 - 100 Words -
-
Technology Sucks

Sep 12, 2017 - 1500 Words -
My 3D Blu-Ray stopped working. It took an hour to figure out the stupid simple cause.
-
Astronomy

Aug 24, 2017 - 100 Words -
-
Eclipse.

Aug 24, 2017 - 3900 Words -
I've been waiting for this eclipse for nearly 40 years. Here's how I got to see it firsthand.
-
Photography

Aug 24, 2017 - 100 Words -
-
Travel

Aug 24, 2017 - 100 Words -
-
iPhone Secure Enclave Firmware Key Found

Aug 17, 2017 - 1700 Words -
The key to decrypt the firmware for the Secure Enclave Processor (SEP) on the iPhone 5S has been disclosed. It's actually potentially a good thing.
-
New Website Engine

Aug 7, 2017 - 800 Words -
I decided the site needed a visual overhaul, and didn't want to keep hacking the old engine, so found a new one.
-
Homestuff

Aug 3, 2017 - 100 Words -
-
New Standing Desk

Aug 3, 2017 - 1100 Words -
Adding a Fully Jarvis J3 standing desk frame to my IKEA desk
-
ShmooCon 2017 Badge (and more) Contest - Solutions

Jan 20, 2017 - 8500 Words -
ShmooCon 13 Badge contest, scoring, solutions to the puzzles.
-
Puzzle-Data

Jan 20, 2017 - 100 Words -
-
ShmooCon 2017 Badge (and more) Contest - Challenges

Jan 20, 2017 - 1400 Words -
Just the challenges from the 2017 ShmooCon badge puzzle / contest. No spoilers.
-
BSidesROC - A (not so quick) Primer on iOS Encryption

Apr 23, 2016 - 100 Words -
Slides from my BSidesROC talk, April 23, 2016. An overview of how iOS encryption works, with emphasis on passcoes and potential attacks.
-
Poem Codes - WWII Crypto Techniques

Mar 27, 2016 - 2700 Words -
A rough introduction to how poem codes work and how they may have been used in practice by SOE agents in WWII.
-
Put away the tin-foil: The Apple unlock case is complicated enough

Feb 19, 2016 - 2100 Words -
A high-level summary of what we know, what we think we know, and what we know we don't know, as well as some words of caution.
-
Mobile

Feb 10, 2016 - 100 Words -
-
Mobile App Authentication using TouchID and Tidas

Feb 10, 2016 - 1000 Words -
A first, rough look at a new mobile app authentication service from Trail of Bits
-
Blizzard of 2016 Time-lapse

Jan 22, 2016 - 1200 Words -
A quick, simple rig to film a time-lapse video of snow piling up on my desk in a blizzard.
-
Weather

Jan 22, 2016 - 100 Words -
-
ShmooCon - My Hash Is My Passport: Understanding Web and Mobile Authentication

Jan 17, 2016 - 400 Words -
Slides from my ShmooCon talk, January 17, 2016. A detailed overview of how Digest, NTLM, and OAuth work in the context of web and mobile applications.
-
DLP Considered Harmful - A Rant about Reliable Certificate Pinning

Nov 24, 2015 - 1600 Words -
Yet another uninformed, unrealistically idealistic rant about how things *ought* to be. Most readers will probably strongly disagree.
-
Pki

Nov 24, 2015 - 100 Words -
-
Thoughts on CyberUL and Infosec Research

Jul 29, 2015 - 1900 Words -
A discussion of ideas I've been kicking around about security research in general, and how current CyberUL speculation fits in.
-
Passwords

Apr 21, 2015 - 100 Words -
-
Salt as a Service: Interesting approach to hashing passwords

Apr 21, 2015 - 1100 Words -
A new service called Blind Hashing, that incorporates salts taken from petabyte-sized cloud databases, hopes to make password cracking obsolete.
-
Nails in the Crypt - White Paper

Mar 6, 2015 - 100 Words -
Nails in the Crypt - White Paper
-
Papers

Mar 6, 2015 - 100 Words -
-
Lenovo, CA Certs, and Trust

Feb 20, 2015 - 1000 Words -
The Lenovo-installed SuperFish man-in-the-middle malware has me thinking again about how the CA system is still broken.
-
ShmooCon - Knock Knock: A Survey of iOS Authentication Methods

Jan 23, 2015 - 1700 Words -
Slides from my ShmooCon talk. A short review of multiple iOS apps and how they handle server authentication, looking at both network use and on-device storage of credentials.
-
Appletv

Nov 18, 2014 - 100 Words -
-
DerbyCon 2013 - Apple TV and Raspberry Pi Slides

Nov 18, 2014 - 100 Words -
DerbyCon 2013 - Apple TV and Raspberry Pi Slides
-
Reverse-Engineering

Nov 18, 2014 - 100 Words -
-
Bypassing the lockout delay on iOS devices

Nov 18, 2014 - 700 Words -
A bug in iOS (fixed in 8.1.1) allows a well-timed reboot to bypass the forced lockout timeout, allowing for multiple PIN attempts.
-
Why I hate voting.

Nov 4, 2014 - 800 Words -
The parties have made voting even more of a hassle, and more infuriating, than the months of attack ads we endure.
-
What's the deal with keyless entry car thefts?

Oct 28, 2014 - 1100 Words -
Videos of people breaking into cars, and reports of hijacked dealer equipment. Real-world example of why backdoors are bad?
-
Link

Oct 27, 2014 - 100 Words -
-
MCX - a lousy substitute for proven technology

Oct 27, 2014 - 700 Words -
MCX - a lousy substitute for proven technology
-
Privacy

Oct 27, 2014 - 100 Words -
-
iPhone SMS forwarding -- cool, but may be risky

Oct 24, 2014 - 700 Words -
If you've enabled SMS forwarding on your iPhone, you might want to ensure that messages don't get displayed on your Mac when it's locked.
-
Rebutting FUD and privacy issues surrounding Yosemite Spotlight

Oct 21, 2014 - 300 Words -
A response from Apple downplays security concerns raised over how Spotlight search works on Yosemite.
-
NoVA Hackers - iOS Cryptography Slides

Oct 14, 2014 - 700 Words -
Slides from a quick NoVA Hackers talk I pulled together based on recent blog posts about Apple iOS encryption and privacy changes.
-
Even more posts about iOS encryption

Oct 8, 2014 - 700 Words -
The "Apple can't decrypt devices for law enforcement" conversation continues to spawn excellent posts and explanations.
-
A (not so) quick primer on iOS encryption

Oct 6, 2014 - 3900 Words -
Making sense of how iOS encryption works, especially what's changed in iOS 8 and how Apple made it harder for law enforcement, can be difficult. I'll try to help.
-
Beacons being deployed in NYC phone booths

Oct 6, 2014 - 300 Words -
Advertising companies are placing Bluetooth beacons in New York City phone booths. Forbes explains this isn't quite as scary as many think.
-
Data

Sep 5, 2014 - 100 Words -
-
Internet of SCADA, or, why does my HVAC blow?

Sep 5, 2014 - 1900 Words -
My HVAC system is constantly failing. I'm building a system to closely monitor temps so I can catch failures earlier. After only a couple days with rough prototypes I'm already learning something useful.
-
Praetorian Crypto Challenge

Aug 25, 2014 - 600 Words -
A fun set of (reasonably) quick crypto, puzzle, and hacking challenges from Praetorian.
-
Stealing user events from foreground apps on Android

Aug 22, 2014 - 200 Words -
Quick description and demo videos for activity hijacking to steal user-entered data like passwords, credit card numbers, and check images. Includes links to USENIX paper.
-
BSidesLV 2014 Badge Contest

Aug 10, 2014 - 4500 Words -
A badge puzzle / mini CTF at BSidesLV 2014. Created by Zack Fasel, sponsered by Urbane Security, won (somewhat soundly) by Darth Null.
-
BSidesLV 2014 Badge Contest - Challenges

Aug 10, 2014 - 500 Words -
Just the challenges for the 2014 BSides Las Vegas badge puzzle / contest. No spoilers.
-
BSLV 2014 - Breaking PRNGs

Aug 6, 2014 - 400 Words -
Quick review of BSidesLV Talk, in which they describe problems with the Mersenne Twister and other similer pseudo-random number generators.
-
Duo Security Bypasses PayPal 2FA for Mobile Apps

Jun 25, 2014 - 300 Words -
Paypal mobile app authenticates, then kicks you out because it's not two-factor compliant. They show how to leverage this into non 2FA access.
-
Early look at iOS 8 configuration profile changes

Jun 18, 2014 - 200 Words -
A quick overview of changes to iOS configuation profile settings in the current iOS 8 beta.
-
More Mobile Malware Melodrama

Jun 17, 2014 - 500 Words -
Lots of press recently about a potentially serious malware called Svpeng. A nice case study in the use of FUD in mainstream tech press.
-
iOS Malware - Still FUDish, not quite a Real Problem (yet)

Jun 10, 2014 - 800 Words -
A consolidated list of known malware for iOS. Depending on your definition of malware.
-
Crazy-Ideas

Jun 2, 2014 - 100 Words -
-
Memory Pressure, Capacity Limits, and Ubiquitous Computing

Jun 2, 2014 - 900 Words -
Last year, Apple introduced advanced power saving techniques. Can they do the same for memory? There’s never enough to smoothly switch between apps. If they can fix that, a world of opportunities opens.
-
Making Tunnelblick + Google Authenticator Easier to Use

May 30, 2014 - 1100 Words -
VPNs which require 2-Factor Google Authenticator codes are a pain to start up in Tunnelblick on OS X. Here's a script to make it easier.
-
Apple ID Compromise and Device Lockout

May 27, 2014 - 400 Words -
Recent reports of users getting locked out of their iOS devices, probably due to compromise of their Apple ID password.
-
iOS Backups are Still Broken

May 19, 2014 - 500 Words -
Backing up iOS devices to iCloud is still opaque and unreliable. And iTunes Wi-Fi backups just don't work at all.
-
How much of your email goes through Google?

May 12, 2014 - 200 Words -
Running your own server to protect the anonymity and content of your email is great, as long as nobody else you exchange messages with uses Gmail. How many of your emails are also on a Google server?
-
Bugs

May 8, 2014 - 100 Words -
-
Inadvertent OS X Mail Loading of Images in SPAM

May 8, 2014 - 300 Words -
Mail.app's protection against loading images on suspected SPAM messages is broken when forwarding the email to a spam-reporting service.
-
Osx

May 8, 2014 - 100 Words -
-
Dark Reading on the VZ DBIR puzzle

May 6, 2014 - 100 Words -
Dark Reading article on the DBIR Puzzle
-
Referrer considered harmful: Leaking location of obscurely shared docs

May 6, 2014 - 300 Words -
Shared files, hidden by the obscurity of their URLs, may be revealed to third parties if the files contain a link to an external site. The remote site can find the file via the referrer header.
-
Apple ID Madness

May 4, 2014 - 1100 Words -
How we set up multiple personal iCloud accounts for the family, and a couple of shared accounts for parents and kids.
-
Blabbering

May 2, 2014 - 100 Words -
-
It's time to (re)start.

May 2, 2014 - 300 Words -
-
BSidesROC 2014 - Crypto Puzzle

Apr 5, 2014 - 100 Words -
-
Crosspost

Mar 10, 2014 - 100 Words -
-
Sanitize your outputs: Apple ID Password Logfile Disclosure

Mar 10, 2014 - 1500 Words -
-
CVE-2014-1279 - Password Disclosure via Apple TV Touch Setup

Mar 10, 2014 - 1400 Words -
-
More Fun with Apple TV Hacking (and Manual RSA Signature Validation)

Feb 21, 2014 - 1800 Words -
-
Apple TV Hacking, Counterattacks, and Certificate Pinning

Feb 11, 2014 - 1000 Words -
-
ShmooCon 2014 - Crypto Puzzle Slides

Jan 19, 2014 - 100 Words -
-
Good fun with bad crypto

Jan 15, 2014 - 1300 Words -
-
Raspberry Pi Media Center on AppleTV - No Jailbreak Required

Sep 29, 2013 - 2600 Words -
-
iStupid: the indescreet SSID tool

Jun 19, 2013 - 200 Words -
-
Hijacking accounts using unicode magic

Jun 18, 2013 - 200 Words -
-
Apple's security strategy: make it invisible

Jun 14, 2013 - 200 Words -
-
A chameleon for your streams

Jun 13, 2013 - 200 Words -
-
iOS 7 and Mavericks: New feature roundup from a security perspective – Intrepidus Group - Insight

Jun 11, 2013 - 100 Words -
-
iOS 7 and Mavericks: New feature roundup from a security perspective

Jun 11, 2013 - 1300 Words -
-
Android Security Overview

Jun 5, 2013 - 100 Words -
-
Skout server leaked nearly-exact location information on users

May 31, 2013 - 200 Words -
-
Auto-updating iOS apps

May 22, 2013 - 100 Words -
-
Two-factor authentication for Twitter: One account at a time

May 22, 2013 - 200 Words -
-
Google Hangouts and XMPP

May 17, 2013 - 400 Words -
-
Recovering iPhone Restrictions Passcode

May 16, 2013 - 100 Words -
-
Social Share Privacy

May 16, 2013 - 200 Words -
-
How To Safely Store A Password

May 16, 2013 - 100 Words -
-
Apple, Forensics, Law Enforcement, and FUD

May 13, 2013 - 1400 Words -
-
iSniff your Wi-Fi and GPS your House

May 10, 2013 - 1300 Words -
-
Risk

May 10, 2013 - 100 Words -
-
Archived-Comments

May 10, 2013 - 100 Words -
-
iSniff your WiFi - Archived Comments

May 10, 2013 - 600 Words -
-
DBIR Cover Challenge 2013

Apr 29, 2013 - 2400 Words -
-
2013 DBIR Puzzle - Archived Comments

Apr 29, 2013 - 300 Words -
-
iOS Configuration Profile Ransomware

Apr 11, 2013 - 600 Words -
-
Phishing

Apr 11, 2013 - 100 Words -
-
ShmooCon 2013 - Crypto Puzzle Slides

Feb 17, 2013 - 100 Words -
-
Conferences

Feb 12, 2013 - 100 Words -
-
Getting ready for ShmooCon

Feb 12, 2013 - 300 Words -
-
Evading evasi0n: iOS 6 Jailbreak Prevention

Feb 5, 2013 - 600 Words -
-
Mdm

Feb 5, 2013 - 100 Words -
-
Tracking Down the UDID Source - Archived Comments

Sep 10, 2012 - 1100 Words -
-
Breach

Sep 10, 2012 - 100 Words -
-
Fidelis Decode This 2012 - Archived Comments

Sep 10, 2012 - 100 Words -
-
Tracking Down the UDID Breach Source

Sep 10, 2012 - 1500 Words -
-
What the flagnog? The Apple / FBI UDID breach, simplified.

Sep 5, 2012 - 1200 Words -
-
Winning the Decode This! puzzle at Black Hat

Aug 17, 2012 - 300 Words -
-
Fidelis Security Systems' Decode This 2012

Aug 17, 2012 - 1200 Words -
-
FidSecSys Decode This 2012 Ciphertext and Hints

Aug 17, 2012 - 200 Words -
-
Apple's iOS Security Overview

Jun 20, 2012 - 600 Words -
-
Apple Using Unsalted Hashes Too?

Jun 7, 2012 - 600 Words -
-
Verizon 2012 DBIR Challenge

Mar 28, 2012 - 400 Words -
-
2012 DBIR Puzzle - Archived Comments

Mar 28, 2012 - 600 Words -
-
2012 Verizon DBIR Cover Challenge

Mar 28, 2012 - 3700 Words -
-
Verizon 2012 DBIR Sources

Mar 28, 2012 - 400 Words -
-
Quick Look at Apple Configurator

Mar 9, 2012 - 800 Words -
-
MDM Hacks - Archived Comments

Feb 27, 2012 - 400 Words -
-
iOS MDM: Preventing Disassociation DOS and Potemkin Devices

Feb 22, 2012 - 600 Words -
-
Verifying a Detached S/MIME Signature in Python

Feb 21, 2012 - 600 Words -
-
BSides Phoenix 2012 Badge Puzzle

Feb 19, 2012 - 1500 Words -
-
BSidesPHX 2012 Images

Feb 19, 2012 - 100 Words -
-
Changes to iOS 5.0 MDM - Archived Comments

Feb 15, 2012 - 1100 Words -
-
ShmooCon 2008 Puzzle - Archived Comments

Feb 10, 2012 - 300 Words -
-
ShmooCon 2008 Badge Puzzle

Feb 4, 2012 - 1900 Words -
-
ShmooCon 2012 Puzzle - Archived Comments

Feb 4, 2012 - 1700 Words -
-
ShmooCon 2012 Badge Puzzle

Feb 3, 2012 - 1800 Words -
-
ShmooCon 2012 Puzzle Data

Feb 3, 2012 - 100 Words -
-
ShmooCon 2012 Puzzle Slides

Feb 3, 2012 - 100 Words -
-
Changes to Apple MDM for iOS 5.x

Jan 31, 2012 - 300 Words -
-
ShmooCon 2012 - Apple MDM Slides

Jan 28, 2012 - 100 Words -
-
iOS MDM Command Reference

Jan 26, 2012 - 100 Words -
-
Finding Which Root CAs You Actually Use

Sep 2, 2011 - 500 Words -
-
BlackHat 2011 Fidelis Puzzle - Archived Comments

Aug 30, 2011 - 100 Words -
-
How to Lose $1000 in Vegas Without Even Gambling

Aug 30, 2011 - 1900 Words -
-
Fidelis Security "Decode This" Black Hat Challenge

Aug 30, 2011 - 100 Words -
-
First Anniversary

Aug 23, 2011 - 600 Words -
-
BlackHat 2011 Preview - Archived Comments

Aug 21, 2011 - 100 Words -
-
Strengths and Weaknesses in Apple's MDM System

Aug 5, 2011 - 1400 Words -
-
BlackHat 2011 - Apple MDM Paper

Aug 4, 2011 - 100 Words -
-
BlackHat 2011 - Apple MDM Slides

Aug 4, 2011 - 100 Words -
-
CarolinaCon Flag Puzzle - Archived Comments

Jul 28, 2011 - 200 Words -
-
DEF CON 16 Puzzle - Archived Comments

Jul 28, 2011 - 100 Words -
-
Inside Apple's MDM Black Box -- Black Hat USA 2011

Jul 28, 2011 - 500 Words -
-
Great Googly Moogly! I'm speaking at Black Hat!

Jul 28, 2011 - 800 Words -
-
DEF CON 16 Punch Card Puzzle

Jul 27, 2011 - 1400 Words -
-
Nails in the Crypt - Archvied Comments

May 23, 2011 - 400 Words -
-
CarolinaCon Flag Puzzle

May 8, 2011 - 1800 Words -
-
Analysis of iOS Location Data from Multiple Devices

Apr 25, 2011 - 2100 Words -
-
Is the iOS 4 location tracking privacy issue overblown?

Apr 20, 2011 - 600 Words -
-
The 2009 Verizon Data Breach Investigation Report

Apr 12, 2011 - 1500 Words -
-
2009 Verizon DBIR Ciphertext

Apr 12, 2011 - 100 Words -
-
NoVAHackers - Nails in the Crypt slides

Apr 11, 2011 - 100 Words -
-
Quantifying the Unknown: Measuring a Theoretical SecurID Attack

Mar 22, 2011 - 1700 Words -
-
The RSA/SecurID Compromise: What is my risk?

Mar 18, 2011 - 900 Words -
-
RSA/SecurID Compromise - Archived Comments

Mar 18, 2011 - 1500 Words -
-
iOS Overlays - Archived Comments

Mar 12, 2011 - 100 Words -
-
VeriFone vs Square - A Draw?

Mar 9, 2011 - 600 Words -
-
Crazy idea for multi-user iPads

Feb 25, 2011 - 700 Words -
-
Simple Bypass of Safari Restrictions on iOS

Feb 15, 2011 - 600 Words -
-
Bypassing MDM Restrictions for Mobile Safari on iOS 4.2

Feb 15, 2011 - 700 Words -
-
ShmooCon 2011 Puzzle - Archived Comments

Feb 9, 2011 - 100 Words -
-
ShmooCon 2011 Badge Contest

Feb 9, 2011 - 4400 Words -
-
ShmooCon 7 Ciphertexts

Feb 9, 2011 - 1200 Words -
-
Breaking a 147-Year-Old Message

Dec 30, 2010 - 4000 Words -
-
Civil War Code Ciphertext

Dec 30, 2010 - 300 Words -
-
Civil War Ciphers Fall!

Dec 30, 2010 - 900 Words -
-
Nails in the Crypt

Dec 22, 2010 - 800 Words -
-
Rainbow Tables for Unix DES Crypt(3) Hashes

Dec 20, 2010 - 600 Words -
-
ToorCon 12 Puzzle - Archived Comments

Dec 7, 2010 - 400 Words -
-
ToorCon 12 Badge Puzzle Ciphertexts

Dec 6, 2010 - 400 Words -
-
ToorCon 12 Badge Puzzle

Dec 6, 2010 - 4500 Words -
-
THOTCON Pre-Sale Code Puzzle

Nov 22, 2010 - 2700 Words -
-
DEF CON 18 Crypto Challenge

Sep 2, 2010 - 3700 Words -
-
DEF CON 18 Crypto Challenge Ciphertexts

Sep 2, 2010 - 600 Words -
-
Puzzles and Contests

Aug 29, 2010 - 1800 Words -
A quick list of some of the puzzles or contests that I've won, with links to writeups (when they exist).
-
ShmooCon 2010 Badge Puzzle Data

Aug 29, 2010 - 100 Words -
-
ShmooCon 2010 Badge Contest

Aug 29, 2010 - 2500 Words -
-
Quahogcon Flag Puzzle - Archived Comments

Aug 24, 2010 - 300 Words -
-
QuahogCon Flag Puzzle

May 20, 2010 - 1900 Words -
-
THOTCON 0x1 - Archived Comments

May 11, 2010 - 200 Words -
-
THOTCON 0x1 Puzzle

May 11, 2010 - 2900 Words -
-
ShmooCon 2009 Badge Contest

Apr 27, 2010 - 2000 Words -
-
Crazy Security Con Weekend!

Apr 23, 2010 - 500 Words -
-
Khanfu

Apr 23, 2010 - 100 Words -
-
Belief-vs-Skepticism - Archived Comments

Apr 20, 2010 - 900 Words -
-
Blind Belief vs Excessive Skepticism

Apr 20, 2010 - 1300 Words -
-
Half-Baked Idea: Isolate Browser Security Contexts to Limit XSS Attacks

Apr 14, 2010 - 1300 Words -
-
It's Time To Start

Apr 14, 2010 - 200 Words -
-
Talks and Presentations

Jan 1, 0001 - 400 Words -