Andrea Barisani(@AndreaBarisani) 's Twitter Profileg
Andrea Barisani

@AndreaBarisani

Head of Hardware Security - WithSecure - @[email protected] - @[email protected]

ID:2697758612

linkhttps://andrea.bio calendar_today01-08-2014 08:41:11

6,9K Tweets

6,6K Followers

983 Following

SummerCon(@SummerC0n) 's Twitter Profile Photo

The Summercon community is heartbroken over the loss of Sophia d'Antoine. An inspiring speaker and cherished friend, Sophia d’Antoine's contributions to Summercon and the infosec community were immeasurable. We offer our heartfelt condolences to her family and all who loved her.

account_circle
Andrea Barisani(@AndreaBarisani) 's Twitter Profile Photo

The System Shock OST on iTunes has all tracks duplicated with their Sound Blaster 2 Version and this just makes me euphoric.

account_circle
Anthony Weems(@amlweems) 's Twitter Profile Photo

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-)

github.com/amlweems/xzbot

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-) github.com/amlweems/xzbot
account_circle
Andrea Barisani(@AndreaBarisani) 's Twitter Profile Photo

No systemd or OS, immutable append only transparency log for all dependencies, single SBOM file, no system() to speak of, single ecosystem for the entire code base.

This doesn’t solve all problems but I feel much more in control.

account_circle
Jeff Geerling(@geerlingguy) 's Twitter Profile Photo

Don't touch an AM radio tower—unless you want to scream out in pain while your finger is playing a commercial!

account_circle
Andrea Barisani(@AndreaBarisani) 's Twitter Profile Photo

One of the best infosec events ever created and, for me, a career changing one. I feel so privileged to have presented there 5 times.

account_circle
Andrea Barisani(@AndreaBarisani) 's Twitter Profile Photo

Slides of my CanSecWest talk are now published!

This device runs pure bare metal Go code, all reproducible, outmost transparency even if Secure Booted and locked down.

Your SBOM is go.mod and not a single line of C in sight, all memory safe.

Slides: github.com/abarisani/abar…

Slides of my @CanSecWest talk are now published! This device runs pure bare metal Go code, all reproducible, outmost transparency even if Secure Booted and locked down. Your SBOM is go.mod and not a single line of C in sight, all memory safe. Slides: github.com/abarisani/abar…
account_circle
Ryan Hurst(@rmhrisk) 's Twitter Profile Photo

Last week, Andrea Barisani presented the hardware component of the Armored Witness at CanSecWest. github.com/abarisani/abar…

This work builds on the work we did in the Transparency team at Google to bring cryptographic verifiability to more applications.

This is the team behind

Last week, @AndreaBarisani presented the hardware component of the Armored Witness at @CanSecWest. github.com/abarisani/abar… This work builds on the work we did in the Transparency team at Google to bring cryptographic verifiability to more applications. This is the team behind
account_circle