Dan Guido(@dguido) 's Twitter Profileg
Dan Guido

@dguido

CEO @trailofbits, organizer @EmpireHacking. Open DMs.

ID:14290525

linkhttps://www.trailofbits.com calendar_today03-04-2008 05:05:38

10,3K Tweets

24,6K Followers

861 Following

Moxie Marlinspike(@moxie) 's Twitter Profile Photo

You know those janky secure send web portal things lawyers, CPAs, etc use for “secure email” — but just upload the attachment to a pile on some random server somewhere?

Those always seemed like a huge disaster waiting to happen to me, but I’ve never seen a major pub compromise?

account_circle
Heather Adkins - Ꜻ - Spes consilium non est(@argvee) 's Twitter Profile Photo

Unpopular opinion: now's the time for us to get serious about measuring open-source projects using SLSA, and getting everyone to Level 4 with mandatory 2-party code reviews. slsa.dev/spec/v0.1/leve…

account_circle
Dan Guido(@dguido) 's Twitter Profile Photo

Does anyone remember a visual AI search engine that hit Hacker News about a month ago? It collapsed under the load. You could e.g., search a music genre and it would map out artists, influences, related trends, major events, etc. Seemed like it was a small, early, team.

account_circle
Maddie Stone(@maddiestone) 's Twitter Profile Photo

🪲And the 2023 Year in Review of Zero-Days Exploited In-the-Wild is out!

This year I teamed up with Jared Semrau & James from Mandiant to write a joint report combining our expertise and providing a more holistic view on in-the-wild 0-days in 2023 🔥🧐

blog.google/technology/saf…

🪲And the 2023 Year in Review of Zero-Days Exploited In-the-Wild is out! This year I teamed up with @JaredSemrau & James from Mandiant to write a joint report combining our expertise and providing a more holistic view on in-the-wild 0-days in 2023 🔥🧐 blog.google/technology/saf…
account_circle
Helthydriver(@Helthydriver) 's Twitter Profile Photo

Early fall last year we received an iTunes Backup: And I found THE *needle* in the haystack! A sample of NSO Pegasus BLASTPASS Exploit Chain.

Have a look at this blogpost which reveals some of my early steps of the analysis.

iverify.io/post/clipping-…

account_circle
Andre(@mryoukhna) 's Twitter Profile Photo

Learn the story behind The Minimal Phone: First E-Ink QWERTY Phone and help us meet our goal. @indiegogo igg.me/at/minimal

account_circle
Josselin Feist(@Montyly) 's Twitter Profile Photo

A lot of people ask us why we use fuzzing over formal methods.

The tldr: fuzzers have a superior effort-to-reward ratio, but what really matter is the quality of your invariants

account_circle
Ate-a-Pi(@8teAPi) 's Twitter Profile Photo

Inflection Deal

> too much capital and talent needed for next generation
> no real way to exit
> Reid Hoffmann looking to engineer an acquihire
> MSFT unwilling to bite at $4 bil
> so they engineered an earn-out deal
> allowing founders and research team to leave
> investors…

Inflection Deal > too much capital and talent needed for next generation > no real way to exit > Reid Hoffmann looking to engineer an acquihire > MSFT unwilling to bite at $4 bil > so they engineered an earn-out deal > allowing founders and research team to leave > investors…
account_circle
Dan Guido(@dguido) 's Twitter Profile Photo

Attacknet is the best available tool for addressing the largest security risks to layer 1 blockchains
twitter.com/trailofbits/st…

account_circle
Dan Guido(@dguido) 's Twitter Profile Photo

.Trail of Bits is making a big investment in post-quantum cryptography (PQC) this year. If that's something you're ready to work on, we're doing security reviews *and* custom engineering.

account_circle
Evan Sultanik(@ESultanik) 's Twitter Profile Photo

I had to try this myself. Trail of Bits was apparently founded by ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ ☕️📚💡 and Elijah Savage, not Dan Guido and Alex Sotirov. It is known for having created the fastest open-source password cracker in the world, Shellphish.

I had to try this myself. @trailofbits was apparently founded by @DanielMiessler and Elijah Savage, not @dguido and @alexsotirov. It is known for having created the fastest open-source password cracker in the world, @shellphish.
account_circle
Empire Hacking(@EmpireHacking) 's Twitter Profile Photo

Join us for beers and brats for Brooklyn Overflow, our social meetup hosted at DSK Brooklyn, our favorite German beer garden. meetup.com/empire-hacking…

account_circle
Dan Guido(@dguido) 's Twitter Profile Photo

.Trail of Bits has not been the most consistent with sharing our vulnerability disclosures over the years 😬.

Today, we dug into our archives and pulled out a pervasive JWT library flaw and a Linux KASLR bypass.
twitter.com/trailofbits/st…

account_circle