Ryan Duff (@flyryan) 's Twitter Profile
Ryan Duff

@flyryan

Former Cyber Operations Tactician - USCYBERCOM. Tradecraft stickler. Tech Policy/Law Hobbyist. Sneakerhead. USAF vet.

ID: 3473141

calendar_today05-04-2007 00:00:50

13,13K Tweet

3,3K Followers

1,1K Following

Ryan Duff (@flyryan) 's Twitter Profile Photo

Since I've been invoked in a post about the security of your product, how is Zengo Wallet a non-custodial wallet when you use a third party to store and validate the biometrics needed for recovery of the wallet? What happens if that third party goes away? Legit curious. Tal Be'ery

Ryan Duff (@flyryan) 's Twitter Profile Photo

My hometown had a block party event downtown for NYE. For the countdown, they put a tobacco leaf on a lift and lowered it. No crazy lights or pyro. Just a leaf going down some.

Ryan Duff (@flyryan) 's Twitter Profile Photo

Wait... What does this prove? They took something that should never touch the internet (a hardware wallet private key) and put it on iCloud. How does this prove the security of ZenGo? This comes off as ZenGo trying to pass this challenge off as a proper representation of their

Ryan Duff (@flyryan) 's Twitter Profile Photo

It's nuts that gov accounts don't have mandatory 2FA honestly but it's also nuts that the SEC didn't have it enabled. Maybe they should have listened to their own advice.

Christopher C. Cuomo (@chriscuomo) 's Twitter Profile Photo

Companies/govt need to be quick abt saying what caused this to stop speculation...they know or will know quickly I am told by two it experts in the space. Transparency!

Ryan Duff (@flyryan) 's Twitter Profile Photo

Has anyone managed to get a statement from AT&T about what’s going on? Their twitter hasn’t been updated in 3 days and their reps are taking customers to DMs to “help”. #attoutage

Ryan Duff (@flyryan) 's Twitter Profile Photo

Sounds like the answer is no. Coming up on 8 hours without any comms from AT&T about what is happening, even though there is rampant speculation. #attoutage

Bad Sector Labs (@badsectorlabs) 's Twitter Profile Photo

The xz package tar's were backdoored. Only discovered because the backdoor slowed down sshd enough for Andres Freund to investigate. Consider the case where the backdoor didn't cause perf issues... How long would this have gone undetected? openwall.com/lists/oss-secu…

Bad Sector Labs (@badsectorlabs) 's Twitter Profile Photo

Are you ready for a world where AI models are better than most junior pentesters? How long until they are as good as senior red teamers?