Phil Ames (@philames) 's Twitter Profile
Phil Ames

@philames

Information security professional. Tweets/opinions are my own.

infosec.exchange/@failames

ID: 37951495

linkhttp://www.linkedin.com/in/phillipames calendar_today05-05-2009 15:54:19

1,1K Tweet

723 Followers

1,1K Following

0xor0ne (@0xor0ne) 's Twitter Profile Photo

Free Rust course developed by the Android team at Google "Comprehensive Rust" google.github.io/comprehensive-… #rustlang

Free Rust course developed by the Android team at Google

"Comprehensive Rust"

google.github.io/comprehensive-…

#rustlang
Phil Ames (@philames) 's Twitter Profile Photo

Now waiting for the "Derek Zoolander school for those who can't use LLMs good and want to learn how to do other stuff good too" to open up.

GitHub Projects Community (@githubprojects) 's Twitter Profile Photo

| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| | Don't Push To Production On Friday | |_________________| \ (•◡•) / \ / —— | | |_ |_

Ben Hawkes (@benhawkes) 's Twitter Profile Photo

"OpenSSH Backdoors" -- a few thoughts on supply-chain attacks against OpenSSH, and what we can learn from both historical and modern events. blog.isosceles.com/openssh-backdo…

Hayden Barnes (@unixterminal) 's Twitter Profile Photo

Microsoft has open sourced its new cross-platform virtual machine layer written in Rust: github.com/microsoft/open… From many of the same team who created WSL, including 𝕓𝕖𝕟 𝕙𝕚𝕝𝕝𝕚𝕤.

yan (@bcrypt) 's Twitter Profile Photo

reminder that the bcrypt hash function ignores input above a certain length! so if you do bcrypt(username || password) for some reason, a sufficiently long username will make it accept any password. to fix this you can sha256 the input first.

nixCraft 🐧 (@nixcraft) 's Twitter Profile Photo

Heads up: Microsoft Office, like many companies in recent months, has slyly turned on an “opt-out” feature that scrapes your Word and Excel documents to train its internal AI systems. This setting is turned on by default, and you have to manually uncheck a box in order to opt

Heads up: Microsoft Office, like many companies in recent months, has slyly turned on an “opt-out” feature that scrapes your Word and Excel documents to train its internal AI systems. This setting is turned on by default, and you have to manually uncheck a box in order to opt
Dino A. Dai Zovi (@dinodaizovi) 's Twitter Profile Photo

The lack of end-to-end encryption through the telco infra *is* the vulnerability. We improved Internet infra security by largely de-privileging the intermediate hops through widespread use of TLS. Now attackers go for VPN boxes because that's where traffic exists in plaintext.

remy🐀 (@_mattata) 's Twitter Profile Photo

A lot of people don’t know this, but any platform Chrome runs on *except iOS* has a fully featured Bluetooth scanner that allows viewing, connecting, and read/writing GATT attributes. Go have some fun. You already have the tools chrome://bluetooth-internals

A lot of people don’t know this, but any platform Chrome runs on *except iOS* has a fully featured Bluetooth scanner that allows viewing, connecting, and read/writing GATT attributes.
Go have some fun. You already have the tools
chrome://bluetooth-internals
Michal Melewski (@carste1n) 's Twitter Profile Photo

A friend of mine (Gynvael Coldwind) is organizing a course about reversing binary files and protocols: hackarcana.com/workshop-sessi… recommendation++

Phil Ames (@philames) 's Twitter Profile Photo

Fun. Atlassian jams some AI enabled app called Rovo into orgs you create. It can't be removed, and you can't delete the org as long as there are active apps in it, leading to no way to delete the org.

Ivan Krstić (@radian) 's Twitter Profile Photo

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…