It's been the sort of day where I discover that I have a surprisingly useful ability to intuit fields in headers that are probably uuids and figure out what this structure is as a result
Did you know that you can impress people by just pasting some bytes into github search and then saying "Ah yes that's an EFI-spec RSA2048-SHA256 signature" (you do not need to do the github bit in front of them)
Anyway simply mechanically copying potentially interesting looking sequences of bytes into search engines is an incredibly underrated part of reverse engineering work
@mjg59 my search history is full of weird hex values and GUIDs.
@mjg59 although you do have to wonder if any vendors are using Mulliner's Canary Tokens to detect reverse engineering https://www.mulliner.org/blog/blosxom.cgi/security/re_canary.html
Collin R. Mulliner

@th @mjg59 wow!

@foone @th @mjg59

We could also call "reverse canary" a "nightingale floor", and preserve the bird reference

https://en.wikipedia.org/wiki/Nightingale_floor

Nightingale floor - Wikipedia