@CaseyDunham

5 Followers
120 Following
252 Posts
Philosophy, Hermeticism, sometimes AppSec.

Apple is FINALLY adding a key transparency mechanism to iMessage:
https://security.apple.com/blog/imessage-contact-key-verification/

This has always been a huge weakness of iMessage, and I'm glad to see it finally being addressed.

Blog - Advancing iMessage security: iMessage Contact Key Verification - Apple Security Research

iMessage broke new ground in 2011 as the first widely available messaging service to provide secure end-to-end encryption by default. Ever since, we’ve been making ongoing improvements to iMessage security to protect our users’ most sensitive communications. This brief technical overview introduces the security model behind iMessage Contact Key Verification, a new feature available in the developer previews of iOS 17.2, macOS 14.2, and watchOS 10.2, that advances the state of the art of key directory security in messaging systems and allows users to verify they’re messaging only with the people they intend.

Blog - Advancing iMessage security: iMessage Contact Key Verification - Apple Security Research

Bill Clinton banned assault weapons in 1994; mass shootings dropped by 43%.

George W. Bush and the GOP let the assault weapons ban expire in 2004; mass shootings increased by 245%.

These numbers tell the whole story.

New #Cybersecurity Roundup: the Clorox hack attack caused a Hidden Valley Ranch shortage, the entire Washington, D.C. voter database was breached, Okta botched its breach response and 1Password got dragged into it, and much more.

Link: https://www.patreon.com/posts/cybersecurity-24-91560256

Cybersecurity Roundup: October 24, 2023 | Violet Blue

Get more from Violet Blue on Patreon

Patreon

I really believe that if your infrastructure can’t survive a user clicking a link, you are doomed. I’m the director of cybersecurity at NSA and you can definitely craft an email link I will click…

r.mtdv.me/TrustThis

I’m starting to prepare my US-timezone open online (In)Secure C++ training - Oct 31st - Nov 3rd (8am - 16pm PST).
If you’re interested (or might be) send me a DM or get in touch through the website.
https://turtlesec.no/blog/insecure-cpp/
(In)Secure C++

Understanding Exploitation to Find and Fix Vulnerabilities

TurtleSec

#GetFediHired

I’m a senior software engineer with 20+ years of experience, most recently leading digital book lending at the NY Public Library. I wrote & maintain the screen-scraping library Beautiful Soup, and co-wrote the book “RESTful Web APIs".

Open to remote contracting, consulting, full-time, or part-time gigs starting in December, programming in #Python, #Rust, or #Go.

Seeking a mission-oriented org, ideally involving publishing, freedom of access to information, or climate resilience.

Employees: We like working in the same homes where we sleep. There's no commute, it's very convenient.

Google: Nah we need you back in the office. But we built hotel rooms here so you can still sleep in the same place you work and there's no commute.

Employees: Uh yeah that's what we already had...

Google: That'll be $99. Which you pay us. To trap you in the office we demanded you come back to.

https://www.theverge.com/2023/8/4/23820061/google-hotel-bay-view-campus-return-to-office

Google’s $99 a night company hotel advertises ‘no commute’ as a perk

As Google nudges employees to work at its just-opened Bay View campus, the company hotel is advertising $99 special rates and “no commute” as a reason to stay.

The Verge

Happy #Bisexual Visibility Day people! May it one day be Bisexual #Liberation Day.    

#BiVisibilityDay