Studying Cybersecurity at HPI in Potsdam
| Website | https://aaronschlitt.de |
| City | Potsdam |
| Pronouns | he/him |
| Website | https://aaronschlitt.de |
| City | Potsdam |
| Pronouns | he/him |
OH: "Ein Söderstream"
"Kann man damit auch Wurstwasser sprudeln"?
You may remember my talk on iPhone Mirroring at #38c3. I have now published a blog post about my findings in threat modelling and researching the security of this new feature. There are also a few more details that I was able to talk about now.
https://aaronschlitt.de/threat-modelling-and-analyzing-iphone-mirroring/
@SoniEx2 @fionafokus The issue with just putting the patches on the internet without any coordination is that anyone reading them might be able to reconstruct an exploit to abuse the vulnerability while server administrators do not have a chance to protect themselves, i.e., because no release is available yet.
Instead, it is good practice to coordinate this process so that the time from the patches becoming public and an update being available is as short as possible.
(Edit: public visibility)
Having spent the past eight months as a research assistant at Jiska Classen's chair for Mobile Security, I had the chance to give a talk on one of the community stages at the 38 Chaos Communication Congress. iPhone MirroringSlide DownloadiPhone Mirroring_FINAL.pdf5 MBdownload-circle Talk Description The tight integration between