Daniel Roethlisberger

808 Followers
697 Following
375 Posts
security & software engineering · cyber defense · civil society
Websitehttps://daniel.roe.ch
GitHubhttps://github.com/droe

The Perils of Privatized Cyberwarfare

Privatized cyberwar will complicate oversight, create counterintelligence risks, fuel arms races and insecurity, and put civilians at risk.

https://www.lawfaremedia.org/article/the-perils-of-privatized-cyberwarfare

*Student Worker Position in the Mozilla Firefox Application Security Team*

I'm hiring for a part-time student role in Mozilla's Firefox Application Security team in Berlin/Germany (remote possible). We are trying to reach students from a broad range of backgrounds, not only people who already see themselves as "security people". It is required that applicants are enrolled in a university in Germany.

https://www.mozilla.org/en-US/careers/position/gh/7998284/

Mozilla Careers — Firefox Security Student Worker — Open Positions

Mozilla is hiring a Firefox Security Student Worker in Remote Germany, New Products, Firefox, Core Services, Mozilla.org, Firefox, Firefox, Core Services, New Products,…

Mozilla
Amnesty is recruiting a Technologist in their team researching digital surveillance abuse, this is an amazing position in an amazing team. Location is limited to a few places and deadline is really soon
https://careers.amnesty.org/jobs/vacancy/technologist-4246/4274/description/
Amnesty International Careers

Amnesty International Careers, Jobs, Search and Apply

Amnesty International Careers

Amazing: #Debian is now shipping reproducible packages 💪

https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html

Thanks to everyone who helped make this happen!

See https://reproducible-builds.org/ if you are not familiar with the topic

bits from the release team

A secret diplomatic letter written in 1498 once carried sensitive intelligence about England & Scotland to the Spanish court. More than five centuries later, historians from the University of Toronto have decoded its cipher and produced the most accurate version of the text yet.

Cryptographers, take note, we need to re-introduce non-injective permutations! </joke>
"Ayala sometimes used multiple symbols for the same letter, making the text even more difficult to decode.”

https://www.medievalists.net/2026/04/secret-letter-detailing-late-medieval-britain-fully-decoded/

Secret Letter Detailing Late Medieval Britain Fully Decoded - Medievalists.net

A secret medieval letter detailing late medieval England and Scotland has been decoded by a team of historians.

Medievalists.net

#QEMU 11.0 is out! And with it an exciting feature I was working on: Support for #nitroenclaves. Yes, you can now launch your enclave via -kernel directly in QEMU 😁

https://wiki.qemu.org/ChangeLog/11.0

ChangeLog/11.0 - QEMU

NEW: Researchers have identified extensive spying campaigns abusing well-known weaknesses in the global cellphone infrastructure to track and locate targets.

Two (unnamed for now) surveillance vendors, whose customers are likely government agencies, were allegedly behind these spy campaigns.

The research exposes an industry that remains still largely in the shadows, armed with tech that can track people without the need to use spyware such as Pegasus.

http://techcrunch.com/2026/04/23/surveillance-vendors-caught-abusing-access-to-telcos-to-track-peoples-phone-locations-researchers-say/

Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say | TechCrunch

The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.

TechCrunch

A pretty significant change in resolver behavior is proceeding:

"[...] BIND 9 is switching to a parent-centric model of delegations. [...] The NS records in the child domain will be treated as normal DNS records and returned as authoritative data, but they will no longer overwrite the delegation data for the domain."

https://lists.isc.org/pipermail/bind-users/2026-April/110552.html

So much of what you may have learned about how #DNS works around the turn of the century is now out of date.

BIND 9.21+/9.22: parent-centric delegations and no TTL-based cleaning

Getting serious ADHD and building software nobody asked.

checksec for Mach-O
https://github.com/ChiChou/macchk

⚠️ Warning: vibe coded

We publish a major Citizen Lab report on Webloc, an ad-based mass surveillance system that monitors the movements and personal characteristics of hundreds of millions people globally based on data obtained from mobile apps and digital advertising.

Customers include ICE, El Salvador and Hungary.

Our research shows that ad-based surveillance is now used by military, intelligence and law enforcement agencies down to local police in several countries.

Full report here:
https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/