Gabriele Biondo

22 Followers
63 Following
21 Posts
25 y+ penetration testing • Reverse Engineer • Lecturer • macOS independent security researcher
Irreverent, misanthropic, cat lover
Research and traininghttps://bytearchitect.io
Tools - 0tHhttps://zero-the-hero.run
Tools - the Mechanixhttps://www.mechanix.run
Consultinghttps://www.reveng3.org

Reverse Engineering or Necromancy? 🧟‍♂️⚖️

What do you do when the company goes dark, the app vanishes from the App Store, and your "smart" scale becomes a 100€ paperweight?

You reverse it.

I’m starting a new series on ByteArchitect about bringing the QardioBase2 back to life. No ChatGPT-farts here—just raw bluetoothd logs, GATT discovery, and the sad sight of a backend that keeps saying "cancelled."

In this first part:
- Sniffing BLE traffic on iOS (without a jailbreak)
- Mapping proprietary GATT services & characteristics
- Realizing the servers are officially dead (RIP Qardio)

If you despise planned obsolescence as much as I do, join me in this "zombie" recovery:

https://bytearchitect.io/security-reversing/Reverse-with-me-Qardio-necromancy/

#ReverseEngineering #Infosec #BLE #iOS #HardwareHacking #Obsolescence #CyberSecurity #GATT #Necromancy

Scroll trīgintā trēs

Arcane curation from the IndieWeb, Fediverse and Cybersecurity realms

shellsharks

Apparently Electric Eye made it to riskybiz. Not bad for day one.

https://news.risky.biz/risky-bulletin-gen-joshua-rudd-confirmed-as-next-cybercom-and-nsa-head/

Gen. Joshua Rudd confirmed as next CyberCom and NSA head

In other news: US to establish new inter-agency cyber cell; UK to launch Online Crime Centre in April; Coruna exploit kit traced back to L3Harris.

Risky.Biz

Stop chasing blacklists. It's a losing game. I built a Rust engine
to spot AitM proxies where they bleed: in the DOM. Meet Electric Eye.

https://bytearchitect.io/network-security/Bypassing-MFA-with-Reverse-Proxies-Building-a-Rust-based-Firefox-Extension-to-Kill-AitM-Phishing/

#infosec #rust #firefox

New post: Hardening macOS pt.5 — Communications

Email clients, providers, PGP, and chat. For a Cypherpunk, talking about communications is like talking politics at the pub. I tried to be factual. Mostly succeeded.

Also: a special note for my Italian readers on PEC. With appropriate levels of contempt.

https://bytearchitect.io/macos-security/MacOS-Hardening-6-email-and-pgp/

#infosec #macOS #privacy #security #PGP #email #Signal

No Hardening macOS this week. Got distracted.

Starkiller is a new phishing kit that proxies REAL login pages in real-time. It steals credentials, MFA tokens and session cookies — and MFA won't save you.

I wrote a full technical analysis: how AitM works, why traditional defences fail, and what to actually do about it.

Also released ja3-probe, a Rust PoC for TLS fingerprinting of phishing proxies.

→ Post: https://bytearchitect.io/network-security/Starkiller-Phishing-Kit-Why-MFA-Fails-Against-Real-Time-Reverse-Proxies/?ref=mastodon
→ PoC: https://github.com/gb-at-r3/ja3Probe

#infosec #phishing #AitM #MFA #TLS #security #rust

Thanks a lot! 🙏

New post: Hardening macOS pt.4 — Secrets

Scams, Apple Keychain (the good and the ugly), the kdbx ecosystem, Strongbox, hardware security keys.

Your password is not enough. It never was.

https://bytearchitect.io/macos-security/Hardening-macOS-pt.4-Secrets-management/?utm\_source=mastodon&utm\_medium=social&utm\_campaign=hardening-pt4

#infosec #macOS #privacy #security #passwords #MFA #YubiKey

Hardening macOS 4: Secrets Management & Hardware Security Keys

Professional macOS secrets management: why Apple Keychain fails for power users and how to master .kdbx, Strongbox, and YubiKeys for a hardened workflow.

The Byte Architect
Using Facebook in the UK? You may have received the message: “Want to subscribe or continue to use our Products for free with ads?” You can’t bypass it. You're forced into a binary choice about whether to pay £2.99 per month so you can use Meta’s platforms without your personal information being used to sell advertising, or to continue without paying and allow your personal information to be used for adverts. https://www.openrightsgroup.org/blog/to-consent-or-pay/
To consent or pay?

If you live in the UK and have a Facebook or Instagram account, you have probably received a message when you’ve logged in asking you if you “Want to subscribe or continue to use our Products for free with ads?

Open Rights Group