Jason Geffner

532 Followers
202 Following
185 Posts
Principal Security Architect at Microsoft. Formerly at Google, Amazon, CrowdStrike.
GitHubhttps://github.com/geffner
Good morning, #BlueHat!
Whoever at Intel is in charge of naming mnemonics has become drunk with power over the years:

@GitHubSecurityLab posted https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/ last week, and one thing that really stood out to me was, "This again shows the importance of properly addressing security issues and recording them by assigning a CVE-ID, so that downstream users can apply the relevant security patches. Unfortunately, vendors sometimes see having security vulnerabilities in their products as a damage to their reputation and try to silently patch or downplay security issues instead."

Customers absolutely value secure software, but they also value honesty and transparency. To all vendors, it's possible to be a successful company and also to have CVEs associated with your products.

Don't believe me? The top five most successful software companies have a total of 33,783 CVEs associated with them.

Be honest, be transparent. Your customers will appreciate it.

Pwning the all Google phone with a non-Google bug - The GitHub Blog

It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.

The GitHub Blog
Enjoying this 2009 bottle of Hair of the Dog “Matt”. Its name is quite a coincidence, since Matt Gaetz said that this 14 year old beer is too old for him.

The official NYC Crime Map (https://maps.nyc.gov/crime/) uses skin-tone colors for its legend; the darker the skin-tone color, the higher the crime rate.

WTF? Could they not have picked a different color scheme??

NYC Crime Map

View NYC crime statistics and locations

NYC.gov
Convinced my 7-year-old daughter that this is the TikTok app.
Time to start eating smartphones.
My wife was trying to convince me that a horse-drawn carriage would be romantic, but I think horses are terrible artists.