Lorenzo Franceschi-Bicchierai

@lorenzofb@infosec.exchange
7.7K Followers
1.8K Following
855 Posts
Real-time cyber historian of the late capitalist era @TechCrunch. Posts about infosec, surveillance by day. 🍕, ⚽️, 🎸, 🎮 by night. 
☎️ Signal: +1 917 257 1382
💻 Keybase/Telegram: @ lorenzofb
✉️ lorenzo@techcrunch.com
Previously: VICE Motherboard, Mashable, WIRED's Danger Room.
Twitterhttps://twitter.com/lorenzofb
Personal Sitehttps://lorenzofb.com
PronounsHe/him
Searchable viatootfinder
TechCrunchhttps://techcrunch.com/author/lorenzo-franceschi-bicchierai/

According to my sources, Cellebrite used to purchase iPhone prototypes (aka dev-fused devices), which had lower security features, to develop its zero-days. Corellium's founder Chris Wade also purchased them back in the day, according to sources.

https://www.vice.com/en/article/the-prototype-dev-fused-iphones-that-hackers-use-to-research-apple-zero-days/

In case you are wondering, this chart shows what U.S. carriers do if they receive a government surveillance request.
Might go back to fiction while I write my book, to get some inspiration from something that's not another non-fiction book about surveillance or startups.

. @jsrailton has some words that underscore just how important and potentially impactful this ruling is. Huge win for WhatsApp, but more than that, a devastating loss for NSO, and for all its spyware competitors.

https://techcrunch.com/2025/05/06/nso-group-must-pay-more-than-167-million-in-damages-to-whatsapp-for-spyware-campaign/

NSO Group must pay more than $167 million in damages to WhatsApp for spyware campaign | TechCrunch

The five-year legal battle between the Meta-owned company and the most notorious spyware maker in the world ends with a huge win for WhatsApp.

TechCrunch

Skype is getting shut down today. It was certainly one of the most revolutionaries chat apps in history.

Skype was the first major chat app to implement end-to-end encryption, prompting authorities all over the world to freak out about it, and look at spyware as a solution.

“Skype calls have excellent sound quality and are highly secure with end-to-end encryption,” Skype’s homepage read in 2004. 

https://techcrunch.com/2025/03/03/as-skype-shuts-down-its-legacy-is-end-to-end-encryption-for-the-masses/

As Skype shuts down, its legacy is end-to-end encryption for the masses | TechCrunch

iMessage, Signal, and WhatsApp have made E2EE the default for messaging, but Skype paved the way decades ago.

TechCrunch
Looks like there's a second person who was notified by Apple of being a target of government spyware: another right-wing activist in the Netherlands.

Do you have any tips about cybersecurity, surveillance, spyware, zero-days...all things cyber?

Contact me here: ☎️ Signal: + 1 917 257 1382

📷Keybase/Telegram: lorenzofb

2/ fin

The official website of zero-day broker Zerodium has been updated in December of last year. There are no price lists nor any information anymore, just an email and a PGP public key.

🤔

If you know what's happening there...let me know.

https://zerodium.com

ZERODIUM - The Premium Exploit Acquisition Platform

ZERODIUM is the leading exploit acquisition platform for premium zero-days and advanced cybersecurity research. Our platform allows security researchers to sell their 0day (zero-day) exploits for the highest rewards.

I am starting to think these Lockdown Mode notifications are even dumber and confusing than I thought.

I get them all the time while I chat with someone, for example, after their first message. Apparently, they don't do anything because the conversation keeps going. (This happens with people who are in my contact list btw)

But then, the other day I saw one one of these warnings, which named a person I wasn't messaging with at the time.

Should I assume this means they were messaging me and Lockdown Mode prevented them?

Does anyone know what these notifications actually mean? Or what they are supposed to tell a Lockdown Mode user?