Michael van Niekerk ๐Ÿฆ€ โ˜•๏ธ โš›

118 Followers
271 Following
2K Posts

Programs all the stacks.
Rust, Java, React Native biased.
Maker of wares that are soft and wares that are hard.

Comments and opinions are that of my own.

๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡ธ๐Ÿ‡ฟ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡ฒ๐Ÿ‡ฟ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฒ๐Ÿ‡ฝ๐Ÿ‡ฑ๐Ÿ‡ธ๐Ÿ‡ต๐Ÿ‡ฆ๐Ÿ‡ป๐Ÿ‡ช๐Ÿ‡ฟ๐Ÿ‡ผ๐Ÿ‡ฟ๐Ÿ‡ฒ๐Ÿ‡ง๐Ÿ‡ผ๐Ÿ‡ญ๐Ÿ‡ท๐Ÿ‡น๐Ÿ‡ท

LinkedInhttps://www.linkedin.com/in/mvniekerk
Githubhttps://www.github.com/mvniekerk
Do I have any followers familiar with Embassy + smoltcp + STM32, and interested in a paid consulting gig? I've got a company seeing dropped / missing packets, and it could be an interesting project + fun investigative writeup.
Android 16 for the Fairphone 6 is here. Still slower than some mainstream brands, but much faster than previous Android rollout. Hope they keep improving!

Pinephone Pro Linux mainlining thread

Decided to  make a thread on the work I'm doing on the Pinephone Pro and pin it to my profile. Here's the list of things I've done so far:

- https://fosstodon.org/@Logical_Error/115523837605100152
- https://fosstodon.org/@Logical_Error/115863006627226016

Mainlining Guide: https://forum.mainlining.org/t/upstream-pinephone-pro-patches/138

Had to pause Pinephone Pro development because I got demotivated a bit, but hopefully I'll be able to continue in the near future. Stay tuned~

LogicalErzor (@[email protected])

fixing pinephoneproโ€™s build in pmOS im not sure what happened but for some reason i couldnโ€™t do pmbootstrap build device-pine64-pinephonepro --force i got a fix that was merged in now https://gitlab.postmarketos.org/postmarketOS/pmaports/-/merge_requests/7308 im assuming that there was a pmb update that changed the build dir. since pmb doesnt rebuild existing packages, this was a problem waiting to strike on the next ppp build wouldve liked to figure out what went wrong, but got bisecting pmbootstrap and pmaports gives a lot of errors :/

Fosstodon

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR โ€” MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs โ€” without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

๐ŸŽ‰ picoCAD 2 is out! ๐Ÿฅณ
Model, texture, and animate - in a single lo-fi, easy to use package. 
GIF, GLTF, OBJ, and sprite sheet export. 
Available now on Steam and Itch!
Check it out! http://picocad.net

Thanks for boosting! โค๏ธ ๐Ÿ™

If you feel like you're hating life, you're just hating _your_ life.

You are allowed (and able) to change _your_ life.

Whenever there's still life there's still hope. Grab onto something or someone to get you through. Seek help.

How South Africa built, and dismantled, its nuclear bombs.

https://www.youtube.com/watch?v=nsTmZNBR3-o

Pelindaba: How South Africaโ€™s Engineers Built Six Atomic Bombs in Secret โ€” Then Dismantled

YouTube
I don't know who needs to hear this, but the Mazda service system has FULLY INTERACTIVE 3D WIRING DIAGRAMS with zoom, rotate and pan ๐Ÿ˜ฉ
Back when Ronald Reagan and Walter Mondale were running for president, the ๐˜—๐˜ฆ๐˜ฏ๐˜ต๐˜ฆ๐˜ค๐˜ฐ๐˜ด๐˜ต๐˜ข๐˜ญ ๐˜Œ๐˜ท๐˜ข๐˜ฏ๐˜จ๐˜ฆ๐˜ญ ran this. Itโ€™s still very good advice. Itโ€™s not how Christian nationalists behave though.

Dabao has launched!!!

Open hardware, firmware, software from @bunnie !

https://www.crowdsupply.com/baochip/dabao/updates/our-campaign-has-launched

Our Campaign Has Launched!

Today marks the start of the Dabao campaign. If you're interested in open source hardware, security, or trust, I'm offering you a chance to order some of the first evaluation boards for a mostly-open, security-oriented microcontroller. Dabao is an evaluation board for the Baochip-1x SoC, a microcontroller that raises the bar on inspectable hardware, bringing you a system-on-chip (SoC) that you can check from the silicon all the way to the software.

Crowd Supply