| https://twitter.com/0x30n | |
| Work | https://blackwinghq.com |
| Personal | https://c0nfusion.org |

| https://twitter.com/0x30n | |
| Work | https://blackwinghq.com |
| Personal | https://c0nfusion.org |
If you enjoy PCalc or Dice, a repost on the Black Friday deal linked below would be very helpful in getting the word out on the 50% off sale. I absolutely hate doing marketing, and always just feel like saying “buy my stuff, it's okay I guess!”, but this is not exactly conducive to selling copies.
Windows Hello fingerprint security failures! Great work from
Blackwing!
"We initially implemented this attack on a Raspberry Pi 4, but reimplemented it in TamaGo on the USB armory since the RPi4 takes too long to boot and we wanted a quicker demo. 😜"
Introducing the PCalc “More Than 42% Off Super Sale” for #blackfriday!
PCalc iOS: $4.99 down from $9.99
https://apps.apple.com/us/app/pcalc/id284666222
PCalc Mac: $4.99 down from $9.99
https://apps.apple.com/us/app/pcalc/id403504866
Dice by PCalc iOS: $0.99 down from $1.99
https://apps.apple.com/us/app/dice-by-pcalc/id1468680083
Dice by PCalc Mac: $0.99 down from $1.99
https://apps.apple.com/us/app/dice-by-pcalc/id1479250666
Everything is roughly 50% off until the end of Monday 27th November. It's extremely rare for PCalc to go on sale like this, so act now!
A Touch of Pwn - multiple vulnerabilities in the top three fingerprint sensors embedded in laptops successfully exploited, allowing complete bypass of Windows Hello authentication
*yells into the megaphone*
The "remote" in remote code execution refers to where the attack originates. Any type of vulnerability which requires local execution to exploit may be referred to as an arbitrary code execution vulnerability, a local code execution, or in special cases a local privilege escalation vulnerability.
Do not fall for the corporate propaganda!
“It’s better than nothing” These words are the enabler of so many worthless security “solutions”. From phishing testing, to SAST, to “threat intel feeds”, to well, look around the floor of RSA… Instead of identifying real problems and finding or engineering solutions that fix those problems, “security” continues to bolt on the cheapest “solution”, masking the real problem and kicking it down the road, claiming “it’s better than nothing”. Unfortunately, it’s really not better than nothing.