Drew Springall

260 posts

Drew Springall

Drew Springall

@_aaspring_

Security Researcher. (opinions are my own)

Beigetreten Ocak 2015
74 Folgt377 Follower
Drew Springall
Drew Springall@_aaspring_·
@jhalderm 5/5 If written today, we would include references to later-events (Coffee Co GA, Mesa Co CO, others' public discoveries, etc) plus our further-improved understanding of the vulns/weaknesses/etc. @jhalderm and I will be updating and submitting for peer-review later this summer.
English
1
1
12
696
Drew Springall
Drew Springall@_aaspring_·
@jhalderm 4/5 the report you see is ~2 years old (filed Jul2021) and reflects understanding/knowledge at that time but everything is still valid and correct. We asked the vendor to point-out any technical inaccuracies or misunderstandings over a year and a half ago and have heard nothing.
English
1
3
11
935
Drew Springall
Drew Springall@_aaspring_·
Great work protecting everyone from "offensive content" there @twitter.
Drew Springall tweet mediaDrew Springall tweet media
English
0
0
1
390
Drew Springall
Drew Springall@_aaspring_·
@umbernhard @braden_crimmins I don't see how it could be viewed as an unrealistic threat. There's an open-world of possibilities for obtaining identity. Could be small-scale (counter allows few before/after) or large-scale (all-day surveillance footage allows entire polling place).
English
0
0
0
0
Drew Springall retweetet
J. Alex Halderman
J. Alex Halderman@jhalderm·
1/ Colleagues and I have found a serious privacy flaw that affects Dominion ICP and ICE ballot scanners. We've already informed Dominion, CISA, EAC, and state officials, and we've created a site to help officials and the public understand the issue: DVSorder.org
English
35
248
372
0
Drew Springall
Drew Springall@_aaspring_·
4/4 We'd be excited to work with election officials to see whether other systems have similar vulns and how to best defend. Many people have made many claims about election security and the best way to sort true from false is to perform serious technical analysis.
English
2
5
18
0
Drew Springall
Drew Springall@_aaspring_·
3/ We only tested two software versions of a single EAC-certified system (as part of a pre-2020 lawsuit in GA). The vendor didn't give us or CISA access to test other versions or their claimed fixes. It also hasn't publicly stated what other versions share these vulns (if any).
English
1
5
14
0
Drew Springall
Drew Springall@_aaspring_·
1/4 @jhalderm and I investigated the security of the Dominion ImageCast X BMD used in Georgia and our findings aren't pretty. @CISAgov just published an advisory about vulnerabilities we found and I hope the full report we sent them will be available soon. cisa.gov/uscert/ics/adv…
English
7
22
36
0
Drew Springall
Drew Springall@_aaspring_·
Well that looks...not good. Someone might wanna check on the @hbomax integration testing infrastructure.
Drew Springall tweet mediaDrew Springall tweet media
English
1
0
1
0
Matthew Green
Matthew Green@matthew_d_green·
@jiceman I don’t know. If someone tells me this person explicitly and knowingly activated features that caused their phone to record this info I’d be less horrified.
English
3
0
1
0
Matthew Green
Matthew Green@matthew_d_green·
It’s pretty insane that your phone OS not only routinely collects your precise location but sends it up to a server to be persistently logged. I know we’re used to this, but this shouldn’t be happening.
English
4
87
293
0
Drew Springall
Drew Springall@_aaspring_·
@0xfraq Absolutely. If everything's good, just hit me up here, in the Slack, or at aaspring@auburn.edu.
English
0
0
1
0
fraq
fraq@0xfraq·
@_aaspring_ Hey, this may or may not work out. Let me talk with Dr. Green and see if there is any conflict first.
English
1
0
0
0