Angehefteter Tweet
Mudge
4.7K posts

Mudge
@dotMudge
Make a dent in the universe. Find something that needs improvement: go there and fix things. If not you, then who? {he/they}
DARPA^2|Stripe|Google|L0pht Beigetreten Eylül 2011
336 Folgt62.9K Follower

Dr. Morris (he doesn’t like being called Jr. he and his father have different names) was doing well the last I heard.
I believe he’s still a professor at a very prestigious academic institution.
He was going to be great no matter what field he chose (the security field was basically closed off by a particular professor at the time who made a big fuss and lobbied to have the book thrown at him).
Fortunately there were good people like Steve Bellovin and others who went to bat for him and fought the zealot.
English

Aleph took it much further and made it much more accessible.
I’m proud to have contributed in even the slightest way.
Today In Infosec@todayininfosec
1995: Mudge published "How to Write Buffer Overflows", one of the first papers about buffer overflow exploitation. Then @dotMudge sent a copy to @aleph_one, who wrote "Smashing the Stack For Fun and Profit" in 1996. Seminal paper to seminal paper. Mudge's: insecure.org/stf/mudge_buff…
English

@herrmann1001 If I recall the worm targeted two architectures, each running their own Unix builds.
The exploit for the Vax CPU did not work due to the way the stack grows on that architecture.
Later, someone modified the exploit to get it working on both architectures - nothing like PoCs!
English

Taking a moment for a PSA:
I still get occasional random messages saying I made a difference, or otherwise encouraged someone at some point.
Those messages mean a lot.
If someone’s contributions meant something to you along your journey drop them a note.
It’s a small thing with big impact.
Thanks for the artwork Eddie the Y3t1!

English

@cantcomputer Sure is. He had a multi-domain impact on my life.
So I did what my PSA espouses - a long time ago.
English
Mudge retweetet

Dino Dai Zovi @dinodaizovi is induced in the @SummerC0n Hall Of Fame alongside @dotMudge @nudehaberdasher and @heidishmoo. Congratulations Dino for an amazing security impact across industry and government. Well deserved!

English

@jhietaniemi @j08ny Fantastic stuff, thank you. Already familiar with that work and I’m asking for citations to measurements on the original post.
The origin research showing more than [3,4] data points.
Thanks
English

@MikePFrank Those are great infographics, but would be much more useful for my work if you could cite the existing data sources (and frequency of samples) for your forecasts.
I imagine you have them. Would you point me to them please? It would be very helpful :)
English

@dotMudge And, here's a forward-looking chart I made based on the 2022 International Roadmap for Devices & Systems:

English

Zero Knowledge Proofs are fascinating.
There’s now a SafeDocs PDF reader driven by Formal Methods from DARPA (disclaimer: I work for DARPA): pdfa.org/resource/arlin…
Think about the combination of ZKP and attainable formal methods in software 😃
Jacob@jacobeverly
The world once the government realizes they can regulate entities with verifiable programs instead of arbitrary checkpoints and probing
English
Mudge retweetet













