Julian Horoszkiewicz

32 posts

Julian Horoszkiewicz banner
Julian Horoszkiewicz

Julian Horoszkiewicz

@ewilded

Infosec fanboy, reverse engineer

Poland Beigetreten Aralık 2024
396 Folgt257 Follower
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks: atos.net/wp-content/upl…
English
5
90
431
95.9K
Julian Horoszkiewicz retweetet
It's FOSS
It's FOSS@Itsfoss·
I find it frustrating that none of these "guardians" of Linux and open source have reacted to the OS-level age verification law: - Linux Foundation - Open Source Initiative - Free Software Foundation - Software Freedom Conservancy
English
243
919
6.1K
176.9K
Julian Horoszkiewicz retweetet
GrapheneOS
GrapheneOS@GrapheneOS·
We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. uattest.net
English
54
1.1K
6.1K
145.2K
Julian Horoszkiewicz retweetet
MidnightBSD
MidnightBSD@midnightbsd·
Important: We have revised our license to include additional jurisdictions implementing the age verification laws. Residents of Brazil are no longer authorized to use MidnightBSD. We will not implement ID checks as Brazil requires. (not just attesting age)
GIF
English
131
332
2.6K
216.4K
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
My second public acknowledgement for a kernel-mode vulnerability: nvidia.com/en-us/security… 😉 This one is for a pool overflow in NVIDIA Install Helper Service (NVI2SystemService64.sys). Because at the time I had discovered and reported the issue the product had already reached EOL, the vendor will not assign a CVE number to it. In other words, this vulnerability did not make it to CVE because it stayed unreported for too long. This policy approach to EOL products is quite common among vendors and exemplifies one of numerous scenarios for which CVE as a tool for vulnerability and risk management is not sufficient. For anyone interested in such scenarios, I recommend reading my article dedicated to this subject: hackingiscool.pl/slipping-throu….
Julian Horoszkiewicz tweet media
English
0
0
0
105
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
My first public acknowledgement for a kernel-mode vulnerability 😉 CVE pending. #hof" target="_blank" rel="nofollow noopener">asus.com/security-advis…
Julian Horoszkiewicz tweet media
English
0
0
1
98
Julian Horoszkiewicz retweetet
Naomi Brockwell priv/acc
Naomi Brockwell priv/acc@naomibrockwell·
The entire world is moving to criminalize privacy. We can't let them do that. Privacy is the foundation of a free society. Privacy is protection against powerful people. Privacy is normal.
GrapheneOS@GrapheneOS

We were contacted by a journalist at Le Parisien newspaper with this prompt: > I am preparing an article on the use of your secure personal data phone solution by drug traffickers and other criminals. Have you ever been contacted by the police? Are you aware that some of your clients might be criminals? And how does the company manage this issue? Absolutely no further details were provided about what was being claimed, who was making it or the basis for those being made about it. We could only provide a very generic response to this. Our response was heavily cut down and the references to human rights organizations, large tech companies and others using GrapheneOS weren't included. Our response was in English was translated by them: "we have no clients or customers" was turned into "nous n’avons ni clients ni usagers", etc... GrapheneOS is a freely available open source privacy project. It's obtained from our website, not shady dealers in dark alleys and the "dark web". It doesn't have a marketing budget and we certainly aren't promoting it through unlisted YouTube channels and the other nonsense that's being claimed. GrapheneOS has no such thing as the fake Snapchat feature that's described. What they're describing appears to be forks of GrapheneOS by shady companies infringing on our trademark. Those products may not even be truly based on GrapheneOS, similar to how ANOM used parts of it to pass it off as such. France is an increasingly authoritarian country on the brink of it getting far worse. They're already very strong supporters of EU Chat Control. Their fascist law enforcement is clearly ahead of the game pushing outrageous false claims about open source privacy projects. None of it is substantiated. iodéOS and /e/OS are based in France. iodéOS and /e/OS make devices dramatically more vulnerable while misleading users about privacy and security. These fake privacy products serve the interest of authoritarians rather than protecting people. /e/OS receives millions of euros in government funding. Those lag many months to years behind on providing standard Android privacy and security patches. They heavily encourage users to use devices without working disk encryption and important security protections. Their users have their data up for grabs by apps, services and governments who want it. There's a reason they're going after a legitimate privacy and security project developed outside of their jurisdiction rather than 2 companies based in France within their reach profiting from selling 'privacy' products. discuss.grapheneos.org/d/24134-device… Here's that article: archive.is/AhMsj

English
68
1K
4.7K
174.7K
Julian Horoszkiewicz retweetet
No to Digital ID
No to Digital ID@NoToDigitalID·
Do you want to be de-banked over digital ID rules? Vietnam is terminating bank accounts without a linked digital ID. We are not exaggerating when we say this is what could happen in the UK. It is already happening elsewhere. The people must remain in control, we must reject Digital ID.
No to Digital ID tweet media
English
58
787
1.7K
23.7K
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
OSCP is no job experience, it does not even teach actual pentesting and its passing criteria are based on collecting the flags, not on "how pretty the report is". Also, the part about no sleep and no food is BS. Seeing a trend of non-technical juniors without actual passion for infosec believing that OSCP makes one a "senior".
English
0
0
1
267
Nick VanGilder
Nick VanGilder@nickvangilder·
I would argue that the massive flood of new people trying to “break in” as juniors has actually raised the bar for juniors. Every day, hundreds of people wake up and decide they want to become a 5up3r l33t penetration tester or hax0r. And that’s awesome. There’s two problems though: 1) there just aren’t that many penetration testing roles available and 2) employers want to hire the best of the best. We might not like it, but when there’s a major surplus of candidates (and there is), employers can afford to be picky. And they will be. Can you blame them? That’s just supply and demand at work. When the market shifts and there’s a shortage of qualified talent for these roles, requirements loosen. But right now? The market’s flooded, the bar’s getting higher, and the competition is fierce. Plan and adjust accordingly.
Nick VanGilder tweet media
English
39
37
551
165.2K
Julian Horoszkiewicz retweetet
Reclaim The Net
Reclaim The Net@ReclaimTheNetHQ·
The UK is rolling out a national digital ID, the “Brit Card," despite 2.7M+ signatures against it. Tied to borders, benefits, and public services, it’s the spine of a new surveillance state. Combined with the Online Safety Act, identity verification is becoming mandatory to live, work, and speak.
Reclaim The Net@ReclaimTheNetHQ

UK Government Dismisses Public Outcry, Pushes Ahead with Controversial Digital ID Plan reclaimthenet.org/uk-digital-id-…

English
18
95
353
15.4K
Julian Horoszkiewicz retweetet
Keith
Keith@gnukeith·
Isn’t she the person who proposed chat control? Seems like a weird behavior for someone who proposed the regulation. It’s not so fun when you are the one getting your messages analyzed is it now? Hypocrite.
Fidias Panayiotou@Fidias0

Von der Leyen is Deleting Texts AGAIN

English
15
139
755
28.2K
Julian Horoszkiewicz retweetet
Tuta
Tuta@TutaPrivacy·
🚨 Denmark keeps pushing for Chat Control - but we keep pushing back! Join us in our fight for #privacy ✊ Check why #Germany is the deciding factor 🇩🇪 and learn how to stop #Chatcontrol (including email addresses of German politicians): 👉 tuta.com/blog/chat-cont…
Tuta tweet media
English
36
327
1.1K
38K
Julian Horoszkiewicz retweetet
vittorio
vittorio@IterIntellectus·
Americans have absolutely no idea how bad things are in Europe They are going into a totalitarian dictatorship the likes of which Orwell thought were too insane to come up with
gigi 𓂃⋆.˚@p0lar_fawn

is this a joke??????????

English
231
914
7.3K
177.1K
Julian Horoszkiewicz retweetet
Mike Benz
Mike Benz@MikeBenzCyber·
ChatControl will allow the EU to use keyword filters to probe into what every private citizen says to friends and family about private topics, using AI and machine learning models to create heatmaps of dissidents. Combined with hate speech laws, it’s a recipe for utter disaster.
Mike Benz tweet media
@levelsio@levelsio

🇪🇺 My fellow Europeans You have to fight ChatControl 💪 Don't let @vonderleyen read your chats! metalhearf.fr/posts/chatcont…

English
380
3.3K
9.1K
425.2K
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
As long as vendors can hide vulnerabilities by bullying researchers and their own clients with NDAs and SLAPP, it doesn't really matter what system we use to exchange information about issues. Also, there's many other scenarios in which this just doesn't work as it should: hackingiscool.pl/slipping-throu…
English
0
1
2
1.1K
b1ack0wl
b1ack0wl@b1ack0wl·
CVE has always been garbage. Researchers have been treating it like a trophy collection for years and the descriptions usually contain minimal to no details about the bug itself. We need something new and useful imo
English
38
58
762
72.9K