Collin Mulliner

16.7K posts

Collin Mulliner banner
Collin Mulliner

Collin Mulliner

@collinrm

security engineering

NYC metro area Joined Kasım 2007
705 Following8.5K Followers
Collin Mulliner retweeted
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
Everyone today is a hacker in a sense but there are very few OG hackers on which shoulders we stand Oh dude, Felix “FX” Lindner you were so much a hackers hacker and you will be missed RIP my friend and thank you
Daniel Cuthbert tweet media
English
51
135
582
78.4K
Collin Mulliner retweeted
joernchen
joernchen@joernchen·
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/3]
English
3
112
73
37.2K
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
So, I’m not sure there is any good time to announce this, but as of August 31st I will be leaving NYU for good, to seek my fortune in industry with XBOW!
English
48
6
341
24.9K
Collin Mulliner
Collin Mulliner@collinrm·
SummerC0n 2025 good to be back!
Collin Mulliner tweet media
English
1
0
4
290
Collin Mulliner retweeted
Summercon
Summercon@SummerC0n·
Gazing across the throngs at this month’s NYSEC, all we can think is: can’t wait to see you all again in July. Summercon 2025 July 11–12 @ Littlefield, Brooklyn Tickets: eventbrite.com/e/summercon-20…
English
0
4
13
2.6K
Collin Mulliner retweeted
Summercon
Summercon@SummerC0n·
Summercon 2025 Call for Papers Since 1987, Summercon has been where serious security research meets irreverent hacker culture. We're looking for original, technically rigorous presentations that challenge assumptions and advance the state of the art. CFP: summercon.org/cfp/
English
1
15
22
5.2K
Collin Mulliner retweeted
sergey bratus
sergey bratus@sergeybratus·
The submission deadline for the 11th LangSec IEEE Security & Privacy workshop langsec.org/spw25/ is extended to January 31, 2025. Please send us your papers, research reports, posters or panel proposals! #langsec
English
0
5
9
2.3K
Collin Mulliner retweeted
Natalie Silvanovich
Natalie Silvanovich@natashenka·
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium.org/issues/3686956…
English
3
102
306
50.4K
Collin Mulliner
Collin Mulliner@collinrm·
If you are a guy in your 20s, buy a Lenovo X1 even if you have to go into debt.
English
0
1
7
839
Collin Mulliner retweeted
Dino A. Dai Zovi
Dino A. Dai Zovi@dinodaizovi·
The highest level of security engineering is proactively building systems that make insecure states unrepresentable, attack classes rendered extinct, vulnerabilities not exploitable, and attack paths not viable for attacker gain.
English
1
16
43
5.4K
Collin Mulliner retweeted
Julian Cohen
Julian Cohen@HockeyInJune·
Over the past few weeks, I’ve been reinvigorating a SIM swap detection platform we originally designed and built at @tagomisystems. The underlying concept was to safeguard customer accounts—especially those reliant on SMS-based MFA—by identifying whether a phone number had undergone a SIM swapping attack. This system was designed to be an early indicator of compromised accounts, even if users were using phishing-resistant MFA on our platform. We worked closely with well known mobile network security researchers, mobile virtual network operators, and other industry intelligence sharing groups. Our goal was to ensure the solution propagated rapidly and comprehensively across the industry, given the seriousness of SIM swapping attacks. SIM swapping remains a relatively cheap yet highly effective way to circumvent MFA, especially for high-value targets. While SMS-based MFA continues to be common for banks, investment accounts, and other critical financial platforms, it is also one of the most vulnerable methods of second-factor authentication. What is a SIM swap? A SIM swap occurs when a mobile network operator (MNO) reassigns a phone number to a new IMSI (International Mobile Subscriber Identity), whether for legitimate reasons (changing carriers, upgrading devices) or malicious purposes (intercepting SMS messages). Detection mechanism: By comparing the IMSI used during previous account activity with the current IMSI, we can identify a SIM swap event. At that point, service providers can apply stricter controls, such as restricting high-risk transactions or forcing more secure authentication flows. Implementation Challenges: TMSIs (Temporary Mobile Subscriber Identities) are insufficient for detection due to their short-lived nature. Accessing IMSI information directly has become more difficult over time, largely due to expanded "privacy" concerns that limit how carriers share network-level data. Industry Solutions: Twilio integrated this idea into a commercial API, partnering with carriers that support "SIM swap status checks". Other commercial providers like Vonage have launched similar services. These solutions are valuable, but not foolproof: If a phone number is transferred to a carrier that does not support these "SIM swap status checks", commercial API providers and service providers lose visibility. Additionally, carriers strictly control historical IMSI change logs for "privacy" reasons, preventing service providers from conducting deeper investigations or retrospective analysis. While HLR (Home Location Register) and VLR (Visitor Location Register) lookups can still yield some actionable data, true SIM swap prevention/detection will require architecture improvements at the carrier level and SS7 routing attacks will require network level architecture improvements.
English
1
1
3
986
Collin Mulliner retweeted
sergey bratus
sergey bratus@sergeybratus·
The 11th Language-theoretic IEEE Security & Privacy Workshop will take place on May 15, 2025. Please submit your work by January 20, 2025 and join us in San Francisco! langsec.org/spw25/ #LangSec
English
0
6
13
3K
Collin Mulliner retweeted
Bill Pollock -- nostarch@infosec.exchange
Our Black Friday sale is on now. Unfortunately, you won't see that on mobile just yet so here it is. Follow the bouncing robot. Please share! @nostarch
Bill Pollock -- nostarch@infosec.exchange tweet media
English
1
14
13
6K
Collin Mulliner retweeted
NYSEC
NYSEC@nysecsec·
NYSEC is tomorrow! Tuesday, November 19th @ 6PM. d.b.a. 41 1st Ave. New York, NY 10003
English
0
2
0
468
Collin Mulliner retweeted
KF
KF@d0tslash·
lolooololo
KF tweet media
HT
3
6
34
3.1K