固定されたツイート
Yiannis (John) Kozyrakis | @[email protected]
2.4K posts

Yiannis (John) Kozyrakis | @[email protected]
@ikoz
security engineer | https://t.co/4md7HaGx5W
London, UK 参加日 Ağustos 2008
1K フォロー中1.3K フォロワー
Yiannis (John) Kozyrakis | @[email protected] がリツイート

Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
sockpuppet.org/blog/2026/03/3…
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

I’m super excited about this blogpost. The approach is so counterintuitive, and yet the results are so much better than anything else that we’ve tried for memory safety. We finally understand why.
security.googleblog.com/2024/09/elimin…
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート
Yiannis (John) Kozyrakis | @[email protected] がリツイート

We are excited to announce that Google, Microsoft, and Meta are formally partnering as the founding steering committee to improve app security through a newly restructured App Defense Alliance, under the Joint Development Foundation.
Learn more: hubs.la/Q02873mh0

English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

* People ask LLMs to write code
* LLMs recommend imports that don't actually exist
* Attackers work out what these imports' names are, and create & upload them with malicious payloads
* People using LLM-written code then auto-add malware themselves
vulcan.io/blog/ai-halluc…
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

not every day 4 world-class security teams (all from Google, though that's not all of them...TAG, Mandiant, CrOS Security, and more) co-author a doc... #powerofopen
storage.googleapis.com/gweb-uniblog-p…
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you @POC_Crew!! 🚀💫
github.com/externalist/pr…
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

The Android team has open sourced our internal Rust Training! It's a four day course covering the full spectrum of Rust, from basic syntax to advanced topics like generics and error handling. It also includes Android-specific content on the last day.
google.github.io/comprehensive-…
English

New APVI entry: platform certificates used to sign malware
Found by yours truly :)
bugs.chromium.org/p/apvi/issues/…
English

Yiannis (John) Kozyrakis | @[email protected] がリツイート
Yiannis (John) Kozyrakis | @[email protected] がリツイート

The folks in Chrome who work on securing the web platform API have compiled a great guidelines doc based on their experience. chromium.googlesource.com/chromium/src/+…
Thanks @mikewest et al!
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート
Yiannis (John) Kozyrakis | @[email protected] がリツイート

@Hexploitable @dcuthbert My 7: Olive oil, onions, garlic, peppers, tomatoes, carrots, more olive oil
English

@dcuthbert Not drastically different: Onion, garlic, tomato, paprika, soy sauce, miso, salt
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu fredericb.info/2022/06/breaki… < what an awesome write up
English
Yiannis (John) Kozyrakis | @[email protected] がリツイート

We have finally published Tproxy (objectifsecurite.gitlab.io/tproxy/) our generic TCP interception proxy (think Burp for TCP): TLS handling, wireshark dissection, intercept and modify by hand or with scripts in GUI or CLI.
There is a complete doc with demos (objectifsecurite.gitlab.io/tproxy/Demos/)
English











