Demi Obenour

1.1K posts

Demi Obenour

Demi Obenour

@AlwaysCurious__

Software developer and security researcher. I work at Invisible Things Lab. My https://t.co/7ACW8FQMEa. BLM.

Katılım Ekim 2018
189 Takip Edilen81 Takipçiler
Demi Obenour retweetledi
Jessica Burbank
Jessica Burbank@JessicaLBurbank·
Why would the government have an obligation to search for and save the life of a billionaire who willingly took a submarine to the ocean floor but not a kid with cancer who can’t afford healthcare?
English
1.1K
7K
65.6K
3.2M
Demi Obenour
Demi Obenour@AlwaysCurious__·
@SwiftOnSecurity There still needs to be an on-premises device fronting the management interface.
English
1
0
1
1.3K
Demi Obenour
Demi Obenour@AlwaysCurious__·
I will be SO happy when an intranasal COVID-19 vaccine that produces sterilizing immunity becomes widely used.
English
0
0
6
377
Demi Obenour
Demi Obenour@AlwaysCurious__·
@kpcyrd IMO only the first makes any sense. Main reason we can’t have per-user /tmp is Xorg but that is deprecated.
English
0
0
0
17
kpcyrd@chaos.social 🏴
Linux security is so broad, it ranges from "you can write whatever to /tmp it's all namespaced anyway" to "you need to consider the permissions of every file you create because Debian ships world-readable home directories by default"
English
1
0
2
135
Demi Obenour retweetledi
Jaraparilla 🇾🇪 🇵🇸 🇱🇧
@RnaudBertrand Imagine if the USA closed all their overseas bases, cut military spending by 90%, and tried to actually compete with China by building infrastructure, educating citizens and growing their own economy. Radical concept, I know.
English
24
46
208
5.4K
Demi Obenour
Demi Obenour@AlwaysCurious__·
@SwiftOnSecurity The correct solution is an _on-premises_ reverse proxy connected to the device via a physical cable (no switches!). Preferably with the reverse proxy server’s own listening endpoint bound to a VPN interface.
English
1
0
0
168
Demi Obenour
Demi Obenour@AlwaysCurious__·
@SwiftOnSecurity Sorry, but Azure AD Application Proxy is _not_ the correct tool for this, because the connection from the cloud to the on-premises management interface is still unprotected.
English
4
0
1
3.8K
Demi Obenour
Demi Obenour@AlwaysCurious__·
To the best of my knowledge, formal verification (preferably with the proofs made publicly available) is the only way to stop the stream of easy software-only attacks.
English
0
0
0
152
Demi Obenour
Demi Obenour@AlwaysCurious__·
The point is that being certified to e.g. EAL5+ and AVA_VAN.5 has turned out to not actually mean very much. Devices meant to guard against state-level actors have repeatedly fallen to much weaker attackers.
English
1
0
0
174
Demi Obenour
Demi Obenour@AlwaysCurious__·
That bugs have been found in Google’s Titan M2 is not okay. The standard for security chips like that should be EAL7: formal verification.
English
1
1
5
497
Javier Davalos
Javier Davalos@javierdavalos·
Dear @Apple & @Unity: Nice to meet you, I make @FigminXR, likely the most popular #MixedReality app in the world. ♥️ I really love the idea of a shared app space in #AppleVision, fantastic, well done! 🙁 I'm not happy that #AR devs are forced to make use of it. You don't allow us to make simple direct ports like you do with #VR Apps. Please allow the creation of fully immersive #AR apps that don't require Unity #PolySpatial, it's literally one line of code: "passthroughEnabled = true" I'm certain that our customers will eventually demand we support the shared app space, there is no need to force our hand, they will. Many #AR pioneers would love to be part of your ecosystem but you are making it exceedingly hard, please reconsider. cc @DanMillerDev @vvuk
English
12
9
85
27.8K
Demi Obenour
Demi Obenour@AlwaysCurious__·
@javierdavalos @Apple @unity @FigminXR That leaves only one other option, and that is to ensure that untrusted apps cannot access sensitive data at all. This results in a declarative API, which is exactly what Apple implemented.
English
0
0
0
24
Demi Obenour
Demi Obenour@AlwaysCurious__·
@javierdavalos @Apple @unity @FigminXR I’m not sure if confinement (preventing a process from exfiltrating data) is even possible on Apple’s GPUs, and even if it was, the overhead would almost certainly be prohibitive.
English
1
0
0
24
henry 🌘
henry 🌘@hdevalence·
for indoor air, if you don’t already have a way to clean your air, you need one. good news is box fan filters work well, because the biggest thing is to max out the volume of processed air. for outdoor air, get N95 masks WITH VALVES that conform to the face, like the 3M 9211
henry 🌘 tweet mediahenry 🌘 tweet mediahenry 🌘 tweet media
English
2
1
2
986
henry 🌘
henry 🌘@hdevalence·
one thing i haven’t seen much discussion of in the east coast smoke discourse is that it’s in all likelihood going to be like this for weeks of months, this isn’t a one-off event
English
4
3
15
1.5K