BarbossHack

1.7K posts

BarbossHack banner
BarbossHack

BarbossHack

@BarbossHack

Engineer with beard.

France Katılım Ocak 2018
886 Takip Edilen175 Takipçiler
BarbossHack
BarbossHack@BarbossHack·
@P4mui J’avais acheté le Pixel 8, mais 300ms de latence sur la synchro labiale en bluetooth, je l’ai renvoyé pour un iPhone (je suis un peu pointilleux 😌)
Français
0
0
0
39
P4mui 
P4mui @P4mui·
Je me demande si certains utilisateurs iOS seraient prêt à retenter l'expérience Android Car pour énormément : soit ils ont utilisé une très vieille version d'Android soit un très mauvais smartphone pas cher avant d'économiser pour un iPhone.. ce qui du coup ne montre pas la vraie expérience Android
Français
102
4
110
28.7K
BarbossHack
BarbossHack@BarbossHack·
@topjohnwu Nice! And which tool do you use to flash the firmware?
English
1
0
0
221
John Wu
John Wu@topjohnwu·
Let me introduce samloader-rs: • Inspired by the Python samloader project • Download Samsung firmware directly from Samsung servers • Support downloading with multiple connections • Decrypt the file on-the-fly, no separate decryption step github.com/topjohnwu/saml…
English
3
22
173
7K
John Wu
John Wu@topjohnwu·
After purchasing my Z Trifold, I discovered the existing open source tooling for Samsung firmware downloading is quite lacking in features. I didn't find any existing open source tool that supports parallel download + on-the-fly decryption. So I decided to build my own!
English
6
16
278
16.1K
BarbossHack
BarbossHack@BarbossHack·
It looks like no one is actually testing @telegram reproducible builds against Play Store APKs. I found errors in their bundle process, and their apkfrombundle script always returns "APK has difference!" (don't get me wrong: no backdoors, just a broken bundle process)
English
0
0
0
61
BarbossHack
BarbossHack@BarbossHack·
@OreoB1scuit @_B13ss3d_ But you will still need a jailbroken iPhone to decrypt the IPA downloaded with ipatool. If you find a way to do it, I'm interested.
English
0
0
0
89
Biscuit
Biscuit@OreoB1scuit·
how you guys get IPA file without IPhone for bug bounty ?
English
2
0
6
1.1K
Proton Support
Proton Support@ProtonSupport·
This headline is misleading. Proton did not provide any information to the FBI. The Swiss government received a legal request involving a case where a police officer was shot, and explosives were found during an incident in 2024. Assaulting a police officer is a severe criminal offense, often treated more seriously than regular assault, raising the bar for legal assistance in the world. Even then, only payment info was disclosed which is optional on the account; no emails, messages, or content. If anything, this case proves how little data Proton actually holds. For users who want maximum anonymity, we accept cash and crypto.
English
44
34
598
81.8K
SIGNAL
SIGNAL@SIGNAL_RETURN·
I've been vocally critic of @ProtonMail. Exposure of them doxing a user today made me rethink how we can use the leaps in cryptography to achieve truly private email without changing SMTP. We did it. Provably private mail is coming. No more single point of failure. 🫡💛
English
41
86
1.5K
88.3K
Mwangi Wa Maina
Mwangi Wa Maina@MwangiEMaina·
Hey @ProtonVPN, @ProtonMail you have something to say about this? You handed private data to the swiss government who handed it over to the FBI. so much for the so-called privacy!
Mwangi Wa Maina tweet media
English
4
3
15
4.3K
Proton Support
Proton Support@ProtonSupport·
The Swiss government received a legal request involving a case where a police officer was shot, and explosives were found during an incident in 2024. Assaulting a police officer is a severe criminal offense, often treated more seriously than regular assault, raising the bar for legal assistance in the world. No service can operate entirely outside the law, and Swiss law requires compliance with valid legal orders in serious criminal cases. What we can promise is that the legal bar in Switzerland is among the highest in the world, and our architecture ensures we have as little data as possible to hand over. Only payment info was disclosed, which is optional on the account, no emails, no messages, no content. If anything, this case proves how little data Proton actually holds. For users who want maximum anonymity, we accept cash and crypto.
English
7
4
102
4K
BarbossHack
BarbossHack@BarbossHack·
@kemar74 Le Nom du Vent 🤩 Il faudrait que je le relise d’ailleurs 📖
Français
0
0
1
173
Marc Simonetti
Marc Simonetti@kemar74·
Some golden art for today, to rinse the soul.
Marc Simonetti tweet mediaMarc Simonetti tweet mediaMarc Simonetti tweet mediaMarc Simonetti tweet media
English
18
119
1.4K
35.3K
BarbossHack
BarbossHack@BarbossHack·
@bortzmeyer Mais dans le ClientHello ya pas que le SNI, ya aussi des tonnes de paramètres que le client envoie, et dont les gens (@Cloudflare) se servent pour faire du fingerprint TLS (ja3/ja4); du coup c’est aussi la fin du fingerprint TLS ?
Français
1
0
0
145
Stéphane Bortzmeyer
Stéphane Bortzmeyer@bortzmeyer·
RFC 9849: TLS Encrypted Client Hello Quand un client #TLS se connecte, il envoie en clair au serveur le nom utilisé, le #SNI. Ce #RFC fournit une solution, #ECH (Encrypted Client Hello), qu'on pourrait traduire par « salutation chiffrée ». bortzmeyer.org/9849.html
Français
2
7
19
4.1K
BarbossHack
BarbossHack@BarbossHack·
@Numerama C’est faux, vous devriez corriger votre article erroné 👍 « Les frais d’inactivité ne s’appliqueront pas aux clients présents avant le lancement de Sumeria » « les frais d’inactivité ne seront pas prélevés sur les comptes de type porte-monnaies Lydia » sumeria.eu/blog/non-class…
Français
1
2
23
13.4K
Numerama
Numerama@Numerama·
Rappel : il vous reste peu de temps pour fermer votre compte Lydia / Sumeria avant l'application des frais d'inactivité. Et non, désinstaller l'appli ne suffit pas à clôturer le dossier.
Numerama tweet media
Français
14
52
162
639.7K
BarbossHack
BarbossHack@BarbossHack·
@Ced_haurus BreachForum (BF) c'est en fait BasicFit mais je peux pas le prouver 👀
Français
1
0
13
3.5K
BarbossHack retweetledi
Ankama Animations
Ankama Animations@AnkamaAnim·
✨ La Quête d’Ewilan débarque en série animée ! Fidèle adaptation du roman de Pierre Bottero, à découvrir dès maintenant sur France.tv et Okoo (France), Auvio (Belgique) et Play RTS (Suisse). 🌀 Propulsée dans le monde de Gwendalavir à seulement 13 ans, Camille voit son destin basculer et apprend la vérité sur ses origines. Cette sortie marque le tout premier chapitre de la collaboration entre Ankama Animations et Andarta Pictures. ❤
Ankama Animations tweet media
Français
20
151
785
32.9K
BarbossHack
BarbossHack@BarbossHack·
@BastiUi @DFintelligence Le violet en fondu ça fait trop site web Saas, le dernier ça fait trop roman policier, le blanc ne se démarque pas assez, le vert est génial 🟢
Français
0
0
0
182
BarbossHack
BarbossHack@BarbossHack·
@seblatombe C’est bien de donner une tribune à ces hackers pour qu’ils puissent se faire mousser 👍
Français
0
0
0
83
Seb
Seb@seblatombe·
⏰ À 9h, je publie un thread sur l’affaire Safran. Éléments exclusifs + réponses de la source qui revendique l’attaque.
Français
5
3
19
3.4K
BarbossHack
BarbossHack@BarbossHack·
@aarshps @ArtemR @APKMirror @Cloudflare Isn’t this kind of high-quality residential proxy that uses browser stacks usually intended for smaller-scale operations such as web scraping or similar, rather than for running large-scale DDoS attacks?
English
1
0
1
64
Aarsh
Aarsh@aarshps·
@ArtemR @BarbossHack @APKMirror @Cloudflare JA4 is useless against high-quality residential proxies. They use real browser stacks, so the fingerprint is legitimate. Blocking it would result in massive false positives.
English
1
0
2
132
Artem Russakovskii
Artem Russakovskii@ArtemR·
I thought I got pretty good at protecting @APKMirror from scraper and other malicious bot traffic using hundreds of tricks as part of our Enterprise @Cloudflare account, but this week the final boss has arrived - DDoS through residential proxies masking as real traffic. I love a new challenge though! This should be fun...
English
2
1
48
4.2K