Daniel Micay

21K posts

Daniel Micay banner
Daniel Micay

Daniel Micay

@DanielMicay

Security researcher/engineer working on mobile privacy/security. Founder of @GrapheneOS.

Toronto, Ontario, Canada Katılım Haziran 2018
358 Takip Edilen11.7K Takipçiler
Daniel Micay
Daniel Micay@DanielMicay·
@crookedRebel I don't want someone publicly spreading lies about me using GrapheneOS. If you were a GrapheneOS community member and targeted other open source developers this way, you would be quickly banned. It's you who is toxic, not the person you're targeting talking about your harassment.
English
1
0
1
101
Daniel Micay
Daniel Micay@DanielMicay·
@crookedRebel We've provided a large amount of evidence and the ongoing harassment is plainly visible across many platforms. You're making false accusations towards me based on fabricated stories from people spearheading the harassment. You're providing a demonstrating of libel and bullying.
English
1
0
1
90
Daniel Micay
Daniel Micay@DanielMicay·
Lots of infosec people are still following and interacting with @hackerfantastic years after they became a QAnon believer and started posting endless unsubstantiated conspiracy drivel and misinformation. Now they're participating in Kiwi Farms harassment. x.com/GrapheneOS/sta…
GrapheneOS@GrapheneOS

This post is needed to debunk misinformation from a charlatan (@hackerfantastic) masquerading as being a legitimate security researcher. They used to be quite successful at duping people into believing they were legitimate by taking credit for other people's work and fabricating vulnerabilities, which hasn't held up for them in the long term. They have historical follows from actual researchers from before their credibility disintegrated which is part of why people still fall for it. They are not a legitimate researcher and many of their past claims of exploits including phony systemd exploits have been debunked. Lennart Poettering is one of several people to debunk their made up vulnerabilities and had their replies hidden along with being blocked, which is the same approach they just took with us (see the hidden posts at x.com/hackerfantasti… for an example). The many unsubstantiated claims they make should not be believed. We can't reply at all within those threads anymore due to the new way blocking works so we're replying here instead. Their main attempt at attacking us is making the ridiculous and downright desperate false claim that somehow the only purpose of GrapheneOS is using OpenBSD heap allocators, which it hasn't even used since before we made hardened_malloc in 2018: x.com/hackerfantasti… x.com/hackerfantasti… x.com/hackerfantasti… Our hardened_malloc project is an important sub-project protecting very well against the majority of remote code execution exploits in the userspace part of the OS. However, it's a tiny portion of our overall work and only one of many major privacy and security features we provide. Even if we did still use OpenBSD malloc for 32-bit apps on older devices still supporting them, that wouldn't be a significant part of the project at all. They're promoting that people use a highly insecure device without the most basic hardware, firmware and software security features where data can be trivially extracted from the device without even using exploits and where far more vulnerabilities are exposed with negligible protection against them being exploited: x.com/hackerfantasti… GrapheneOS is a Linux distribution based on the Android Open Source Project (AOSP). Compared to a traditional desktop Linux distribution, AOSP is already very hardened and provides dramatically better privacy and security. It's a night and day difference. Traditional desktop Linux distributions struggle to deploy exploit protections from the early 2000s and lack proper app sandboxing. They lack systemic privacy and security work throughout the OS as a whole. They're really a bunch of largely anti-security projects glued together into a frankenstein OS with the development direction set by these individual projects, not the distributions. They ship what's provided to them, and the result is not a particularly secure OS. iOS and AOSP are far more secure than these operating systems. A bunch of companies having badly maintained forks of AOSP does not reflect on AOSP itself, but even those are far more secure than traditional desktop operating systems if they're doing the bare minimum of providing security patch backports. Android Open Source Project without our improvements is far more secure than desktop Linux distributions. It already has a far more hardened kernel with a huge amount of attack surface reduction via the kernel configuration, very advanced use SELinux and to a lesser extent seccomp-bpf. The differences in userspace are far more dramatic. It has a well designed mandatory app sandbox and sandboxing heavily used throughout the OS. It has strict full system SELinux MAC/MLS policies which the OS is developed around rather than being added on afterwards. The majority of new code is being written in memory safe languages (Rust, Java, Kotlin). It was always focused on memory safety, sandboxing, etc. from the start. Privacy and security are a major focus throughout it and many design compromises are made for them rather than being an afterthought. Backwards incompatible privacy and security changes are made to the app sandbox on a yearly basis. Our features compared to the latest release of the standard Android Open Source Project are documented at grapheneos.org/features. This page only covers our improvements and does not cover the standard AOSP privacy and security features. The subset of our features which have been landed upstream by us such as FORTIFY_SOURCE for the Linux kernel string library have been removed from our features page. Our hardened_malloc project provides great protection against heap corruption vulnerabilities in userspace but that's just one small part of the overall GrapheneOS project. Prior to making our hardened_malloc project in 2018, we used our own fork of OpenBSD malloc ported to Linux and extended with significant additional security features. This had to be replaced as a whole to provide substantially better security against heap vulnerabilities. This charlatan (@hackerfantastic) is spreading misinformation about GrapheneOS because they had a business deal with Copperhead after the failed takeover attempt on GrapheneOS. They were trying to sell devices with their insecure, closed source fork of legacy GrapheneOS versions. They hold a grudge against us based on their business venture failing and are trying their best to spread misinformation about it. Unfortunately for them, they don't have the faintest clue about what we work on and what we provide in current generation GrapheneOS. They responded to us responding with polite, accurate information by hiding our posts, blocking us and doubling down on blatant misinformation which we already pointed out. If you want to go down a deep rabbit hole, look into how the company they co-founded, Hacker House, got money through government corruption. If they keep going down the road of supporting harassment content targeting our team, we can make a post about this.

English
2
0
19
2.2K
Daniel Micay retweetledi
James Surowiecki
James Surowiecki@JamesSurowiecki·
Just figured out where these fake tariff rates come from. They didn't actually calculate tariff rates + non-tariff barriers, as they say they did. Instead, for every country, they just took our trade deficit with that country and divided it by the country's exports to us. So we have a $17.9 billion trade deficit with Indonesia. Its exports to us are $28 billion. $17.9/$28 = 64%, which Trump claims is the tariff rate Indonesia charges us. What extraordinary nonsense this is.
James Surowiecki@JamesSurowiecki

It's also important to understand that the tariff rates that foreign countries are supposedly charging us are just made-up numbers. South Korea, with which we have a trade agreement, is not charging a 50% tariff on U.S. exports. Nor is the EU charging a 39% tariff.

English
2.4K
21.3K
92.8K
19.8M
Daniel Micay retweetledi
ELINT News
ELINT News@ELINTNews·
So when U.S. Key Hole reconnaissance satellites see Kh-101 cruise missiles targeted at power plants and hospitals being loaded on to Tu-95’s in Russia, they won’t be warning Ukraine in advance. Nice, another absolutely unconscionable decision.
Deborah Haynes@haynesdeborah

UPDATE: The US has stopped sharing "all" intelligence with Ukraine, a Ukrainian source has said.  Previously the source, with knowledge of the situation, said the halt in the follow of intelligence had been "selective", only affecting information that could be used for attacks inside Russia.  "A few hours ago, the exchange of all information was stopped," the source said.  With @safarov_

English
272
1.9K
7.4K
359.2K
Daniel Micay retweetledi
LaurieWired
LaurieWired@lauriewired·
In an 1997 AI class at UT Austin, a neural net playing "infinite-board" Tic-Tac-Toe found an unbeatable strategy: Choose moves billions of squares away, causing your opponent's to run out of memory and crash, forfeiting their turn. The winning move was to kill your enemy.
LaurieWired tweet media
English
78
452
8.7K
204.6K
Daniel Micay retweetledi
Nikola Toshev
Nikola Toshev@ntoshev·
@elonmusk This was never Zelensky's choice. Peace makes sense only with REAL security guarantees, which no one is willing to provide. US, UK, France, and Russia all "guaranteed" Ukraine's security when it surrendered its nukes 20 yrs ago. Russia has been breaking each and every deal since!
English
20
33
624
25.2K
Daniel Micay
Daniel Micay@DanielMicay·
@kommentlezz They don't take it very seriously. He got a 4 year sentence for trying to physically harm people with law enforcement. Law enforcement and the court system don't acknowledge that the people are being used as a dangerous weapon and that people can and do get harmed/killed by them.
English
1
0
8
310
Pavel Dmitriev
Pavel Dmitriev@kommentlezz·
@DanielMicay How come it's taken them that long to find him?
Kazakhstan 🇰🇿 English
1
0
2
297
Daniel Micay
Daniel Micay@DanielMicay·
Can someone in the US file a FOIA request about arstechnica.com/security/2025/… to find out if they were the person paid to try to have me killed by law enforcement? There's a chance it could be traced back to the person who paid for it. I can contact the detectives here about it.
English
1
0
10
1.7K
Daniel Micay
Daniel Micay@DanielMicay·
I supported people being attacked by Kiwi Farms before I was being targeted in this way. I've needed similar support especially after I was swatted in April 2023 and targeted by a Kiwi Farms user with a huge following weeks later with a typical mix of fabrications and bullying.
English
0
0
10
1.2K
Daniel Micay
Daniel Micay@DanielMicay·
It gets very tiring that most people with any kind of issue with GrapheneOS jump right to joining in with pushing fabricated stories about me and harassment. Silence of the infosec community about this ongoing harassment for many years and particularly right now is deafening.
English
1
0
12
1.4K
Daniel Micay retweetledi
Yair Rosenberg
Yair Rosenberg@Yair_Rosenberg·
I will just point out that this was how the University of Michigan announced its current DEI program in 2022. Seems like they are living up to their promise!
Yair Rosenberg tweet media
English
15
149
1.1K
129.6K
Daniel Micay retweetledi
Matti Palli 🧙‍♂️
At Keflavik airport, there’s a guy whose job it is to guess the nationality of anyone leaving the country and click the right flag. They must be hiring only the advanced racists for this job, someone who can tell a Norwegian from a Swede with just a glance
Matti Palli 🧙‍♂️ tweet media
English
392
3.3K
79.6K
3.2M
Daniel Micay retweetledi
Daniel Micay
Daniel Micay@DanielMicay·
@moyix Since they're virtual machines, they can snapshot and restore them including moving them across machines. Planned downtime wouldn't normally be visible. They hopefully did update the hosts at some point but you wouldn't be able to see that beyond a tiny downtime at some point.
English
0
0
4
176
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
Whoops, apparently DigitalOcean machines can really stay up a long time when you forget about them
Brendan Dolan-Gavitt tweet media
English
4
0
19
2.2K