FallenWings ☄️
6.1K posts

FallenWings ☄️
@YukiFallenWings
The kind of guy which makes you go "Wait. Where have I seen you again?"
Living in Existence itself. Katılım Haziran 2012
640 Takip Edilen180 Takipçiler
Sabitlenmiş Tweet

@yuzhinok People that live in peace too long forget the terrors of war.
Most dont appreciate something till they lose it. Ignorance is bliss but its also a choice. And many chose poorly.
English

Among countries like China, South Korea, Israel and Singapore, where the military is somewhat prominent in society
It seems to only be Singapore where the military is not highly respected by society. Even the Israelis view their own military in a more positive light than sinkies
Mothership@MothershipSG
'Can't SAF do something?': Netizen complains about NSmen taking the bus, gets clowned on bit.ly/4vYKFlh
English

Vtuber fans with multiple oshi tags
Veridis | Hringhorni Resident@VeridisArpegius
Damn he's really hitting the
Eesti

@mitsukanehive You get free translations by volunteers.
Dont be a prick.
English
FallenWings ☄️ retweetledi
FallenWings ☄️ retweetledi
FallenWings ☄️ retweetledi

The largest Piracy site in existence is now in the sights of governments to take it down
Nyaa the world’s largest anime torrent site has become the target of a piracy crackdown following the arrest of a first uploader (seeder) who shared a copyrighted work on the platform.
The Cyber Investigation Division of the Kyoto Prefectural Police and the Fushimi Police Station arrested a man residing in Sagamihara City on July 28, 2026.
With major players like HiAnime and other major anime piracy sites dead. CODA and other agencies will likely shift their attention to Nyaa in a bid to curb the copyright infringement that has reportedly bled the anime industry dry for years.
This could be the great burning of Alexandria in Anime form if it continues to escalate.

English
FallenWings ☄️ retweetledi
FallenWings ☄️ retweetledi

@theabibyama Say thanks to low effort clips for the summary when it drops
English

@CrossesTheRoad @MuratMgrb @Raspberry_Pi I don't blame the manufacturers as much as sam since they are reacting instead of proactive
Companies are souless giants with only one driving factor which is money.
On paper, the money checked out.
That doesnt grant them forgiveness tho
English

@YukiFallenWings @MuratMgrb @Raspberry_Pi The ram manufacturers are also on it because they don't really care if they make profit with selling to consumers or if they make even more profit with selling to datacenters
English

@Fl0atingSign Also another theory
Performance arts used to have all the best
Which leads to all of them having tons of sex.
Which spread STDs like crazy.
Which then killed all the top performancers, only leaving the mid and the bad as the "best"
Those that truely held art died with them
English

Do you want to know why the arts are declining?
High art like opera, ballet, theater never made money. They used to be supported by an elite made of wealthy patrons who spent a fortune on those things because they liked them.
This is your “elite” now. Tasteless, gauche.
Julie Chen@0xJuliechen
pov: your company sponsored a yacht gala to Alcatraz with 150 hot ppl the most popular side event at YC sus 🛳️💃
English

FallenWings ☄️ retweetledi

x.com/niemerg/status…
This proposal wouldn't hide that a wipe occurred and would help adversaries exploit and recover data from the device. It isn't a new idea and people have proposed variations of this hundreds of time for years. These proposals wouldn't hold up against widely available forensic software. Giving an attacker access to a decoy profile would make it far easier for them to exploit the device. Without a shut down or reboot, a device was previously in After First Unlock state would be very vulnerable to having data extracted.
GrapheneOS has strong protection against data extraction without depending on a duress PIN/password. The default enabled protections combined with a strong passphrase and 2nd factor fingerprint PIN would have provided fantastic protection for the data on the device. Reducing the device auto-reboot timer would be even better. The secure element would have protected the data with only a random 6 digit PIN instead of a passphrase in practice too.
All of our features are designed to work against adversaries aware of GrapheneOS. Our duress PIN/password is no different. Adversaries aware of GrapheneOS face a dilemma about whether a PIN/password provided by the user is going to unlock the device or wipe it. It wasn't designed around being a secret resulting in an unpleasant surprise for an adversary. We also plan to provide it as part of secure element rate limiting on future devices built to run GrapheneOS to prevent bypassing it with an OS exploit.
Triggering our duress PIN/password feature wipes both hardware keystores, the secure element as a whole and disk encryption metadata. Each of these 3 steps is enough on their own to reliably wipe material needed to obtain the key encryption keys for disk encryption. It happens nearly instantly and it wouldn't be secure if it took a bunch of time or depended on actually erasing any of the encrypted data. Shutting down the device triggers clearing sensitive data from RAM and registers to complete the process. It's necessary to clear a lot of sensitive data from memory and registers including decrypted encryption keys in TEE memory.
Giving an adversary access to a profile on the device instead of shutting down or rebooting would be very problematic. It would give them an immense amount of attack surface for exploiting the device to recover sensitive user data. If the Owner user is in After First Unlock state, the adversary has given massive attack surface for exploiting the device to obtain all of the data from the main user. It would be the extreme opposite of the attack surface reduction and exploit protections provided by GrapheneOS.
GrapheneOS and apps running on it could continue to function indefinitely after the key derivation material is wiped. It already has disk encryption keys loaded into Trusted Execution Environment memory and is using those for inline disk encryption via wrapped keys. Only functionality depending on hardware keys would be broken. If there were profiles in After First Unlock state those would still be available. An attacker exploiting the device would recover the same data as before wiping the key encryption keys.
Forensic data extraction companies have access to GrapheneOS and we don't have access to their software. We cannot rely on security through obscurity or knowing how their software works including which vulnerabilities they exploit. Fooling widely available forensic software into believing a decoy profile is the Owner user isn't feasible. It would need to provide a fully functional Android Debug Bridge (ADB) environment which is completely impractical.
People should consider the fact that they likely haven't thought about this nearly as much as us. There are good reasons for why we designed this feature the way we did and it's working as intended in the real world. The feature becoming widely known about is a requirement for it to work as intended by creating a dilemma for adversaries. The main thing we need now is secure element support for it which we can get implemented for future devices as part of our Motorola Mobility partnership and future OEM partnerships.
Allan@niemerg
“duress” password is incorrectly designed—it shouldn’t be apparent to the attacker that it was triggered and should instead open to an innocuous and data free home screen while nuking everything in the background
English

Seems that I'll not be out of job for quite awhile
Jinsu@Jinsus
@MidgeGames82 dawg I asked chat gpt and told it my exact setup told me it could be something with the hdmi so just covering all the bases before I give up
English

@mahouarms Please do.
I had quite an experience in 2020 when i dropped that feedback in discord 😂
English

thanks for getting us to #1 of Popular New Releases 🫶
We're working on an urgent list of bugs and tweaks that slipped through 1.0 and it should be up within a week

English


















