Anestis Bechtsoudis

1.3K posts

Anestis Bechtsoudis banner
Anestis Bechtsoudis

Anestis Bechtsoudis

@anestisb

InfoSec Engineer @census_labs - Driven by passion for challenges

Greece Katılım Ocak 2011
302 Takip Edilen929 Takipçiler
Anestis Bechtsoudis retweetledi
argp
argp@_argp·
Congratulations to my @census_labs colleague Zisis Sialveras (@_zisis) for being accepted to present his amazing work on VMware vulnerability research and exploit development at Black Hat USA 2024: #bugs-of-yore-a-bug-hunting-journey-on-vmwares-hypervisor-40085" target="_blank" rel="nofollow noopener">blackhat.com/us-24/briefing…
English
0
6
39
4.1K
Anestis Bechtsoudis
Anestis Bechtsoudis@anestisb·
@dwizzzleMSFT @parityzero Thanks for sharing. Looking forward to adding stronger access control on top (AppContainer SID based?). Eliminating key lifting is a great first step, but protecting against unauthorised key usage from admin/system-level actor is also essential. Identity keys desperately need it.
English
1
0
0
257
Anestis Bechtsoudis
Anestis Bechtsoudis@anestisb·
I’m hiring to grow our confidential computing security eng. team (edge devices & cloud platforms). If hypervisors, virt, attestation, (v)TPM, KVM, crosvm, SGX/TDX/SEV-SNP/VMPL, dynamic passthrough & VirtIO tickle your brain, drop me a message to discuss potential opportunities.
English
0
7
28
9.9K
Anestis Bechtsoudis retweetledi
CENSUS
CENSUS@census_labs·
CENSUS is a sponsor of the 6th Cybersecurity in Financial Services Summit 2023 taking place on November 21st in London. Our presentation titled “AI-Are we doomed?” will shed light to the fascinating yet scary world of AI and how it affects #Financial Institutions & Cybersecurity.
CENSUS tweet media
English
0
3
2
1.8K
Anestis Bechtsoudis retweetledi
Dimitris Glynos
Dimitris Glynos@dfunc·
If you enjoy working on software security assessments, please note that our "Application Security Engineer" position is now also open for remote working #cfase" target="_blank" rel="nofollow noopener">census-labs.com/openings/#cfase #infosec
English
0
4
3
0
Anestis Bechtsoudis retweetledi
Dimitris Glynos
Dimitris Glynos@dfunc·
Do you enjoy working on Trusted Boot, Trusted Execution Environments, Secure Elements, HSMs, CPU virtualization, hardware attestation, embedded architecture sec. reviews, hardening kernels, system components or bare metal firmware? This job is for you: #cfese2021a" target="_blank" rel="nofollow noopener">census-labs.com/openings/#cfes
English
1
11
19
0
Anestis Bechtsoudis retweetledi
argp
argp@_argp·
Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027); epic logical exploitation writeup by huku: census-labs.com/news/2021/04/1…
English
4
264
597
0
Anestis Bechtsoudis retweetledi
Jeff Vander Stoep
Jeff Vander Stoep@jeffvanderstoep·
Rust in the Android platform! We’re excited to announce that the Android Open Source Project (AOSP) now supports the Rust programming language for OS development! security.googleblog.com/2021/04/rust-i…
English
6
261
899
0
Anestis Bechtsoudis retweetledi
Bjoern Kerler
Bjoern Kerler@viperbjk·
This was never meant to be released. bkerler.github.io/2020/08/03/bri… I once reported the xpu2/xpu3 0-day to qc, and they seem to have fixed it on the latest sdm platform, thus it's time to release this now. Enjoy getting full control. It's easiest using it on an unfused device :D
English
1
14
17
0
Anestis Bechtsoudis retweetledi
Dimitris Glynos
Dimitris Glynos@dfunc·
We're growing our hardware lab team at @census_labs. Now looking for a dedicated electronics engineer. For more information see: #cfee2020a" target="_blank" rel="nofollow noopener">census-labs.com/openings/#cfee
English
0
2
3
0
Anestis Bechtsoudis
Anestis Bechtsoudis@anestisb·
@shawnwillden @phhusson @MishaalRahman @topjohnwu @DanielMicay Thanks for sharing. Curious how QC will impl. the UDS latch. Assume similar to SHK don’t want ODM to fuse so will be OEM burned at SecBoot enable stage. QFPROM r/w perm table in shadow mem is the main acl for fuses afaik, which with EL3 exec is modifyable. Any info you can share?
English
1
0
1
0
John Wu
John Wu@topjohnwu·
If you are curious how all this thing works, check out this wiki page for a brief intro. en.wikipedia.org/wiki/Trusted_e… As I said, if you manage to break into TEE, publish a paper, be famous (academically), and enjoy the bounty money 😉
John Wu@topjohnwu

To hack this thing, you have to either find a vulnerability in TEE firmware (which will be patched ASAP once found) or hardware (less likely to happen) to break the cryptography. Breaking TEE won't be easy, which is why many security researchers are actively working on it.

English
3
4
111
0
Anestis Bechtsoudis retweetledi
Shawn Willden
Shawn Willden@shawnwillden·
@phhusson @MishaalRahman @topjohnwu @DanielMicay If you're not familiar with the DICE concept, here it is: Start with a device-unique secret fused into the SoC. The ROM uses this secret and a hash of the first bootloader stage to derive an EC key pair, then flips a switch that disables access to the fuses until next reboot.
English
3
4
9
0
Anestis Bechtsoudis retweetledi
chompie
chompie@chompie1337·
I repurposed @maddiestone's #BadBinder PoC for the S8/S8 Active Snapdragon. I bypass DAC + SELinux + Knox/RKP using a couple techniques I developed that I haven't seen used before. PoC here: github.com/chompie1337/s8…
English
4
102
288
0
Anestis Bechtsoudis
Anestis Bechtsoudis@anestisb·
VdexExtractor 0.6.0 released with Android 10 support. Seems that new 021 version has minor changes to support Vdex files generated from InMemoryDexClassLoader. To worry about perf there, G seems to invest a lot on it. | github.com/anestisb/vdexE…
English
0
9
21
0