Sergey Simakov (@[email protected])

6.9K posts

Sergey Simakov (@sergesim@infosec.exchange) banner
Sergey Simakov (@sergesim@infosec.exchange)

Sergey Simakov (@[email protected])

@sergesim

Cloud-scale security engineering and all the things. My tweets are my own.

Greater Seattle Katılım Kasım 2008
3.3K Takip Edilen762 Takipçiler
Sergey Simakov (@[email protected]) retweetledi
Matei Zaharia
Matei Zaharia@matei_zaharia·
ACM CAIS is a the first research conference focused on agentic and AI systems, and will run in San Jose this year. The deadline is coming up Feb 27th — submit your papers here: caisconf.org
English
0
13
43
5.1K
Sergey Simakov (@sergesim@infosec.exchange)
Very bad experience with @avianca for AV 191 today: 1) cannot explain why only 1 person of 2 able to check-in online. With unclear “incomplete” message 2) refuses to support suitcase that was checked in by Alaska on the way to FLL, that they don’t have it in the system!
English
4
0
0
2K
Sergey Simakov (@[email protected]) retweetledi
Phil Venables
Phil Venables@philvenables·
Post Quantum Cryptography - Time to Get Going. There are wide ranging estimates on the time frame in which to be concerned about the existence of a cryptographically relevant quantum computer (i.e. one that can break RSA / ECC in reasonable time). But the three triggers/warnings to look at are: 1. Are there machines with higher numbers of physical qbits. 2. Are there less physical qbits needed to make good logical qbits. 3. Are there other advances that reduce the number of logical qbits needed. If all 3 are blinking red that you will want to bring in your time frames for when your PQC migration is done. This blog from Google highlights significant progress on reducing the number of physical qbits needed to factor RSA 2048. Warning lights are starting to switch on. security.googleblog.com/2025/05/tracki… If you haven't even started planning your PQC migration then you really should start. Some guidance on how to get going here: philvenables.com/post/post-quan…
Phil Venables tweet media
English
1
4
10
2.1K
Sergey Simakov (@[email protected]) retweetledi
Jean-Michel Besnard
Jean-Michel Besnard@jmbesnard_maz·
Want to check for #ESC15 ? Use the following cypher with #BloodHound MATCH p=(:Base)-[:MemberOf*0..]->()-[:Enroll|AllExtendedRights]->(ct:CertTemplate)-[:PublishedTo]->(:EnterpriseCA)-[:TrustedForNTAuth]->(:NTAuthStore)-[:NTAuthStoreFor]->(:Domain) WHERE ct.enrolleesuppliessubject = True AND ct.authenticationenabled = False AND ct.requiresmanagerapproval = False AND ct.schemaversion = 1 RETURN p Thanks @Jonas_B_K More information available here: trustedsec.com/blog/ekuwu-not…
Jean-Michel Besnard tweet media
English
2
66
201
17K
Sergey Simakov (@[email protected]) retweetledi
Alec Muffett
Alec Muffett@AlecMuffett·
IN CASE YOU MISSED IT: The EU — in private — amended draft digital identity regulation to create a legally-mandated surveillance backdoor in HTTPS. Over 300 academics & tech experts YESTERDAY published an open letter calling on the EU to fix this + follow web standards instead:
Alec Muffett@AlecMuffett

Hot on the heels of #ChatControl and in the name of “identity” and “consumer choice” the EU seeks the ability to undetectably spy on HTTPS communication; 300+ experts say “no” to #Article45 of #eIDAS #QWAC alecmuffett.com/article/108139

English
6
170
230
29.9K
Sergey Simakov (@[email protected]) retweetledi
Phil Venables
Phil Venables@philvenables·
Caricatures of Security People 2. Cryptographer turned Security Guru Says things like: “If only people more than just me realized that security processes are important we’d be in a much better place.” philvenables.com/post/caricatur…
Phil Venables tweet media
English
0
3
9
3.9K
Royal Hansen
Royal Hansen@royalhansen·
Arguably the greatest room in any art museum on the planet
Royal Hansen tweet mediaRoyal Hansen tweet mediaRoyal Hansen tweet mediaRoyal Hansen tweet media
English
3
0
15
1.5K
Sergey Simakov (@[email protected]) retweetledi
Nick Sullivan
Nick Sullivan@grittygrease·
Encrypted Client Hello (ECH) is a new proposed standard that improves encryption and metadata protection for connections online that use TLS for security. After years of testing and refinement, it's finally happening. Chrome has been testing ECH for months, and is now enabling it by default in Chrome 117: chromestatus.com/feature/619670…. Firefox is not far behind: elevenforum.com/t/encrypted-cl…. Cloudflare just launched support for ECH for all customers: blog.cloudflare.com/announcing-enc…. These changes amount to the removal of the hostname from cleartext for huge chunk of Internet communication. Considering how long the hostname has been in cleartext and how many products were built around that assumption, it's going to be an interesting rollout.
English
13
149
509
97.9K
Sergey Simakov (@[email protected]) retweetledi
Christian Blichmann 🇺🇦 (on bksy and Mastodon)
In the spirit of "this talk could've been a tweet", I just pushed a button: #BinDiff is now open source. - Snapshot release, no major new functionality - Release binaries later today or tomorrow - This is my 20% and I won't we able to act on PRs until end of Q4 (OOO traveling)
Christian Blichmann 🇺🇦 (on bksy and Mastodon) tweet media
English
8
340
1K
210.8K
Sergey Simakov (@[email protected]) retweetledi
Royal Hansen
Royal Hansen@royalhansen·
"We’re working towards a future of personalized vulnerability detection with little manual effort from developers. With the addition of LLM generated fuzz targets, OSS-Fuzz can help improve open source security for everyone." security.googleblog.com/2023/08/ai-pow…
English
0
11
64
25.5K
Sergey Simakov (@[email protected]) retweetledi
Science Is Strategic
Science Is Strategic@scienceisstrat1·
But the overall risk for Europe 🇪🇺 is that its prosperity and influence will continue to decline given how important technology is to economic vitality and competitiveness (21/25)
Science Is Strategic tweet media
English
4
30
203
24.7K