Jeremy Boone

2K posts

Jeremy Boone

Jeremy Boone

@uffeux

HW/FW security researcher @ fruit company

Canada Katılım Mayıs 2009
420 Takip Edilen1.3K Takipçiler
Jeremy Boone
Jeremy Boone@uffeux·
Hello friends. Check out this awesome and unique role that just opened up on my team in SEAR. Wanna secure Apple silicon, ROMs, iBoot, and more? jobs.apple.com/en-us/details/…
English
7
52
175
29.1K
Jeremy Boone retweetledi
Jiska
Jiska@naehrdine·
Broadcom and Cypress chips have the same HCI "backdoor" allowing to write to the Bluetooth chip's RAM. This feature is used for firmware patches. We didn't request CVEs for that 9 years ago. Instead, we built the InternalBlue Bluetooth research framework. github.com/seemoo-lab/int…
Tarlogic@Tarlogic

🔷 A backdoor in the ESP32 chip would allow it to infect millions of devices. Miguel Tarascó and @antonvblanco have revealed this at the @rootedcon this backdoor and presented a tool to perform Bluetooth security audits on any gadget. tarlogic.com/news/backdoor-…

English
4
91
331
40.4K
Jeremy Boone retweetledi
jon
jon@jon_roelofs·
@evilsocket any interest in working on security in compilers? my team is looking for someone with a peculiar intersection of skills/interests: jobs.apple.com/en-us/details/…
English
3
14
92
37.2K
Jeremy Boone retweetledi
Ivan Krstić
Ivan Krstić@radian·
🔺New on the Apple Security Research blog: introducing Private Cloud Compute! We believe this is the most advanced security architecture ever deployed for cloud AI compute at scale. security.apple.com/blog/private-c…
English
14
143
408
95.9K
Jeremy Boone retweetledi
Jacques Fortier
Jacques Fortier@jacquesgt·
Are you excited to use the power of safe modern programming languages like Swift to make software more secure? My SPEAR team at Apple is hiring a Swift Software Engineer to do exactly that! jobs.apple.com/en-us/details/…
English
3
24
52
16.4K
Jeremy Boone retweetledi
Ivan Krstić
Ivan Krstić@radian·
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world. security.apple.com/blog/imessage-…
English
7
124
361
60.6K
Jeremy Boone retweetledi
quarkslab
quarkslab@quarkslab·
Is remote code execution in UEFI firmware possible? Yes it is. Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers. Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-nine…
quarkslab tweet media
English
5
205
343
78.6K
Jeremy Boone
Jeremy Boone@uffeux·
@4Dgifts Check out the Tianocore Bugzilla. These were first reported in October and November of 2022. Amazing.
English
1
0
2
51
Jeremy Boone
Jeremy Boone@uffeux·
@ryanaraine According to the sequence of steps in this document, I am still stuck at Step #1 after 300+ days. Tianocore hasn't even begun to engage IFVs, ODMs or OEMs. I think the Tianocore PSIRT lives in a time dilation vortex.
English
1
5
7
3K
Jeremy Boone
Jeremy Boone@uffeux·
@ryanaraine I reported 2 vulns in EDK2 that are still unfixed. They are... let me check... 336 days old. Tianocore security team ghosted me. Had to engage downstream vendors to get any traction whatsoever. Still, no fix in sight.
English
1
7
18
4.1K
Jeremy Boone retweetledi
Kevin Dunn
Kevin Dunn@kdunn_security·
Public Report – Caliptra Security Assessment During August and September of 2023, Microsoft engaged NCC Group to conduct a security assessment of Caliptra v0.9. The assessment identified 26 vulnerabilities, which were promptly addressed by the Caliptra... bit.ly/3SaMNWM
Kevin Dunn tweet media
English
0
1
1
248
Jeremy Boone retweetledi
Greg Hilton
Greg Hilton@GregHil14555931·
Public Report – Caliptra Security Assessment During August and September of 2023, Microsoft engaged NCC Group to conduct a security assessment of Caliptra v0.9. The assessment identified 26 vulnerabilities, which were promptly addressed by the Caliptra... bit.ly/3QoVImr
Greg Hilton tweet media
English
0
1
1
207