Mathy Vanhoef

3.5K posts

Mathy Vanhoef banner
Mathy Vanhoef

Mathy Vanhoef

@vanhoefm

Prof. @KU_Leuven | Ex-Postdoc NYU | Network Security & Crypto | FragAttacks & KRACK | https://t.co/cFWyCYRZyH

Orion Arm Katılım Şubat 2011
1.6K Takip Edilen14.4K Takipçiler
Sabitlenmiş Tweet
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com
English
32
1.1K
2.7K
0
Mathy Vanhoef retweetledi
Proton VPN
Proton VPN@ProtonVPN·
1/4 Google has known about a bug that breaks VPN apps for 7 months, leaving users exposed with no warning or error, just a VPN app that stopped working in the background. If you're using ANY VPN on Android, you can help us by getting Google's attention to fix it. Details 👇 🧵
English
44
367
2.8K
206.7K
Mathy Vanhoef retweetledi
وزارة الدفاع |MOD UAE
الدفاعات الجوية الإماراتية تتعامل مع 137 صاروخاً و209 طائرة مسيرة أعلنت وزارة الدفاع أن القوات الجوية والدفاع الجوي لدولة الإمارات العربية المتحدة نجحت منذ بدء الهجوم الإيراني، في التعامل مع وتدمير 137 صاروخاً باليستياً و209 طائرة مسيّرة أُطلقت باتجاه أراضي الدولة، مؤكدةً الجاهزية العالية لمنظومات الدفاع الجوي وقدرتها على التعامل مع مختلف التهديدات. وأوضحت الوزارة إلى أنه ومنذ بدء الهجوم تم رصد 137 صاروخاً باليستياً إيرانياً تم إطلاقه تجاه الدولة، حيث تم تدمير 132 صاروخاً، فيما سقط 5 منها في مياه البحر، كما تم رصد 209 طائرة مسيرة إيرانية، وتم اعتراض 195 منها، فيما وقعت 14 منها داخل أراضي ومياه الدولة، وتسببت ببعض الأضرار الجانبية. وأشارت الوزارة إلى أنه ونتيجة التصدي الفعال للصواريخ والمسيرات، سقطت بعض الشظايا في مناطق متفرقة في الدولة، مما أدى إلى حدوث أضرار مادية بسيطة في عدد من الأعيان المدنية. وأكدت الوزارة أن الجهات المختصة تحركت على الفور بكامل جاهزيتها وإمكاناتها للتعامل مع الوضع وفق الإجراءات المعتمدة في مثل هذه الحالات، وتم اتخاذ التدابير اللازمة لضمان سلامة السكان وتأمين المواقع المتأثرة. وأدانت الوزارة هذا الهجوم بأشد العبارات، مؤكدة رفض الدولة القاطع لمثل هذه الأعمال التي تمثل تصعيداً خطيراً وعملاً جباناً يهدد أمن وسلامة المدنيين ويقوض الاستقرار. وشددت الوزارة على أن هذا الاستهداف يُعدّ انتهاكاً صارخاً للسيادة الوطنية وللقانون الدولي، وأن الدولة تحتفظ بحقها الكامل في الرد على هذا التصعيد واتخاذ جميع الإجراءات اللازمة لحماية أراضيها وشعبها والمقيمين فيها، وبما يضمن صون سيادتها وأمنها واستقرارها ويحمي مصالحها ومقدراتها الوطنية. وأعربت الوزارة أنها على أهبة الاستعداد والجاهزية للتعامل مع أية تهديدات، وأنها تتخذ كافة الإجراءات اللازمة للتصدي بحزم لكل ما يستهدف زعزعة أمن الدولة واستقرارها، وأكدت أن سلامة المواطنين والمقيمين والزوار تمثل أولوية قصوى لا يمكن التهاون فيها. وتهيب الوزارة بالجمهور الكريم استقاء المعلومات من المصادر الرسمية في الدولة، وتجنب تداول الشائعات أو المعلومات غير الموثوقة. #وزارة_الدفاع #وزارة_الدفاع_الإماراتية #MOD #UAEMinistryOfDefence
وزارة الدفاع |MOD UAE tweet media
العربية
2.1K
4.2K
11.8K
6.9M
mRr3b00t
mRr3b00t@UK_Daniel_Card·
ok very cool, I'm using #AirSnitch to overcome guest isolation and I can port scan other clients inside this isolated network. This network is 'ISOLATED' and guest isolation is enabled....
mRr3b00t tweet mediamRr3b00t tweet media
English
6
14
119
12.9K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@vanhoefm still working on this... but seems to work...
mRr3b00t tweet media
English
2
0
10
1.5K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
@nmschulte Both are open-source router distributions. DD-WRT was run on Netgear R7000 and OpenWrt on D-Link DIR3040. I'd expect most attacks to be independent of the driver(s) these devices use, and apply to dd-wrt and OpenWrt in general. But might be good to explicitly confirm that :)
English
0
0
14
1.8K
Nathan Schulte
Nathan Schulte@nmschulte·
@vanhoefm You claim "OpenWRT 24.10" is a piece of hardware (and similar DD-WRT), but its implementation varies naturally based on the target/device it is installed. Which target(s)/device(s) did you use in your research with OpenWRT/DD-WRT; or does it not matter, only hostapd cfg? Thanks!
English
1
0
5
2.2K
John🩻
John🩻@shdwstar·
@vanhoefm Air snitch is a very well chosen name.
English
1
0
14
2.7K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
@UK_Daniel_Card @0x686967 Yeah I'm trying to clarify that we can't just break any Wi-Fi network. We bypass client isolation, which is a more specific threat model. Though in one of our university networks, the co-located open network could be used to attack devices on the co-located Enterprise SSID ;)
English
1
0
7
196
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@0x686967 Haha yes! This is almost certainly being. Overstated in terms of risk imho
English
3
0
2
510
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
A big thanks to all co-authors: @zhouxinan @drivertomtt Zhutian @pkqzy888 Zhaowei, Srikanth And if you want more information, come to our Black Hat Asia talk ;) #airsnitch-breaking-client-isolation-in-wi-fi-networks-51283" target="_blank" rel="nofollow noopener">blackhat.com/asia-26/briefi…
English
0
1
39
5.4K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
Crypto is often bypassed instead of broken. And AirSnitch does exactly that: bypass crypto. A malicious insider, or someone connected to a co-located open Wi-Fi, can attack and intercept the traffic of others. If you don't rely on client/network isolation, you are safe.
English
1
3
62
7.5K
Mathy Vanhoef retweetledi
AIRLIVE
AIRLIVE@airlivenet·
Personal Wi-Fi hotspot named “I have a bomb, everyone will die” triggered NATO Quick Reaction Alert airlive.net/incident/2026/…
English
17
87
617
88.9K
Mathy Vanhoef retweetledi
Mushtaq Bilal, PhD
Mushtaq Bilal, PhD@MushtaqBilalPhD·
🚨Don't use Anna's Archive — it's pirate website with 61M+ books and 95M+ research papers freely available. We should all try to make billion-dollar academic publishers richer.
Mushtaq Bilal, PhD tweet media
English
176
3K
23.9K
2.4M
Mathy Vanhoef retweetledi
Arvind Narayanan
Arvind Narayanan@random_walker·
This is the story of how reading “The Selfish Gene” when I was around 15 changed my career decades later. It’s a terrific book. But beyond its substance, it changed my view of what science can be. It showed me that there are simple but profound ideas waiting to be discovered. I’d thought of the frontier of science as necessarily esoteric, but the book proved otherwise. Richard Dawkins’s writing also showed me that it’s possible to explain novel and profound ideas in a way that even a child (me) could understand them. When I grew up and became a researcher, I never stopped thinking about this. I began to gravitate toward the simplest questions within my areas of expertise, rather than the hardest, contrary to the norm in science. And I taught myself how to communicate my ideas to as broad an audience as possible. Unfortunately, the peer review process heavily penalizes this approach, because the value system prioritizes abstruseness, when ideally it should be the opposite. But no matter — I found that simpler ideas, when they do get published, are much more widely read, which made it all worthwhile. Besides, pushing to make ideas as simple and as simply communicated as possible often made them *better ideas*, more robust and widely applicable than initially anticipated. Aspirations should be balanced with an awareness of one’s limitations. Not everyone can be as successful as Dawkins; I realized that I couldn’t count on my ideas being so powerful that they would spread on their own (fittingly, the term “meme” was coined in The Selfish Gene!) So I’ve tried to put as much effort into spreading ideas as I do into generating and explaining them. That’s a topic I’ve written about here before and probably will again.
Arvind Narayanan tweet media
English
11
54
474
60.6K