Watch This Space

1.4K posts

Watch This Space banner
Watch This Space

Watch This Space

@wtsdev

Watch This Space: A security research blog.

The Interwebs Sumali Ağustos 2024
485 Sinusundan584 Mga Tagasunod
Watch This Space
Watch This Space@wtsdev·
@zeroxjf At least they're patched! But yeah, this is definitely breaking my perspective on these exploits being narrow and secretive. I wonder what (if any one thing) has caused these things to leak.
English
0
0
3
202
johnny
johnny@zeroxjf·
@wtsdev With key vulnerabilities in the chain being patched as recently as iOS 26.2/26.3!
English
1
0
1
288
Watch This Space
Watch This Space@wtsdev·
@zeroxjf Yeah. I felt safer when I saw that the original Coruna write-up mentioned CVE's that were years old. But I'm now hearing rumors and such that there's stuff in the wild now for much newer (and more recent) iOS versions. Scary stuff!
English
1
0
1
309
johnny
johnny@zeroxjf·
@wtsdev Completely agree - this is all pretty concerning. Apple has raised the barrier enough to sideline most independent researchers, yet their systems still appear exposed to well-resourced state actors
English
1
0
2
587
Watch This Space
Watch This Space@wtsdev·
Electron 41 is out! It includes a new security feature I contributed and the team let me write a blurb in their announcement blog post! Shoutout and thanks to the team for working with me on this! I'm really enjoying contributing to Electron. electronjs.org/blog/electron-…
English
0
1
6
219
clearbluejar
clearbluejar@clearbluejar·
Grateful to have presented "Reverse Engineering Apple Security Updates" at @REverseConf last week. Great crowd, solid questions, and an incredibly well-run event. Orlando was the right vibe for the RE community. Slides coming soon!
clearbluejar tweet mediaclearbluejar tweet mediaclearbluejar tweet media
English
2
2
35
1.6K
thaidn
thaidn@XorNinja·
We have some exciting news to share: @blacktop__ is joining Calif to work on a range of R&D projects focused on Apple and AI security. If you work in the Apple security ecosystem, he’s already a household name. He’s the creator of: * ipsw – the ubiquitous Apple firmware analysis tool: github.com/blacktop/ipsw * darwin-xnu-build – reproducible XNU kernel builds: github.com/blacktop/darwi… * ipsw-diffs – automated diffing of Apple releases: github.com/blacktop/ipsw-… * The only public deep-dive on Apple’s Lockdown Mode: github.com/blacktop/prese… His tooling is so good that even Apple engineers use it. If you do reverse engineering, chances are you’ve touched his Rust headless IDA MCP server: github.com/blacktop/ida-m…. People have literally collected CVEs and bug bounties just by digging through the diffs produced by his tools. With @brucedang, @Little_34306 and now @blacktop__, we're building a serious Apple security force at Calif. We’ll have more announcements in this space soon! If you're interested in Apple security, AI, automated bug discovery, reverse engineering, or hacking, we’re hiring: calif.io/jobs.
English
5
22
222
29.3K
Watch This Space
Watch This Space@wtsdev·
@theo @notyouravgcoder Interestingly, I remember never liking Sublime Text. Atom felt so much nicer to use. Then, of course, VS Code came out and was even better.
English
0
0
0
77
Watch This Space
Watch This Space@wtsdev·
@speedyfriend433 Unclear. At best, it would likely fall under their discretionary $1,000 reward mentioned in this blog: security.apple.com/blog/apple-sec… I say "discretionary" as their blurb in the article is vague on circumstances and appears potentially misaligned with what I've heard from others.
English
1
0
5
323
Speedyfriend67
Speedyfriend67@speedyfriend433·
Does apple still pay for stable macOS LPE?
English
3
2
8
2.7K
Watch This Space
Watch This Space@wtsdev·
@theo Wouldn't be surprised if it's a kernel thing they just chose not to backport to Sequoia.
English
0
0
0
209
Theo - t3.gg
Theo - t3.gg@theo·
Heads up. New Studio Display XDR from Apple requires you to be on Tahoe to get the full capabilities. You're capped at 60hz on Sequoia. I might return it over this.
Theo - t3.gg tweet media
English
57
3
570
59.9K
Watch This Space
Watch This Space@wtsdev·
@OrdinaryInds They may have seen an error when they tried to commit without a message and decided to go down the path of figuring out how to commit without one instead of learning how to include a message.
English
0
0
0
11
Jack Fields
Jack Fields@OrdinaryInds·
I’m desperate to know why they need to consistently make empty commits with no commit message at all. Their git history:
GIF
English
1
0
2
333
Jack Fields
Jack Fields@OrdinaryInds·
I can’t tell if it’s worse that they needed to ask AI how to commit or that they felt the need to immediately share it with the world. Vibe coders need to be studied.
Jack Fields tweet media
English
3
0
10
791
Watch This Space
Watch This Space@wtsdev·
@mitchellh @cjwestland Yeah, I definitely understand that impulse of others. I personally try to watch what I post publicly because I'm aware of how things can look. I know I'm probably in the minority on that.
English
0
0
0
50
Mitchell Hashimoto
Mitchell Hashimoto@mitchellh·
As a product person, some of the most important feedback you can get is why someone bounced on first use. It's also some of the hardest to get and social media remains the best way to get it. Product people MUST aggressively pay attention. E.g. x.com/mitchellh/stat… There's a lot of complainers and noise and you just have to learn to not take that personally. The people who have worked closely with me know that what people say on the internet REALLY doesn't bother me. Instead, I'm always just digging for the nugget of truth in there, the objectively useful piece of data hiding behind the childish emotional temper tantrums online people throw (just so I don't insult anyone here, the quoted tweet here was not that, it was direct and to the point). If you get your feelings hurt by people on the internet, you're going to miss out on good feedback for genuine improvement.
Mitchell Hashimoto@mitchellh

@kolyasya_pro Looks like we don't do tilde expansion (confirmed on my side). That's a bug. Use an absolute path and you'll be fine, I'll fix this for 1.3.1 for you.

English
24
31
652
65.9K