Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dguido
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
dguido
7mo ago
I use Cape every day on my iPhone. The service is excellent, and the security features haven't ever interfered with my use of the phone. They have a convenient mobile app for setting up extra features like the IMSI rotation and getting
2.
▲
by
dguido
7mo ago
I have a conflict of interest here (I am an advisor to Cape, also a security expert, and my company has done security audits for Cape), you should absolutely look more deeply into what Cape has created. Their service is fundamentally differ
3.
▲
by
dguido
9mo ago
If you want a VPN you can trust, deploy your own with AlgoVPN: https://github.com/trailofbits/algo
4.
▲
by
dguido
11mo ago
We're a bit non-committal about who this affects in the blog, but phew man, there are a lot of agent systems that will fall victim to this general class of attack.
5.
▲
by
dguido
1y ago
Hi! I'm the author of this PR and the maintainer for Algo. Claude Code has been a tremendous help dealing with a project of this scope and size. This PR to eliminate storing lots of sensitive data on the host was an interest of mine fo
6.
▲
by
dguido
1y ago
Hi all, CEO of Trail of Bits here. PajaMAS includes all our guidance for building multi-agent systems securely, including core design principles, a multi-agent security checklist, and framework selection criteria. Hope it helps!
7.
▲
by
dguido
1y ago
This is cool, and I'm glad to see someone doing this, but I also feel obligated to mention that you can also just quickly deploy your own VPN server that only you have access to with AlgoVPN: https://github.com/trailofb
8.
▲
by
dguido
1y ago
In case anyone is looking for them, here are the exploits for these EOL devices. I avoided allowing Trail of Bits to release exploits for 13 years, but I decided it was finally time for a policy change. We'll be dropping a lot more as
9.
▲
by
dguido
2y ago
Please stop putting salespeople in charge of highly technical product companies like Sonos. I'm so glad that Tom Conrad is an engineer by training. I hope he can turn this mess around. The key technical change that broke Sonos was aban
10.
▲
by
dguido
2y ago
As the editor of this blog, I can assure you that AI did not craft the introduction. As a general rule, we include all the most relevant details in the above-the-fold section, allowing readers to quickly determine if the content warrants th
11.
▲
by
dguido
2y ago
Strong recommend on using meow.com. You can get interest on your primary checking account, and easy access to high yield treasury management services. I’ve been following the Evolve Bank fallout on the FinTech Weekly newsletter, and the who
12.
▲
by
dguido
3y ago
For fun things you can do with a good working jailbreak, check out this integrity validator that checks if your phone is free of malware by exploiting it: https://github.com/trailofbits/ios-integrity-validator
13.
▲
by
dguido
3y ago
Good work, this is super cool!
14.
▲
by
dguido
3y ago
Oh neat! I didn't realize. It's good! I could have been fooled it was done by a whole team :D
15.
▲
by
dguido
3y ago
I appreciate how organized the Consensys guide is laid out. It's pretty easy to read. Trail of Bits has a similar guide that is a little more in-the-weeds technically. It also covers, what we think is, essential background about certai
16.
▲
by
dguido
3y ago
We need this for code understanding models like StarCoder and the like
17.
▲
by
dguido
4y ago
Trail of Bits does this kind of work ( https://www.trailofbits.com )! Tbh there is a much larger market for application of existing technology (e.g., pentests) than development of new technology (e.g., DARPA programs and the 1% of
18.
▲
by
dguido
5y ago
We're using most of the exact same file-based indicators as MVT. It's really refreshing that Amnesty shared so much of what they found -- it made our own process of testing our checks against their discoveries much easier.
19.
▲
by
dguido
5y ago
Trail of Bits here -- while this is mostly correct, there are also parts of the runtime that dead file forensics won't be able to identify. There's no harm in doing both and, in fact, we'd recommend it if you're concerne
20.
▲
by
dguido
5y ago
Ugh, I have been advocating "Solidity--" for years and can't get funding to build it (Trail of Bits). We use two tools to offer quick turnaround automated testing and verification for Solidity: Echidna (like QuickCheck for So
21.
▲
by
dguido
5y ago
Yes! Please do apply. We have a tight-knit team of experts, industry leading tools, and a work environment that promotes continued learning. You'll get paid well and quickly become a leading industry expert. Here's our job req for
22.
▲
by
dguido
6y ago
If you're looking for a hardening guide for iOS, then try the iVerify app. It will help you detect jailbreaks, check critical security settings, and teach you about many more. https://blog.trailofbits.com/2019/11&#
23.
▲
by
dguido
6y ago
It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service
24.
▲
by
dguido
6y ago
yep, https://github.com/warner/magic-wormhole
25.
▲
by
dguido
6y ago
Firefox Send, SendSafely, and Magic Wormhole are all end-to-end encrypted. https://send.firefox.com/ https://www.sendsafely.com/ https://github.com/warner/magic-wormhole https:/&
26.
▲
by
dguido
6y ago
The main reason is political: It would let senators stay in their home districts and campaign for their entire time in office, making it easier to neglect their duties to write and pass legislation. Politicians may be more motivated to work
27.
▲
by
dguido
6y ago
I seem to be mistaken :-x. Moloch was never provided with early funding from CFT. I confused a few interactions I had with their project's original authors in 2013. It _feels_ like something CFT would have funded, but it was started on
28.
▲
by
dguido
6y ago
Fuckkkkk I think I found the source of my confusion. I am wrong, you are right. I DID find documents about Moloch floating around my Google Drive from ~2013-ish. I believe I invited your co-author Eion to present at a conference I was runni
29.
▲
by
dguido
6y ago
That's odd. Are you one of the original authors? The CFT project list had Moloch on it. I'll try and dig it up, it's probably floating around my Google Drive. You may want to speak with Eoin Miller, as I believe he was the po
30.
▲
by
dguido
6y ago
Yep! As far as I'm aware, a number of military services (I think the USAF) have been public about using Moloch on their networks. It was money well spent by DARPA.
More ›