James Forshaw's Avatar

James Forshaw

@tiraniddo.dev.bsky.social

Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.

1,742 Followers  |  183 Following  |  129 Posts  |  Joined: 11.08.2023  |  2.4643

Latest posts by tiraniddo.dev on Bluesky

I guess there’s something about Superman movies. Man of steel is one of the only movies I’ve ever walked out of. And that was with my wife so didn’t even need the solo advantage it was just that bad. Wasn’t planning on seeing the new one tbh.

21.07.2025 06:55 — 👍 1    🔁 0    💬 0    📌 0

Now if only you’d stop trying to make it out of date 😄 then again that’s what second editions are for.

02.07.2025 15:09 — 👍 6    🔁 0    💬 1    📌 0
Preview
Introduction to Network Trace Analysis 06: Kerberos it’s AUTH-some! | Microsoft Community Hub New to the series? Be sure to check out the previous posts!    Introduction to Network Trace Analysis Part 0: Laying the...

Good Monday morning tech nerds. One of my devs wrote *another* blog post about kerberos (I'm creating an army of crazy bloggers). This one you might consider bookmarking.

16.06.2025 14:51 — 👍 53    🔁 21    💬 2    📌 0
Preview
A Look in the Mirror - The Reflective Kerberos Relay Attack It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...

🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live:

🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos:
blog.redteam-pentesting.de/2025/reflect...

11.06.2025 08:04 — 👍 7    🔁 3    💬 1    📌 2

Sure but maybe it shouldn’t be remembering them wholesale in the first place?

22.05.2025 01:29 — 👍 2    🔁 0    💬 1    📌 0

I despair that in the UK you now need ID to buy a cutlery set with normal non-sharp table knives. And if they ban sharp points on kitchen knives I assume they’ll ban metal files so you can’t grind a new point on them. I just don’t see how it really helps other than pandering to the tabloids.

21.05.2025 14:53 — 👍 0    🔁 0    💬 1    📌 0
Preview
Enhance your application security with administrator protection Introduction Administrator protection is a new Windows 11 platform security feature that aims to protect the admin users on the device while still allowing them to perform the necessary functions whic...

We are removing default admin in Windows 11, get your apps ready now

blogs.windows.com/windowsdevel...

19.05.2025 18:11 — 👍 38    🔁 20    💬 2    📌 1

The distinction without a difference.

14.05.2025 20:46 — 👍 3    🔁 0    💬 0    📌 0
Off-by-One Conference 2025 Off-by-One Conference is a cybersecurity conference where like-minded professionals gather and exchange technical insights while gaining knowledge from one another. As the offensive security landscape...

@tiraniddo.dev and Eugene Lim—authors of Windows Security Internals and From Day Zero to Zero Day—are at Off-By-One doing what they do best: giving keynotes and running a smart device hacking village, respectively.

offbyone.sg

08.05.2025 02:24 — 👍 5    🔁 1    💬 0    📌 0

Maybe I’ll pop down to sf for rsa tomorrow. I’ve fortunately never gone before but this is my last chance and I really need a new ai security product.

29.04.2025 04:44 — 👍 6    🔁 0    💬 0    📌 0

I apologize for the void moaning back 😄

25.04.2025 12:06 — 👍 3    🔁 0    💬 0    📌 0

To be fair they are specialisms not everyone can be both. I’ve know quite a few people who are the exact opposite.

25.04.2025 11:40 — 👍 1    🔁 0    💬 1    📌 0

Even funnier that’s it’s Kneecap. What does she think their name references?

22.04.2025 13:45 — 👍 1    🔁 0    💬 0    📌 0
Preview
Microsoft Recall on Copilot+ PC: testing the security and privacy implications A look at the risks and tradeoffs with Microsoft Recall.

I took a look at the changes to Microsoft Recall, which is rolling out to compatible Windows devices soon.

Photographic memory that stores all your deleted messages, keystrokes etc 😅

doublepulsar.com/microsoft-re...

21.04.2025 21:26 — 👍 97    🔁 47    💬 6    📌 8

You mean the iPhone with signal on it?

21.04.2025 19:16 — 👍 4    🔁 0    💬 0    📌 0

When they were talking about the UK-US trade deal that could be struck after brexit they really meant only 10% tariffs instead of 20%

03.04.2025 12:36 — 👍 5    🔁 1    💬 2    📌 0
Preview
GitHub - decoder-it/KrbRelayEx-RPC Contribute to decoder-it/KrbRelayEx-RPC development by creating an account on GitHub.

KrbRelayEx-RPC tool is out! 🎉
Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;)
github.com/decoder-it/K...

14.03.2025 10:18 — 👍 9    🔁 10    💬 0    📌 0

Good. When Microsoft actually play fair in this I’m sure it’ll be welcomed. A blog post about future plans isn’t a substitute.

27.02.2025 23:25 — 👍 0    🔁 0    💬 1    📌 0

And that photo really seals it, "Hi poors, how are you? *aside to aide* They can't jump the fence can they?"

20.02.2025 14:45 — 👍 1    🔁 0    💬 0    📌 0

Invoke EU right to be forgotten?

18.02.2025 20:09 — 👍 1    🔁 0    💬 0    📌 0

Tbh the real cowardice is not changing it outright for all English locales and instead putting it in parentheses. They’re already angering people with their dumb decision I doubt they could make it worse by clearly throwing in the towel.

14.02.2025 04:24 — 👍 1    🔁 0    💬 0    📌 0

What does Bing call it? Oh wait no one cares.

14.02.2025 02:32 — 👍 0    🔁 0    💬 1    📌 0
Preview
Understanding Network Access in Windows AppContainers Posted by James Forshaw, Project Zero Recently I've  been delving into the inner workings of the Windows Firewall. This is interesting to ...

TBH googleprojectzero.blogspot.com/2021/08/unde... is probably more comprehensive.

11.02.2025 19:54 — 👍 3    🔁 1    💬 0    📌 0

I can now see why my email offering to give the NSA exclusive access to an ultra rare uber 1337 EoP in Windows NT 3.1 bounced 😭

Truly the dumbest timeline.

10.02.2025 15:21 — 👍 11    🔁 1    💬 0    📌 0

When physical risks are "There's more guns than people" I could perhaps see some hesitancy. Though, there are people like AOC pushing back. However, most are too set in their ways and too beholden to their benefactors that they don't want to rock the boat. It might even be good for them.

03.02.2025 11:07 — 👍 2    🔁 0    💬 1    📌 0

Are you really upper middle class if you’re doing your own shopping? 😄

03.02.2025 08:07 — 👍 3    🔁 0    💬 0    📌 0
Post image

hey quick question does Goliath win in that story

02.02.2025 18:06 — 👍 33596    🔁 5395    💬 1073    📌 559

Funnily the de minimis exception was something I was going to miss going back to the uk. I guess it doesn’t matter now 😂

02.02.2025 14:46 — 👍 2    🔁 0    💬 1    📌 0

I wonder how it impacts bonded warehouses? Presumably the base tariff would increase. I ordered some parts from digikey recently and the tariff cost was an explicit line item on the invoice.

02.02.2025 14:42 — 👍 1    🔁 0    💬 1    📌 0

Glad I did a aliexpress blitz in December 😄

02.02.2025 14:37 — 👍 1    🔁 0    💬 1    📌 0

@tiraniddo.dev is following 18 prominent accounts