Ivan Kwiatkowski's Avatar

Ivan Kwiatkowski

@justicerage.bsky.social

Security Researcher @Meta. Writer. Would-be musician. Maintainer of Manalyze and Gepetto. Trolling on a purely personal capacity.

343 Followers  |  26 Following  |  17 Posts  |  Joined: 28.10.2023  |  1.5957

Latest posts by justicerage.bsky.social on Bluesky

Post image

I guess I'm not getting rich this year either.

03.01.2025 15:35 — 👍 1    🔁 0    💬 0    📌 0
Post image 20.12.2024 20:19 — 👍 3    🔁 0    💬 0    📌 0
Preview
US recommends encrypted messaging as Chinese hackers linger in telecom networks US official: “Impossible for us to predict when we’ll have full eviction.”…

A friendly hello to politicians still considering weakening/banning encryption in messaging apps.

arstechnica.com/tech-policy/...

04.12.2024 20:27 — 👍 4    🔁 1    💬 0    📌 0

Ayant dirigé une petite maison d'édition, je suis loin d'être convaincu que ce soit le marché de l'occasion qui nuise le plus à l'économie du livre...
- Les tarifs des imprimeurs ont explosé
- Le marché est ultra-saturé
Et plus on va vers le tout-numérique, plus le débat de l'occasion est caduque.

30.11.2024 23:17 — 👍 1    🔁 0    💬 0    📌 0

I have cool features in store for Gepetto, but I need some free time to implement them! The work in that space definitely isn't done.
One corner I backed myself into is the fact that the plugin supports many different LLMs and providers that all have different capabilities and APIs. It slows me down

22.11.2024 01:53 — 👍 1    🔁 0    💬 0    📌 0

But AFP produces a lot of text, and it was becoming more and more time-consuming to read through everything (esp. since I don't care about minor/misc news).
So I created a new feed that pushes an AI-generated brief every 6 hours:

afpdigest.feeds.kwiatkowski.fr

Hope it's useful to someone!

17.11.2024 00:51 — 👍 1    🔁 0    💬 0    📌 0

I use RSS *a lot* to keep informed about a great many things. When a feed doesn't exist for a website I like, I create scrappers to generate one as this is the main way I consume information. That's what I did with AFP press releases (🇫🇷 content, sorry).

afp.feeds.kwiatkowski.fr

17.11.2024 00:51 — 👍 1    🔁 0    💬 1    📌 0

New blog post: "So you want to work in cybersecurity".

Every time I post research on X/Twitter, I get DMs asking how to get into cybersecurity. Instead of repeating myself ad nauseam, I wrote down all my thoughts on the subject here: blog.kwiatkowski.fr/cybersecurit...

Personal opinion obviously.

23.01.2024 10:34 — 👍 0    🔁 0    💬 0    📌 0
Post image

But wait, do you have many rules that need to be checked for compliance? I got you covered, there's also an API with a complete Python script provided.

The paint is still fresh and I have ideas for improvements, but I hope you'll find it useful!

14.01.2024 18:58 — 👍 0    🔁 0    💬 0    📌 0
Post image

#100DaysofYARA

I created a web service that allows you to verify on which yara versions your rule compiles. In the past, shipping rules to customers, I wondered if there were limitations but couldn't find out easily. Now I can.

yaravalidator.manalyzer.org

14.01.2024 18:57 — 👍 1    🔁 0    💬 1    📌 0

I have the pleasure to announce I'm joining @harfanglab@bird.makeup as Lead Cyber Threat Researcher starting tomorrow!
I'll be working on APTs from everywhere, reversing malware, writing FOSS tools and blog posts!

11.11.2023 09:37 — 👍 0    🔁 0    💬 1    📌 0

I get that, but bad behavior is almost never detected in the first place AFAIA. I would be happier if we spent our energy blocking mis-issued certs based on CAA rather than spending all our political capital ensuring a bad situation doesn't get worse.

06.11.2023 17:34 — 👍 0    🔁 0    💬 1    📌 0

What I could have bought: MacBook Pro 16.2 M2, 16GB RAM, 512 GB of storage.
What I got instead: server with 128 GB RAM, 244 TB of storage.

No wait, I couldn't have gotten the MacBook, it's more expensive.

04.11.2023 15:14 — 👍 0    🔁 0    💬 0    📌 0

I'm not denying the potential for abuse when governments add their CAs into browsers, but it feels like the world we live in already.
In any case, can't help but recall this old and epic "Honest Achmed's root certificate: bugzilla.mozilla.org/show_bug.cgi...

03.11.2023 10:43 — 👍 0    🔁 0    💬 1    📌 0
Post image

I'm seeing a lot of noise regarding EIDAS and the provision that would force browsers to accept government CAs. Isn't it missing the point? My browser seems to trust hundred of CAs already, surely a decent percentage of them are hacked or front-ends for intelligence agencies?

03.11.2023 10:42 — 👍 0    🔁 0    💬 1    📌 0

It's probably only a few categories (including politics), but good enough for me. At least I don't have to wait for news websites to rehash the releases and pretend they've done journalism anymore.

29.10.2023 00:52 — 👍 0    🔁 0    💬 0    📌 0

For a very long time, I've been frustrated that there was no way to get the direct feed from @afpfr.bsky.social
(French news agency). I've finally found a source I can scrap, so I published an RSS feed here that anyone can use freely: feeds.kwiatkowski.fr/afp.xml

29.10.2023 00:52 — 👍 3    🔁 0    💬 1    📌 0

@justicerage is following 19 prominent accounts