Arrigo Triulzi's Avatar

Arrigo Triulzi

@cynicalsecurity.bsky.social

IT Security, cynically aged. Maths. Some nukes. Longing for Symbolics and Connection Machines. Keeper of Ancient Computing Lore. Wassenaar intangible Ⓐ

447 Followers  |  144 Following  |  580 Posts  |  Joined: 22.05.2023  |  2.3327

Latest posts by cynicalsecurity.bsky.social on Bluesky

There is something about Heathrow, and UK airports in general (except LCY), which defeats understanding. I have been going through since the 1980s and the experience is unchanged, just shinier.

04.08.2025 09:38 — 👍 0    🔁 0    💬 0    📌 0

There is always Heathrow in Summer to provide you with the very worst expectations.

04.08.2025 09:34 — 👍 1    🔁 0    💬 1    📌 0
Preview
AWS deleted my 10-year account and all data without warning After 10 years as an AWS customer and open-source contributor, they deleted my account and all data with zero warning. Here's how AWS's 'verification' process became a digital execution, and why you s...

"In Cloud we Trust"™

www.seuros.com/blog/aws-del...

04.08.2025 07:48 — 👍 3    🔁 3    💬 0    📌 0
What gets the Attention?

Consulting the OWASP top 100,000 from the Appendix to the Addendum to the Supplement to the Apocrypha, Volume 127, we see…

#17,245 Spectre
#17,246 POODLE
#17,247 Meltdown
#17,248 Rowhammer
#17,249 DROWN
#17,250 ROCA
…
What do all of these have in common?

No-one ever uses them
* there are 17,244 easier ways to carry out an attack
* this is why they've been referred to as "stunt cryptography"

Stunt cryptography attack
* You have a 0.00001% chance of recovering 2 bits of plaintext from a single message

Any of the OWASP top ten
* You have a 100% chance of recovering the plaintext of all the messages

What gets the Attention? Consulting the OWASP top 100,000 from the Appendix to the Addendum to the Supplement to the Apocrypha, Volume 127, we see… #17,245 Spectre #17,246 POODLE #17,247 Meltdown #17,248 Rowhammer #17,249 DROWN #17,250 ROCA … What do all of these have in common? No-one ever uses them * there are 17,244 easier ways to carry out an attack * this is why they've been referred to as "stunt cryptography" Stunt cryptography attack * You have a 0.00001% chance of recovering 2 bits of plaintext from a single message Any of the OWASP top ten * You have a 100% chance of recovering the plaintext of all the messages

Periodic reminder about stunt hacking¹.

You will get done by phishing.

Nothing else matters.
__
¹ www.cs.auckland.ac.nz/~pgut001/pub...

04.08.2025 07:46 — 👍 7    🔁 2    💬 0    📌 0
TS celebrating seL4 Day

TS celebrating seL4 Day

Today is the 16th anniversary of the completion of se4’s proof of implementation correctness, and the 11th anniversary of seL4 being open-sourced.
Happy #seL4 Day from all at Trustworthy Systems!

29.07.2025 02:26 — 👍 22    🔁 6    💬 0    📌 0
The Hail Mary Cloud And The Lessons Learned

The long version of why you need key authentication for SSH servers: "The Hail Mary Cloud and the lessons learned" nxdomain.no/~peter/hailm... #ssh #passwordgroping #unix #linux #openbsd #freebsd #pf #packetfilter

Also, The 4th edition of the Book of PF is coming soon: nxdomain.no/~peter/yes_t...

29.07.2025 08:48 — 👍 3    🔁 2    💬 0    📌 0

Oh, it is just the provision of information to one of the worst possible jurisdictions where to send any form of information, never mind rather sensitive information about possible abuse targets, the rest is just icing on the cake, is it not?

24.07.2025 06:30 — 👍 2    🔁 1    💬 0    📌 0

Perhaps if someone rephrased the UK ID verification as "sending information about minors to the USA where we don't quite know who is in the Epstein files" might actually help to focus minds?

24.07.2025 06:28 — 👍 6    🔁 4    💬 1    📌 0

Non possiamo semplicemente organizzare la "coda infernale" per loro?

23.07.2025 13:49 — 👍 1    🔁 0    💬 0    📌 0

it adds "stupidity" to the menu.

22.07.2025 06:35 — 👍 0    🔁 0    💬 1    📌 0

Your cloud database is not co-mingled, it is co-pwned.

21.07.2025 14:23 — 👍 1    🔁 0    💬 0    📌 0

It is an attack.

20.07.2025 18:18 — 👍 1    🔁 0    💬 0    📌 0
SLF Digest

Latest Security Liberation Front issue is out!

slf.fish

17.07.2025 16:34 — 👍 2    🔁 2    💬 0    📌 0

Hopefully they did not have a banner with “like what you see? be part of it!”, given the current world…

10.07.2025 03:47 — 👍 1    🔁 0    💬 0    📌 0

That would be a "yes", then.

08.07.2025 16:01 — 👍 0    🔁 0    💬 0    📌 0

It is the plan B career for most Italians in IT … ;P

07.07.2025 08:10 — 👍 1    🔁 0    💬 0    📌 0

“Our windows make you feel in the air”

05.07.2025 11:06 — 👍 0    🔁 0    💬 1    📌 0

It must be really difficult to run a marketing campaign for a Russian windows & frames manufacturer.

05.07.2025 10:37 — 👍 1    🔁 0    💬 1    📌 0

You should have just written "Shit sekurity software brings clowns to 8.5m boxes"

04.07.2025 09:12 — 👍 0    🔁 0    💬 0    📌 0

You know how Italians have a habit of trying out political ideas before the rest of the world catches on…

25.06.2025 17:48 — 👍 1    🔁 0    💬 0    📌 0
Film poster for “Fascisti su Marte” (“Fascists on Mars”).

Film poster for “Fascisti su Marte” (“Fascists on Mars”).

Ah, there is a script for the latter bit.

See en.wikipedia.org/wiki/Fascist...

25.06.2025 17:35 — 👍 3    🔁 1    💬 1    📌 1

Better than “I’ll send it to my number and authenticate you”… #truestory

25.06.2025 17:29 — 👍 1    🔁 0    💬 0    📌 0

I am also puzzled as to dodging of uncharted landmines while walking to the beach, amongst other fabulous "surprises"… that place was a fortress which outclassed all the other fortresses built across Albania.

25.06.2025 16:41 — 👍 2    🔁 0    💬 0    📌 0

One wonders whether the companies doing their risk assessments and completing their SBOMs actually have the courage to write something like "if this is backdoored we're stuffed" or "this is a critical dependency but we don't even pay for support".

I bet the answer is "no".

23.06.2025 09:22 — 👍 1    🔁 0    💬 0    📌 0

It is 2025 and we have companies still expecting free, and immediate, 24x7 support from open-source maintainers of projects they liberally use and have never contributed to in any way or form, God forbid paying for support.

Time to backdoor them all? Or timebomb them?

23.06.2025 08:59 — 👍 4    🔁 1    💬 0    📌 0
Post image

YES 😍 1 year till the next AREA41 conference🥳
The new location is www.thehall.ch and we are excited to grow🤩
18.-19.June 2026
-> a41con.ch

20.06.2025 15:24 — 👍 11    🔁 8    💬 0    📌 0

weird, it worked for me when I grabbed it but I was using Waterfox.

19.06.2025 19:40 — 👍 0    🔁 0    💬 1    📌 0

It is getting better by the hour: apparently now, since Iran got hit by Stuxnet, the US enrichment plant (which one?) is going to “be hacked back”…
No issues there: no Siemens PLCs in US enrichment plants and, er, no enrichment plant except the Urenco in Louisiana doing reactor-grade fuel…

19.06.2025 17:34 — 👍 2    🔁 0    💬 0    📌 0

I wish I had come up with the Hans Blix clip, I wish… ;)

No, it was a friend asking in good faith because he had heard it on the news.

19.06.2025 16:22 — 👍 1    🔁 0    💬 0    📌 0

UPDATE: the complete report, in English, is out¹.

__
¹ archive.today/2kJ4i

19.06.2025 16:22 — 👍 8    🔁 5    💬 1    📌 0

@cynicalsecurity is following 20 prominent accounts