Profile avatar
novafacing.bsky.social
Security @ MORSE, v0.1.0 security tools on GitHub šŸ³ļøā€šŸŒˆ @[email protected]
139 posts 278 followers 312 following
Regular Contributor
Active Commenter

I wrote a blog post on hardening Virtualization-Based Security enclaves. Check it out!

Today I am thankful for Lane 8 for helping me get work done for 9 years running open.spotify.com/playlist/1JQ...

I stand with Ukraine and the truth that Russia is an invader.

I use gamma seal buckets to store rice to stop anything from getting in, but it turns out it was a good call because it stops da rice weevils from getting out. Guess I gotta start freezing 20lb bags of rice somehow!

Running is fr a life hack this is ridiculous, should have started sooner

your outie uses git checkout -b rather than git switch -c

Oh hell yeah `float_next_up_down` got stabilized!

Learning so much about PRNGs has made so much stuff in crypto that felt like dark magic super clear. I now genuinely feel lines like `#define MAGIC_MATRIX 0x13371337` without a comment linking you to a class on binary matrix math are so exclusionary.

Age yourself with the first computer you used.

Your yearly reminder that Cash App Taxes is completely free for everyone with no income limits and significantly better than Turbo Tax! I will keep shilling until all tax programs are free file!

MORSE is continuing to grow it's UK team. If you're interested in Windows Security and breaking things.. this is remote work within the UK. jobs.careers.microsoft.com/global/en/jo...

Reading linux drama makes me really appreciate the QEMU maintainers

So close google I actually wanted the glib docs!

@crowdsupply.bsky.social has some of the worst customer service I've ever encountered, it's actually kind of ridiculous. 1-2 weeks between messages with no action identified and I'm sitting here with a $250 paperweight. Kickstarter is somehow not this bad

Iā€™m very excited to announce that we at V8 Security have finally published our first version of Fuzzilli that understands Wasm! Go check it out at https://github.com/googleprojectzero/fuzzilli. While we still have a way to go in improving it, we think it shows a promising approach!

I know I really like my side project right now because in school I would procrastinate work by immaculately organizing my music but now I don't even have playlists I just put it on radio

New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...

After playing around with @bevyengine.org engine - looks like its concepts are super similar to what we have in #LibAFL @aflplusplus.bsky.social (its 'ECS' == our AnyMap) This makes sense, we took inspiration from game engines initially, but it's still interesting to see. š—§š—Ÿ;š——š—„: š—™š˜‚š˜‡š˜‡š—²š—暝˜€ š—®š—暝—² š—“š—®š—ŗš—²š˜€

2024 was a significant year for decompilation, constituting a possible resurgence in the field. Major talks, the thirty-year anniversary of research, movements in AI, and an all-time high for top publications in decompilation. Join me for a retrospective: mahaloz.re/dec-progr...

THEYRE MAKING NEW PEBBLES WHAT HOLY SHIT ericmigi.com/blog/why-wer...

Part 1 of how administrator protection came to be: Evolving the windows user model. Happy to see this finally published. techcommunity.microsoft.com/blog/microso...

Making a glossary and index in latex is absolute cheeks is the glossaries-extra package really the best we've got? Manually annotating every single occurrence?

Hanging up my last claim to being alt in any way by getting my nose ring taken out (it won't stop getting inflamed) šŸ˜­

Welcome back to real life to all tiktokers in the house tonight

Got a random urge to play warframe for the first time in 4(?) years and I can still hang in max level stuff but I have *no* idea what is happening is there a website for "it's been X years since I played this what did I miss"

Is there a way to make `cargo install` cache built dependencies through failure? Kinda sucks you need to rebuild all 200+ crates if one of their build scripts fails because you don't have graphene-gobject installed.