Elektrine lite

← Feed

René Mayrhofer :verified: 🇺🇦

rene_mobile@infosec.exchange

<p>Prof. for networks and security at <a href="https://infosec.exchange/tags/JKULinz" class="mention hashtag" rel="tag">#<span>JKULinz</span></a>, formerly leading Android platform security at <a href="https://infosec.exchange/tags/Google" class="mention hashtag" rel="tag">#<span>Google</span></a>. This account will mostly carry IT security stuff, occasionally politics and other comedy.</p><p>Screeching voice of the minority. I will not cooperate with fascists or nazis - traditional or neo; Austrian, German, US, Russian, or otherwise. I will not help build surveillance and oppression states. Never again.</p><p>&quot;I need privacy, not because my actions are questionable, but because your judgement and intentions are.&quot;</p><p>Statements are only my own opinion, not my employers&#39;.</

Posts

  • Post #3813112

    Why do US media outlets still call it the DoD when the department&#39;s own website calls itself Department of War (https://www.war.gov/). Is this trying to downplay the new agenda?

  • Post #3239702

    I&#39;m leaving #Google: https://www.mayrhofer.eu.org/post/leaving-google/ While I believe that I have been able to do some good with my continuing (part-time) engagement in the Android security and privacy team since returning to Austria a couple of years ago, the deal with the US #DoW is completely misaligned with my personal ethical principles. I will, therefore, no longer be able to act as a contact point to Google-internal teams and discussions, but will continue our research on private di...

  • Post #2409456

    Releasing a universal #Linux #kernel #exploit with very little or even no previous time to distribute a patch through distributions is not cool. Doing it on the day before a weekend - on two weekends in a row - is just being an asshole. Looking at you, #CopyFail and #DirtyFrag. You may think it helps your PR, that people will queue to use your cool new AI/agentic/whatever tool because you found the bug. You may think that releasing the full exploit because somebody else was even quicker with &...

  • Post #1634740

    We have opened a job posting for a (maximum 6 years) post-doc position at JKU Linz (@jkulinz) in networks and security: https://karriere.jku.at/hcm/jobexchange/showJobOfferDetail.do?jobOfferId=8a7ec1e69cf609ed019d24e15bd17c6e&amp;amp;j=&amp;amp;languageChanged=true If you&amp;#39;d like to work with us on timely topics like digital identity (very much including EUDI), embedded system security (including Android), software supply chain security (fixing your future xz and trivy dependencies), and...

  • Post #1350484

    RE: https://ec.social-network.europa.eu/@EUCommission/116408720976324749 Unfortunately, this is not ready. The current GitHub repository is a start - a (fairly expensive) prototype (https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues). Before any wider rollout, however, this needs to: * stabilize in its feature set (e.g., which form of app/device attestation); * be verified in detail by independent audits - the quick checks done by some security/privacy researchers...

  • Post #1347750

    I have been trying for hours to debug what I thought was a #Treafik regression causing massive CPU usage to the point that my own (very small) dockerized services I host for my family are getting slow and hard to reach. But no, my meager virtual server is just being DDoSed by stupid #AI bots downloading pieces of my webpage over and over and over again. It looks like the steps described in https://www.mayrhofer.eu.org/post/defenses-against-abusive-ai-scrapers/ are no longer working, and I need...

  • Post #1347749

    #Trump, #Musk, #Putin, #Netanjahu, #Erdoğan, #Orban, #LePenn, and #Kickl are #populist #fascists. There, I said it publicly. Many more western politicians have clear fascist, illiberal tendencies, including previous #FPÖVP chancellors and current governors (Austrian #federalism does not work any more and needs to be severely limited to get back to a functioning government). [https://www.derstandard.at/story/3000000021253/was-kickl-als-volkskanzler-bedeuten-wuerde is a good summary of some reas...

  • Post #1347178

    Last Saturday, I was honored and delighted to give the keynote at Grazer Linuxtage #GLT26, a large #Linux event with a lot of history (23 years and counting!) and still a dedicated team behind it. Title: &amp;quot;What can we learn from Android for other embedded Linux systems security?&amp;quot; Slides are available at https://pretalx.linuxtage.at/glt26/talk/J8GCHE/, talk recording at https://media.ccc.de/v/glt26-615-what-can-we-learn-from-android-for-other-embedded-linux-systems-security

  • Post #1212197

    New blog post on why I think that GenAI/LLM coding agents use for finding vulnerabilities and generating PoC code to demonstrate exploitability is going to be painful, but most probably a good thing in the mid term: https://www.ins.jku.at/blog/vulnerability-reports-and-llms/ (Energy consumption and other resource usage is still a problem of those types of LLMs, though!)

  • Post #1182929

    Today, two open letters from academics on the scientific arguments against the current #CSS (client side scanning) initiatives have been released: * The first (in English, internationally coordinated) one is online at https://tinyurl.com/CSAScientistsLetter and still open for additional signatures. * The second (in German, by #Austrian academics) one is online at https://www.ins.jku.at/chatcontrol/ and explicitly includes law experts in addition to the arguments from a security, privacy, and A...

  • Post #985314

    RE: https://graphics.social/@metin/116335353888270814 For anybody (still) using #LinkedIn on a regular basis (and I understand that there are reasons for it), you may want to do that with #Firefox for the moment. At least the extensions scanning seems to be done only on Chrome browsers according to https://browsergate.eu/how-it-works/, even if all the other profiling is probably browser agnostic. I personally take this as an opportunity to ignore that platform completely for the time being. My...

  • Post #783698

    I just learned that a new release of the decentralized, open source Android (and iOS, but that requires a centralized Apple service) key attestation library warden-supreme has landed. It explicitly supports alternative/custom roots of trust for the attestation chain now and comes with a test for @GrapheneOS keys: https://github.com/a-sit-plus/warden-supreme/blob/development/serverside/roboto/src/test/kotlin/GrapheneOsTests.kt Nice! That&amp;#39;s a good match to our academic research direction...

  • Post #588824

    The democratic, liberal, dependable USA that I have known and respected for most of my adult life is dead and will not be revived even after the orange clown stops pretending to be king. It cannot, because the concept of the USA in the world outside its own borders very much depended on soft power, which requires trust. That trust is gone, completely, and probably irrevocably for at least a generation. It saddens me deeply that all the value, all the good that this long-term stability and trust...