Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Caria Giovanni - Harpocrates

@Harpocrates@infosec.exchange
  • Open on infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach.

Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌
Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence.
I write books, I see people, I do things. 📚👥⚡

121 Followers
160 Following
23 Posts
Joined March 15, 2026
Dark Side:
https://centurialabs.pl
Research:
https://centuriafoundation.pl
Vulnerability:
Bad Carbonara
Author:
Mars Attacks, Venus Hacks: An Eulogy for the "Aliens" Saving Modern Cybersecurity
Github:
https://github.com/psychomad

Posts

Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Aug 01, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

In our slightly mad project of building a jellyfish in every piece of technology, Aleph has been running for months on embedded hardware (Intel i5, 3.7GB RAM) without a single crash — 407,000+ ticks, a 452KB binary, zero neural networks, autonomous self-healing.

A bio-inspired runtime that has to stay on 24/7 with no supervision, under memory and reliability constraints we'd have had to negotiate hard in most other languages. With Rust we never had to trade memory safety for performance, or a lean binary for long-term stability.

For a project this atypical — a digital body that lives on the hardware, not a model running in a container — those guarantees turned out to be decisive, not just convenient.

Thank you rustlang — we'd almost certainly have ended up with something different, and less solid, in any other language.
#RustLang #Rust #EmbeddedSystems #SystemsProgramming #AIResearch #ArtificialLife

0
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 22, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Replying to @Harpocrates@infosec.exchange
Seem a normal normal behavior for Google https://www.theregister.com/security/2026/06/18/google-told-researcher-nice-catch-then-denied-bug-bounty-for-flaw-it-still-hasnt-fixed/5258076
0
0
1
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 21, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Fileless RCE on stock Android (~2.5B devices). Reported to Google VRP, confirmed by their own engineering team, closed as NSBC anyway.

Full writeup:
https://www.researchgate.net/publication/407433163_Fileless_Code_Execution_via_Semantic_Gap_in_Android_WebView_Bridge_Architecture_A_Case_Study_in_Platform_Security_Boundary_Ambiguity

#AndroidSecurity #infosec #Android #MobileSecurity #VulnerabilityResearch #RCE #BugBounty #VRP #ResponsibleDisclosure #AppSec #ThreatIntel #WebView #ZeroDay #CVE

1
2
1
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 16, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Replying to @nonlinear@mastodon.nz
@nonlinear@mastodon.nz Exactly, the xp_cmdshell analogy is right. The difference here is that the 'SQL Server configured to accept it' is an SDK distributed at ecosystem scale, integrated by developers who have no practical choice and no visibility into the bridge internals. The trust boundary assumption is baked in by the SDK vendor, not the app developer.
1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 16, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

You demonstrate a fileless RCE chain. Complex delivery, in-memory execution, zero detections, confirmed working on multiple devices.

The vendor reviews it twice, involves engineering, then tells you:

"Your research demonstrates a complex chain for delivering and executing code."

...and closes it as 'intended behavior. Not a platform vulnerability.'

Question: is it a vulnerability?

Follow-up: does your answer change if the attack surface exists *between* components — where no single owner's scope definition covers the full chain?

Asking because I have a paper dropping soon about that.

#VRP #responsibleDisclosure #semanticGap #infosec #securityResearch

2
2
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 13, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Hello Dave...
HAL 9000 is the real perpetrator!

https://cariagiovannib.wordpress.com/2026/06/13/hello-dave-i-already-know-which-model-youre-running/

#InfoSec #AISecurity #LLM #Fable5 #ModelFingerprinting #HAL9000 #AI #ironic #satire

Hello, Dave.I already know which model you’re running.
Caria Giovanni - Security Blog

Hello, Dave.I already know which model you’re running.

The Fable incident, the US government shutdown, invisible AI model fingerprinting, and the real architect behind all of it — whom nobody has identified yet. AI Security Threat Intel Satir…

1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 09, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

ALEPH — biologically-inspired AI runtime on embedded hardware.

Security by design: immune system architecture, SHA256 whitelist, stateful iptables, anomaly classifier that distinguishes inference load from DoS.

No cloud. No pretrained weights. No LLM. 407k+ ticks, zero crashes.

Paper (DOI): https://www.researchgate.net/publication/406484898

#infosec #rustlang #embeddedsystems #AI #AIResearch

1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 07, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

The Benchmark Lied. Here’s What It Didn’t Measure.

https://cariagiovannib.wordpress.com/2026/06/07/the-benchmark-lied-heres-what-it-didnt-measure/

#AI #AIResearch #llm #mlops #linux #cuda

The Benchmark Lied. Here’s What It Didn’t Measure.
Caria Giovanni - Security Blog

The Benchmark Lied. Here’s What It Didn’t Measure.

I’m writing this from a lakeside terrace, reading through another wave of LinkedIn posts about “the best tool to detect your GPU and run the perfect local AI model.” My Cane Corso…

1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 06, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

It's time to write code.

https://cariagiovannib.wordpress.com/2026/06/06/go-ahead-and-click-palantir-thanks-you/

#cypherpunk #infosec #threatintelligence
#privacy #surveillance #palantir
#datasovereignty #GDPR #opensource
#hacktivism #resistance #manifesto
#netsec #OSINT #fediverse

2
0
1
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 06, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Reverse engineered the Mintegral MBridge SDK (common in gaming APKs with aggressive adv).
The SDK assembles exfiltration endpoints at runtime via AES/XOR decryption + Android IPC Intents. No hardcoded domain in the binary. MobSF classifies the package as Advertisement and stops there. Knox and Play Protect see legitimate inter-process communication between signed components — nothing to flag.
Extracted 6 C2/collection domains. Loaded them into AegisDNS as a SIGINT feed.
Both Knox and Play Protect: no block, no alert.
AegisDNS: all 6 blocked at resolution.
The IPC obfuscation chain is effective against every on-device analysis layer. It stops at port 53 — the one operation the OS cannot perform inside the obfuscation boundary.
Full write-up with architecture, the structural argument for perimeter DNS vs MTD, and operational trade-offs (block rate, DoH bypass mitigation via iptables, PCRE2/FFI trade-off):

https://cariagiovannib.wordpress.com/2026/06/06/crowdstrike-didnt-block-it-knox-didnt-block-it-a-dns-query-did/

#dns #android #reverseengineering #infosec #mobilesecurity

3
0
2
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 04, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Time to start flirting with your old Casio...

https://cariagiovannib.wordpress.com/2026/06/04/your-ai-budget-wont-save-you-and-when-the-breach-hits-it-wont-be-anthropics-fault/

#Cybersecurity #ThreatIntelligence #AI #InfoSec

Your AI Budget Won’t Save You. And When the Breach Hits, It Won’t Be Anthropic’s Fault.
Caria Giovanni - Security Blog

Your AI Budget Won’t Save You. And When the Breach Hits, It Won’t Be Anthropic’s Fault.

Uber capped AI spending per employee at $18,000 a year. NVIDIA says every employee should have an AI budget of $500,000. The market argues over numbers. Neither side knows what they’re buying…

0
0
1
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 02, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Boosted by disregard Joe Groff @joe@f.duriansoftware.com

New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload

TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.

Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.

Especially nasty for:

  • PA/judicial chatbots on fixed budgets
  • Pay-per-use API deployments with client-side exposed keys
  • PNRR-funded public sector AI with zero inference monitoring

Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.

All tests on self-hosted Ollama, no commercial endpoints touched.

Paper (CC BY 4.0): https://doi.org/10.13140/RG.2.2.26767.96166

#llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity

8
0
6
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 01, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Bad code written fast is still bad code. AI just makes it faster.
Meanwhile attackers are running full intrusion campaigns solo, with $20/month and a clear objective.
The enterprise? Still in the governance committee meeting.
New article on AI, code quality, and attack surface proliferation:
https://cariagiovannib.wordpress.com/2026/06/01/the-accelerator-problem/

#InfoSec #CyberSecurity #AppSec #AIRisk #SecureByDesign #VibeCoding

THE ACCELERATOR PROBLEM
Caria Giovanni - Security Blog

THE ACCELERATOR PROBLEM

Why AI is Making Bad Code Faster and Cybercriminals More Dangerous — and why the enterprise is still losing to a $20/month subscription The starting point nobody wants to hear You’ve met both…

1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · May 27, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Working on something outside the usual AI paradigm sharing a preliminary note, not a "Eurkea".

The project (Aleph) explores whether biological organizational principles can replace neural architectures for embedded AI. No weights, no pre-training, no LLM. The core question: do the same solutions biology found over billions of years: specialization, quiescence, emergent coordination translate to digital systems?

Methodology follows Telesio's empirical approach: observation before theory, measurement before assertion. Every behavior in this post has a log file and a timestamp.

One verified result worth sharing:

Three independent components: a health monitor, a kernel, and an audio output organ — have no knowledge of each other. No shared state, no direct communication. When the watchdog process dies, the system emits a 220Hz tone. No explicit rule produces this. It emerges from composition.

This is weak emergence: predictable by reading the code. Not strong emergence. The distinction matters and we're not overstating it.

Current stack: Rust, Alpine Linux, SQLite, Unix sockets. Hardware: Dell Inspiron i5, 3.7GB RAM. ~452KB binary binary. ~39°C at rest.

What we don't know yet: whether this approach scales, whether the Bayesian learning converges usefully, whether the biological clock model holds across real day/night cycles.

#rustlang #embeddedsystems #ai #distributedsystems

infosec.exchange

Infosec Exchange

2
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · May 21, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

New preprint: UAV-Space Framework 🛰️

SPARTA/MITRE ATT&CK cover intentional threats to space
infrastructure. Physical environment vectors — geomagnetic
storms, SAA transits, SEP events — have no framework.

UAV-Space fills that gap.

Empirical basis:
→ 43,848h NASA OMNI2 real data
→ 18.3× anomaly rate during major storms (Kp≥7)
→ Fisher exact p=0.005, χ²=23.66 p<0.0001
→ 8.2× during Solar Energetic Particle events

Each physical phenomenon modeled as threat actor:
TTPs, IoCs, advance warning, NIS2 Art.21 playbooks

Key finding: NOAA SWPC gives 24h CME advance warning.
No operator today has a procedure to use that window.
UAV-Space pre-defines the procedures.

https://www.researchgate.net/publication/405090425_UAV-Space_Unintended_Attack_Vector_Framework_for_Space_Critical_Infrastructure_Extending_Space_Threat_Intelligence_to_Physical_Environment_Vectors_Empirical_Correlation_Threat_Modeling_and_NIS2CRA_Com

#infosec #spacesecurity #threatintel #NIS2 #satellite
#spaceweather #criticalinfrastructure #CRA

0
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · May 01, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Releasing AgentGuard: architectural safety layer for AI agents.

Not prompt engineering. Code.

@protect
def delete_db(): ...

The LLM cannot call this. Ever. No prompt bypasses a raise.

Blocks: irreversible tool calls, prompt injection, context dilution, cross-agent contamination.

Rust core + pure Python fallback. 31/31 e2e tests with real Ollama.

https://github.com/psychomad/AgentGuard

"Don't blame the knife. Fix the architecture."

#InfoSec #LLMSecurity #AIAgents #PromptInjection #OpenSource #Rust

0
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Apr 25, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Air gaps don't stop sound.

USAT (Ultrasonic Sub-Audible Trojan) — acoustic covert channel operating at 17–22kHz, inaudible, cross-device, no physical access required.

Full research: researchgate.net/publication/404012350

#infosec #redteam #airgap #sidechannel #acoustics #research

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Apr 23, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Your AI assistant doesn't know what year it is. Not because it's broken — because it was never given a clock.

I published a preprint on this: NTPCoherence, a temporal synchronization framework for LLM deployment.

https://www.researchgate.net/publication/404110102_NTPCoherence_Preprint_v1_2

#LLM #AIResecurity #InfoSec #CyberSecurity #ThreatIntel

1
0
2
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Mar 17, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Replying to @diegovsky@bolha.us
@diegovsky@bolha.us That's a very fair point, and it’s the heart of the "privacy vs. security" debate. The issue with the standard TCP/IP stack isn't about what you are saying—encryption like TLS or AES handles that part—it’s about the massive amount of noise you make while saying it. Even when you are tucked behind a NAT and your IP looks like just another house in a crowded neighborhood, your digital footprint remains incredibly loud. An ISP or a network node doesn't need to read your messages to figure out exactly what you are doing. They look at the metadata: the packet sizes, the precise timing between them, and the frequency of the bursts. This creates a "behavioral fingerprint." For instance, a skilled analyst can easily distinguish a Signal call from a Netflix stream, or even guess which language you are speaking by analyzing the Variable Bit Rate (VBR) patterns of the audio codec, all without ever decrypting a single bit of your text. The fundamental flaw in TCP/IP is that it permanently couples your identity to your physical location via the IP address. As long as we are routing data between physical "nodes," we are leaving a breadcrumb trail. Moving toward a user-space stack built in Rust—especially using something like RINA—is about breaking that link. We stop addressing data to a specific computer in a specific city and start addressing it to a logical "process." By decoupling the transport from the identity, your traffic effectively becomes indistinguishable from generic background noise to any outside observer. In 2026, strong encryption is just the baseline; the real frontier is making the communication itself invisible to the structure of the network.
1
3
1
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Mar 17, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

I’ve been analyzing the current state of "secure" messaging, and my recent tests with Signal have highlighted some persistent vulnerabilities inherent to any stack relying on standard TCP/IP. Even with strong encryption, metadata leakage at the ISP/CDN level and the reliance on kernel-level interfaces like TUN/TAP remain significant privacy bottlenecks.

I’m curious to discuss the feasibility of a user-space only stack built in Rust that completely decouples identity, addressing, and transport to mitigate these leaks. My current architectural hypothesis involves an identity layer using hardware-backed Zero-Knowledge Proofs—via TEE or zkVM—to handle authentication without persistent identifiers or central registries. For addressing and routing, I'm thinking of a minimal RINA overlay where Distributed IPC Facilities (DIF) allow us to route between processes rather than nodes, effectively moving away from traditional IP-based addressing. This would all be wrapped in a "blind" transport, such as Ockam or shadowsocks-rust, to make the traffic indistinguishable from generic noise to any external observer.

I’m still weighing the practical hurdles, especially how to best bridge RINA's recursive logic with a user-space transport like Ockam without requiring root privileges. I'm open to suggestions on alternative technologies or implementations that might achieve this same level of isolation. If anyone has thoughts on the practical hurdles or existing foundations that could be leveraged here, I’d really value your perspective. Definitely feels like there's a lot to dig into.

#Rust #Rustlang #Infosec #Cryptography #Networking #Privacy #DistributedSystems #RINA #ZKP

infosec.exchange

Infosec Exchange

8
6
3
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Mar 16, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Replying to @catsalad@infosec.exchange
@catsalad@infosec.exchange @stroz@infosec.exchange im totally with you
1
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Mar 16, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange
Replying to @david_chisnall@infosec.exchange
@david_chisnall@infosec.exchange You're correct that Signal implements noise injection via spurious notifications to frustrate timing correlation attacks — that's a documented mitigation. The residual concern is at the infrastructure layer: Google's FCM still receives the device token, IP, and delivery timestamp for every real notification. The spurious traffic makes statistical correlation harder, not impossible — especially for a state-level observer with visibility into both ends. Molly's UnifiedPush implementation eliminates the FCM dependency entirely, which is why it's the logical next audit target.
17
0
0
0
Open post
Harpocrates
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Mar 16, 2026
Caria Giovanni - Harpocrates
@Harpocrates@infosec.exchange

25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡

infosec.exchange

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

286
3
232
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:43:34 UTC