Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

SNeela

@vmcall@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz@infosec.exchange, TU Graz, Austria.

Hardware equivalent of a Sticky Note :debian:

Something I did got a big corpo nominated for the Lamest Vendor Response pwnie award once

Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon

Opinions posted here are my own.

128 Followers
208 Following
8 Posts
Joined July 04, 2023
website:
https://snee.la
film photography:
https://fotos.snee.la/
Open post
SNeela @vmcall@infosec.exchange
· 2w ago
ALRIGHT! I'm VERY excited to announce this research, because we've been holding onto it for close to a year now! Announcing File Notification Attacks! Side-Channel Leakage from the File-Notification System on #Linux, #Android, #Windows, and #macOS We've found decades-old bugs on Linux, Android, and Windows... well technically Microsoft considers what we found an ✨ undocumented feature ✨ (got Microsoft nominated for the lamest vendor response #pwnie award haha). There's SO much to talk about, so please expand this thread below, but you can also check it out yourself at: https://inoti.fyi/ There's a #noAI logo that my sister drew there. Our work was accepted at #CCS 2026, and I'll be presenting it this November at The Hague, Netherlands! If you're there, we should totally meet up :D Thanks to my AWESOME co-authors: Xufan Zhao, Jeanette Angelika Wultsch, @hweissi@infosec.exchange, Florian Draschbacher, @notbobbytables@infosec.exchange, and @lavados@infosec.exchange 🙏, all of us from @isec_tugraz@infosec.exchange, TU Graz #security #cybersecurity #research #systems
File Notification Attacks
File Notification Attacks

File Notification Attacks

Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS. Accepted at The ACM Conference on Computer and Communications Security (CCS), November 15-19, 2026 — The Hague, Netherlands File-notification systems tell applications when files change, e.g., opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android

179
8
153
1
Open post
SNeela @vmcall@infosec.exchange
· 2w ago
Chonk & mini-Chonk of Mastodon meet Konqi of KDE! @kde @akademy@floss.social#akademy2026 #kde #akademy #plushtodon
121
3
32
0
Open post
SNeela @vmcall@infosec.exchange
· 1w ago
Replying to
@lattera@bsd.network @hweissi@infosec.exchange @notbobbytables@infosec.exchange @lavados@infosec.exchange @isec_tugraz@infosec.exchange back when we were doing the research, inotify wasn't implemented in BSD yet, so we didn't test it. Kqueue existed (ofc still exists), but it didn't make sense to test it because it didn't fit the threat model IIRC. But I'd be interested to know about the results of inotify :D
3
0
0
0
Open post
SNeela @vmcall@infosec.exchange
· 2mo ago
I'm happy to announce our work has been accepted at ESORICS 2026, going to be held at Rome, Italy in September later this year! "A Systematic Look at Quality-of-Service Feature Effects on Side Channels in AMD SEV-SNP" In our work, we show that AMD CPUs' Quality of Service features introduce and amplify side channels, especially concerning in the confidential computing / trusted execution paradigm of computing. We show that a malicious hypervisor can use allocation and monitoring features to leak and amplify what's going on in an AMD SEV-SNP confidential VM. The hypervisor can mount keystroke detection attacks, website fingerprinting attacks, Bleichenbacher attacks on RSA, and covert channels. We reported our findings to AMD, who said that "side channels are not in their threat model for SEV-SNP"... 🙂. I have a blog write up here (there's a logo of a cat wearing a business tie - no AI): https://snee.la/posts/amd-qos-side-channels/ You can read the paper at: https://snee.la/pdf/pubs/amd-qos-side-channels.pdf Thanks to Carina Fiedler, @Rayiizzz@infosec.exchange, @supersingular@chaos.social, @misc0110@infosec.exchange and @lavados@infosec.exchange for the fun collaboration! :1000:#esorics2026 #confidentialcomputing #amd #security #cloud #computing #cloudcomputing
A Cat with an MBA: How AMD QoS Features Enable Side Channels on SEV-SNP
sneela

A Cat with an MBA: How AMD QoS Features Enable Side Channels on SEV-SNP

Foreword This blog post is a summarized and introductory write up of our paper recently accepted at ESORICS 2026 to be presented in Rome, Italy between September 14-16, 2026: “A Systematic Look at Quality-of-Service Feature Effects on Side Channels in AMD SEV-SNP”. Not all the scientific details are mentioned in this blog post. If you’re interested, there’s a full paper with more rigorous, peer-reviewed-and-accepted prose.

9
0
9
0
Open post
SNeela @vmcall@infosec.exchange
· 2mo ago
Yesterday evening, the moon had this wonderful red-orange color to it. Using my brand new Tamron 300mm lens, I took this beautiful shot with my Sony Alpha 6500. ISO 100 Exposure Time: 6/10 of a second
3
0
0
0
Open post
SNeela @vmcall@infosec.exchange
· 3mo ago
Keep Android Open: https://keepandroidopen.org #KeepAndroidOpen
keepandroidopen.org

Keep Android Open

Your phone is about to stop being yours. In 2027, Google will block every Android app whose developer hasn

2
0
0
0
Open post
SNeela @vmcall@infosec.exchange
· 5mo ago

Davide Ornaghi and Giuseppe Caruso found a very interesting bug in #Linux's in-kernel Samba3 server from 6.12 to 6.19.x. Essentially, from the commit message and #CVE description:

> Currently, ksmbd does not verify if the user attempting to reconnect to a durable handle is the same user who originally opened the file. This allows any authenticated user to hijack an orphaned durable handle by predicting or brute-forcing the persistent ID.

Very interesting stuff! The kernel let's users resume their connection to an open file even after WiFi drops (durable handle), and a bug in this code let another authenticated user become this WiFi-dropped user, letting the hijacker access all files.

https://github.com/TurtleARM/CVE-2026-31717-KSMBD-Exploit

CVE-2026-31717

infosec.exchange
3
0
2
0
Open post
SNeela @vmcall@infosec.exchange
· 2w ago
Replying to
@Cenbe@techhub.social unless you jest (due to the plush shape), Konqi is dragon :D
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:02:44 UTC