k0ntax1s's profile picture. Ph.D. in Computer Science. Security and Privacy. (On Mastodon: @kontaxis@mastodon.social)

Georgios Kontaxis

@k0ntax1s

Ph.D. in Computer Science. Security and Privacy. (On Mastodon: @[email protected])

Pinned

Verifying myself: I am kontaxis on Keybase.io. 48aChilCrFSgjyJ_X54MuLZU9vQiNSiXEWmG / keybase.io/kontaxis/sigs/…


Georgios Kontaxis reposted

Inflight wifi didn't work so of course I had to debug it. It appears the problem is lack of DHCP lease. The WiFi was using 8 hour leases, which was time enough for many planeloads of passengers to embark/disembark. A quick ARP scan at the time showed there were 55 devices on the…

ErrataRob's tweet image. Inflight wifi didn't work so of course I had to debug it. It appears the problem is lack of DHCP lease. The WiFi was using 8 hour leases, which was time enough for many planeloads of passengers to embark/disembark.

A quick ARP scan at the time showed there were 55 devices on the…
ErrataRob's tweet image. Inflight wifi didn't work so of course I had to debug it. It appears the problem is lack of DHCP lease. The WiFi was using 8 hour leases, which was time enough for many planeloads of passengers to embark/disembark.

A quick ARP scan at the time showed there were 55 devices on the…
ErrataRob's tweet image. Inflight wifi didn't work so of course I had to debug it. It appears the problem is lack of DHCP lease. The WiFi was using 8 hour leases, which was time enough for many planeloads of passengers to embark/disembark.

A quick ARP scan at the time showed there were 55 devices on the…
ErrataRob's tweet image. Inflight wifi didn't work so of course I had to debug it. It appears the problem is lack of DHCP lease. The WiFi was using 8 hour leases, which was time enough for many planeloads of passengers to embark/disembark.

A quick ARP scan at the time showed there were 55 devices on the…

Georgios Kontaxis reposted

SMTP Smuggling - Spoofing E-Mails Worldwide sec-consult.com/blog/detail/sm…


Georgios Kontaxis reposted

Today @FTC took action against Rite Aid for recklessly using facial recognition tools, leading to innocent people being wrongly accused of shoplifting. Our order prohibits the firm from using facial surveillance tools for 5 years, among other protections. ftc.gov/news-events/ne…


Georgios Kontaxis reposted

The full text of "Firewalls and Internet Security, Second Edition”, by Bill Cheswick, Avi Rubin, and myself, has been released under a Creative Commons license at wilyhacker.com. We include the full LaTeX source of the book, since we typeset it ourselves.


Georgios Kontaxis reposted

Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues papers.mathyvanhoef.com/usenix2023-wif…


Georgios Kontaxis reposted

Messaging Layer Security: Secure and Usable End-to-End Encryption ietf.org/blog/mls-secur…


Georgios Kontaxis reposted

Zoom and dark patterns. Click a meeting link. It auto-downloads Zoom. Ignore that. The 'launch meeting' page gives no indication that you can join via browser but suggests install the Zoom Client. Click 'launch meeting' & you get the choice to 'Join from your Browser'.

PrivacyMatters's tweet image. Zoom and dark patterns.

Click a meeting link.  It auto-downloads Zoom.

Ignore that. The 'launch meeting' page gives no indication that you can join via browser but suggests install the Zoom Client.

Click 'launch meeting' & you get the choice to 'Join from your Browser'.
PrivacyMatters's tweet image. Zoom and dark patterns.

Click a meeting link.  It auto-downloads Zoom.

Ignore that. The 'launch meeting' page gives no indication that you can join via browser but suggests install the Zoom Client.

Click 'launch meeting' & you get the choice to 'Join from your Browser'.

Georgios Kontaxis reposted

From the TLS newsletter: Mike Malone wrote a blog post about using short-lived certificates to avoid having to deal with revocation. buff.ly/3Jn8QUg

feistyduck's tweet image. From the TLS newsletter: Mike Malone wrote a blog post about using short-lived certificates to avoid having to deal with revocation. buff.ly/3Jn8QUg

Georgios Kontaxis reposted

When can two TCP sockets share a local address? blog.cloudflare.com/the-quantum-st… @jkbs0 did a cool investigation on when bind-before-connect can reuse local port occupied by connect() and vice-versa. The results will shock you! :)


Georgios Kontaxis reposted

📢Our work on automated discovery of memory safety vulnerabilities in DL frameworks has been accepted at @USENIXSecurity 2023! Jointly with @neochristou @di_jin42 @Vatlidak @baishakhir | arxiv.org/abs/2209.14921 | gitlab.com/brown-ssl/ivys… | 39 CVEs 😎🤘💣#ivysyn #brownssl #usesec23

vkemerlis's tweet image. 📢Our work on automated discovery of memory safety vulnerabilities in DL frameworks has been accepted at @USENIXSecurity 2023! Jointly with @neochristou @di_jin42 @Vatlidak @baishakhir | arxiv.org/abs/2209.14921 | gitlab.com/brown-ssl/ivys… | 39 CVEs 😎🤘💣#ivysyn #brownssl #usesec23

Georgios Kontaxis reposted

Really excited to see Google doing OHTTP with Fastly. My sources tell me it only took Fastly 45 minutes to build this. Amazing! Awesome to see this technology being used in the wild. Next up, OHTTP for DNS. developer.chrome.com/blog/oblivious…


Georgios Kontaxis reposted

I'm very excited about the types of things OHTTP infrastructure will enable, so it's great to see it deployed in practice. e.g., I could imagine collecting signals of page breakage from tracking protection.

Really excited to see Google doing OHTTP with Fastly. My sources tell me it only took Fastly 45 minutes to build this. Amazing! Awesome to see this technology being used in the wild. Next up, OHTTP for DNS. developer.chrome.com/blog/oblivious…



Georgios Kontaxis reposted

MVP?

RetroTechDreams's tweet image. MVP?

Georgios Kontaxis reposted

Windows 98 Setup

RetroTechDreams's tweet image. Windows 98 Setup

Georgios Kontaxis reposted

Let’s move the web PKI forward - together. chromium.org/Home/chromium-…


Georgios Kontaxis reposted

Lemmings (1991)

RetroTechDreams's tweet image. Lemmings (1991)

Georgios Kontaxis reposted

That brings up the question of what should be revoked? For ages, I have been saying revocation reasons don't make sense in the WebPKI. Well Mozilla agreed and has worked on defining those reasons better blog.mozilla.org/security/2022/…


Georgios Kontaxis reposted

Well this is not awesome. @Raspberry_Pi Camera v3 produces RF EMI on the GPS L1 frequency when enabled. Enough to make a GPS receiver maybe 20cm away from the camera cable drop lock. Camera v2 doesn't do this.

vk5qi's tweet image. Well this is not awesome. @Raspberry_Pi Camera v3 produces RF EMI on the GPS L1 frequency when enabled. Enough to make a GPS receiver maybe 20cm away from the camera cable drop lock. Camera v2 doesn't do this.

United States Trends

Loading...

Something went wrong.


Something went wrong.