lazytyped's profile picture. Barely grasping the small picture. Opinions are all someone else's

twiz

@lazytyped

Barely grasping the small picture. Opinions are all someone else's

twiz reposted

I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: security.apple.com/blog/memory-in…


twiz reposted

Amazing work! I’m surprised to see Apple managed to get synchronous tag checking in production. I wouldn’t have bet on that given the performance constraints. Getting the sign off to get so much security-specific silicon is also a huge accomplishment.

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…



twiz reposted

There have been various debates about how to improve memory safety with some advocating for rewriting all critical software in newer programming languages. I believed that would take too long and updating CPUs, lang runtimes, and compilers ships faster:👇 security.apple.com/blog/memory-in…


twiz reposted

Congrats to everyone at SEAR for this; this is a crazy announcement. security.apple.com/blog/memory-in…


twiz reposted

Congratulations to the Apple team! I'm proud to have contributed to the inception of MTE in 2017. Hopefully, other vendors will catch up.

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…



twiz reposted

Ugh apple might make me buy an M5 max mac Am on a maxed out M4 Max machine but sync MTE always-on is just too great. And tensor cores on the GPU is just the cherry on top And sad thing I knew that MTE was coming when I got my M4...


twiz reposted

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…


twiz reposted

2026 Apple Security Research Device Application is now live. Apply at security.apple.com/research-devic…! * Arbitrary code with arbitrary entitlements * Arbitrary code injection into existing processes * Arbitrary SPTM, TXM, KernelCache firmwares * Downgrades to old builds * ...and more


twiz reposted

My position on the "doomsday" risk of superhuman AGI is that if IQ offered you a decisive advantage, the world would be run by nerds. I think it's essentially a geek power fantasy. The returns on puzzle-solving skills rapidly diminish past some modest threshold.


twiz reposted

In 2020, I solved a gnarly reverse engineering challenge in PlaidCTF. Only 9 teams solved. It's a huge pile of Typescript. Everything is named after a fish. The catch? There's no code, only types. How do they perform computation using just the type system? (Spoiler: Circuits!)

gf_256's tweet image. In 2020, I solved a gnarly reverse engineering challenge in PlaidCTF. Only 9 teams solved.

It's a huge pile of Typescript. Everything is named after a fish.

The catch? There's no code, only types. How do they perform computation using just the type system?

(Spoiler: Circuits!)

I’d lowkey throw a few big classic movie scenes through this and then play them at a trivia

INTRODUCING: pxl-srt It sorts pixels in an image by color (i implemented and deployed this 20min after seeing this tweet)

IceSolst's tweet image. INTRODUCING: pxl-srt
It sorts pixels in an image by color (i implemented and deployed this 20min after seeing this tweet)


twiz reposted

saw someone on here say that i make five figures a month off twitter. buddy, ELON MUSK doesn't even make five figures a month off twitter


twiz reposted

This is a good time to point out how cybersecurity has become a business of transferring accountability to third parties (you don't buy security, you buy someone to blame when it all goes down). But it's largely symbolic since nobody is liable, and this might even be a feature.


twiz reposted

Why did past societies build so much "useless" beauty everywhere — and why did we stop? It might be a measure of a culture's health... (thread) 🧵

the_culturist_'s tweet image. Why did past societies build so much "useless" beauty everywhere — and why did we stop?

It might be a measure of a culture's health... (thread) 🧵

twiz reposted

"UBSan can check this" is not a security position.


Oh that’s your so-called experts. Never meet your heroes! But go listen to Halvar, even if he stays away 10 years.

Kinda weird to prep a keynote related to security when I've been very diligently not paying a lot of attention in the last 5 years.



twiz reposted

I will, unfortunately, have to disappoint you: C is a High Level Language that compiles to an Semantically-Constrained, Nondeterministic, Abstract Virtual Machine (SCNAVM) that is then projected and modeled onto ${TARGET_PLATFORM}.

Kinda weird to prep a keynote related to security when I've been very diligently not paying a lot of attention in the last 5 years.



twiz reposted

Nobody is talking about this, but Mark Zuckerberg recently made a video commenting on Apple Vision Pro. I’m thinking about uploading it here so I’m the first person to do so today.


twiz reposted

At its most reductive, DTrace can be thought of as dynamic print statements for code that one didn't write -- and it is in fact great for debugging systems

Print statements are great for debugging code, and shit for debugging systems.



Loading...

Something went wrong.


Something went wrong.