Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

René Mayrhofer :verified: 🇺🇦 🇵🇸

@rene_mobile@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Prof. for networks and security at #JKULinz, formerly leading Android platform security at #Google. This account will mostly carry IT security stuff, but occasionally politics and other comedy.

Screeching voice of the minority. I will not cooperate with fascists or nazis - traditional or neo; Austrian, German, US, Russian, or otherwise. I will not help build surveillance and oppression states. Stop the wars, stop the genocide. Never again.

"I need privacy, not because my actions are questionable, but because your judgement and intentions are."

Statements are only my own opinion, not my employers'.

This is currently my primary infosec account in the #Fediverse. It should be #searchable through https://tootfinder.ch. Previous Twitter posts are available in archival form at https://twitterarchive.mayrhofer.eu.org/.

1723 Followers
391 Following
24 Posts
Joined November 05, 2022
Homepage:
https://www.mayrhofer.eu.org
University:
https://jku.at/ins
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 4mo ago
I'm leaving #Google: https://www.mayrhofer.eu.org/post/leaving-google/ While I believe that I have been able to do some good with my continuing (part-time) engagement in the Android security and privacy team since returning to Austria a couple of years ago, the deal with the US #DoW is completely misaligned with my personal ethical principles. I will, therefore, no longer be able to act as a contact point to Google-internal teams and discussions, but will continue our research on private digital identity, end-to-end secure communication and storage, network privacy, (embedded/mobile) operating system security, supply chain transparency, etc. from a purely academic point of view. Android - and in particular AOSP - will remain a research interest, so please feel free to reach out on any of those topics for potential collaborations or discussions on the academic side.
mayrhofer.eu.org
103
2
86
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 1w ago
https://fnl.mit.edu/how-we-learned-to-stop-worrying-and-love-campus-surveillance/ "The tiresomely old-school cost of supporting scholarship and pedagogy is so dull compared to the exciting opportunity of an Ambient.ai contract that will empower the tracking potential of our 500 new surveillance cameras! " "For this reason, we are writing to let the community know about our new arts initiative: The Initiative to Beautify the AI-capable Surveillance Benevolently Installed by our Administrator Overseers and the MIT Corporation In Collaboration with Big Brother Tech Companies. For a handy acronym, you can refer to our project as the IBAISBIAOMITCORPICBBTC initiative." This is brilliant, and exactly how (computer) science and art can collaborate to point out terrible developments.
fnl.mit.edu
1
0
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago

Releasing a universal #Linux #kernel #exploit with very little or even no previous time to distribute a patch through distributions is not cool. Doing it on the day before a weekend - on two weekends in a row - is just being an asshole. Looking at you, #CopyFail and #DirtyFrag.

You may think it helps your PR, that people will queue to use your cool new AI/agentic/whatever tool because you found the bug. You may think that releasing the full exploit because somebody else was even quicker with "leaking" your cool find makes it right. You're wrong. This is neither responsible nor coordinated disclosure. In security, we've tried to learn the hard lessons on keeping in-production, live systems on a global scale safer.

Yes, those bugs have existed for a long time in the kernel source. Yes, other bad actors may already have found them. But you're shining a light on it *and* giving every script kiddie in the world a working exploit to point their mass scans at. That's dangerous. There's a reason why the normal process is to reach out at least to the most widely installed distributions before releasing the bug details publicly. There's a reason why 90 days is a good default - it allows downstream percolation of patches. You can still get the credit. This way, you only create stress for admins.

[For a little relief, refer to https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken for a quick mitigation, because updating kernels and rebooting a fleet of hosts just takes time, weekend or not. #HugOps]

infosec.exchange
72
7
65
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 6mo ago

RE: @metin@graphics.social

For anybody (still) using #LinkedIn on a regular basis (and I understand that there are reasons for it), you may want to do that with #Firefox for the moment. At least the extensions scanning seems to be done only on Chrome browsers according to https://browsergate.eu/how-it-works/, even if all the other profiling is probably browser agnostic.

I personally take this as an opportunity to ignore that platform completely for the time being. My account will remain as a defense against identity theft, but is fully dormant as of now.

graphics.social

Metin Seven: "LinkedIn Is Illegally Searching Your Computer ht…" - Graphics.social

20
0
16
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago

Last Saturday, I was honored and delighted to give the keynote at Grazer Linuxtage #GLT26, a large #Linux event with a lot of history (23 years and counting!) and still a dedicated team behind it.

Title: "What can we learn from Android for other embedded Linux systems security?"

Slides are available at https://pretalx.linuxtage.at/glt26/talk/J8GCHE/, talk recording at https://media.ccc.de/v/glt26-615-what-can-we-learn-from-android-for-other-embedded-linux-systems-security

pretalx.linuxtage.at

What can we learn from Android for other embedded Linux systems security? :: Grazer Linuxtage 2026 :: pretalx

15
1
10
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago

RE: @EUCommission@ec.social-network.europa.eu

Unfortunately, this is not ready.

The current GitHub repository is a start - a (fairly expensive) prototype (https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues). Before any wider rollout, however, this needs to:
* stabilize in its feature set (e.g., which form of app/device attestation);
* be verified in detail by independent audits - the quick checks done by some security/privacy researchers and developers at the moment do *not* replace a systematic code audit; and
* go through interoperability testing with different age credential providers (the Python demo code is certainly not production-ready)
as a minimum bar.

Of all the different approaches being discussed right now for age assurance (see our open letter at https://csa-scientist-open-letter.org/ageverif-Feb2026), this is the least-bad from a privacy and surveillance point of view. It's one of the few directions that might be acceptable in any shape or form - *if the general political decision is to do this at all* (see the letter for counter arguments that still need to be debated). But rushing it won't help. The privacy and security aspects are nuanced, and hard to get right in apps that should be deployed on a wide variety of Hundreds of Millions of smartphones. Let's settle these important details before announcing it as a "solution".

ec.social-network.europa.eu

European Commission: "It is for parents to raise their children. Not pl…" - European Commission on Mastodon

14
1
21
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 6mo ago

I just learned that a new release of the decentralized, open source Android (and iOS, but that requires a centralized Apple service) key attestation library warden-supreme has landed. It explicitly supports alternative/custom roots of trust for the attestation chain now and comes with a test for @GrapheneOS@grapheneos.social keys: https://github.com/a-sit-plus/warden-supreme/blob/development/serverside/roboto/src/test/kotlin/GrapheneOsTests.kt

Nice! That's a good match to our academic research direction on digital identity (https://digidow.eu) - avoiding points of centralization for better resilience (against many types of threats). We'll most probably use this for our prototype Android apps that require or benefit from key attestation guarantees and can't/shouldn't use Play Integrity (e.g., because they only communicate over Tor hidden services with each other, and having a Warden backend included on one side is much easier than coming up with a form of mixnet proxy service for querying central instances while retaining an unlinkability guarantee).

github.com
14
0
11
1
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago

We have opened a job posting for a (maximum 6 years) post-doc position at JKU Linz (@jkulinz@mastodon.social) in networks and security: https://karriere.jku.at/hcm/jobexchange/showJobOfferDetail.do?jobOfferId=8a7ec1e69cf609ed019d24e15bd17c6e&j=&languageChanged=true

If you'd like to work with us on timely topics like digital identity (very much including EUDI), embedded system security (including Android), software supply chain security (fixing your future xz and trivy dependencies), and/or the related underlying methods and technologies, please feel free to reach out!

karriere.jku.at
9
0
25
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 4mo ago
Replying to
@rayk@techhub.social Leaking the bug (potentially to some limited list) is still not the same as leaking the full exploit and making a lot of noise about it. Even it the exploit can be recreated, why make it so easy for everybody to exploit it immediately? Sure, there's always lots of gray in the spectrum of coordinated disclosure. But from what I can see, they didn't seem to try very hard to help people get their systems into a safer state. The bug release page first and foremost points out how easy the exploit it and on how many distributions it works. This is showing off, and not making systems more secure. Yeah, I am not amused.
5
1
5
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 7mo ago

The democratic, liberal, dependable USA that I have known and respected for most of my adult life is dead and will not be revived even after the orange clown stops pretending to be king. It cannot, because the concept of the USA in the world outside its own borders very much depended on soft power, which requires trust. That trust is gone, completely, and probably irrevocably for at least a generation.

It saddens me deeply that all the value, all the good that this long-term stability and trust brought to the USA and the world at large is gone as well. My only hope is that others will accept the responsibility and step up to become the new center of trust in international relations. The EU has the potential for that, but not (yet?) the political will to transcend national interests and rhetoric. China has the economic and military potential, but doesn't share the liberal values (yet?). The world is going to change.

10
1
9
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago

New blog post on why I think that GenAI/LLM coding agents use for finding vulnerabilities and generating PoC code to demonstrate exploitability is going to be painful, but most probably a good thing in the mid term: https://www.ins.jku.at/blog/vulnerability-reports-and-llms/

(Energy consumption and other resource usage is still a problem of those types of LLMs, though!)

ins.jku.at
5
0
4
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 17mo ago

#Trump, #Musk, #Putin, #Netanjahu, #Erdoğan, #Orban, #LePenn, and #Kickl are #populist #fascists. There, I said it publicly.

Many more western politicians have clear fascist, illiberal tendencies, including previous #FPÖVP chancellors and current governors (Austrian #federalism does not work any more and needs to be severely limited to get back to a functioning government).

[https://www.derstandard.at/story/3000000021253/was-kickl-als-volkskanzler-bedeuten-wuerde is a good summary of some reasonable criteria for spotting #fascism, and https://www.diepresse.com/19301692/haben-wir-es-den-faschisten-zu-leicht-gemacht gives more insight into the Austrian variant. https://www.aaup.org/news/professors-are-not-enemy-fascists-are%C2%A0 gives links to the current US government fight against academia.]

The result of this toot is probably that I _really_ shouldn't be traveling to the #US, #Israel, or #Turkey with their current governments. Luckily, I still dare write such statements publicly in Austria and the wider EU. If I really have to get into political trouble, then let it be because I denounce fascism and oppose the abuse of technology to build surveillance states driven by fear. I will not fight with violence, but I can and will fight it with words.

infosec.exchange
16
0
12
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 39mo ago

Today, two open letters from academics on the scientific arguments against the current #CSS (client side scanning) initiatives have been released:

* The first (in English, internationally coordinated) one is online at https://tinyurl.com/CSAScientistsLetter and still open for additional signatures.

* The second (in German, by #Austrian academics) one is online at https://www.ins.jku.at/chatcontrol/ and explicitly includes law experts in addition to the arguments from a security, privacy, and AI perspective.

This debate is expected to gain new steam with #Spain taking over the EU council presidency, given recently leaked statements like "Ideally, in our view, it would be desirable to legislatively prevent EU-based service providers from implementing end-to-end encryption" (https://www.wired.co.uk/article/europe-break-encryption-leaked-document-csa-law).

Please boost on any channels you deem adequate. The discussion is still open, and we have little time to bring it to a more rational level.

#csam #law #eu #privacy #dataprotection #privacy #humanrights #messenger #chat #chatcontrol #signal #whatsapp #telegram #threema #e2ee

infosec.exchange
58
4
89
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 4mo ago
Replying to
@rayk@techhub.social Nobody "forced" them to release all the details and talk to lots of press about #DirtyFrag. Before the press attention, I hadn't heard about it, and I assume that's true for _many_ others as well. Yes, some party may have leaked parts of the find in some limited groups. That doesn't mean the original finder needs to accelerate the publication manyfold.... Seen from the outside, this process created attention, credit, and marketing, but certainly not more security. I try not to guess people's intentions, but judge mostly by the outcome. And that was bad.
1
0
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 8mo ago
Replying to
@webi18n@w3c.social @ Most US and UK companies: please read this!
2
0
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago
Replying to
@gannimo@infosec.exchange Battery life on the AMD 13 (pre-Pro) is not good, also because of s2idle. I like the machine generally, but battery life is bugging me. Not sure of the Intel variant is any better.
1
1
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 9mo ago
@phoenix_r_d Is it possible to get an invite to test it even if I'm not at CCC? 🙏 @airmessenger
1
1
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 17mo ago
Replying to
I declare partial success with much more aggressive connection, request, and transfer rate throttling in the embedded #nginx instance that serves my static page (plus the dynamic link maze that caught the stupid "AI" scraper bots...) behind #traefik (causing the TLS termination part to be overloaded and blocking authenticated users from legitimate access). https://www.mayrhofer.eu.org/post/defenses-against-abusive-ai-scrapers/nginx-default.conf is the current rate limiting config, https://www.mayrhofer.eu.org/post/defenses-against-abusive-ai-scrapers has the explanations. Something like https://blog.lrvt.de/configuring-crowdsec-with-traefik/ will probably have to be the next level of escalation to deal with the issue on a global level.
mayrhofer.eu.org
3
0
1
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 17mo ago
Replying to
@gunstick@mastodon.opencloud.lu I am using Quixotic right now instead of Nepenthes (because it was easier to get to run in my setup and seems quite a bit more efficient). Not sure if Anubis or Checkpoint work without Javascript support - I am trying to keep my (static) webpage completely usable without client-side code execution so far. If a site doesn't have the constraint, they will probably work very well...
1
0
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 41mo ago
Replying to
@ilumium@eupolicy.social The Nitrokey article is wrong or at least inaccurate on many levels. Given the many other open, interesting topics for current smartphone security, this is pretty much a non-event. @nitrokey@social.nitrokey.com @Fairphone@social.weho.st @ilumium@eupolicy.social
2
1
1
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 5mo ago
Replying to
@ilumium @signalapp These are all bandaids and it becomes a cat-and-mouse game with phishers. What would really help (at least for organizations of any size with an admin staff or person) is federated account management. Accounts should be linked to, e.g., an internal LDAP directory or a family group. Everybody inside this org is marked green, everybody outside is different. People from other orgs that have been marked trusted get their own indicators. Individual outside accounts should be marked trusted when the owner is personally known (that's a manual step). Random accounts, however, should be clearly marked as untrusted. Wire does a bit of that. That is, allow list trusted accounts, don't try to block list bad ones.
0
1
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 2mo ago
Why do US media outlets still call it the DoD when the department's own website calls itself Department of War (https://www.war.gov/) Is this trying to downplay the new agenda?
war.gov
0
2
0
0
Open post
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene_mobile@infosec.exchange
· 17mo ago
Replying to
@rnbwdsh@chaos.social User agent strings seem to be intentionally misleading. Some examples I see: "Mozilla/5.0 (X11; U; Linux armv7l; en-GB; rv:1.9.2.3pre) Gecko/20100723 Firefox/3.6.11", "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4", "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/418 (KHTML, like Gecko) Safari/417.9.2", Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.134 Safari/534.16", "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0b6pre) Gecko/20100903 Firefox/4.0b6pre", etc. That's part of why I am calling them out as illegal, malicious DDoS.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:44:02 UTC