René Mayrhofer
🇺🇦 🇵🇸
Prof. for networks and security at #JKULinz, formerly leading Android platform security at #Google. This account will mostly carry IT security stuff, but occasionally politics and other comedy.
Screeching voice of the minority. I will not cooperate with fascists or nazis - traditional or neo; Austrian, German, US, Russian, or otherwise. I will not help build surveillance and oppression states. Stop the wars, stop the genocide. Never again.
"I need privacy, not because my actions are questionable, but because your judgement and intentions are."
Statements are only my own opinion, not my employers'.
This is currently my primary infosec account in the #Fediverse. It should be #searchable through https://tootfinder.ch. Previous Twitter posts are available in archival form at https://twitterarchive.mayrhofer.eu.org/.
Releasing a universal #Linux #kernel #exploit with very little or even no previous time to distribute a patch through distributions is not cool. Doing it on the day before a weekend - on two weekends in a row - is just being an asshole. Looking at you, #CopyFail and #DirtyFrag.
You may think it helps your PR, that people will queue to use your cool new AI/agentic/whatever tool because you found the bug. You may think that releasing the full exploit because somebody else was even quicker with "leaking" your cool find makes it right. You're wrong. This is neither responsible nor coordinated disclosure. In security, we've tried to learn the hard lessons on keeping in-production, live systems on a global scale safer.
Yes, those bugs have existed for a long time in the kernel source. Yes, other bad actors may already have found them. But you're shining a light on it *and* giving every script kiddie in the world a working exploit to point their mass scans at. That's dangerous. There's a reason why the normal process is to reach out at least to the most widely installed distributions before releasing the bug details publicly. There's a reason why 90 days is a good default - it allows downstream percolation of patches. You can still get the credit. This way, you only create stress for admins.
[For a little relief, refer to https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken for a quick mitigation, because updating kernels and rebooting a fleet of hosts just takes time, weekend or not. #HugOps]
For anybody (still) using #LinkedIn on a regular basis (and I understand that there are reasons for it), you may want to do that with #Firefox for the moment. At least the extensions scanning seems to be done only on Chrome browsers according to https://browsergate.eu/how-it-works/, even if all the other profiling is probably browser agnostic.
I personally take this as an opportunity to ignore that platform completely for the time being. My account will remain as a defense against identity theft, but is fully dormant as of now.
Last Saturday, I was honored and delighted to give the keynote at Grazer Linuxtage #GLT26, a large #Linux event with a lot of history (23 years and counting!) and still a dedicated team behind it.
Title: "What can we learn from Android for other embedded Linux systems security?"
Slides are available at https://pretalx.linuxtage.at/glt26/talk/J8GCHE/, talk recording at https://media.ccc.de/v/glt26-615-what-can-we-learn-from-android-for-other-embedded-linux-systems-security
RE: @EUCommission@ec.social-network.europa.eu
Unfortunately, this is not ready.
The current GitHub repository is a start - a (fairly expensive) prototype (https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues). Before any wider rollout, however, this needs to:
* stabilize in its feature set (e.g., which form of app/device attestation);
* be verified in detail by independent audits - the quick checks done by some security/privacy researchers and developers at the moment do *not* replace a systematic code audit; and
* go through interoperability testing with different age credential providers (the Python demo code is certainly not production-ready)
as a minimum bar.
Of all the different approaches being discussed right now for age assurance (see our open letter at https://csa-scientist-open-letter.org/ageverif-Feb2026), this is the least-bad from a privacy and surveillance point of view. It's one of the few directions that might be acceptable in any shape or form - *if the general political decision is to do this at all* (see the letter for counter arguments that still need to be debated). But rushing it won't help. The privacy and security aspects are nuanced, and hard to get right in apps that should be deployed on a wide variety of Hundreds of Millions of smartphones. Let's settle these important details before announcing it as a "solution".
I just learned that a new release of the decentralized, open source Android (and iOS, but that requires a centralized Apple service) key attestation library warden-supreme has landed. It explicitly supports alternative/custom roots of trust for the attestation chain now and comes with a test for @GrapheneOS@grapheneos.social keys: https://github.com/a-sit-plus/warden-supreme/blob/development/serverside/roboto/src/test/kotlin/GrapheneOsTests.kt
Nice! That's a good match to our academic research direction on digital identity (https://digidow.eu) - avoiding points of centralization for better resilience (against many types of threats). We'll most probably use this for our prototype Android apps that require or benefit from key attestation guarantees and can't/shouldn't use Play Integrity (e.g., because they only communicate over Tor hidden services with each other, and having a Warden backend included on one side is much easier than coming up with a form of mixnet proxy service for querying central instances while retaining an unlinkability guarantee).
We have opened a job posting for a (maximum 6 years) post-doc position at JKU Linz (@jkulinz@mastodon.social) in networks and security: https://karriere.jku.at/hcm/jobexchange/showJobOfferDetail.do?jobOfferId=8a7ec1e69cf609ed019d24e15bd17c6e&j=&languageChanged=true
If you'd like to work with us on timely topics like digital identity (very much including EUDI), embedded system security (including Android), software supply chain security (fixing your future xz and trivy dependencies), and/or the related underlying methods and technologies, please feel free to reach out!
The democratic, liberal, dependable USA that I have known and respected for most of my adult life is dead and will not be revived even after the orange clown stops pretending to be king. It cannot, because the concept of the USA in the world outside its own borders very much depended on soft power, which requires trust. That trust is gone, completely, and probably irrevocably for at least a generation.
It saddens me deeply that all the value, all the good that this long-term stability and trust brought to the USA and the world at large is gone as well. My only hope is that others will accept the responsibility and step up to become the new center of trust in international relations. The EU has the potential for that, but not (yet?) the political will to transcend national interests and rhetoric. China has the economic and military potential, but doesn't share the liberal values (yet?). The world is going to change.
New blog post on why I think that GenAI/LLM coding agents use for finding vulnerabilities and generating PoC code to demonstrate exploitability is going to be painful, but most probably a good thing in the mid term: https://www.ins.jku.at/blog/vulnerability-reports-and-llms/
(Energy consumption and other resource usage is still a problem of those types of LLMs, though!)
#Trump, #Musk, #Putin, #Netanjahu, #Erdoğan, #Orban, #LePenn, and #Kickl are #populist #fascists. There, I said it publicly.
Many more western politicians have clear fascist, illiberal tendencies, including previous #FPÖVP chancellors and current governors (Austrian #federalism does not work any more and needs to be severely limited to get back to a functioning government).
[https://www.derstandard.at/story/3000000021253/was-kickl-als-volkskanzler-bedeuten-wuerde is a good summary of some reasonable criteria for spotting #fascism, and https://www.diepresse.com/19301692/haben-wir-es-den-faschisten-zu-leicht-gemacht gives more insight into the Austrian variant. https://www.aaup.org/news/professors-are-not-enemy-fascists-are%C2%A0 gives links to the current US government fight against academia.]
The result of this toot is probably that I _really_ shouldn't be traveling to the #US, #Israel, or #Turkey with their current governments. Luckily, I still dare write such statements publicly in Austria and the wider EU. If I really have to get into political trouble, then let it be because I denounce fascism and oppose the abuse of technology to build surveillance states driven by fear. I will not fight with violence, but I can and will fight it with words.
Today, two open letters from academics on the scientific arguments against the current #CSS (client side scanning) initiatives have been released:
* The first (in English, internationally coordinated) one is online at https://tinyurl.com/CSAScientistsLetter and still open for additional signatures.
* The second (in German, by #Austrian academics) one is online at https://www.ins.jku.at/chatcontrol/ and explicitly includes law experts in addition to the arguments from a security, privacy, and AI perspective.
This debate is expected to gain new steam with #Spain taking over the EU council presidency, given recently leaked statements like "Ideally, in our view, it would be desirable to legislatively prevent EU-based service providers from implementing end-to-end encryption" (https://www.wired.co.uk/article/europe-break-encryption-leaked-document-csa-law).
Please boost on any channels you deem adequate. The discussion is still open, and we have little time to bring it to a more rational level.
#csam #law #eu #privacy #dataprotection #privacy #humanrights #messenger #chat #chatcontrol #signal #whatsapp #telegram #threema #e2ee