Dino A. Dai Zovi
@ddz.bsky.social
1.9K followers 110 following 130 posts
I drink amari and I know things. $ddz LMDDGTFY: https://duckduckgo.com/?q=dino+dai+zovi NYC/BK
Posts Media Videos Starter Packs
Reposted by Dino A. Dai Zovi
kendraserra.bsky.social
New users, on Signal, you can mute chats for a period or permanently. No notifications but you can still see if there are unread messages.

On desktop: in that chat, go to Group Settings, then Notifications. On iPhone: in that chat, click on the name at the top, then go to Sounds & Notifications.
ddz.bsky.social
"Life Safety building automation is pretty awesome. 👏"
thedarktangent.defcon.social.ap.brid.gy
I’m at a #starbucks in a mall, and they accidentally burned my chocolate chip cookie, opening the toaster send smoke everywhere.

The building smoke detectors trigger which kicks on the air handlers to go to maximum to clear any smoke, which also triggers curtains to drop from key ceiling […]
Original post on defcon.social
defcon.social
Reposted by Dino A. Dai Zovi
offensivecon.bsky.social
Our second keynote for Offensivecon 2025 will be Dino Dai Zovi! @ddz.bsky.social
ddz.bsky.social
I'll be doing a speaking!
offensivecon.bsky.social
Our second keynote for Offensivecon 2025 will be Dino Dai Zovi! @ddz.bsky.social
Reposted by Dino A. Dai Zovi
4dgifts.bsky.social
Saw this on the other site but I should comment here:
Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991.
You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns
ddz.bsky.social
Exactly this. We should instead be investing that energy into making authentication in our environment unphishable by making it impossible to give away access to an attacker, even if someone actually wanted to.
risu.bsky.social
I have never once run a phishing sim. I refuse to use the word. I put it in air quotes and say scam by text or email etc
Tech and cyber has been about deflecting blame to anyone else but themselves- which is what sims are. Blaming people when the system they use should protect against issues.
Reposted by Dino A. Dai Zovi
risu.bsky.social
I have never once run a phishing sim. I refuse to use the word. I put it in air quotes and say scam by text or email etc
Tech and cyber has been about deflecting blame to anyone else but themselves- which is what sims are. Blaming people when the system they use should protect against issues.
Reposted by Dino A. Dai Zovi
lorenzofb.bsky.social
NEW: WhatsApp says it has notified 90 victims, including journalists and members of civil society, that they were targeted with spyware made by Paragon.

This is the first time that Paragon is linked to alleged abuse of its products.

techcrunch.com/2025/01/31/w...
WhatsApp says it disrupted a hacking campaign targeting journalists with spyware | TechCrunch
The Meta-owned company said the campaign was linked to Israeli spyware maker Paragon.
techcrunch.com
Reposted by Dino A. Dai Zovi
evacide.bsky.social
Meta says almost 100 journalists and activists were targeted with spyware from Israeli company Paragon Solutions using a zero-click vuln in WhatsApp. If you use an iPhone, enabling Lockdown Mode prevents this from working. www.theguardian.com/technology/2...
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware
www.theguardian.com
ddz.bsky.social
I'm really liking the crisp definitions of and boundaries between product engineering, domain engineering, and infra engineering in this.

How much of your security org builds "what any company would need" (infra) vs. "what is unique to this company but shared across the company" (domain) ?
ddz.bsky.social
There are different privacy concerns and approaches for the training phase of AI as well as for the inference phase of using it. It's a good time to be thinking about what the right approaches are for each.
ddz.bsky.social
+1, security product vendors, services companies, *and* internal teams must always operate under the Hippocratic Oath, "First, do no harm."
ddz.bsky.social
We blogged again! This time about our Data Safety Levels framework, which was inspired by the CDC/WHO Biosafety Levels system and Laboratory Biosafety Manuals. Like biological agents, we also don't want sensitive data to be exposed to humans or escape.

code.cash.app/dsl-framework
Data Safety Levels Framework: The foundation of how we look at data in Block
Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.
code.cash.app
ddz.bsky.social
This is the way ;)
ddz.bsky.social
PRF in WebAuthN is going to enable epic things
ddz.bsky.social
Fraud is such a broad thing, hard to answer. But I think better forms of digital and cryptographic proofs of selective identity information would help. For example, cryptographic proof of personhood, while still remaining anonymous would help reduce amount of bots and such on social media.
ddz.bsky.social
That is true that it is not cool, but the shift to EMV also happened in the US with cardholders not being liable for fraudulent charges by law. I'm not sure what the laws were in AU, but wonder if that was only the situation in EU/UK?
ddz.bsky.social
Any plans on supporting Confidential VMs (e.g. AWS Nitro Enclave, AMD SEV-SNP, Intel TDX) w/ TamaGo unikernels?
ddz.bsky.social
The way that I think about it is that the systems that I think about the security of have grown larger and more complex. Being Security DRI for Square's EMV launch in 2014 was really educational. True to my roots, I found EMV smartcard parsing mem corruption bugs in our firmware before it shipped :)