Pascal Gujer
banner
evilmaid.bsky.social
Pascal Gujer
@evilmaid.bsky.social
security researcher | speaker | trainer | lockpicking | evil maid attacks | maker | https://threema.id/MPK39EB8 | hands-on-security.com
Pinned
🔓 Bitpixie is Back!

Bypass BitLocker in under 5 minutes - no screwdriver needed.
Thomas Lambertz’s talk at 38C3 showed how.

🚀 Join our Breaking BitLocker trainings:
• Zurich: hos.direct/jun25training
• BH USA: hos.direct/bhusa25-23aug / hos.direct/bhusa25-45aug

⏰ Early bird ends in 8 days!
🧠 BREAKING BITLOCKER — Early bird CHF 2999 until Nov 3. Seasoned BHUSA course (3 yrs) back in Zurich, 29–30 Jan 2026. Hands-on: TPM sniffing, DMA, bootloader patching, micro-soldering & RAM key extraction. Open to all professionals — especially valuable for LEA & forensics.
hos.direct/jan26training
October 20, 2025 at 7:20 PM
“Putting all eggs in one basket and all baskets on the Titanic.” - @stefanfrei.bsky.social 🧺🚢

When AWS goes down and takes half the internet with it, maybe it’s time to rethink our basket strategy.

Reuters report: www.reuters.com/business/ret...
AWS status page: health.aws.amazon.com

#AWSOutage
October 20, 2025 at 11:15 AM
✈️ Waiting for a flight → todo list created and stuff done ✅
Used ChatGPT to pull all unfinished projects from our past chats.
Clear head & new focus.
➡️ Stop doomscrolling in downtime.
Try:
🔥 “Go through our past chats and create a todo list with all the projects and unfinished tasks we discussed”
September 19, 2025 at 6:30 PM
🔑 International BitLocker Recovery Key Day – July 19th!

One year ago, many learned the hard way: No offline backup = Locked out!
Don’t get caught off guard – backup your BitLocker keys now!

💡 Quick tip:
manage-bde -protectors -get C:

#BitLockerDay #CyberSecurity #Encryption #DataProtection
July 19, 2025 at 5:27 AM
Got asked for tick tweezers while out fishing.
✅ My Care Plus kit had everything.
🎯 Remove slow, no twist, disinfect.
💡 Info: zecken-stich.ch/wie-wird-ein...
🎒 Kit: www.careplus-shop.de/first-aid-ki...
As a dad, you’re the one they rely on.
#DadHack #legendad #legenddad
June 21, 2025 at 10:05 PM
🚨 Breaking 🚨
Our 2nd Breaking BitLocker session at Black Hat got cut.
Only 3 seats left for the Aug 2–3 run. 🔥
Hands-on. Gritty. Soldering scars? likely.

🎟️ hos.direct/bhusa25-23aug
🇨🇭 No Vegas? Zurich pre-run: hos.direct/jun25training

#BlackHat #CyberTraining #BitLocker
June 12, 2025 at 7:32 AM
Got a flat on the kid trailer.
Not just the tube - tyre was toast too. 😬

Swapped it and used my go-to fix:
the Xiaomi Portable Compressor.
🛠 Precise
♻️ Reusable
🚗 Lives in the car

Way better than CO₂ if you’ve got kids in tow.
🔗 amzn.to/45eSolC #ad

#DadHack #BikeLife #Xiaomi #legendad #legenddad
June 9, 2025 at 5:36 AM
Spent half a day chasing ghosts on the CAN bus. Logic analyzer showed traffic, but the system was dead silent.
Turns out I forgot the termination resistor — the one thing I was told to check first.
Lesson: don’t skip the basics. 🧌🔧
#CANbus #DebuggingFails #ElectronicsLife
June 4, 2025 at 2:41 PM
Forgot the grill tongs at a Swiss Grillplatz.
So I built some — 2 sticks + fishing line = DIY spring-loaded BBQ tongs.
Dad Level: 💪
#legendad #legenddad

Full story here: www.linkedin.com/posts/pascal...

#LifeHack #DadHack #DIY
June 1, 2025 at 6:11 AM
Most people wait.
For clarity. For courage. For the “right” time.

But the truth? You'll rarely feel ready.
Movement brings clarity. Not the other way around.

That first step changes everything.

🚀 Ready to move?
→ Vegas Aug 4-5 hos.direct/bhusa25-45aug
→ Zurich Jun 26-27 hos.direct/jun25training
May 26, 2025 at 10:06 PM
🔧 Dad Hack: Fixing Broken Plastic Parts!
Unleash the secret combo: super glue + baking soda! 🪄

🛠️ drill, key files 😇, precision drivers, super glue, baking soda, plastic wrap
🔁 glue → sprinkle soda → repeat → file/shape
✅ Done! Hard as stone!

What’s your go-to repair trick? 💬

#legendad
May 24, 2025 at 9:30 AM
🔐 Break BitLocker with real tools — not slides.
Black Hat USA training, >50% booked. Early bird ends May 23, 11:59 PM PDT.

You’ll:
🧠 Learn BitLocker internals
📡 Sniff keys
🥾 Attack Bootloader
💻 Take home a hacked test laptop + logic analyzer

👉 hos.direct/bhusa25-23aug
👉 hos.direct/bhusa25-45aug
May 22, 2025 at 8:06 PM
Don’t wait for the wind to change – set your sail. 🚩
At 14, I dreamt of attending #BlackHatUSA. Today, I’m not just attending – I’m an invited trainer.
Years of passion, perseverance, and hacking led here.
Curious about the full story? ;)
@blackhatevents.bsky.social

hos.direct/kjtyv
#bitlocker #bhusa #third #trainer #goals #attract #like #magnets… | Pascal G.
*Don’t Wait for the Wind to Change – Set Your Sail: My Journey to Becoming a Black Hat Trainer* At 14, I read The Art of Intrusion by Kevin Mitnick and first heard about Black Hat and DEF CON. Fasci...
hos.direct
May 20, 2025 at 12:19 AM
“Why do you always carry a knife?”
My great-grandfather told my grandfather, who told my dad, who told me: “A real man always carries a knife.”

Today, I used mine to turn a normal bottle into a spill-proof straw bottle.
Dad Level achieved

What’s your best dad hack?

#LifeHacks #legenddad #legendad
May 17, 2025 at 9:04 AM
🔓 Bitpixie is Back!

Bypass BitLocker in under 5 minutes - no screwdriver needed.
Thomas Lambertz’s talk at 38C3 showed how.

🚀 Join our Breaking BitLocker trainings:
• Zurich: hos.direct/jun25training
• BH USA: hos.direct/bhusa25-23aug / hos.direct/bhusa25-45aug

⏰ Early bird ends in 8 days!
May 15, 2025 at 8:42 PM
🚀 Cybersecurity Training – Feeling lost?

Before every training, I always wonder:
💭“Am I skilled enough?”

Turns out, many of us feel the same! With Breaking BitLocker, we make it easy – from 0 to hero with minimal prerequisites.

Got a funny training story? Let’s hear it!
#CyberSecurity #Training
May 14, 2025 at 2:55 PM
@blackhatevents.bsky.social time for a first post on Bsky 😉
Easter food for thought 🐣
What if BitLocker isn’t as secure as you think?
We show 3 real-world attacks + mitigations at @blackhatevents.bsky.social #BHUSA 2025.
🧰 TPM sniffing, DMA, BitPixie.
🛠️ All hands-on. Hardware kit included.
🇺🇸 hos.direct/bhusa25-45aug
🇺🇸 hos.direct/bhusa25-23aug
May 13, 2025 at 3:35 PM
🚀LocalSend: The Open-Source AirDrop Alternative!

Transfer files over WiFi without internet! Works on Windows, macOS, Linux, Android & iOS.

💡Perfect for travel, meetings, or quick file swaps at home. No cables needed!

localsend.org/de/download
github.com/localsend/lo...

#OpenSource #FileSharing
May 13, 2025 at 12:27 AM
🚨 Our first Breaking BitLocker training at Black Hat USA 2025 is 30% SOLD OUT – weeks before early bird ends!

Learn to break TPM-only BitLocker with real hardware & hands-on techniques. Don’t wait – spots are flying!

Aug 2&3:
hos.direct/bhusa25-23aug
Aug 4&5:
hos.direct/bhusa25-45aug

#BHUSA
May 12, 2025 at 8:13 PM
“0-day” LPE - but only works if you know the password?

That’s not a vuln. That’s literally a feature.

Tired of seeing this stuff blindly reposted by folks who can’t tell access control from exploit. We need fewer click-chasers, more professionals.
April 25, 2025 at 6:29 PM
Easter food for thought 🐣
What if BitLocker isn’t as secure as you think?
We show 3 real-world attacks + mitigations at @blackhatevents.bsky.social #BHUSA 2025.
🧰 TPM sniffing, DMA, BitPixie.
🛠️ All hands-on. Hardware kit included.
🇺🇸 hos.direct/bhusa25-45aug
🇺🇸 hos.direct/bhusa25-23aug
April 17, 2025 at 4:07 PM
🚀 Did you know? You can use Touch ID for sudo on macOS - no more password typing in Terminal

🔐 Just add this at the top of /etc/pam.d/sudo:
` auth sufficient pam_tid.so`

Next time you run sudo, you’ll get a fingerprint prompt.
That's how sudo should feel in 2025.
#macOS #TerminalTips #DevHacks
March 28, 2025 at 8:50 AM
Next.js CVE-2025-29927: Getting far less attention than the alleged ESP backdoor - but far more dangerous. A single HTTP header can bypass auth. Remote exploitable, public PoCs out!
Patch now. Don’t wait.
PoC: github.com/aydinnyunus/CVE-2025-29927
#CyberSec #NextJS #CVE #infosec
GitHub - aydinnyunus/CVE-2025-29927: CVE-2025-29927 Proof of Concept
CVE-2025-29927 Proof of Concept. Contribute to aydinnyunus/CVE-2025-29927 development by creating an account on GitHub.
github.com
March 24, 2025 at 5:11 PM
O2 built an AI granny 👵🏼 named Daisy who traps scammers in 40-minute chats about cats and knitting—just to waste their time. In a cybercrime war where outlaws outnumber the good guys, smart ideas like this are our secret weapon. Time to fight smart.
Your browser is up to date
You can use YouTube's latest features!
youtu.be
March 24, 2025 at 4:13 PM