Ivan Kwiatkowski
banner
justicerage.bsky.social
Ivan Kwiatkowski
@justicerage.bsky.social
Security Researcher @Meta. Writer. Would-be musician. Maintainer of Manalyze and Gepetto. Trolling on a purely personal capacity.
I guess I'm not getting rich this year either.
January 3, 2025 at 3:35 PM
December 20, 2024 at 8:19 PM
A friendly hello to politicians still considering weakening/banning encryption in messaging apps.

arstechnica.com/tech-policy/...
US recommends encrypted messaging as Chinese hackers linger in telecom networks
US official: “Impossible for us to predict when we’ll have full eviction.”…
arstechnica.com
December 4, 2024 at 8:27 PM
I use RSS *a lot* to keep informed about a great many things. When a feed doesn't exist for a website I like, I create scrappers to generate one as this is the main way I consume information. That's what I did with AFP press releases (🇫🇷 content, sorry).

afp.feeds.kwiatkowski.fr
November 17, 2024 at 12:51 AM
New blog post: "So you want to work in cybersecurity".

Every time I post research on X/Twitter, I get DMs asking how to get into cybersecurity. Instead of repeating myself ad nauseam, I wrote down all my thoughts on the subject here: blog.kwiatkowski.fr/cybersecurit...

Personal opinion obviously.
January 23, 2024 at 10:34 AM
#100DaysofYARA

I created a web service that allows you to verify on which yara versions your rule compiles. In the past, shipping rules to customers, I wondered if there were limitations but couldn't find out easily. Now I can.

yaravalidator.manalyzer.org
January 14, 2024 at 6:57 PM
I have the pleasure to announce I'm joining @harfanglab@bird.makeup as Lead Cyber Threat Researcher starting tomorrow!
I'll be working on APTs from everywhere, reversing malware, writing FOSS tools and blog posts!
November 11, 2023 at 9:37 AM
What I could have bought: MacBook Pro 16.2 M2, 16GB RAM, 512 GB of storage.
What I got instead: server with 128 GB RAM, 244 TB of storage.

No wait, I couldn't have gotten the MacBook, it's more expensive.
November 4, 2023 at 3:14 PM
I'm seeing a lot of noise regarding EIDAS and the provision that would force browsers to accept government CAs. Isn't it missing the point? My browser seems to trust hundred of CAs already, surely a decent percentage of them are hacked or front-ends for intelligence agencies?
November 3, 2023 at 10:42 AM
For a very long time, I've been frustrated that there was no way to get the direct feed from @afpfr.bsky.social
(French news agency). I've finally found a source I can scrap, so I published an RSS feed here that anyone can use freely: feeds.kwiatkowski.fr/afp.xml
October 29, 2023 at 12:52 AM