How we made Trail of Bits AI-native (so far)
This post is adapted from a talk I gave at [un]prompted, the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or downlo
This post is adapted from a talk I gave at [un]prompted, the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or downlo
Using dimensional analysis, you can categorically rule out a whole category of logic and arithmetic bugs that plague DeFi formulas. No code changes required, just better reasoning! One of the first le
Iris scan-backed tokens could help stop agent swarms from overwhelming online systems.
Internet-exposed devices that give BIOS-level access? What could possibly go wrong?
Questions remain as Google prepares to lock down Android app distribution in the name of security.
That guest network you set up for your neighbors may not be as secure as you think.
Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. Using adversarial testing guided by our TRAIL threat model, we demonstrated how fo
Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. These bugs potentially affect thousands of downstrea
Last year, our engineers submitted over 375 pull requests that were merged into non–Trail of Bits repositories, touching more than 90 projects from cryptography libraries to the Rust compiler. This wo
Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustw
Even well-known services with millions of users are exposing sensitive data.
Even Google's own earbuds are vulnerable to the Fast Pair hack.
Google says the reports lacked "helpful next steps."
Cellebrite can apparently extract data from most Pixel phones, unless they're running GrapheneOS.
The percentage of companies choosing to pay ransoms dropped significantly, while threat actors shift their tactics in response to decreasing profits.
Ordering DNA for AI-designed toxins doesn't always raise red flags.
Google promises verification will make Android safer, but at what cost?
Meta allegedly prioritized user growth over security, lawsuit said.
Massive 2023 hack was easily preventable, Clorox says.