Live data from Hacker News

Viewing profile — dguido

dguido

HN member
Joined
Wed, Mar 26, 2008, 11:34 PM UTC
HN karma
2,454
Public activity
537 items

About dguido

https://www.trailofbits.com https://www.linkedin.com/in/danguido/

Recent public activity

  1. comment
    Comment #47145644

    I use Cape every day on my iPhone. The service is excellent, and the security features haven't ever interfered with my use of the phone. They have a convenient mobile app for setti…

  2. comment
    Comment #47145599

    I have a conflict of interest here (I am an advisor to Cape, also a security expert, and my company has done security audits for Cape), you should absolutely look more deeply into …

  3. comment
    Comment #46285121

    If you want a VPN you can trust, deploy your own with AlgoVPN: https://github.com/trailofbits/algo

  4. comment
    Comment #45696583

    We're a bit non-committal about who this affects in the blog, but phew man, there are a lot of agent systems that will fall victim to this general class of attack.

  5. comment
    Comment #44954610

    Hi! I'm the author of this PR and the maintainer for Algo. Claude Code has been a tremendous help dealing with a project of this scope and size. This PR to eliminate storing lots o…

  6. comment
    Comment #44953193

    Hi all, CEO of Trail of Bits here. PajaMAS includes all our guidance for building multi-agent systems securely, including core design principles, a multi-agent security checklist, …

  7. comment
    Comment #44920879

    This is cool, and I'm glad to see someone doing this, but I also feel obligated to mention that you can also just quickly deploy your own VPN server that only you have access to wi…

  8. comment
    Comment #44726503

    In case anyone is looking for them, here are the exploits for these EOL devices. I avoided allowing Trail of Bits to release exploits for 13 years, but I decided it was finally tim…

  9. comment
    Comment #42690034

    Please stop putting salespeople in charge of highly technical product companies like Sonos. I'm so glad that Tom Conrad is an engineer by training. I hope he can turn this mess aro…

  10. comment
    Comment #41660623

    As the editor of this blog, I can assure you that AI did not craft the introduction. As a general rule, we include all the most relevant details in the above-the-fold section, allo…

  11. comment
    Comment #41330899

    Strong recommend on using meow.com. You can get interest on your primary checking account, and easy access to high yield treasury management services. I’ve been following the Evolv…

  12. comment
    Comment #37742525

    For fun things you can do with a good working jailbreak, check out this integrity validator that checks if your phone is free of malware by exploiting it: https://github.com/trailo…

  13. comment
    Comment #37742516

    Good work, this is super cool!

  14. comment
    Comment #36886298

    Oh neat! I didn't realize. It's good! I could have been fooled it was done by a whole team :D

  15. comment
    Comment #36882003

    I appreciate how organized the Consensys guide is laid out. It's pretty easy to read. Trail of Bits has a similar guide that is a little more in-the-weeds technically. It also cove…

  16. comment
    Comment #36079087

    We need this for code understanding models like StarCoder and the like

  17. comment
    Comment #34574433

    Trail of Bits does this kind of work ( https://www.trailofbits.com )! Tbh there is a much larger market for application of existing technology (e.g., pentests) than development of …

  18. comment
    Comment #28030778

    We're using most of the exact same file-based indicators as MVT. It's really refreshing that Amnesty shared so much of what they found -- it made our own process of testing our che…

  19. comment
    Comment #28030761

    Trail of Bits here -- while this is mostly correct, there are also parts of the runtime that dead file forensics won't be able to identify. There's no harm in doing both and, in fa…

  20. comment
    Comment #26903533

    Ugh, I have been advocating "Solidity--" for years and can't get funding to build it (Trail of Bits). We use two tools to offer quick turnaround automated testing and verification …

  21. comment
    Comment #26903162

    Yes! Please do apply. We have a tight-knit team of experts, industry leading tools, and a work environment that promotes continued learning. You'll get paid well and quickly become…

  22. comment
    Comment #24094257

    If you're looking for a hardening guide for iOS, then try the iVerify app. It will help you detect jailbreaks, check critical security settings, and teach you about many more. http…

  23. comment
    Comment #23934521

    It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad acto…

  24. comment
    Comment #23655581

    yep, https://github.com/warner/magic-wormhole

  25. comment
    Comment #23655572

    Firefox Send, SendSafely, and Magic Wormhole are all end-to-end encrypted. https://send.firefox.com/ https://www.sendsafely.com/ https://github.com/warner/magic-wormhole https://we…