Senior Product Security Engineer @RedHat | SDE @Fedora | #PSIRT #RHEL | Ex @parrotsec

Joined March 2018
46 Photos and videos
Sandipan Roy retweeted
Quantum computers will one day break the encryption protecting your messages. Apple is preparing for that now and they just made their work public. Apple has open-sourced the post-quantum cryptography code from corecrypto, the encryption library running on over 2.5 billion Apple devices. It protects iMessage, VPNs, and HTTPS connections. Here is why this matters. Most encryption used today relies on math problems that regular computers find nearly impossible to solve. Quantum computers can solve those same problems with ease. They do not exist yet at the scale needed, but the threat is considered real enough that governments and major tech companies are already preparing. The solution is post-quantum cryptography, a new generation of algorithms designed to resist quantum attacks. Apple has picked two of the NIST-standardised ones: ML-KEM and ML-DSA. By open-sourcing the code and the mathematical proofs behind it, Apple is letting independent experts verify that there are no hidden flaws. This is a big deal because a single bug in corecrypto could compromise the security of every app and feature running on 2.5 billion devices. And independent review already proved its value here. During formal verification, researchers found a flaw in an early implementation that standard testing would have missed entirely. This is how security should work. Build it in public, let others verify it, fix what gets found. Apple does not always get credit for open-source contributions. This one deserves it.
11
86
391
11,663
Sandipan Roy retweeted
May 7
💥 Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io
41
703
2,088
531,826
Sandipan Roy retweeted
🚀 DeepSeek-V4 Preview is officially live & open-sourced! Welcome to the era of cost-effective 1M context length. 🔹 DeepSeek-V4-Pro: 1.6T total / 49B active params. Performance rivaling the world's top closed-source models. 🔹 DeepSeek-V4-Flash: 284B total / 13B active params. Your fast, efficient, and economical choice. Try it now at chat.deepseek.com via Expert Mode / Instant Mode. API is updated & available today! 📄 Tech Report: huggingface.co/deepseek-ai/D… 🤗 Open Weights: huggingface.co/collections/d… 1/n
1,650
7,637
45,727
9,875,520
Sandipan Roy retweeted
Apr 19
Reverse engineer and get full root access on the TP-Link Tapo C200 (2025) quentinkaiser.be/security/20… Research by @qkaiser #infosec
3
74
442
25,190
Sandipan Roy retweeted
🧅 TOR archive feed: tor-archive.github.io Every IP that has ever been a TOR node! Searchable with full timeline, exit/guard/middle role, country, ASN, updated hourly since 2024.
4
101
633
47,105
Sandipan Roy retweeted
16 Oct 2025
Arguably the most brilliant engineer in FFmpeg left because of this. He reverse engineered dozens of codecs by hand as a volunteer. Then security "researchers" and corporate employees came along repeatedly insisted "critical" security issues were fixed immediately waving their CVEs. This was hugely demotivating to the fun and enjoyment of reverse engineering.
15 Oct 2025
Replying to @FFmpeg
The maintainer of libxml2 put it very well
155
692
8,824
843,324
Sandipan Roy retweeted
20 May 2025
Bypassing kASLR via Cache Timing : r0keb.github.io/posts/Bypass… kASLR Internals and Evolution : r0keb.github.io/posts/kASLR-… credits @r0keb
7
40
181
27,306
Sandipan Roy retweeted
"Red Hat Enterprise Linux (RHEL) has long been a leader in integrating robust security mechanisms." Discover new insight in our latest blog: #SELinux and #RHEL: A technical exploration of #security hardening red.ht/42RfOMC
6
10
455
SELinux is a powerful tool for enforcing security in Red Hat Enterprise Linux (RHEL). Learn how it works, key commands, and how it mitigates vulnerabilities. Read more 👉 redhat.com/en/blog/selinux-a… #SELinux #rhel #linuxsecurity #cybersecurity #redhat #redhatlinux

38
Sandipan Roy retweeted
Memory Segmentation Cheat Sheet
1
213
1,160
79,512
I got the Hacktoberfest 2024: Level 4 badge from Hacktoberfest! holopin.io/userbadge/cm2kfz1… via @holopin_

3
34
Sandipan Roy retweeted
17 Oct 2024
Want a chance to get a free backpack from Coursera? 🎒 Simply repost and DM us your full name, address, email and phone number. 😊 (Exclusive to learners in the US, UK and India)
1,352
9,796
7,841
1,230,061
Sandipan Roy retweeted
16 Oct 2024
.@mikeferris is making bold statements 💪 See why the largest orgs in almost every sector depend on Red Hat Enterprise #Linux: red.ht/4ha2Caf.
7
21
3,525
Humko neeche utaar lenge log Ishq latka rahega pankhey pe❤️‍🩹 ~Zia Mazkoor
45