Retired security engineer but still hacking when free beer

Joined December 2008
106 Photos and videos
beist retweeted
SPR was designed specifically to eliminate these attacks. Almost all other WiFi deployments carry inherent disconnects between L2/L3 that enable MITM attacks and packet injection, whether EAP-TLS or WPA3.
This seems bad for WiFi encryption: arstechnica.com/security/202…
1
4
3
1,104
3 Dec 2025
2
2
559
beist retweeted
Reminder we are looking for talented security researchers in all areas (iOS, Android, Browser, 0click, AI) 🚀🚀 DM me or shoot us an email at catalystsecurity.com 🦊
1
9
52
6,779
15 Oct 2025
Anyone knows if there are any coworking spaces in Tokyo where the HotDesk (daily pass) seats come with chairs that have wheels and armrests? It would be even better if they also provide external monitors. At WeWork, I noticed HotDesk doesn’t have those kinds of chairs. Thank you!
1
4
874
24 Sep 2025
Can’t believe it’s already been 6 months since I retired. Life after retirement hasn’t been about being “productive,” but about finally using my time however I want. Starting next month I’ll be in Japan, then heading over to Europe and Bangkok, I guess.
1
12
667
24 Sep 2025
I keep up with security news, and I feel the itch to dive back into full-time research—but for now, I’m just enjoying the present. Haven’t really touched computers much, but lately I’ve been hacking about a few hour a week. Using AI to hunt for crashes is still a lot of fun.
8
483
beist retweeted
9 Sep 2025
🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memo…
54
484
2,669
378,244
13 Aug 2025
These days, when I see the results of bug hunting using AI, I truly feel glad that I retired early. Theori at aixcc: theori.io/blog/exploring-tra… Google big sleep: issuetracker.google.com/issu… Xbow: xbow.com/blog/top-1-how-xbow…
3
9
61
7,960
beist retweeted
As a New Year resolution, consider applying to Project Zero :)
It doesn't happen very often, but Project Zero is hiring! goo.gle/41DBQBY Please share with anyone you think would be awesome for the role 🎉 Looking for at least one person. DMs open if you want to reach out about the role. The team: youtu.be/My_13FXODdU
3
6
47
7,293
5 Jan 2025
The Parallels VM escape bug reminds me of a bug I reported to VMware about two years ago. I was waiting until a patch was released before posting, but I ended up forgetting. Just an LPE bug on the host side, feel free to check it out if you're curious. (A colleague of mine forgot his MacBook password, so I discovered the bug in order to read the admin hash and crack it. He made a 'guest' account luckily before.) The diagram might look ugly, tho. PoC is available if you want, but it's a simple logic bug, so easy to exploit.
2
4
51
5,242
5 Jan 2025
For a new setup (Mac mini and LG Dual-up display), I spent some hours and it’s pretty nice! Cursor so much helped me out crash prl_vm_app on the host side (Parallels VM escape). Have not finished the exploit yet but it’s likely exploitable. (Sorry, the cables are still messy.)
2
1
9
2,350
24 Dec 2024
This is an older feature, but it's still one of my favorites in Parallels. Using the prlctl command, you can easily load snapshots right from the Terminal. (If you’re curious about any commands, ChatGPT provides great explanations!) Especially during kernel-level fuzzing, when the system tends to slow down significantly, it’s often more efficient to restore a snapshot than to perform a clean-up. The same applies to user-level fuzzing as well.
4
1,256
24 Nov 2024
Google Tokyo office was amazing! Great food and view. And the location is golden. Thanks for feeding me! @kapitanpetko Probably I need another chance to visit there again for the party.
9
1,265
15 Oct 2024
Who comes to PoC conference this year? Speaker list is here - powerofcommunity.net/speaker…

1
1
3,243
21 Sep 2024
Tokyo is a paradise for hackers who love booze and bar bites. See you at CODEBLUE! codeblue.jp/2024/en/time_tab…

8
1,178
13 Aug 2024
There are AI security-related talks at SSTF, the security conference hosted by Samsung. They'll cover AIxCC (Defcon contest) Also other technical sessions. It's unclear if English interpretation is available, but if you're in Korea, it's worth attending! research.samsung.com/sstf

1
5
16
1,859
18 Jul 2024
Do any of my X friends know a sales representative from Micro Focus, OpenText? Need quick communication regarding a purchase. Asking for a friend, thank you!
1
743