iOS security, politics, tech and traveling. Not really on social media anymore.

Joined January 2011
48 Photos and videos
20 Nov 2025
Can’t stress this enough. High taxation incentives people to get more days off instead of more money. In NL it’s not unusual to have a 4 days work week. People call me out for working on Sundays because “it’s weird”
20 Nov 2025
It's probably hard for Americans to imagine this because it's their normal But being European and living in Europe and being radically honest when I arrive in America the main feeling I get is just endless abundance Non-honest (I'd say many to most) Europeans will not be able to deal with this abundance and start coping "zOmG but if you hit your knee you will go bankrupt cause healthcare bills" and "look at the homeless tents" and "lol look at the Amerifats!!!" Even if fully true, that's kinda besides the point, the range of America is much wider, the bottoms are lower and the peaks are higher People are (in some ways literally) hungry to work and climb the social ladder which even if worse now than it ever was is still much more present in America than it is in Europe I can barely get people to come to my house to do construction work in Europe, while in America I'd have them working the same day, because people want money, because unlike Europe there's not much free gov money That makes the system more oiled in a way because people WANT to work and that makes people work and build things The problem is most Europeans will never ever respect "the hustle", they're stuck in the socialized welfare systems that worked in the 1960s and fairness, which is an absolutely beautiful ideal but stops working when you run out of money like Europe does now in 2025
3
2,021
12 Nov 2025
“We can easily bypas KASLR using prefetch attack these days. Entrybleed is the most famous prefetch attack variant.” iOS security is leaving dust to any other platform. It’s hard to believe KASLR is still not a standard mitigation nowadays ssd-disclosure.com/lpe-via-r…
4
8
81
6,996
Adam Donenfeld retweeted
5 Nov 2025
Recently, there was a clash between the popular @FFmpeg project, a low-level multimedia library found everywhere… and Google. A Google AI agent found a bug in FFmpeg. FFmpeg is a far-ranging library, supporting niche multimedia files, often through reverse-engineering. It is entirely the result of volunteers and a marvellous piece of technology. For people who have never been on the receiving end of ‘security researchers’, it is difficult to understand why there is a pushback against them. Think about the commons. In Quebec, these are pieces of land where farmers send their cows during the summer. It is collectively owned, like FFmpeg. Everyone is responsible to care for the commons if they are using it. If you are not using it, you are supposed to stay away. Now, imagine a rich corporation comes in and sends its well-paid agents into the commons to find issues with it. Maybe a broken barrier or a dangerous hole. So far so good… But instead of fixing the issues, the corporation says “you have a month to fix the issue or else I will report you to the government”. How much love would the big corporation get in this context? Why do the security researchers insist on disclosing the issue without having contributed to fixing it? So that they can get credit for it. That's their entire scheme: find issues, irrespective of whether they affect the use case of their employer... after all, all issues no matter how small can be potentially significant at some point... and then brag about it without doing the hard work of trying to fix it. Let me be clear that no everyone working in security behaves this way. Many are good actors. But there are enough 'security researchers' behaving as parasites that it has become a recognizable pattern. « But Daniel, who should be fixing the bugs then? » If you are paying for commercial support, then get in touch with the folks you are paying. If you are not paying, then it is on you. It says so in the licenses. It is part of the moral code open source. It is part of the legal framework. Let me be clear. You do not get to bite back at Linus Torvalds if a bug in the linux kernel crashes your server. What you do is that you identify the issue, narrow it down and propose a fix. If you cannot do it, then you pay someone to do it. Or you just do not use Linux.
59
292
2,407
206,346
30 Oct 2025
“Scan the codebase” ➡️ “Discover vulnerabilities” lol
30 Oct 2025
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. openai.com/index/introducing…
1
4
1,504
Adam Donenfeld retweeted
24 Oct 2025
The story gets stranger... Apparently I was never able to use the 🇪🇺 EU's GPUs in the first place Because I wasn't on their pre-approved organization list of "Horizon 2020" So how can you join the Horizon 2020 list as an organization? Well, you can't. It was made in 2014 and closed in 2020! ????
24 Oct 2025
Replying to @levelsio
The way I read this... aren't you excluded by default because your organization is not on the origination list for Horizon 2020?
387
233
4,028
1,831,973
Adam Donenfeld retweeted
Serious bugs often occur in third-party components integrated by other software. @ifsecure and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click. project-zero.issues.chromium…

7
65
268
65,392
Adam Donenfeld retweeted
Extreme views and narratives are over-represented on social media, per FT:
107
60
505
112,477
Adam Donenfeld retweeted
🤨
176
132
1,844
255,814
Adam Donenfeld retweeted
22 Sep 2025
It hasn’t been announced properly, but The Apple Wiki admins & me grab firmware keys shortly after each major & minor release (e.g. 26.0 and 26.1) We also constantly fill the gaps in the old versions & platforms, e.g. M3 Max and A7 & S1P/S2/T1 & S3 SEP theapplewiki.com/wiki/Firmwa…
2
4
72
7,731
9 Sep 2025
That aged badly
28 Jun 2025
Still extremely bearish on this happening
1
11
2,322
Adam Donenfeld retweeted
7 Sep 2025
Got curious how much faster Linux is than macOS for small-file access and creation. The results are shocking: curl -L cdn.kernel.org/pub/linux/ker… -o linux.tar.xz time tar -xf linux.tar.xz Framework Desktop: 1.6s MBP M4 Pro: 12.2s Over 7x faster on these 90K files!! 🤯

162
212
3,812
465,802
3 Sep 2025
Can't help but wonder about the number of years of human work that we lost because macOS can't upgrade more than one iPhone at a time.
5
904
Adam Donenfeld retweeted
30 Aug 2025
Europeans have no idea how ridiculous their washing'n'drying situation is. Totally cooked by eco-insanity. We just got a TOP-OF-THE-LINE Miele heat-pump setup, and it's still fucking 6:20 hours to do a single wash dry!! Would take 1.5 hours in the US on our gas/vented setup.
824
278
8,246
1,647,608
Adam Donenfeld retweeted
21 Aug 2025
AI efficiency is important. Today, Google is sharing a technical paper detailing our comprehensive methodology for measuring the environmental impact of Gemini inference. We estimate that the median Gemini Apps text prompt uses 0.24 watt-hours of energy (equivalent to watching an average TV for ~nine seconds), and consumes 0.26 milliliters of water (about five drops) — figures that are substantially lower than many public estimates. At the same time, our AI systems are becoming more efficient through research innovations and software and hardware efficiency improvements. From May 2024 to May 2025, the energy footprint of the median Gemini Apps text prompt dropped by 33x, and the total carbon footprint dropped by 44x, through a combination of model efficiency improvements, machine utilization improvements and additional clean energy procurement, all while delivering higher quality responses. See the blog or technical paper for more about our methodology and ongoing efforts. Blog: cloud.google.com/blog/produc… Link to detailed paper: services.google.com/fh/files…
150
771
3,986
745,196
Adam Donenfeld retweeted
19 Aug 2025
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/3]
3
112
71
37,368
Adam Donenfeld retweeted
A year ago a friend spent thousands of $ on a Unitree Robotics robot that was never sent. His emails have been ignored and no refund or updates have been received. When he complained here, he's been harassed by bots. #UnitreeScamAlert #UnitreeScam #Unitree #UnitreeRobotics
2
4
2
5,714
Adam Donenfeld retweeted
What the fuck is going on in the United Kingdom? They've got advertisements unironically saying WiFi is bad for the environment. Who are these people???
287
479
5,760
345,431
30 Jul 2025
Looks like on latest macOS, even with FileVault on, it is still possible to SSH into a machine and unlock it: "This system is locked. To unlock it, use a local account name and password. Once successfully unlocked, you will be able to connect normally."
2
4
1,161