I use Cape every day on my iPhone. The service is excellent, and the security features haven't ever interfered with my use of the phone. They have a convenient mobile app for setting up extra features like the IMSI rotation and getting support. As a tech savvy user, it matches what I want.
I'm a target for a variety of things, and knowing that no one can SIM swap me is worth the subscription alone. The SS7 protections, encrypted voicemail, secondary numbers, IMSI rotation, etc are all a bonus.
I have a conflict of interest here (I am an advisor to Cape, also a security expert, and my company has done security audits for Cape), you should absolutely look more deeply into what Cape has created. Their service is fundamentally different than other "security-focused cell providers" (mostly snake oil IMHO) because Cape wrote their own mobile core, nearly from scratch. They control the whole software stack and have done really innovative things with it.
Here are a few things you might want to look at more closely:
We're a bit non-committal about who this affects in the blog, but phew man, there are a lot of agent systems that will fall victim to this general class of attack.
Hi! I'm the author of this PR and the maintainer for Algo. Claude Code has been a tremendous help dealing with a project of this scope and size. This PR to eliminate storing lots of sensitive data on the host was an interest of mine for a while, but Claude Code let me finally make progress on it. I tried to strike a balance between security and privacy (you need logs to investigate issues!). Let me know what you think. Thanks!
Hi all, CEO of Trail of Bits here. PajaMAS includes all our guidance for building multi-agent systems securely, including core design principles, a multi-agent security checklist, and framework selection criteria. Hope it helps!
This is cool, and I'm glad to see someone doing this, but I also feel obligated to mention that you can also just quickly deploy your own VPN server that only you have access to with AlgoVPN: https://github.com/trailofbits/algo
In case anyone is looking for them, here are the exploits for these EOL devices. I avoided allowing Trail of Bits to release exploits for 13 years, but I decided it was finally time for a policy change. We'll be dropping a lot more as time goes on now.
Please stop putting salespeople in charge of highly technical product companies like Sonos. I'm so glad that Tom Conrad is an engineer by training. I hope he can turn this mess around.
The key technical change that broke Sonos was abandoning their reliable UPnP (Universal Plug and Play) system for device discovery in favor of mDNS, while also shifting from direct device communication to a cloud-based API approach. This new architecture made all network traffic encrypted and routed through Sonos cloud servers (even for local operations), adding significant overhead and latency, especially for older Sonos devices with limited processing power. They also switched from native platform-specific UX frameworks to a JavaScript-based interface while moving music service interactions through their cloud instead of direct SMAPI calls, resulting in slower performance and reduced functionality.
For a more extended discussion, see this excellent LinkedIn post from Andy Pennell, a principal engineer at Microsoft with a deep technical understanding of Sonos systems. He created one of the most successful third-party Sonos apps for Windows Phone and worked directly with Sonos on their official Windows Phone 8 app.
As the editor of this blog, I can assure you that AI did not craft the introduction. As a general rule, we include all the most relevant details in the above-the-fold section, allowing readers to quickly determine if the content warrants their time. This is consistent across all our blog posts.
Strong recommend on using meow.com. You can get interest on your primary checking account, and easy access to high yield treasury management services.
I’ve been following the Evolve Bank fallout on the FinTech Weekly newsletter, and the whole situation scares me about Mercury. I used to bank with them, but the sanctions by the Federal Reserve and the continued disclosures about lacking KYC and money laundering controls has me worried there are other problems.
I appreciate how organized the Consensys guide is laid out. It's pretty easy to read. Trail of Bits has a similar guide that is a little more in-the-weeds technically. It also covers, what we think is, essential background about certain automated analysis techniques like static analysis and how fuzzers work. Check it out!
Tbh there is a much larger market for application of existing technology (e.g., pentests) than development of new technology (e.g., DARPA programs and the 1% of tech firms that need something new). There are a handful of others, but the market doesn't support dozens of other firms like Trail of Bits. There is some innovation that happens in Series A and B security startups but IMHO that quickly gives way to pressures of building an enterprise sales team.
We're using most of the exact same file-based indicators as MVT. It's really refreshing that Amnesty shared so much of what they found -- it made our own process of testing our checks against their discoveries much easier.
Trail of Bits here -- while this is mostly correct, there are also parts of the runtime that dead file forensics won't be able to identify. There's no harm in doing both and, in fact, we'd recommend it if you're concerned.
Ugh, I have been advocating "Solidity--" for years and can't get funding to build it (Trail of Bits).
We use two tools to offer quick turnaround automated testing and verification for Solidity: Echidna (like QuickCheck for Solidity) and Manticore (a symbolic verifier). They each let you write high level properties in the span of 1-2 weeks that cover a large amount of potential use cases.
I'm a target for a variety of things, and knowing that no one can SIM swap me is worth the subscription alone. The SS7 protections, encrypted voicemail, secondary numbers, IMSI rotation, etc are all a bonus.