this whole generative ai and vibe coding thing, to me, has this very strong aura of, like david lynch would say, "big sadness"

Show thread

Unveiled at #TROOPERS25 - Hexagon fuzzing unlocked

Hexagon is the architecture in Qualcomm basebands - they power most of the world's leading smartphones.

Until now, this baseband was out of reach.

We released the first open-source toolchain for system-mode Hexagon fuzzing, presented by Luca Glockow (@luglo), Rachna Shriwas, and Bruno Produit (@bruno) at @WEareTROOPERS

Full post: srlabs.de/blog-post/hexagon-fu

How we opened up mobile firmware in 3 steps:
1. Boot real iPhone basebands with a custom QEMU fork
2. Rust-powered fuzzer controls execution via JSON configs
3. Ghidra integration maps coverage across threads

This brings full visibility to Qualcomm’s 4G/5G/GPS stacks.

Reproducible. Extendable. Open source.

Hexagon’s no longer off-limits - mobile security just got a lot more transparent.


🔗 Try it yourself: github.com/srlabs/hexagon_fuzz
📚 Docs: github.com/srlabs/hexagon_fuzz
🖥️ Slides from Troopers25: github.com/srlabs/hexagon_fuzz
🛠️ Issues, ideas, or contributions? PRs welcome.

I did a thing. while working on native NFC capabilities, i ended up writing a test program which reads all the info from EMV cards (such as Visa/Master/Amex) and dumps it to try and learn the payload.

the info shown in the #GTK interface is fairly basic mostly as demo, but it dumps a lot more to the shell:
github.com/FakeShell/nfc-teste

it may be possible to use this for malicious purposes with the right skill set, so please use it responsibly =)

#flx1 #furilabs #linuxmobile #mobilelinux

Test stand is pretty roasted. It is going to take some work to get back up and running.

bird.makeup/@clwphoto1/1935681

A recent intense Russian airstrike in Kyiv severely damaged a building used by Boeing, per Financial Times. Boeing is one of the most prominent American businesses present in Ukraine, with its operations largely focused on engineering and technical support

@purism i havent seen a lot of doing the last 2 years, updates to the software to make the L5 better over time and fully functional yet have to materialize

Update: YouTube has just reinstated the video, after what I presume is a human review process. I wish it didn't take making noise on socials to get past the 'AI deny' process :(

Go forth, and self-host all the things! youtube.com/watch?v=3hFas54xFtg

Show thread
Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml