Readit News logoReadit News
dguido commented on 8M users' AI conversations sold for profit by "privacy" extensions   koi.ai/blog/urban-vpn-bro... · Posted by u/takira
dguido · 9 days ago
If you want a VPN you can trust, deploy your own with AlgoVPN: https://github.com/trailofbits/algo
dguido commented on Prompt injection to RCE in AI agents   blog.trailofbits.com/2025... · Posted by u/vinhnx
dguido · 2 months ago
We're a bit non-committal about who this affects in the blog, but phew man, there are a lot of agent systems that will fall victim to this general class of attack.
dguido commented on Sensitive AlgoVPN privacy, logging, Ansible changes now authored by Claude   github.com/trailofbits/al... · Posted by u/slacktivism123
dguido · 4 months ago
Hi! I'm the author of this PR and the maintainer for Algo. Claude Code has been a tremendous help dealing with a project of this scope and size. This PR to eliminate storing lots of sensitive data on the host was an interest of mine for a while, but Claude Code let me finally make progress on it. I tried to strike a balance between security and privacy (you need logs to investigate issues!). Let me know what you think. Thanks!
dguido commented on Hijacking multi-agent systems in your PajaMAS   blog.trailofbits.com/2025... · Posted by u/Qwuke
dguido · 4 months ago
Hi all, CEO of Trail of Bits here. PajaMAS includes all our guidance for building multi-agent systems securely, including core design principles, a multi-agent security checklist, and framework selection criteria. Hope it helps!
dguido commented on A privacy VPN you can verify   vp.net/l/en-US/blog/Don%2... · Posted by u/MagicalTux
dguido · 4 months ago
This is cool, and I'm glad to see someone doing this, but I also feel obligated to mention that you can also just quickly deploy your own VPN server that only you have access to with AlgoVPN: https://github.com/trailofbits/algo
dguido commented on Exploiting zero days in abandoned hardware   blog.trailofbits.com/2025... · Posted by u/ingve
dguido · 5 months ago
In case anyone is looking for them, here are the exploits for these EOL devices. I avoided allowing Trail of Bits to release exploits for 13 years, but I decided it was finally time for a policy change. We'll be dropping a lot more as time goes on now.

Here's the exploit for the Netgear WGR614v9: https://github.com/trailofbits/exploits/tree/main/junkyard-2...

Here's the exploit for the BitDefender Box 1: https://github.com/trailofbits/exploits/tree/main/junkyard-2...

There's a lot of included detail so you can learn how to write your own and really understand every decision we made in writing them.

dguido commented on Sonos CEO steps down after app update debacle   reuters.com/business/reta... · Posted by u/saaaaaam
dguido · a year ago
Please stop putting salespeople in charge of highly technical product companies like Sonos. I'm so glad that Tom Conrad is an engineer by training. I hope he can turn this mess around.

The key technical change that broke Sonos was abandoning their reliable UPnP (Universal Plug and Play) system for device discovery in favor of mDNS, while also shifting from direct device communication to a cloud-based API approach. This new architecture made all network traffic encrypted and routed through Sonos cloud servers (even for local operations), adding significant overhead and latency, especially for older Sonos devices with limited processing power. They also switched from native platform-specific UX frameworks to a JavaScript-based interface while moving music service interactions through their cloud instead of direct SMAPI calls, resulting in slower performance and reduced functionality.

For a more extended discussion, see this excellent LinkedIn post from Andy Pennell, a principal engineer at Microsoft with a deep technical understanding of Sonos systems. He created one of the most successful third-party Sonos apps for Windows Phone and worked directly with Sonos on their official Windows Phone 8 app.

https://www.linkedin.com/pulse/what-happened-sonos-app-techn...

dguido commented on AWS Nitro Enclaves: Attack Surface   blog.trailofbits.com/2024... · Posted by u/ingve
hdjdjfb · a year ago
Why is the first section written by AI?
dguido · a year ago
As the editor of this blog, I can assure you that AI did not craft the introduction. As a general rule, we include all the most relevant details in the above-the-fold section, allowing readers to quickly determine if the content warrants their time. This is consistent across all our blog posts.
dguido commented on Cautionary tale on using Chase bank for indie business   jxnl.co/writing/2024/09/2... · Posted by u/nell
dguido · a year ago
Strong recommend on using meow.com. You can get interest on your primary checking account, and easy access to high yield treasury management services.

I’ve been following the Evolve Bank fallout on the FinTech Weekly newsletter, and the whole situation scares me about Mercury. I used to bank with them, but the sanctions by the Federal Reserve and the continued disclosures about lacking KYC and money laundering controls has me worried there are other problems.

dguido commented on Exploiting the iPhone 4   axleos.com/exploiting-the... · Posted by u/codyd51
dguido · 2 years ago
For fun things you can do with a good working jailbreak, check out this integrity validator that checks if your phone is free of malware by exploiting it: https://github.com/trailofbits/ios-integrity-validator

u/dguido

KarmaCake day2446March 26, 2008
About
https://www.trailofbits.com https://www.linkedin.com/in/danguido/
View Original