Opens profile photo
Follow
@mikko
@mikko
CRO at . Infosec speaker and author. My latest book "If It's Smart, It's Vulnerable" is coming out from Wiley in August. I stand with Ukraine.
Finlandmikko.comJoined March 2009

@mikko’s Tweets

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

Spotify's free text fields can & have been used for fetching encoded payloads or C2. Just like pastebin & Britney Spear's SoMe have been used in the past. Surprised it is not used more. Anything that contains text that is accessible from DNS or web is a possible infil vector.
Quote Tweet
open.spotify.com/track/4CutWJxN
7
29
Kanye West made $170M in 2021. Hedge fund manager Jim Simons made $3400M in 2021.
Quote Tweet
Taylor Swift is the world's highest-paid celebrity. She made $170M in 2016. Michael Platt is a hedge-fund manager. He made $1500M in 2016. twitter.com/Forbes/status/
6
20
58
Cryptocurrency has done more for computer security than I'd ever expected (basically, instant bug bounty for lots of tech, and an actual market demand for real security vs. compliance-focused games.)
27
113
935
tl;dr Yes, 128-bit security is all what you need.
Quote Tweet
People often ask the question - is 128-bit security enough? Is AES-128 enough for high security applications? In this thread, I’ll do the calculation. I’ll assume that AES should be about 8 times faster than SHA256 in ASIC (this is conservative). 1/n
Show this thread
5
9
29
Nordex, another major wind turbine manufacturer hit by ‘cyber incident’ (normally meaning ransomware). Note that the release comes two days after the attack - and no mention of OT systems. I’m also noting that a lot of green energy companies were targeted lately. Coincidence? 🇷🇺
Image
15
139
232
Show this thread
Image
Quote Tweet
The Ukrainian parliament has approved a law with a list of rewards for Russian military equipment. Russian soldiers defecting to Ukraine with a warship or a jet can now claim up to $1 million. A tank or an artillery piece would be worth a $100,000 reward.
Show this thread
22
48
This story is completely and utterly false.
Quote Tweet
🔺 EXCLUSIVE: China staged a huge cyberattack on Ukraine’s military and nuclear facilities in the build-up to Russia’s invasion, according to intelligence memos obtained by The Times thetimes.co.uk/article/china-
Show this thread
10
118
265
Show this thread
Engineers who kept Ukraine’s port city online have gone missing or died in the carnage inflicted by Russia’s siege. Hope remains that Ukrainian cities knocked off the internet map will come back online fast once the shelling ends.
1
29
82
If true, this is worrisome on many levels. First, they believe this is necessary. Second, by isolating from others, their psyche starts to change. Third, they can be fed false information either deliberately or as a consequence of the system.
Quote Tweet
Bellingcat investigator says Russia's defense minister Shoigu and other senior officials, possibly including Putin, are residing in nuclear bunkers near Ufa in the Ural mountains, according to recent flight data twitter.com/christogrozev/…
Show this thread
10
25
103
Background: shareholders of F-Secure have decided to split the company into a consumer business and an enterprise business. The plan is to list both companies separately in the stock exchange.
2
13
126
Show this thread
My talk about online terrorism from 10 years ago.
Quote Tweet
RSA (@RSAConference) has published a shortened version of my 2012 talk "Terrorist Groups in the Online World": youtube.com/watch?v=pBwkI9 [14'24"]
1
3
18
Impressive technology. I saw someone comment that when Meta sees this, they will acquire Nvidia to use this technology in their metaverse. I didn’t have the heart to tell them that Nvidia has a bigger market cap than Meta.
Quote Tweet
Trained in minutes, rendered in seconds. ⏱️ Our Instant NeRF from NVIDIA Research turns 2D photos into 3D scenes in the blink of an #AI. #nerfies #neuralnetworks #SX70 #GTC22 nvda.ws/36HL5GB
Embedded video
0:43
115.1K views
3
34
230
REWARD! Up to $10M for information on EVGENY GLADKIKH. This Russian hacker sought to damage U.S. and global energy facilities with malware. Help us stop him! Text us info on him at the number below or contact us via our Tor-based tips line.
Image
28
252
280