So I'm writing a tutorial on abusing the MAC framework in to create rootkits. Here's the repo that'll contain the PoC code used in the tutorial:

Hey guys and any interested reversers/others,

I made my own version of GP0's "mpscript" tool for exploration of the engine.

Here it is, along with an almost year-old MpEngine.dll (obviously vulnerable to the bug that GP0 found, in case anybody wants to investigate that further).

Private symbols are included for both binaries. (~Year-old Windows private symbols sets leaked somewhat recently.)

Mirror far and wide.

Constant time #AES is in #OpenBSD! T-tables are gone from #IPsec and other places where it matters. Matters for everything that doesn't have AES-NI. Time to upgrade your sparc64 VPN gateways and enjoy the slowdown!

I decided to do a detailed explanation of the message replay attack that was presented together with @veorq at HITB, Infiltrate, and Troopers17:

Thinkpad's are not considered consumer PC's I guess since my x220 would be vulnerable if I had ran stock bios + AMT. Since it supports intel vPro on the chipset/cpu.

Better disable AMT while you still can...

Back from , it was pretty great! Our talk on Signal went well and people apparently liked it (slides at: Now - Markus Vervier - Hunting for Vulnerabilities in Signal.pdf).
We're working on a post-quantum sig scheme, hash-based, that we hope to submit to NIST. Code name: Gravity. May or may not rely on B2b and The hardest part is to design something simple enough yet fast and stateless. SPHINCS is fast and stateless but incomprehensible. Goldreich is stateless and simpler but inefficient. Looking for a middle ground.

