Latest News

Read all latest blog posts

HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588
March 10, 2025

HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588

HOWTO: build ATF (Trusted Firmware ARM) and OPTEE for RK3588 To better implement the protection of digital assets in embedded systems, we have chosen the RK3588 as the prototype platform.

Read More
Risk analysis of Log4Shell (CVE-2021-44228) and mitigation
December 17, 2021

Risk analysis of Log4Shell (CVE-2021-44228) and mitigation

Risk analysis of Log4Shell (CVE-2021-44228) and mitigation Log4Shell is a high impact exploitable bug in Java logging framework logj4.

Read More
VaultBoot: Next-Gen Firmware Security Solution
September 19, 2021

VaultBoot: Next-Gen Firmware Security Solution

Background Firmware is a special type of software, mainly used for the control and communication of the underlying hardware.

Read More
VaultFuzzer: A state-based approach for Linux kernel
September 13, 2021

VaultFuzzer: A state-based approach for Linux kernel

Background Since the beginning of computer software development, software quality has become an inevitable issue in the field of software testing.

Read More
VED (Vault Exploit Defense): A threat detection and prevention system
September 6, 2021

VED (Vault Exploit Defense): A threat detection and prevention system

Background In the beginning of the hacker's era, a long-term battle for control of the “CORE” in memory has been waged since Aleph One published the paper Smashing The Stack For Fun And Profit on Phrack Issue 49 in 1996.

Read More
What every CISO and security engineer should know about Intel CSME
July 16, 2021

What every CISO and security engineer should know about Intel CSME

Background The majority of infosec community are trying to ignore the risks below the OS in past decades but it’s impossible to bury all of them at low cost today.

Read More
VaultHSM report: The way to confirm whether the Smart Card (J3H145) supports RFC-6979 ECDSA implementation
July 7, 2021

VaultHSM report: The way to confirm whether the Smart Card (J3H145) supports RFC-6979 ECDSA implementation

Background The original implementation of DSA-type signature algorithm (including ECDSA) needs a random number which belongs to the same mathematical object of the private key (an element of GF(p), in which p is a prime number).

Read More
Public crypto audit report: lurch/OMEMO
June 17, 2021

Public crypto audit report: lurch/OMEMO

lurch/OMEMO Security Assessment Crypto is a neutral technology just like the natural existence (“For he makes his sun rise on the evil and on the good, and sends rain on the just and on the unjust.

Read More
Vault1317 protocol: a modern approach for metadata protection with deniability
June 2, 2021

Vault1317 protocol: a modern approach for metadata protection with deniability

vault1317/signal-dakez: An authenticated key exchange protocol with a public key concealing and a participation deniability designed for secure messaging Richard B.

Read More