<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>press-release on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/categories/press-release/</link><description>Recent content in press-release on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 09 Jul 2024 07:00:45 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/categories/press-release/index.xml" rel="self" type="application/rss+xml"/><item><title>Trail of Bits named a leader in cybersecurity consulting services</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/07/09/trail-of-bits-named-a-leader-in-cybersecurity-consulting-services/</link><pubDate>Tue, 09 Jul 2024 07:00:45 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/07/09/trail-of-bits-named-a-leader-in-cybersecurity-consulting-services/</guid><description>Trail of Bits has been recognized as a leader in cybersecurity consulting services according to The Forrester Wave™: Cybersecurity Consulting Services, Q2 2024. In this evaluation, we were compared against 14 other top vendors and emerged as a leader for our services. Read the report on our website. What is the Forrester Wave™? Forrester is […]</description></item><item><title>iVerify is now an independent company!</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/08/28/iverify-is-now-an-independent-company/</link><pubDate>Mon, 28 Aug 2023 07:00:45 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/08/28/iverify-is-now-an-independent-company/</guid><description>We’re proud to announce that iVerify is now an independent company following its four-year incubation at Trail of Bits. Originally developed in-house to ensure that our personal phones, which store data essential to our work and private lives, were secured to the standards of security professionals, iVerify quickly showed that it could be valuable to […]</description></item><item><title>We need a new way to measure AI security</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/03/14/ai-security-safety-audit-assurance-heidy-khlaaf-odd/</link><pubDate>Tue, 14 Mar 2023 08:00:47 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/03/14/ai-security-safety-audit-assurance-heidy-khlaaf-odd/</guid><description>Trail of Bits has launched a practice focused on machine learning and artificial intelligence, bringing together safety and security methodologies to create a new risk assessment and assurance program. This program evaluates potential bespoke risks and determines the necessary safety and security measures for AI-based systems.</description></item><item><title>We’re streamers now</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/11/14/livestream-workshop-fuzzing-echidna-slither/</link><pubDate>Mon, 14 Nov 2022 08:30:23 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/11/14/livestream-workshop-fuzzing-echidna-slither/</guid><description>Over the years, we’ve built many high-impact tools that we use for security reviews. You might know some of them, like Slither, Echidna, Amarna, Tealer, and test-fuzz. All of our tools are open source, and we love seeing the community benefit from them. But mastering our tools takes time and practice, and it’s easier if […]</description></item><item><title>Managing risk in blockchain deployments</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/06/24/managing-risk-in-blockchain-deployments/</link><pubDate>Fri, 24 Jun 2022 09:00:09 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/06/24/managing-risk-in-blockchain-deployments/</guid><description>Do you need a blockchain? And if so, what kind? Trail of Bits has released an operational risk assessment report on blockchain technology. As more businesses consider the innovative advantages of blockchains and, more generally, distributed ledger technologies (DLT), executives must decide whether and how to adopt them. Organizations adopting these systems must understand and […]</description></item><item><title>Are blockchains decentralized?</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/06/21/are-blockchains-decentralized/</link><pubDate>Tue, 21 Jun 2022 05:00:39 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/06/21/are-blockchains-decentralized/</guid><description>A new Trail of Bits research report examines unintended centralities in distributed ledgers Blockchains can help push the boundaries of current technology in useful ways. However, to make good risk decisions involving exciting and innovative technologies, people need demonstrable facts that are arrived at through reproducible methods and open data. We believe the risks inherent […]</description></item><item><title>Announcing the new Trail of Bits podcast</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/06/20/announcing-the-new-trail-of-bits-podcast/</link><pubDate>Mon, 20 Jun 2022 22:00:42 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/06/20/announcing-the-new-trail-of-bits-podcast/</guid><description>Trail of Bits has launched a podcast. The first five-episode season is now available for download. The podcast and its RSS feed are available at trailofbits.audio, and you may subscribe on all major podcast outlets, including Apple iTunes, Spotify, Gaana, Google Podcasts, Amazon Music, and many others. Listening to our podcast is like having a […]</description></item><item><title>Reinventing Vulnerability Disclosure using Zero-knowledge Proofs</title><link>https://miscreants.github.io/blog.trailofbits.com/2020/05/21/reinventing-vulnerability-disclosure-using-zero-knowledge-proofs/</link><pubDate>Thu, 21 May 2020 07:50:27 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2020/05/21/reinventing-vulnerability-disclosure-using-zero-knowledge-proofs/</guid><description>We, along with our partner Matthew Green at Johns Hopkins University, are using zero-knowledge (ZK) proofs to establish a trusted landscape in which tech companies and vulnerability researchers can communicate reasonably with one another without fear of being sabotaged or scorned. Over the next four years, we will push the state of the art in […]</description></item><item><title>Our Full Report on the Voatz Mobile Voting Platform</title><link>https://miscreants.github.io/blog.trailofbits.com/2020/03/13/our-full-report-on-the-voatz-mobile-voting-platform/</link><pubDate>Fri, 13 Mar 2020 07:52:37 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2020/03/13/our-full-report-on-the-voatz-mobile-voting-platform/</guid><description>Voatz allows voters to cast their ballots from any geographic location on supported mobile devices. Its mobile voting platform is under increasing public scrutiny for security vulnerabilities that could potentially invalidate an election. The issues are serious enough to attract inquiries from the Department of Homeland Security and Congress. However, there has been no comprehensive […]</description></item><item><title>Mainnet360: joint economic and security reviews with Prysm Group</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/12/09/introducing-mainnet360-a-joint-economic-and-security-assessment-with-prysm-group/</link><pubDate>Mon, 09 Dec 2019 07:00:52 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/12/09/introducing-mainnet360-a-joint-economic-and-security-assessment-with-prysm-group/</guid><description>On Monday, October 28th at the Crypto Economics Security Conference, Trail of Bits announced a new joint offering with Prysm Group: Mainnet360. Carefully designed to produce a comprehensive assessment of the security and economic elements of blockchain software, Mainnet360 gives teams a broader perspective that will allow them to build safer and more resilient systems. […]</description></item><item><title>Introducing iVerify, the security toolkit for iPhone users</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/11/14/introducing-iverify-the-security-toolkit-for-iphone-users/</link><pubDate>Thu, 14 Nov 2019 09:38:48 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/11/14/introducing-iverify-the-security-toolkit-for-iphone-users/</guid><description>“If privacy matters, it should matter to the phone your life is on.” So says Apple in their recent ads about Privacy on the iPhone and controlling the data you share—but many of the security features they highlight are opt-in, and users often don’t know when or how to activate them. But hey… we got […]</description></item><item><title>Announcing the Crytic $10k Research Prize</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/11/13/announcing-the-crytic-10k-research-prize/</link><pubDate>Wed, 13 Nov 2019 07:00:35 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/11/13/announcing-the-crytic-10k-research-prize/</guid><description>At Trail of Bits, we make a significant effort to stay up to date with the academic world. We frequently evaluate our work through peer-reviewed conferences, and we love to attend academic events (see our recent ICSE and Crypto recaps).</description></item><item><title>Crytic: Continuous Assurance for Smart Contracts</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/08/02/crytic-continuous-assurance-for-smart-contracts/</link><pubDate>Fri, 02 Aug 2019 06:50:36 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/08/02/crytic-continuous-assurance-for-smart-contracts/</guid><description>Note: This blog has been reposted from Truffle Suite’s blog. We are proud to announce our new smart contract security product: &lt;a href="https://crytic.io/"&gt;https://crytic.io/&lt;/a&gt;. Crytic provides continuous assurance for smart contracts. The platform reports build status on every commit and runs a suite of security analyses for immediate feedback. The beta will be open soon. Follow us […]</description></item><item><title>Trail of Bits Named in Forrester Wave as a Leader in Midsize Cybersecurity Consulting Services</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/07/16/trail-of-bits-named-in-forrester-wave-as-a-leader-in-midsize-cybersecurity-consulting-services/</link><pubDate>Tue, 16 Jul 2019 11:20:19 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/07/16/trail-of-bits-named-in-forrester-wave-as-a-leader-in-midsize-cybersecurity-consulting-services/</guid><description>Trail of Bits was among the select companies that Forrester invited to participate in its recent report, The Forrester Wave™: Midsize Cybersecurity Consulting Services, Q2 2019. In this evaluation, Trail of Bits was cited as a Leader. We received the highest score among all participants in the current offering category, among the highest scores in […]</description></item><item><title>Seriously, stop using RSA</title><link>https://miscreants.github.io/blog.trailofbits.com/2019/07/08/fuck-rsa/</link><pubDate>Mon, 08 Jul 2019 06:50:43 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2019/07/08/fuck-rsa/</guid><description>Here at Trail of Bits we review a lot of code. From major open source projects to exciting new proprietary software, we’ve seen it all. But one common denominator in all of these systems is that for some inexplicable reason people still seem to think RSA is a good cryptosystem to use. Let me save […]</description></item><item><title>$10,000 research fellowships for underrepresented talent</title><link>https://miscreants.github.io/blog.trailofbits.com/2018/12/20/10000-research-fellowships-for-underrepresented-talent/</link><pubDate>Thu, 20 Dec 2018 10:00:32 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2018/12/20/10000-research-fellowships-for-underrepresented-talent/</guid><description>The Trail of Bits SummerCon Fellowship program is now accepting applications from emerging security researchers with excellent project ideas. Fellows will explore their research topics with our guidance and then present their findings at SummerCon 2019. We will be reserving at least 50% of our funding for marginalized, female-identifying, transgender, and non-binary candidates. If you’re […]</description></item><item><title>We crypto now</title><link>https://miscreants.github.io/blog.trailofbits.com/2018/11/07/we-crypto-now/</link><pubDate>Wed, 07 Nov 2018 06:50:17 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2018/11/07/we-crypto-now/</guid><description>Building and using cryptographic libraries is notoriously difficult. Even when each component of the system has been implemented correctly (quite difficult to do), improperly combining these pieces can lead to disastrous results. Cryptography, when rolled right, forms the bedrock of any secure application. By combining cutting-edge mathematics and disciplined software engineering, modern crypto-systems guarantee data and communication privacy.</description></item><item><title>"AMD Flaws" Technical Summary</title><link>https://miscreants.github.io/blog.trailofbits.com/2018/03/15/amd-flaws-technical-summary/</link><pubDate>Thu, 15 Mar 2018 13:58:03 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2018/03/15/amd-flaws-technical-summary/</guid><description>Two weeks ago, we were engaged by CTS Labs as independent consultants at our standard consulting rates to review and confirm the technical accuracy of their preliminary findings. We participated neither in their research nor in their subsequent disclosure process. Our recommendation to CTS was to disclose the vulnerabilities through a CERT. Our review of [&amp;hellip;]</description></item><item><title>Parity Technologies engages Trail of Bits</title><link>https://miscreants.github.io/blog.trailofbits.com/2018/02/09/parity-technologies-engages-trail-of-bits/</link><pubDate>Fri, 09 Feb 2018 07:50:46 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2018/02/09/parity-technologies-engages-trail-of-bits/</guid><description>We’re helping Parity Technologies secure their Ethereum client. We’ll begin by auditing their codebase, and look forward to publishing results and the knowledge we gained in the future. Parity Technologies combines cryptography, cellular systems, peer-to-peer technology and decentralized consensus to solve the problems that have gone unaddressed by conventional server-client architecture. Their Ethereum client is designed for […]</description></item><item><title>Trail of Bits joins the Enterprise Ethereum Alliance</title><link>https://miscreants.github.io/blog.trailofbits.com/2017/10/19/trail-of-bits-joins-the-enterprise-ethereum-alliance/</link><pubDate>Thu, 19 Oct 2017 07:50:38 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2017/10/19/trail-of-bits-joins-the-enterprise-ethereum-alliance/</guid><description>We’re proud to announce that Trail of Bits has joined the Enterprise Ethereum Alliance (EEA), the world’s largest open source blockchain initiative. As the first information security company to join, and currently one of the industry’s top smart contract auditors, we’re excited to contribute our unparalleled expertise to the EEA. As companies begin to re-architect […]</description></item><item><title>iOS jailbreak detection toolkit now available</title><link>https://miscreants.github.io/blog.trailofbits.com/2017/10/12/ios-jailbreak-detection-toolkit-now-available/</link><pubDate>Thu, 12 Oct 2017 07:50:22 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2017/10/12/ios-jailbreak-detection-toolkit-now-available/</guid><description>We now offer a library for developers to check if their apps are running on jailbroken phones. It includes the most comprehensive checks in the industry and it is App Store compatible. Contact us now to license the iVerify security library for your app. Jailbreaks threaten your work Users like to install jailbreaks on their […]</description></item><item><title>Automated Code Audit’s First Customer</title><link>https://miscreants.github.io/blog.trailofbits.com/2016/10/04/first-ever-automated-code-audit/</link><pubDate>Tue, 04 Oct 2016 07:50:46 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2016/10/04/first-ever-automated-code-audit/</guid><description>Last month our Cyber Reasoning System (CRS) -developed for DARPA’s Cyber Grand Challenge– audited a much larger amount of code in less time, in greater detail, and at a lower cost than a human could. Our CRS audited zlib for the Mozilla Secure Open Source (SOS) Fund. To our knowledge, this is the first instance […]</description></item><item><title>Windows network security now easier with osquery</title><link>https://miscreants.github.io/blog.trailofbits.com/2016/09/27/windows-network-security-now-easier-with-osquery/</link><pubDate>Tue, 27 Sep 2016 07:50:01 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2016/09/27/windows-network-security-now-easier-with-osquery/</guid><description>Today, Facebook announced the successful completion of our work: osquery for Windows. “Today, we’re excited to announce the availability of an osquery developer kit for Windows so security teams can build customized solutions for their Windows networks… This port of osquery to Windows gives you the ability to unify endpoint defense and participate in an […]</description></item><item><title>Tidas: a new service for building password-less apps</title><link>https://miscreants.github.io/blog.trailofbits.com/2016/02/09/tidas-a-new-service-for-building-password-less-apps/</link><pubDate>Tue, 09 Feb 2016 06:50:54 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2016/02/09/tidas-a-new-service-for-building-password-less-apps/</guid><description>For most mobile app developers, password management has as much appeal as a visit to the dentist. You do it because you have to, but it is annoying and easy to screw up, even when using standard libraries or protocols like OAUTH. Your users feel the same way. Even if they know to use strong […]</description></item><item><title>Speaker Lineup for THREADS ’14: Scaling Security</title><link>https://miscreants.github.io/blog.trailofbits.com/2014/10/02/threads-14-scaling-security/</link><pubDate>Thu, 02 Oct 2014 08:00:20 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2014/10/02/threads-14-scaling-security/</guid><description>For every security engineer you train, there are 20 or more developers writing code with potential vulnerabilities. There’s no human way to keep up. We need to be more effective with less resources. It’s time to make security a fully integrated part of modern software development and operations. It’s time to automate. This year’s THREADS […]</description></item><item><title>Trail of Bits Adds Mobile Security Researcher Nicholas DePetrillo to Growing Team</title><link>https://miscreants.github.io/blog.trailofbits.com/2014/07/15/trail-of-bits-adds-mobile-security-researcher-nicholas-depetrillo-to-growing-team/</link><pubDate>Tue, 15 Jul 2014 08:50:09 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2014/07/15/trail-of-bits-adds-mobile-security-researcher-nicholas-depetrillo-to-growing-team/</guid><description>New York, NY (July 15th, 2014)—Veteran computer security researcher Nicholas DePetrillo has joined Trail of Bits, the New York-based security company, as Principal Security Researcher. Trail of Bits Co-founder and CEO Dan Guido announced the hire today. DePetrillo brings the headcount of the firm, which was founded by a team of three in 2012, to […]</description></item><item><title>Dear DARPA: Challenge Accepted.</title><link>https://miscreants.github.io/blog.trailofbits.com/2014/06/03/dear-darpa-challenge-accepted/</link><pubDate>Tue, 03 Jun 2014 18:45:41 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2014/06/03/dear-darpa-challenge-accepted/</guid><description>We are proud to have one of the only seven accepted funded-track proposals to DARPA’s Cyber Grand Challenge. Computer security experts from academia, industry and the larger security community have organized themselves into more than 30 teams to compete in DARPA’s Cyber Grand Challenge —- a first-of-its-kind tournament designed to speed the development of automated security […]</description></item><item><title>Trail of Bits Releases Capture the Flag Field Guide</title><link>https://miscreants.github.io/blog.trailofbits.com/2014/05/20/trail-of-bits-releases-capture-the-flag-field-guide/</link><pubDate>Tue, 20 May 2014 09:00:33 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2014/05/20/trail-of-bits-releases-capture-the-flag-field-guide/</guid><description>Free Online Coursework Allows Students, Professionals to Build Essential Offensive Security Skills New York, NY (May 20, 2014)–Security researchers at Trail of Bits today introduced the CTF Field Guide (Capture the Flag), a freely available, self-guided online course designed to help university and high school students hone the skills needed to succeed in the fast-paced, [&amp;hellip;]</description></item><item><title>Introducing Javelin</title><link>https://miscreants.github.io/blog.trailofbits.com/2014/02/24/introducing-javelin/</link><pubDate>Mon, 24 Feb 2014 08:44:38 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2014/02/24/introducing-javelin/</guid><description>Javelin shows you how modern attackers would approach and exploit your enterprise. By simulating real-time, real-world attack techniques, Javelin identifies which employees are most likely to be targets of spearphishing campaigns, uncovers security infrastructure weaknesses, and compares overall vulnerability against industry competitors. Javelin benchmarks the efficacy of defensive strategies, and provides customized recommendations for improving […]</description></item></channel></rss>