<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Baptiste David on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/baptiste-david/</link>
    <description>Recent content in Baptiste David on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 02 Oct 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/baptiste-david/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Release of ERNW White Paper 73: Analyzing WinpMem Driver Vulnerabilities</title>
      <link>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</link>
      <pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</guid>
      <description>&lt;p&gt;Today we are releasing a new white paper that delivers a technical analysis of&#xA;security weaknesses discovered in WinpMem, an open-source Windows memory&#xA;acquisition driver widely used in digital forensics.&lt;/p&gt;&#xA;&lt;p&gt;After a concise primer on relevant Windows internals (virtual vs. physical&#xA;memory, page tables and PTEs, CR3 context switching, and kernel and user memory&#xA;separation), the report examines how both the fundamental design of WinpMem and&#xA;specific implementation choices create severe risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - The Face Swap</title>
      <link>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</guid>
      <description>&lt;p&gt;In the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;last blog post&lt;/a&gt;,&#xA;we discussed the full authentication flow using Windows Hello for Business&#xA;(WHfB) with face recognition to authenticate against an Active Directory with&#xA;Kerberos and showcased existing and new vulnerabilities. In this blog post, we&#xA;dive into the architectural challenges WHfB faces and explore how we can exploit&#xA;them.&lt;/p&gt;&#xA;&lt;p&gt;The majority of the work was conducted in the context of the “Windows Dissected”&#xA;project. This project, funded by the BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – the German Federal Office for Information Security),&#xA;has the goal to perform ” various in-depth security analyses of&#xA;security-critical components and functions in Windows.” Over the next years we&#xA;will discuss these results here once they are published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business – Past and Present Attacks</title>
      <link>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</guid>
      <description>&lt;p&gt;Windows Hello for Business is a key component of Microsoft’s passwordless&#xA;authentication strategy. It enables user authentication not only during system&#xA;sign-in but also in conjunction with new and advanced features such as Personal&#xA;Data Encryption, Administrator Protection, and Recall. Rather than depending on&#xA;traditional passwords, Windows Hello leverages a PIN or biometric methods – such&#xA;as fingerprint or facial recognition – to unlock cryptographic keys protected by&#xA;the Trusted Platform Module (TPM).&lt;/p&gt;</description>
    </item>
    <item>
      <title>CrowdStrike: What is the worldwide BSOD all about?</title>
      <link>https://insinuator.net/2024/08/crowdstrike-what-is-the-worldwide-bsod-all-about/</link>
      <pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/08/crowdstrike-what-is-the-worldwide-bsod-all-about/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article is about the massive BSOD triggered by CrowdStrike worldwide on July 19. Analysis and information from CrowdStrike or other sources are regularly published, completing what is expressed here. Updates may also be provided in the future.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Friday, July 19, is a day to be remembered in computing history as the day of one of the biggest BSODs (Blue Screens of Death). We have seen air traffic come to a standstill over the USA and people climbing ladders with USB sticks to update giant screens. The impact was still measurable over many days. The question on everyone’s lips is how that all happened. CrowdStrike provided, on a regular basis, an explanation for people to understand what happened. But explanations can be hard to understand, especially for one who would like to read directly within CrowdStrike’s internal wording in their publications and regarding technical driver implementation details. Also, the analysis misses some points we consider relevant for secure software development. This article discusses conclusions from this massive crash, especially the necessity to change our mindset about software. This means we should understand, document, and evaluate independently software provided by vendors to know exactly what we install on our systems and to figure out the risk that may be taken by using the software. The time of naive belief in software magic must end with a third party’s independent review of the software, analysing its reliability, security, and stability. This is an activity we have been doing at ERNW for years, especially for e.g. the German Federal Office for Information Security (BSI)&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>c0c0n 2023 – A Short Retrospective</title>
      <link>https://insinuator.net/2023/10/c0c0n-2023-a-short-retrospective/</link>
      <pubDate>Tue, 17 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/c0c0n-2023-a-short-retrospective/</guid>
      <description>&lt;p&gt;Two weeks ago, I was at the &lt;a href=&#34;https://india.c0c0n.org/2023/&#34;&gt;c0c0n&lt;/a&gt; conference in&#xA;Cochin (India). This conference is quite special for at least two&#xA;considerations. At first, this is – to the best of my knowledge – one of the few&#xA;conferences which officially brings together hackers, industrials, politics, and&#xA;security forces. This is not always obvious for all these different persons to&#xA;talk together, may be due to a lack of mutual understanding ?. But for a couple&#xA;of days, all of them meet, talk, exchange, and they share mutual needs and&#xA;appropriate solutions. And this may explain the second consideration, why c0c0n&#xA;is one of the oldest cyber security conferences in India (more than 15 years).&#xA;And yes, this is the conference where police forces directly pick you up from&#xA;the gates of your plane at airport, sitting you at the back of a police car to&#xA;drive you to your hotel with emergency lights ?&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
