peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ ls -t writing/ | less # page 13 of 13

Latest articles · page 13 of 13

  • Digital privacy for board directors: the eighteen-post version

    An honest start to a long series. What digital privacy actually means for a board director in 2023, why the home / travel / work boundary is the right framing even though it leaks, and why children deserve four of the eighteen posts.

    • 6 min read
  • AI

    INT8 quantisation, in numbers — and why INT16 is the boring choice

    What "INT8-quantised inference" actually means once you do the arithmetic, why dropping from FP32 to INT8 is a cliff and dropping to INT16 isn't, and why every interesting question about putting an ML model on real silicon ends up here.

    • 11 min read
  • What the teenagers taught the Fortune 500

    LAPSUS$ compromised Microsoft, Okta, Nvidia, Samsung, Vodafone, and several others in a few months. They were teenagers using social engineering and MFA fatigue. The lesson, awkwardly, is that the dominant compromise vector in 2022 is social, not technical.

    • 8 min read
  • Log4Shell, and the inventory question we cannot keep ducking

    A month on from CVE-2021-44228, the headline-grabbing exploits have slowed but the underlying problem has not. The discomfort of the past month was not really about Log4j. It was about how few firms could answer the question 'where is it running?'

    • 7 min read
  • wlan0: the unlocked back door on every TV

    Part 4 of 4. Once you have root on the TV, the most useful thing on the device isn't the data on it — it's the second network interface nobody disabled. What this bypasses, why the SIEM is blind to it, and what to do about it.

    • 10 min read
  • Pegasus, and the question for UK boards we have been pretending not to face

    The Pegasus Project disclosures last month confirmed what specialists have privately known for years: commercial spyware is a mature, well-funded industry, and its customer list includes governments most UK firms do business with. The board question is what to do about it.

    • 7 min read
  • From the embedded browser to a shell on a smart TV

    Part 3 of 4. From the AIT-triggered page load to a shell prompt. CVE-2020-6383, shell.js, SMACK, and the public Samsung Q60T root chain.

    • 11 min read
  • The lab rig: re-broadcasting HbbTV into a test bench

    Part 2 of 4. What I built on the bench to study HbbTV attacks safely. Hardware, software, the AIT injection step, and the legal bit (do not transmit DVB into open air).

    • 9 min read
  • Colonial Pipeline: the CNI lesson the UK should not need to learn the hard way

    Five weeks after the DarkSide ransomware attack on Colonial Pipeline shut down 45% of US East Coast fuel supply, what UK critical national infrastructure boards should be doing about it.

    • 7 min read
  • The TV in the corner: what HbbTV actually is

    Part 1 of 4. A primer on HbbTV from a security researcher's bench. Why I think the smart TV mounted on the meeting-room wall is the most under-considered attack surface in any UK office in 2021.

    • 7 min read
  • Hafnium and the patch-window asymmetry

    Five weeks after the Microsoft Exchange ProxyLogon disclosure, the dust is settling on what may turn out to be the most consequential mass-exploitation event of the decade. What it teaches us is structural, not tactical.

    • 7 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…