Laurent Clévy's Avatar

Laurent Clévy

@lorenzo2472

Reverse engineering, files formats and crypto. https://github.com/lclevy

204
Followers
576
Following
141
Posts
23.12.2023
Joined
Posts Following

Latest posts by Laurent Clévy @lorenzo2472

Diagram titled “Transformer attention.” It shows three steps of the attention computation with code snippets beside each step. The first step is “Scale factor 1/√dₖ,” highlighting code that computes the reciprocal square root. The second step is “Dot product Q · K,” showing code performing a dot-product accumulation. The third step is “Scaling + max tracking,” highlighting code that multiplies by the scale factor, stores the value, and updates a running maximum. The phrase “Transformer attention” appears prominently in the center.

Diagram titled “Transformer attention.” It shows three steps of the attention computation with code snippets beside each step. The first step is “Scale factor 1/√dₖ,” highlighting code that computes the reciprocal square root. The second step is “Dot product Q · K,” showing code performing a dot-product accumulation. The third step is “Scaling + max tracking,” highlighting code that multiplies by the scale factor, stores the value, and updates a running maximum. The phrase “Transformer attention” appears prominently in the center.

The slides from my @re-verse.io talk, "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels", are now online!

Slides: nicolo.dev/files/pdf/re...

Plugin: github.com/seekbytes/pt...

08.03.2026 13:06 👍 5 🔁 2 💬 1 📌 0

Simple age check for Linux:

Just have the shell ask the user to check the host IP on first boot.

If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇

08.03.2026 20:50 👍 40 🔁 7 💬 6 📌 0
Post image

Spread the word! @phrack.org CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :)
phrack.org

07.03.2026 17:33 👍 25 🔁 16 💬 0 📌 1
Preview
VulHunt Vulnerability Detection Framework by Binarly's REsearch Team

We @binarly.bsky.social just open-sourced our VulHunt framework at RE//verse!

GitHub: github.com/vulhunt-re/v...
Documentation: vulhunt.re/docs
Slack: join.slack.com/t/vulhunt/sh...

vulhunt.re

07.03.2026 23:22 👍 11 🔁 6 💬 1 📌 0
Post image

👩‍🦰 Connaissez-vous les femmes de la tech ? À l’occasion de la journée internationale des femmes, nous voulons proposons de regarder les travaux de
👉 Mathilde Saliou
👉 Ophélie Coelho
👉 Timnit Gebru
👉 Abeba Birhane
👉 Astha Kapoor
👉 Amba Kak
👉 Sasha Luccioni
👉 Rumman Chowdhury
👉 Naomi Klein

08.03.2026 07:30 👍 40 🔁 26 💬 1 📌 3
Le journalisme peut-il survivre à YouTube ? Gaspard G & Pierre Haski
Le journalisme peut-il survivre à YouTube ? Gaspard G & Pierre Haski YouTube video by Le Monde de Pierre Haski

Le journalisme peut-il survivre à YouTube, devenu le « premier média de France » avec 43 millions d’utilisateurs ? Récemment arrivé sur @YouTube moi-même, j’en parle avec un vétéran les plus suivis, Gaspard G. Retrouvez notre conversation sur ma chaîne.
youtu.be/N9_-EJleCHM?...

07.03.2026 11:51 👍 31 🔁 8 💬 1 📌 2
OpenSecurityTraining2 - Training RFPs

OST2 is putting out a request for proposals for an opportunity to be funded to create classes on UEFI and/or ACPI. If you are interested, please reach out to teach🌀ost2.fyi with a proposed class syllabus.
ost2.fyi/Training-RFP...

06.03.2026 14:13 👍 3 🔁 4 💬 0 📌 2
Preview
BSidesSF 2026: 📙 Practical (and impractical) git commit... View more about this event at BSidesSF 2026

I will be speaking at BSides SF in a couple of weeks! It will be about git, certificates, SSH, and, obviously, TPMs. bsidessf2026.sched.com/event/2E1g3/...

06.03.2026 07:04 👍 19 🔁 6 💬 0 📌 0
Preview
Qu'est-ce qu'on va faire de toi ? - Regarder le documentaire complet | ARTE Une classe maternelle classée REP offre, entre imaginaire et échos de l’actualité, une version miniature du vivre-ensemble. Une irrésistible immersion qui capte comme rarement le regard d’enfants sur ...

Le vivre-ensemble à hauteur d'enfants ⤵️

05.03.2026 17:05 👍 23 🔁 5 💬 0 📌 1
Post image

Reverse engineers often spend a lot of time deciphering third-party firmware libraries. At RE//verse 2026 (Fri, 5 PM), Benoit & Sami will introduce SightHouse, an open-source tool to automatically identify third-party functions and speed up analysis.
Join us!

05.03.2026 14:37 👍 3 🔁 2 💬 0 📌 0
Preview
« Les Russes n’osent plus parler » : le témoignage d’un journaliste de la Manche dans son nouveau livre Journaliste originaire de Saint-Lô (Manche) et correspondant en Russie, Paul Gogo sort le 11 mars 2026 son nouveau livre « Moscou parano, la Russie de Poutine mise à nu ».

Je suis nul en com' mais ce livre est important pour moi, il s'agit d'un récit de mes derniers mois en Russie. Moscou parano sera disponible mercredi prochain dans toutes les librairies ! actu.fr/societe/les-...

04.03.2026 19:00 👍 275 🔁 119 💬 12 📌 4

Effet Streisand assuré 😂

04.03.2026 13:38 👍 90 🔁 18 💬 4 📌 0

J'abuse encore.... demande urgente en région de Zaporizhia pour un générateur, un ecoflow et à Kharkiv pour des câbles coaxiaux... Un budget d'environ 1700 euros
Merci d'avance pour eux... ❤️❤️❤️

02.03.2026 11:29 👍 32 🔁 36 💬 3 📌 0
closeup of diy open wave receiver with overlay text that says "open source hardware summit 2026 may 23/24 TU Berlin Get your ticket!"

closeup of diy open wave receiver with overlay text that says "open source hardware summit 2026 may 23/24 TU Berlin Get your ticket!"

We are so excited to announce the talks and workshop schedule for #OHS2026! Check out the lineup and see who is joining us from all over the world to talk open source hardware and maybe even register for one of the incredible workshops we'll have running on Day 2: 2026.oshwa.org/schedule/

28.02.2026 14:56 👍 17 🔁 11 💬 0 📌 2
Preview
Motorola News | Motorola's new partnership with GrapheneOS Motorola announces three new B2B solutions at MWC 2026, including GrapheneOS partnership, Moto Analytics and more.

Motorola announces a partnership with GrapheneOS Foundation ; they will work to strengthen Smartphone Security and collaborate on future Devices engineered with #GrapheneOS compatibility motorolanews.com/motorola-thr...

02.03.2026 16:45 👍 3 🔁 2 💬 0 📌 0
Post image

Reverse engineers often spend significant time deciphering third-party libraries within firmware. My talk, scheduled for Friday at 5 PM at Reverse, introduces SightHouse, an open-source initiative aimed at automatically identifying third-party functions to enhance analysis efficiency.

02.03.2026 15:20 👍 4 🔁 4 💬 0 📌 0
Samuel, 10 ans, écrit dans son journal « Là j’ai la sensation du dimanche et c’est une sensation que je veux pas ressentir » et nous non plus.
Une image extraite de la série en animation d’Emilie Tronche « Samuel » sur arte.

Samuel, 10 ans, écrit dans son journal « Là j’ai la sensation du dimanche et c’est une sensation que je veux pas ressentir » et nous non plus. Une image extraite de la série en animation d’Emilie Tronche « Samuel » sur arte.

heureusement, le travail autour de la saison 2 a commencé

01.03.2026 17:45 👍 65 🔁 7 💬 0 📌 0
Post image

Ouvriers sur la tour Eiffel, 1932 📷

01.03.2026 06:47 👍 108 🔁 21 💬 9 📌 2
Post image Post image Post image

HMS Rapp was the patrolboat that jammed the Russian drone, a patrolboat in the Tapper-class (Brave-class).

27.02.2026 19:58 👍 53 🔁 10 💬 2 📌 0
Post image Post image Post image

🆕 #Android Samsung #Knox (Secure Folder) history log artifact in #ALEAPP.
🪵 SQLite database contains a log of items requested be moved in or out of the secure folder in Samsung Android devices.
👏 Thanks to HSI Digital Forensics Examiner Geovanny Perez for the discovery of this artifact.

#DFIR

27.02.2026 23:28 👍 2 🔁 2 💬 0 📌 0
Preview
AirSnitch: Breaking Wi-Fi Client Isolation: Technique Index, Tool Usage & Defenses This morning I came across another interesting paper submitted at the NDSS Symposium 2026 like the BLERP paper already documented in this forum, but this time challenging the Wi-Fi client isolation th...

Think your guest Wi-Fi is isolated from your main network? Think again.
AirSnitch (NDSS'26) breaks client isolation on every router tested: from home APs to enterprise WPA2/3-Enterprise. Full MitM in seconds, sometimes leaking WPA2 traffic in plaintext: 🔗 community.penthertz.com/t/airsnitch-...

28.02.2026 08:11 👍 1 🔁 2 💬 0 📌 0

We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others.

NDSS'26 paper: www.ndss-symposium.org/wp-content/u...
GitHub: github.com/vanhoefm/air...

26.02.2026 18:32 👍 15 🔁 8 💬 4 📌 0
Notre corps n'est pas compatible avec l'apesanteur
Notre corps n'est pas compatible avec l'apesanteur YouTube video by Scilabus

Cela faisait bien longtemps que je n'étais pas passée par ici ! Merci pour tous vos partages (surtout pour la vidéo sur l'impesanteur qui a été un énorme projet)
www.youtube.com/watch?v=iG6B...

25.02.2026 18:32 👍 110 🔁 24 💬 3 📌 0
Video thumbnail

🛰️ We've found our way to BlueSky 📍

Follow us as we navigate the world of satellite navigation: Galileo, EGNOS, Celeste, NAVISP, FutureNAV and so much more!

24.02.2026 08:47 👍 161 🔁 20 💬 13 📌 3

🔱The MARSEC COE has now published the conference proceedings from last year's conference, and on pp. 177-193 you can find my paper, titled "Combatting the Shadow Fleet: Countering Maritime Sabotage, Surveillance and Disruption".

🔐 Lots of good papers, open access:
www.marseccoe.org/wp-content/u...

23.02.2026 15:27 👍 27 🔁 14 💬 2 📌 0
Accueil | JdLL GravCMS

Les JdLL (Journées du Logiciel Libre) auront lieu à l'ENS Lyon les 30 et 31 mai 2026. L'appel à participation est ouvert jusqu'au 15 mars #OpenSource #Lyon www.jdll.org

23.02.2026 15:09 👍 2 🔁 4 💬 0 📌 0
Preview
Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes | Dark Mentor LLC We hold this truth to be self-evident&#58; SUFFERING BUILDS STRENGTH! In this talk I will walk you through the trials, tribulations, and triumph(!) of the worst debugging setup I've ever hacked together, which I used to reverse engineer the Realtek RTL8761B* family of Bluetooth chips.<p>This work was done because Bluetooth security tools are in an abominable state. We use "CSR4" (Cambridge Silicon Radio) dongles that don't support packets newer than Bluetooth 4.0 (released in 2010!), just to be able to spoof the Bluetooth Device Address (BDADDR) for MitM attacks.<p>Veronica Kovah & I have been creating Bluetooth security classes for <a href="https://ost2.fyi/">OpenSecurityTraining2</a>. And we wanted to use better hardware; ideally something that supports BT 5.4 (released in 2023). So I bought a bunch of cheap dongles off Amazon, and found that most of them used the same RTL8761B chip. So the goal was clear&#58; at a minimum, figure out a way to spoof the BDADDR on these dongles. But I also a set out a nice-to-have stretch goal - to figure out how to use these dongles to send custom LMP packets (which are architecturally not meant to be under full user control.) That way, could replace a bulky and expensive $55 dev board (that is only used for BT Classic), with a cheap and small $14 USB dongle (which has a better antenna to boot!) This would make Blue2thprinting (released at Hardwear.io 2023), and thus Bluetooth reconnaissance & vulnerability assessment, cheaper & better.<p>Bloodied (but not broken) by the ordeal, I achieved my goals and stretch goals. And given that there are no public descriptions of how Realtek Bluetooth chips work, I look forward to sharing hitherto-unknown information about how to navigate and understand these mostly-16-bit-MIPS-code systems. And I'll discuss how their ROM-"patch"ing firmware update mechanism works, how you can patch it to change its code too, and the security implications thereof.

Video released for "Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes" (from @hardwear-io.bsky.social). Slides & video link here:
darkmentor.com/publication/...

23.02.2026 12:28 👍 4 🔁 3 💬 0 📌 0

Let's try this again 👋

Hi Bluesky - I'm Massachusetts' Attorney General. You might know me from suing President Trump nearly 50 times, beating Uber and Lyft in court, or being the first woman of color elected to statewide office in MA.

I officially left X today - help me find my MA people?

21.02.2026 16:32 👍 13763 🔁 3498 💬 896 📌 187
Preview
Twin Peaks - Séries et fictions | ARTE Œuvre majeure de David Lynch, rencontre unique du soap avec le septième art, cette plongée dans les méandres d’une petite ville américaine se savoure comme un mauvais rêve dont on ne voudrait jamais s...

L'intégrale de « Twin Peaks », la série culte de David Lynch est disponible sur arte.tv 👉 www.arte.tv/fr/videos/RC...

08.01.2026 09:04 👍 435 🔁 202 💬 11 📌 45
[CVE-2026-0714] TPM-sniffing LUKS Keys on an Embedded Device In October 2025, we performed a security assessment of the ARM-based Moxa UC-1222A Secure Edition industrial computer.

Recovering LUKS decryption key by passively monitoring the SPI bus between the SoC and the discrete TPM 2.0 device (Moxa UC-1222A)

www.cyloq.se/en/research/...

#infosec

21.02.2026 12:48 👍 8 🔁 3 💬 0 📌 0