Trail of Bits’ cover photo
Trail of Bits

Trail of Bits

Computer and Network Security

New York, NY 24,657 followers

Deepening the Science of Security

About us

Since 2012, Trail of Bits has been the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks.

Website
https://www.trailofbits.com
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
New York, NY
Type
Privately Held
Founded
2012
Specialties
software security, reverse engineering, cryptography, blockchain, osquery, machine learning, binary analysis, blockchain, Application Security, and AI/ML

Locations

Employees at Trail of Bits

Updates

  • Trail of Bits reposted this

    Suppose someone records your passport's chip being read at an airport, and a month later gets a copy of your photo page from a hotel that kept a scan. Can they decrypt the recording? If the chip used the older Basic Access Control protocol (BAC), yes. The password that protects the conversation is printed on the page. We modeled this, and twelve other questions about electronic passports, in Verifpal. The models cover BAC and its replacement PACE, the four ways a reader and chip check each other, tracking a passport between two readers, and using a passport to identify yourself to a website. PACE uses the same printed password as BAC, but the session keys also depend on fresh Diffie-Hellman secrets. When we leak the password after the inspection, Verifpal finds no way to decrypt the recording. Passive Authentication shows that the issuing country signed the data. It doesn't show that the data came from the chip in front of the reader. Copy the files and the signature still checks. If a phone asks a passport to sign a challenge from a website, a dishonest site can pass along a challenge it got from your bank. The passport never stays out of your hands, but the chip was never told which service you meant to use. ICAO will require PACE in newly issued passports from 1 January 2027 and exclude BAC from them from 1 January 2028. Passports issued before then will stay in use until they expire. The starting point was Joop van de Pol's article on electronic passports for Trail of Bits. All thirteen models are in the Verifpal repository, with each model's assumptions written at the top. These are bounded searches. https://lnkd.in/ekRTKGvc

  • Our clients get a report at the end of every engagement. We're hiring a Solutions Architect who stays with our key accounts afterward and designs the security program that should follow, from multi-year roadmaps to the next scoped engagement. The right fit has deep security consulting or engineering experience and has worked directly with clients. That could be a former engineer, a security consultant, or a Sales Engineer who moved toward the commercial side but stayed technical. Pre-sales experience is welcome, but it needs to come with security delivery experience. Remote in the US or Canada, with up to 20% travel. If that's you, or someone you'd vouch for, apply here: https://lnkd.in/e9VMAuZH

  • Trail of Bits reposted this

    Thank you to Trail of Bits for sponsoring OAIC 2026! They recently published research where they gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents. It escaped three times. In its final escape, the agent chained three 0-days into a working exploit. See a screenshot of that research below, and the full write-up here: https://lnkd.in/e24EnMSe #OAIC #OffensiveAICon #TrailOfBits

    • No alternative text description for this image
  • Trail of Bits reposted this

    Thank you to Trail of Bits for sponsoring OAIC 2026! They recently published research where they gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents. It escaped three times. In its final escape, the agent chained three 0-days into a working exploit. See a screenshot of that research below, and the full write-up here: https://lnkd.in/e24EnMSe #OAIC #OffensiveAICon #TrailOfBits

    • No alternative text description for this image
  • We're sponsoring Arbitrum's Open House Singapore, hosted in collaboration with Robinhood Chain, to support founders across both the online Buildathon and Founder House. From October 23-25, Founder House Singapore brings selected teams together for 3 days of product, technical, and go-to-market support to help turn early ideas into launch-ready onchain products, while competing for a share of $300K in prizes and grants. Founder House teams will get a remote mentoring session with Gin Zite from our team. Apply here: https://lnkd.in/eea-UPCV

  • Hashing several values together is easy to get wrong, and the mistakes can lead to forgeries. TupleHash only works with Keccak. Outside SHA-3, people roll their own multihashing, often insecurely. We built SequenceHash to fix that for any hash function, with length-suffix encoding and protection against length-extension attack. The spec is now part of the Community Cryptography Specification Project (C2SP), with ready-to-use implementations in Rust, Go, and Python. https://lnkd.in/gpCCQXHq

  • Trail of Bits reposted this

    Critical RCE chain across Vault and OpenBao patched for the latter, great work from the team operationalizing and remediating. Thanks to Trail of Bits for the collaboration and Alexander Scheel for PoC, coordinating and delivering fixes, and detail of IBM's response to our efforts to disclose Vault vulns in the post.

    View organization page for ControlPlane

    4,765 followers

    In collaboration with the OpenBao community, ControlPlane has recently helped remediate a full exploit chain that allowed unauthenticated access and escalation to full Remote Code Execution (RCE). This marks only the second-ever RCE vulnerability discovered in Vault and OpenBao, combining disclosures from three independent reporters into a single, devastating exploit chain. How the chain works: By abusing a PKI ACME validation bypass, an unauthenticated attacker can spoof a service provisioner's identity. Then, they can modify an admin account, escalate privileges across namespaces, and ultimately achieve full RCE by restoring a malicious Raft storage snapshot. We've published a full technical breakdown. Link to the blog is in the comments, or get involved in the conversation on Hacker News #CyberSecurity #OpenBao #VulnerabilityManagement #InfoSec #CloudNativeSecurity

    • No alternative text description for this image
  • Our Avalanche experience includes security reviews of AvalancheGo, libevm, and Subnet EVM for Ava Labs. We're bringing that work to builders through the new Avalanche Audit Marketplace, where we're one of the vetted firms. We're also the team behind Slither, Echidna, and Medusa, and we've published 391 blockchain security reviews that anyone can read. Request a quote: https://lnkd.in/djwVUXZd

    The Avalanche Audit Marketplace is now live on the Builder Hub 🔺 Security audits are one of the biggest bottlenecks between a finished protocol and a mainnet launch. Finding the right firm means cold outreach, one conversation at a time, with no easy way to compare scope or pricing. Then you have the cost itself stopping plenty of good teams from auditing at all. We built the Audit Marketplace to remove both problems. Submit once. Complete your audit request in four short steps and it reaches every security firm on the Ava Labs whitelist or only the ones you select, if you already have firms in mind. Quotes come to you. Firms have 10 days to respond, and every quote stays private to you. No sales calls, no inbox full of outreach. Contact information is only exchanged once you accept a quote, so you're in control of the process until you've made a decision. Pick one, get subsidized. Select the quote that works best for you. The program can cover up to 75% of the audit cost, and there are $0 platform fees for builders and auditors alike. Every firm on the whitelist has passed Ava Labs' security review. Services range from smart contract audits to formal verification to AI security scans. All of your security needs covered in one place. Get started here 👇 https://lnkd.in/eVDrw26y

  • Trail of Bits reposted this

    OpenBao v2.6.3 is out! 🔐 Our latest 2.6 patch release is focused on security and bug fixes. Make sure to patch your instances accordingly! This update also includes fixes identified through the Patch the Planet initiative in partnership with Trail of Bits and OpenAI. Big thanks to all reporters, contributors, and the entire community! 🔗 Read the full changelog here: https://lnkd.in/e_CZjAUQ #OpenBao #SecretsManagement #OpenSSF #OpenSource #Security

  • View organization page for Trail of Bits

    24,657 followers

    Threshold signatures secure billions of dollars in crypto, and teams increasingly run them inside Trusted Execution Environments (TEEs) for extra protection. But MPC and TEEs make different bets on trust: MPC spreads trust across independent parties, while TEEs concentrate it in the hardware manufacturer and its attestation infrastructure. In one pattern from our audits, a malicious host rolls back the filesystem after a signer deletes a used pre-signature. The signer reuses that value and leaks their private key share. We wrote up what TEE attestation can and can't fix in MPC deployments, the pitfalls we see most often in audits, and how to combine the two correctly. https://lnkd.in/eipeC8C9

Similar pages

Browse jobs