{"articles":[{"author":"Mark Esler","date":"2026-06-06","description":"A runtime-verified survey of 27 RSA implementations for the behavioral (ROBOT / Ok-Err) PKCS#1 v1.5 decryption oracle. The oracle is open by default in self-contained implementations; it is closed only where the backend (OpenSSL ≥3.2, NSS) or a TLS-only design supplies implicit rejection. No timing claims.","readingTime":9,"title":"Many RSA Libraries Leave the Bleichenbacher Oracle Open","url":"https://hexproof.dev/datagrams/bleichenbacher-oracle-survey/","wordCount":1717},{"author":"Mark Esler","date":"2026-06-06","description":"RSA PKCS#1 v1.5 decryption that returns Ok on valid padding and Err on invalid is a Bleichenbacher padding oracle. A ~300-line proof of concept recovers a full plaintext and forges a signature against a current implementation using only that one bit per query, no timing, no key. The fix is to stop using RSA PKCS#1 v1.5 encryption.","readingTime":5,"title":"An Ok/Err Result Is a Bleichenbacher Oracle","url":"https://hexproof.dev/datagrams/ok-err-is-a-padding-oracle/","wordCount":873},{"author":"Mark Esler","date":"2026-05-16","description":"MetaMask Android v7.76.0 does not zero the seed phrase or vault password after autolock. Same class as Demonic (CVE-2022-32969). Fix named in source since 2023.","readingTime":10,"title":"MetaMask Demonic Mobile: seed phrase survives autolock on Android","url":"https://hexproof.dev/datagrams/metamask-demonic-mobile-android/","wordCount":2058},{"author":"Mark Esler","date":"2026-04-30","description":"Cerberus on Google Play: €5/month buys silent camera, microphone, GPS, and SMS access on a victim's phone. Researchers reported it to Google as intimate-partner-violence spyware in 2018; Google removed it later that year on an unrelated policy and relisted it in 2023. Google AdMob pays the developer; Google Firebase hosts the command-and-control backend.","readingTime":11,"title":"Cerberus is stalkerware. Google Play hosts it.","url":"https://hexproof.dev/datagrams/cerberus-on-play/","wordCount":2274},{"author":"Mark Esler","date":"2026-04-30","description":"Decompiling Cerberus Stalkerware (LSDroid SRL): a static reverse engineering of 9 APKs across 8 packages, two distribution channels, three companion apps on Google Play. Documents the 44 FCM commands, the operator-state Realtime Database, the HiddenApiBypass dependency that gated the 2023 Play return, and the v3.8.0 reflected-binder-stub root toolkit. Includes attribution data, a chronology, and per-class indicators of compromise.","readingTime":84,"title":"Cerberus Anti-theft is stalkerware: a reverse engineering","url":"https://hexproof.dev/datagrams/cerberus-stalkerware-re/","wordCount":17769},{"author":"Mark Esler","date":"2026-04-08","description":"How Claude Code, Aider, Cursor, Windsurf, and Copilot engineer the systems around their models — and what the architecture reveals about each team's priorities. From source code and leaked prompts.","readingTime":15,"title":"The Fossil Record of Harness Engineering","url":"https://hexproof.dev/datagrams/fossil-record-harness-engineering/","wordCount":3129}],"description":"Security and systems performance research","feeds":{"json":"/index.json","rss":"/datagrams/index.xml"},"llms":"/llms.txt","site":"hexproof"}