I'm an information security professional working in the field for about 17 years, mostly doing security audits and pen-tests.
I've done information security auditing and testing to major portuguese and european companies (retail, banking, insurance, telcos).
I'm currently working as a security researcher at BitSight, a cybersecurity ratings company.
I sometimes speak about information security at conferences and meetings.
Some stuff I did of interest:
- In 2015 I found and exploited a memory corruption vulnerability on a TomTom GPS sportswatch, bypassing several security measures, including encrypted firmware updates. All without touching a screwdriver.
- I wrote Cupid, an implementation of the heartbleed attack for wireless networks, implemented as patches for hostapd and wpa_supplicant.
- I authored a Burp Suite extension to handle and inject inside AES encrypted payloads.
- I wrote the original paper for DNS Cache Snooping.
- In another millenium I’ve co-authored a phrack article that, among other things, implemented a covert TCP sniffer inside the Linux kernel.
All my recent slide decks are available on slideshare.net.
I’m mostly interested in security research, covering the usual topics:
- Operation System design models (trusted path computing, security models, etc.);
- Web Application security (lots of experience here…);
- Low level protocols design and implementation;
- Debugging & disassembling software & hardware;
- Mobility and embedded systems, Android/IOS, wearables, IoT;
- Futurology, new uses for technology, new forms of interaction.