Head of Security Engineering+Architecture (SEAR) at Apple. I don’t speak for my employer.

San Francisco, CA
🔺NEW: Apple is expanding Private Cloud Compute (PCC) beyond our data centers. PCC on Google Cloud: NVIDIA Confidential Computing, Intel TDX, and Google's Titan chip, with capabilities that go far beyond a traditional confidential computing deployment. security.apple.com/blog/expa…
12
95
509
55,410
🔺NEW: Formally verified post-quantum ML-KEM and ML-DSA in corecrypto, with correctness proven from the FIPS spec down to hand-optimized ARM64 assembly — a world first at multi-billion device scale. And we're releasing our Isabelle libraries, ARM64 model, and Cryptol-to-Isabelle translator to advance the state of the art in verified cryptography! security.apple.com/blog/form…
10
102
432
48,948
🔺New security-focused developer event on March 5 at Apple Park: featuring sessions on Memory Integrity Enforcement, new tools in Enhanced Security in Xcode, Apple’s defensive security engineering approach, Swift adoption in security-sensitive code, and how to apply all these techniques to protect apps. Sign up: developer.apple.com/events/v…
3
44
140
16,280
🔺This is the first talk I've given in 6 years – featuring formal verification of post-quantum cryptography, the evolution of the Secure Page Table Monitor, a view into Memory Integrity Enforcement, updates to Apple Security Bounty… and a personal note.
The collection is complete! 🎬 We just uploaded @radian's keynote to our YouTube channel piped.video/watch?v=Du8BbJg2…
4
49
207
61,268
Great News! 👏 @Apple announced they will be donating 1000 iPhone 17s with the much more secure Memory Integrity Enforcement to high-risk users! Another meaningful step that Apple is taking to protect journalists, activists & dissidents from commercial spyware! 1/
4
9
50
13,096
🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memo…
54
484
2,658
380,909
🔺New on Apple Security Research blog: a deeply comprehensive Private Cloud Compute security guide, and an unprecedented Virtual Research Environment allowing you to run production PCC software right on your Mac with Apple silicon. And up to a $1M bounty! security.apple.com/blog/pcc-…
12
164
576
100,958
Ivan Krstić retweeted
Are you excited to use the power of safe modern programming languages like Swift to make software more secure? My SPEAR team at Apple is hiring a Swift Software Engineer to do exactly that! jobs.apple.com/en-us/details…
3
24
48
16,739
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world. security.apple.com/blog/imes…
6
120
356
62,060
Ivan Krstić retweeted
With iOS 17.2 and macOS 14.2 now released, Contact Key Verification 🔐 is available for everybody to enable. Very proud of the work the team has done to ship this groundbreaking feature and advance the state of iMessage security! security.apple.com/blog/imes…
2
33
92
13,736
If you are interested in uArch Security, we just opened an internship position at @Apple! The position is focused on offensive research, and you will be contributing to the security of some of our most advanced CPUs in one of the coolest teams. Apply at: jobs.apple.com/en-us/details…
4
26
104
20,308
Ivan Krstić retweeted
I have been beta testing the new ASB submission portal for over a year. Apple did an awesome job with this! You can: ✅see the status of your report ✅typically get more frequent updates ✅see the CVE, bounty, advisory for each case ✅export all to CSV security.apple.com/bounty/
3
13
48