Ivan Krstić Profile
Ivan Krstić

@radian

Followers
11,038
Following
900
Media
5
Statuses
72

Head of Security Engineering+Architecture (SEAR) at Apple. I don’t speak for my employer.

San Francisco, CA
Joined March 2011
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@radian
Ivan Krstić
5 years
My Cryptographic Engineering team did fantastic work on the rigorous privacy properties of the new Find My system. Wired takes a look:
15
301
771
@radian
Ivan Krstić
5 years
Now live! 🔺The new Apple Security Bounty! 🔺The new Apple Platform Security guide, featuring Mac for the first time! (PDF version: ) 🔺My Black Hat 2019 talk: Happy holidays! 🎄
8
300
745
@radian
Ivan Krstić
2 years
While the vast majority of users will never be the victims of highly targeted cyberattacks, Apple will work tirelessly to protect the small number of users who are. I’m deeply proud of our next steps, including a groundbreaking feature: Lockdown Mode.
40
188
688
@radian
Ivan Krstić
2 years
LIVE: Apple Security Research, our new blog and website at ! We launch with an update on Apple Security Bounty (), and a deep dive into some fundamental XNU memory safety improvements with kalloc_type (). Enjoy!
30
243
638
@radian
Ivan Krstić
5 years
Mac secure boot (with two world firsts: DMA defense from PCIe Bus 0, and the Option ROM sandbox), iOS kernel integrity, Pointer Auth Codes (PAC), APRR register, Page Protection Layer (PPL), and novel Find My crypto — all in my slides from Black Hat 2019!
6
178
562
@radian
Ivan Krstić
3 years
The steps Apple is taking today will send a clear message: in a free society, it is unacceptable to weaponize powerful state-sponsored spyware against innocent users and those who seek to make the world a better place.
26
151
519
@radian
Ivan Krstić
6 years
Happy iOS 12 day! Our updated iOS Security Guide is hot off the presses:
7
213
376
@radian
Ivan Krstić
7 months
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world.
9
133
377
@radian
Ivan Krstić
5 years
Very excited to return to the Black Hat stage this year to talk about some world-class Apple security features! iOS code integrity and Pointer Authentication Codes, Mac secure boot with the T2 Security Chip, the crypto behind the Find My feature, and more:
@BlackHatEvents
Black Hat
5 years
New #BHUSA Briefing “Behind the scenes of iOS and Mac Security” by Ivan Krstić ( @radian ), Head of Apple Security Engineering and Architecture provides technical details of several key technologies new to iOS 13 and the Mac
0
31
120
7
95
335
@radian
Ivan Krstić
7 years
Terrific writeup in the Financial Times. Incredibly proud of my team – astounding talent and clarity of purpose in protecting users on a billion devices, from silicon to software. And we’re hiring. Want to work with the finest security group in the world? My DMs are open!
@FinancialTimes
Financial Times
7 years
How the iPhone earned its security record
1
41
78
7
119
331
@radian
Ivan Krstić
7 years
Regarding Spectre and Meltdown impact on iOS, macOS and Safari/WebKit:
6
232
301
@radian
Ivan Krstić
6 years
We’ve released the first Security Overview for the Apple T2 Security Chip! Mac secure boot, storage encryption, and more, e.g.: “Mac portables with the T2 chip have a hardware disconnect that ensures the microphone is disabled when the lid is closed.”
5
153
298
@radian
Ivan Krstić
8 years
Slides are up for my Black Hat talk, Behind the Scenes with iOS Security:
2
198
275
@radian
Ivan Krstić
7 years
The updated iOS Security Guide now covers iOS 10:
3
123
213
@radian
Ivan Krstić
7 years
Security Update 2017-001 is now available for High Sierra, addressing the root login problem.
9
288
177
@radian
Ivan Krstić
7 years
The updated iOS Security Guide now covers iOS 11.2, including Face ID and Apple Pay Cash:
2
98
164
@radian
Ivan Krstić
4 months
🔺Now live: the May 2024 update to the Apple Platform Security Guide!
5
44
140
@radian
Ivan Krstić
7 years
It’s my privilege to work with the best team in the world. Want to shape the next 10 years of cutting-edge security with us? DMs are open.
@mikko
@mikko
7 years
iPhone is 10 years old today. After 10 years, not a single serious malware case. It's not just luck; we need to congratulate Apple on this.
159
9K
13K
0
42
95
@radian
Ivan Krstić
7 years
New on Face ID: . Incl: “TrueDepth camera randomizes …depth map captures, projects a device-specific random pattern”
1
52
91
@radian
Ivan Krstić
5 years
Plus the new Apple Security Bounty, featuring all Apple platforms and open to everyone, million dollar max payout, live later this year — and iOS Security Research Device program, an unprecedented, Apple-supported research platform for talented researchers, coming next year!
4
26
71
@radian
Ivan Krstić
3 years
@TimoHirvonen @axi0mX My 2016 Black Hat talk goes into detail on Data Protection, and covers master key derivation in the process. Relevant part of the talk is here:
1
0
9
@radian
Ivan Krstić
4 years
@winocm It’s my pleasure and privilege!
0
0
9
@radian
Ivan Krstić
4 years
@ohunt @realmrpippy @gte This is called Fast Permission Restrictions (APRR). A CPU register is used to avoid the overhead of a syscall and walking PTEs. See 22:11 into this talk:
1
1
9
@radian
Ivan Krstić
5 years
@alexstamos Find My crypto is one of the topics we’ll cover at Black Hat!
@radian
Ivan Krstić
5 years
Very excited to return to the Black Hat stage this year to talk about some world-class Apple security features! iOS code integrity and Pointer Authentication Codes, Mac secure boot with the T2 Security Chip, the crypto behind the Find My feature, and more:
7
95
335
0
4
6
@radian
Ivan Krstić
4 years
@laparisa @arrkay And now, for your small-world moment: @arrkay and I took abstract algebra together in college! 🧮
1
0
7
@radian
Ivan Krstić
4 months
@Goran_Majic Hi Goran – see the section titled "Enable DIT for constant-time cryptographic operations" in , and especially: "Apple cryptographic routines ... in the operating system enable DIT internally."
1
0
5
@radian
Ivan Krstić
5 years
@wbm312 @nxthompson @CryptoVillage Find My crypto is one of the topics we’ll cover at Black Hat!
@radian
Ivan Krstić
5 years
Very excited to return to the Black Hat stage this year to talk about some world-class Apple security features! iOS code integrity and Pointer Authentication Codes, Mac secure boot with the T2 Security Chip, the crypto behind the Find My feature, and more:
7
95
335
1
0
5
@radian
Ivan Krstić
5 years
@secparam Find My crypto is one of the topics we’ll cover at Black Hat!
@radian
Ivan Krstić
5 years
Very excited to return to the Black Hat stage this year to talk about some world-class Apple security features! iOS code integrity and Pointer Authentication Codes, Mac secure boot with the T2 Security Chip, the crypto behind the Find My feature, and more:
7
95
335
0
0
4
@radian
Ivan Krstić
7 years
@cory_scott Thank you, Cory!
0
0
3
@radian
Ivan Krstić
11 months
@aaronp613 Good catch, thanks!
0
0
3
@radian
Ivan Krstić
7 years
@axi0mX good suggestion, thanks! I’ll take a look at what we can do about adding it to the guide.
0
0
2
@radian
Ivan Krstić
7 years
@BrianTRice will take a look for the next version, it’s a good suggestion. Thanks!
0
0
2
@radian
Ivan Krstić
6 years
@tapbot_paul Hey Paul! Take a look at under “Verify that your app is Developer ID-signed and notarized” and let me know if that answers your question.
0
0
2
@radian
Ivan Krstić
4 years
@patrickc Thanks, Patrick – hope you’re well!
0
0
2
@radian
Ivan Krstić
5 years
@RajNR Thanks for the kind words, Raj! Yes, both slides and video will be available.
0
0
2
@radian
Ivan Krstić
7 years
@veorq let me know if you have any feedback!
3
0
2
@radian
Ivan Krstić
7 years
@BRIAN_____ @veorq good catch, thank you – will fix in next version
0
0
2