Eric Chiang's Avatar

Eric Chiang

@ericchiang.bsky.social

@oblique.security. Ex Google Security, CoreOS. ericchiang.github.io

103 Followers  |  117 Following  |  33 Posts  |  Joined: 07.03.2024  |  2.0973

Latest posts by ericchiang.bsky.social on Bluesky

It turns out workload identity isn't a complete mess in 2025 (only a little one)? Wrote a bit about authenticating GitHub Actions identity directly using OpenID Connect.

31.07.2025 23:22 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Oh hey, what's this fancy new IAM company?

23.06.2025 20:27 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A friend needs a Workday test instance to build something interesting. Anyone know how to get one?

(A Workday instance; I kinda already know how to get a friend.)

09.06.2025 23:30 β€” πŸ‘ 50    πŸ” 4    πŸ’¬ 8    πŸ“Œ 0

We're doing new container runtimes in 2025? Hell yeah

09.06.2025 21:02 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

So if I'm reading this right

Step 1 - generate a private key with no forward secrecy

Step 2 - upload private key to twitter (but don't worry it's protected by a low entropy PIN)

Ummmmmmmmm

05.06.2025 15:51 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
So that's effectively the AWS story, which is terrible but at least it's possible to cobble together something that works and you can audit. Google looked at this and said "what if we could express how much we hate Infrastructure teams as a service?" Expensive coffee robots were engaged, colorful furniture was sat on and the brightest minds of our generation came up with a system so punishing you'd think you did something to offend them personally.

So that's effectively the AWS story, which is terrible but at least it's possible to cobble together something that works and you can audit. Google looked at this and said "what if we could express how much we hate Infrastructure teams as a service?" Expensive coffee robots were engaged, colorful furniture was sat on and the brightest minds of our generation came up with a system so punishing you'd think you did something to offend them personally.

Every day I'm glad my job isn't staring into the IAM abyss of a large Cloud org.

matduggan.com/iam-is-the-w...

16.05.2025 21:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

What a sicko

07.05.2025 20:34 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Every time you feel useless, remember that GitHub as a notifications tab

07.05.2025 20:02 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Meta Awarded $167 Million in Damages From Israeli Cybersecurity Firm

who needs coherent cyber policy when we excel so much at corporate ligation?

www.nytimes.com/2025/05/06/t...

07.05.2025 02:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
runtime: green tea garbage collector · Issue #73581 · golang/go Green Tea 🍡 Garbage Collector Authors: Michael Knyszek, Austin Clements Updated: 2 May 2025 This issue tracks the design and implementation of the Green Tea garbage collector. As of the last update...

New experimental garbage collector for Go programs! github.com/golang/go/is...

02.05.2025 18:54 β€” πŸ‘ 123    πŸ” 41    πŸ’¬ 2    πŸ“Œ 2

@mayakaczorowski.com's been using it a ton and had great things to say.

05.04.2025 18:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

πŸ“£Today, we’re super excited to announce our latest product addition: Continuous Profiling for GPUs! Check out the use cases and sign up for early access on the announcement post! πŸ”₯πŸ“ˆ

www.polarsignals.com/blog/posts/2...

01.04.2025 15:49 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 5

You're not even using nix packages? What kind of tech hipster are you?

27.03.2025 16:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.

Scraping Kubernetes codebases for os/exec continues to pay dividends

www.wiz.io/blog/ingress...

26.03.2025 18:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Next.js and the corrupt middleware: the authorizing artifact CVE-2025-29927

"middleware:middleware:middleware:middleware:middleware" is the new bloody mary

zhero-web-sec.github.io/research-and...

24.03.2025 14:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I really wish progressive web apps took off so every app didn't come with a chrome fork

24.03.2025 01:25 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - Zouuup/landrun: Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel. Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel. - Zouuup/landrun

Awesome to see Landlock making unprivileged isolation so easy. As someone who maintained bubblewrap jails, I'm hoping that this takes over user namespaces. Things like network controls are always mess there.

github.com/Zouuup/landrun

23.03.2025 17:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Quick reminder:

14.03.2025 21:48 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Was it petty? Yes. Was it necessary? Also yes.

14.03.2025 22:45 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Quick reminder:

14.03.2025 21:48 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

"No way to see this coming" says only auth protocol with regular auth bypasses

github.blog/security/sig...

14.03.2025 21:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
A Python code comment that says "Welcome to the spaghetti factory"

A Python code comment that says "Welcome to the spaghetti factory"

"Vibe coding will ruin the quality of our codebase!"

The codebase:

github.com/pandas-dev/p...

12.03.2025 22:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

On my way to New York! I’ll be in there from Monday until Thursday evening, and still have some room to meet on Wednesday afternoon, anyone want to chat databases/observability/performance? Feel free to DM me!

02.03.2025 17:08 β€” πŸ‘ 11    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Eric Chiang | Confidential Compute and GPUs

I finally read up NVIDIA Confidential Compute, so you don't have to! Surely this will make all of our AI secure

ericchiang.github.io/post/confide...

28.01.2025 16:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Do OSS, it'll be fun!

*Ten years later and still getting reports on my day off about other people's buggy implementations*

20.01.2025 18:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

According to Giraffe Security, AWS staff have somehow managed to re-introduce the same RCE vulnerability into its platform three times over the past four years

giraffesecurity.dev/posts/amazon...

08.01.2025 22:47 β€” πŸ‘ 40    πŸ” 10    πŸ’¬ 2    πŸ“Œ 1
Preview
Attestations: A new generation of signatures on PyPI For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestatio…

One of the coolest pieces of security tech I read about in 2024 was PyPI's builder identity verification done by Trail Of Bits. Didn't see much fanfare in my feeds when it was published, but defiantly worth the read.

blog.trailofbits.com/2024/11/14/a...

05.01.2025 18:32 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Streaming media DRM has nothing to do with TPMs and the FSF is just plain wrong: mjg59.dreamwidth.org/70954.html

02.01.2025 01:16 β€” πŸ‘ 49    πŸ” 12    πŸ’¬ 3    πŸ“Œ 0
git-codereview command - golang.org/x/review/git-codereview - Go Packages

Reminds me of Go's codereview plugin, which presents a higher level "change" abstraction on top of git. Figure if you're running a large project, you've already got a PR style guide. Much easier if you can just say "use this tool to contribute"

pkg.go.dev/golang.org/x...

29.12.2024 02:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If the rust compiler is slow, why don't rustaceans simply rewrite it in rust?

25.12.2024 20:18 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@ericchiang is following 19 prominent accounts