erbbysam

erbbysam

@erbbysam.bsky.social

Software security, cryptography etc

1,032 Followers 159 Following 14 Posts Joined Nov 2024
7 months ago
VRP @ Google -- a look inside a large self-hosted VRP

What's strange about go.dev/play/p/4fc3Y... πŸ‘€

Attend my presentation in the Bug Bounty Village @ DEFCON today at 5pm to learn more!

2 0 0 0
10 months ago
Post image

PhD Timeline xkcd.com/3081

60,137 20,579 591 831
11 months ago

I missed the "Top Secret//ORCON//Signal" banner, my bad

1 0 0 0
11 months ago

Quick question -- in Signal, how do I differentiate my EZpass scam messages from those sent by the Pentagon?

1 0 0 1
1 year ago
Call for Proposals 2025 – BSides CambridgeMA

BSides CambridgeMA CFP is open!!! bsidescambridgema.org/call-for-pro... πŸ‘€πŸŽ‰

0 0 0 0
1 year ago

To answer your first question -- yes, we would accept submissions for golang.org/x repos

1 0 1 0
1 year ago

πŸ€¦β€β™‚οΈ amazing spot. Our intention was to only remove it for one-liner changes as reflected on the rules page. We updated the blog post to match!

1 0 1 0
1 year ago

Good question, let me check with our team and I'll get back to you

1 0 1 0
1 year ago
Preview
Blog: Level Up Your Open Source Karma (And Your Wallet) by Improving Security This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased ...

πŸ›‘οΈπŸ’Έ We've revamped our Patch Rewards Program, extending its scope and increasing rewards for security patches – with a particular focus on memory safety, including bonus multipliers!

bughunters.google.com/blog/5273064...

5 2 1 0
1 year ago
My Bitcoin wallets on Google Drive from ~2013

🎡Should I open it? Or should I keep it sealed?

6 0 2 0
1 year ago
Preview
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!) The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...

I don't often post about my work but bughunters.google.com/blog/6355265... is actually super cool thing my team is doing. These short term redteams focused on just stealing our passwords were always amazing to highlight how severely broken complex systems are. The internal writeups are so, so fun!

18 9 0 1
1 year ago

Reported, thanks for the headsup

1 0 0 0
1 year ago

Check out the OSS Fuzz projects scope line :) github.com/google/oss-f...

1 0 1 0
1 year ago
Preview
Open Source Security Patch Rewards The Patch Rewards program rewards proactive improvements to security in open source projects.

bughunters.google.com/open-source-... for fixing?

2 0 1 0
1 year ago
Digital equipment corporation inter-departmental correspondence envelope

Going to start posting here more often. If this doesn't work out, I found a good fallback.

4 0 0 0
1 year ago

Hello wΜΆoΜΆrΜΆlΜΆdΜΆ blue sky!

7 0 0 0