Skip to content
← all posts
Hot Takes

Systems, not bugs

The folk doing really cutting-edge vulnerability research right now: if you peel the paint off how they're doing it, it's because they think about security at a system level, and not necessarily at an individual bug level. Take someone who thinks like that, give them crazy tools to think like that in a million directions, more quickly, without needing to sleep, and cool stuff happens.

It's been really interesting watching the '90s vulnerability research crew shift from "this is all hype, it's fancy autocomplete" to "oh, okay, no, this is a big part of how things work in the future." That lag was interesting. They're all pretty much across the line at this point.

From my conversation with Fede Kirschbaum on XBOW's Offense Taken.

Casey Ellis
Casey Ellis
Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.
bio →

Comments ·

members only