Skip to content

More posts

All →
Personal

Little update: “Rumors of my death have been greatly exaggerated”

It’s been just over three weeks since I randomly “let the Internet know” that I was heading in for unexpected heart surgery...

21 Jul 2024 · 5 min read
Policy

Builders and Breakers: Partnering for Secure Elections

In September 2023, the IT-ISAC Elections Industry SIG launched a first-of-its kind pilot program in which election technology providers gave security researchers access to modern voting technology under the principles of Coordinated Vulnerability Disclosure.

13 Jun 2024 · 6 min read
Security

Bugs on a Plane: Implementing a Bug Bounty in an Airline IT/OT Environment

Bug bounty programs are a valuable tool for security efforts but only if they are correctly applied. This is particularly true for airlines who have to secure both the IT business systems and OT aircraft systems that enable the business to operate safely.

13 Jun 2024 · 6 min read
Teach

AI security: Tool, Target, Threat

The Tool/Target/Threat taxonomy for AI security — a shared vocabulary for the three orientations every conversation collapses without, built during EO 14110.

04 Apr 2024 · 4 min read
Personal

My office setup — Part 3 (US edition)

Optimizing my home office space for a work-from-home/hybrid setup became a bit of a hobby during the pandemic, and since returning to the USA from Australia in 2021 I've essentially replicated the successful aspects of the Sydney setup, with a few modifications.

18 Sep 2023 · 3 min read
Policy

DEF CON 31 Policy — All Your Vulns Are Belong to Terms and Conditions

DEF CON 31 Policy - All Your Vulns Are Belong to Terms and Conditions - DEF CON panel featuring David Rogers, Katie Trimble-Noble, Harley Geiger, and myself. Recorded on September 15, 2023 at DEF CON 31 in Las Vegas, Nevada.

17 Sep 2023 · 34 min read
Security

The RSnake Show!

Recording this was a tonne of fun and we cover a LOT of ground - There's a general theme of system-level thinking, vulnerability and transparency, and the personal pursuit of potential through things like entrepreneurship. It's very much a backstory and #thoughtops conversation.

24 Aug 2023 · 2 min read
Building

My #hackersummercamp 2023 moves

Here are my moves for #hackersummercamp 2023...

08 Aug 2023 · 1 min read
Thinking

KEYNOTE: Release the Hounds, Part 2

Casey delivers "Release the Hounds, Part 2 - 11 Years Is A Long-Ass Time" as the keynote for BSides Knoxville on May 12th, 2023. This talk covers the history of vulnerability disclosure and crowdsourced security testing platforms, and dives into cybersecurity entrepreneurship.

22 Jun 2023 · 1 min read
Building

Bugcrowd: 10 Years On, and Still Just Getting Started

On the 1st of September 2012 during a flight from Melbourne to Sydney, a series of ideas I’d been working on for a year or more coalesced with a bunch of conversations I’d just had, the lightbulb went off, and Bugcrowd was born.

01 Sep 2022 · 4 min read
Building

#HSC2022 in Pics

A small selection of selfies and pics from #HSC2022. It was a good homecoming.

21 Aug 2022 · 5 min read
Security

Where the bloody hell were you — The Great 2020 COVID Bug-In

During Hacker Summer Camp, I was asked "where do you, uh, live now and stuff" a lot. Forgive this slightly indulgent post, but I wanted to blog a little bit of our story, and some of the thinking that went into executing our trans-pacific COVID bug-in back in 2020.

20 Aug 2022 · 9 min read