analysis

07
Mar
The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851

The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851

Alfred Hobbs: The OG bug bounty hunter who cracked England’s ‘unpick-able’ locks. His breaker mindset exposed flaws, sparked innovation, and proved no system is perfect.
5 min read
20
Aug
Where the bloody hell were you - The Great 2020 COVID Bug-In

Where the bloody hell were you - The Great 2020 COVID Bug-In

During Hacker Summer Camp, I was asked "where do you, uh, live now and stuff" a lot. Forgive this slightly indulgent post, but I wanted to blog a little bit of our story, and some of the thinking that went into executing our trans-pacific COVID bug-in back in 2020.
9 min read
04
Aug
9 Must-See Talks at #hackersummercamp 2022

9 Must-See Talks at #hackersummercamp 2022

Here's a list of the talks that I'm going to get myself along to at Blackhat and DEF CON this year, and why...
3 min read
28
Jul
Digital and Personal Self-Care at #hackersummersamp - "New Normalish" Edition

Digital and Personal Self-Care at #hackersummersamp - "New Normalish" Edition

I usually write a piece for first-timers and newbies on how to get the most out of Hacker Summer Camp and how to stay safe digitally and physically. This tradition began in the early days of Bugcrowd, when DEF CON was part of new-hire induction.
6 min read
26
May

What are the security risks of open sourcing the Twitter algorithm?

What are the security risks of open sourcing the Twitter algorithm?Experts debate whether open source Twitter is a net
1 min read
26
Jun
The Bar Fight Risk Taxonomy

The Bar Fight Risk Taxonomy

After hearing "vulnerability" and "threat" used interchangeably for a >9,000th time I decided to do something about it, and the Bar Fight Risk Taxonomy was born.
4 min read
08
May
On Project Zero's 90+30 vulnerability disclosure policy changes

On Project Zero's 90+30 vulnerability disclosure policy changes

Google is acknowledging the increasing prevalence of n-day exploitation in the wild, particularly over the past 18 months (e.g. the CISA/NSA memo) have taken their next step in refining how they strike balance between these forces.
4 min read
09
Jan
Outrage is cheap

Outrage is cheap

Outrage is cheap and of fleeting value. Introspection and change are expensive, precious, and resilient... and very easy to miss if everything is the other guy’s fault.
2 min read
01
Dec
Van Buren v. United States - Oral Argument

Van Buren v. United States - Oral Argument

The Supreme Court heard oral argument in Van Buren v. United States, a case concerning a statute of the Computer Fraud and Abuse Act (CFAA) and violations of terms of service agreements.
41 min read
25
Oct
The Third-Quarter

The Third-Quarter

"I'm exactly the same as I was nine months ago, but I'm also completely different."