thoughtops

16
Dec
2025 security predictions retrospective

2025 security predictions retrospective

This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.
6 min read
07
Mar
The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851

The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851

Alfred Hobbs: The OG bug bounty hunter who cracked England’s ‘unpick-able’ locks. His breaker mindset exposed flaws, sparked innovation, and proved no system is perfect.
5 min read
18
Sep

My office setup - Part 3 (US edition)

Optimizing my home office space for a work-from-home/hybrid setup became a bit of a hobby during the pandemic, and since returning to the USA from Australia in 2021 I've essentially replicated the successful aspects of the Sydney setup, with a few modifications.
3 min read
27
Aug
Public Comment from Casey Ellis, Bugcrowd re DRAFT BOD 20-01

Public Comment from Casey Ellis, Bugcrowd re DRAFT BOD 20-01

Dear Director Krebs and CISA/DHS team, Thank you for the opportunity to comment on this Binding Operational Directive...
6 min read
31
Aug

Making noise

“We had a problem with a few needles, and as an industry decided that the best thing to do was
1 min read
31
May
Solve 99% of Your Infosec Problems with this One Weird Trick!

Solve 99% of Your Infosec Problems with this One Weird Trick!

99% of good infosec is equivalent to remembering to wash your hands after you use the bathroom. As an industry, we should be working to make that easier.