Dylan(@InsecureNature) 's Twitter Profileg
Dylan

@InsecureNature

Security researcher, public speaker and founder.

Forbes 30 Under 30

Truffle Security @trufflesec

https://t.co/vxEH7Cftbg

Prev @Netflix

ID:1282920360015327233

linkhttps://TruffleSecurity.com calendar_today14-07-2020 06:10:45

782 Tweets

2,8K Followers

221 Following

Dylan(@InsecureNature) 's Twitter Profile Photo

We cofounded Truffle Security for this reason.

Everyone's putting all their attention into fixing Javascript CVE's and fixing XSS.

Meanwhile, most of the time you're popped because an AWS key is in the wrong place.

account_circle
Truffle Security(@trufflesec) 's Twitter Profile Photo

🔒 How many secrets leak on public gists?

Of 37,323 checked, only 11 with secrets! 🤯

🤔Why so few?

👉Find out the unexpected reasons and secure your gists with 🐷 TruffleHog.

trufflesecurity.com/blog/do-secret…

account_circle
Truffle Security(@trufflesec) 's Twitter Profile Photo

Join us for an evening filled with expert security insights and valuable peer networking on 4/23 OWASPBayArea Meetup. Don't miss talks by Dylan, Sam Curry, and Denis Smajlović.

👉 Secure your spot now: meetup.com/bay-area-owasp…

Join us for an evening filled with expert security insights and valuable peer networking on 4/23 @OWASPBayArea Meetup. Don't miss talks by @InsecureNature, @samwcyo, and @DSDeniso. 👉 Secure your spot now: meetup.com/bay-area-owasp…
account_circle
Truffle Security(@trufflesec) 's Twitter Profile Photo

New TruffleHog open-source script 🐷 helps make Docker Build Cloud is here! 🐳🧱☁️ 🐳more secure!

🔍 Scans every Docker image tag & architecture for leaked secrets

👉Get the script for a more comprehensive scan of Docker images: trufflesecurity.com/blog/scan-ever…

account_circle
Dylan(@InsecureNature) 's Twitter Profile Photo

This is a lawyer who accidentally mashed the Yubikey 2fa button into the DocuSign, and a CEO that signed it into a binding contract.

account_circle
Dylan(@InsecureNature) 's Twitter Profile Photo

Sometimes it's fun to do some light hearted, low stakes research.

Hope others enjoy learning about SysRq, like I did!

account_circle
Dylan(@InsecureNature) 's Twitter Profile Photo

GPT4 is capable of reading and writing base64 without running it through a decoder (something no human is capable of doing) chat.openai.com/share/c6d48ac3…

GPT4 is capable of reading and writing base64 without running it through a decoder (something no human is capable of doing) chat.openai.com/share/c6d48ac3…
account_circle
Truffle Security(@trufflesec) 's Twitter Profile Photo

💁💥 Today we’re unlocking a novel method of detecting AWS canary tokens, completely statically, without setting them off.

This feature is now natively built into TruffleHog, learn more: trufflesecurity.com/blog/canaries

💁💥 Today we’re unlocking a novel method of detecting AWS canary tokens, completely statically, without setting them off. This feature is now natively built into TruffleHog, learn more: trufflesecurity.com/blog/canaries
account_circle
Dylan(@InsecureNature) 's Twitter Profile Photo

🔒📷So with here, can CanonUSA Sony @samsungmobile and NikonUSA start making sensors with baked in Hardware Security Modules (HSM's) that cryptographically sign the images they take?

🔒📷So with #Sora here, can @CanonUSA @Sony @samsungmobile and @NikonUSA start making sensors with baked in Hardware Security Modules (HSM's) that cryptographically sign the images they take?
account_circle