Eric Chiang (@erchiang) 's Twitter Profile
Eric Chiang

@erchiang

I write bugs. @obliquesecurity, prev @google, @coreos he/him

ID: 87515498

linkhttps://ericchiang.github.io calendar_today04-11-2009 19:44:11

841 Tweet

1,1K Followers

162 Following

Eric Chiang (@erchiang) 's Twitter Profile Photo

.Tailscale's amazing. Local git daemon on one machine, git clone git://[addr]/[path] on another. Took more time to figure out the git daemon flags than set up Tailscale And apparently I already have a Personal Pro account?

.<a href="/Tailscale/">Tailscale</a>'s amazing. Local git daemon on one machine, git clone git://[addr]/[path] on another. Took more time to figure out the git daemon flags than set up Tailscale

And apparently I already have a Personal Pro account?
Dmitry Vyukov (@dvyukov) 's Twitter Profile Photo

Excited to present new(?) approach to #fuzzing where one doesn't need to write fuzz functions. Wanna fuzz all binaries on github - no problem. Just give the fuzzer binaries to test. No false positives & 100% fidelity. Blender: whole-program fuzzing: github.com/dvyukov/centip…

Eric Chiang (@erchiang) 's Twitter Profile Photo

BSidesSF talks are up! "You can't work harder to keep up with scale. You can't hire fast enough to keep up with scale. If you try to be a hero, you will burn out." - ? youtube.com/watch?v=c3B-ig…

Polar Signals (@polarsignalsio) 's Twitter Profile Photo

🚀 The day has arrived! We are thrilled to announce the general availability of our continuous profiling cloud product. Welcome to a new era of observability! Learn about the details in our announcement blog post. polarsignals.com/blog/posts/202…

Andrea Barisani (@andreabarisani) 's Twitter Profile Photo

This nice library allows PKCS#11 over RPC calls to be served over a socket. github.com/google/go-p11-… I imported it in GoKey and modified its SSH server to accept SSH forwarding of that interface. Works like a charm. github.com/usbarmory/GoKe…

This nice library allows PKCS#11 over RPC calls to be served over a socket.

github.com/google/go-p11-…

I imported it in GoKey and modified its SSH server to accept SSH forwarding of that interface.

Works like a charm.

github.com/usbarmory/GoKe…
Runa Sandvik (@runasand) 's Twitter Profile Photo

Google created the Advanced Protection Program to help high-risk individuals keep their accounts secure. The program is great (I’ve used it for years!), it’s just a shame the company rarely mentions it. glitchcat.xyz/p/googles-adva…

Maya Kaczorowski (@mayakaczorowski) 's Twitter Profile Photo

Rather than a security tool alerting the security team (in Slack), who then needs to find the right person to ping (also in Slack) — what if the tool just short circuited that and went right to the source (in Slack, of course)? mayakaczorowski.com/blogs/slacksec…

Eric Chiang (@erchiang) 's Twitter Profile Photo

Confidential Compute always seems like a breakthrough security technology for a threat model basically no one has. Now that GPUs are embracing it, will it finally find a use with AI? ericchiang.github.io/post/confident…

Maya Kaczorowski (@mayakaczorowski) 's Twitter Profile Photo

What I've been up to the last few months: working on the untrendy but important problem of authorization in corporate environments. Check it out!

Dylan (@insecurenature) 's Twitter Profile Photo

Hackers reportedly used something called "TruffleHog" during their attack. They also used "child_process", and something called HTTP, something called TLS, and something called TCP. Please be on the lookout for any of these hacking tools being used in your environment.