Sign in

Alex Rebert

@ayper.bsky.social
173 followers 212 following 4 posts

Memory Safety @ Google. Previously co-founder of Mayhem Security (formerly known as ForAllSecure). Opinions here are my own.

PostsRepliesMedia
Reposted by Alex Rebert
David Adrian @dadrian.io · 23/08/2026
I wrote a post about how security undervalues preventing problems, and how this can be exasperated by AI and the vulnpocalypse, even though AI should actually make robustness much easier for defenders. Read it here: dadrian.io/blog/posts/w...
dadrian.io
Playing whack-a-mole is losing
I want to juxtapose two classes of people in the security industry on the defender side of security engineering for products. The first are the Security as Identity people. This goes back to the secur...
092
Reposted by Alex Rebert
Sophie Schmieg @sophieschmieg.infosec.exchange.ap.brid.gy · 12/08/2026
Don't like what I'm posting? Become my boss and tell me to cut it out! Or just become my boss and be cool, that's also possible and encouraged. www.linkedin.com/jobs/view/44530271…
linkedin.com
Google hiring Engineering Director, Product Security, Core in Zurich, Zurich, Switzerland | LinkedIn
Posted 1:35:05 AM. Note: By applying to this position you will have an opportunity to share your preferred working…See this and similar jobs on LinkedIn.
174
Reposted by Alex Rebert
Zardus @zardus.bsky.social · 28/04/2026
Can we translate all C to Rust? The susceptibility of C to memory corruption has long been a cybersecurity pain point, and coding agents can free us of it. Read on for my recent experiments in this space, and apt & docker repos that you can pull rust-converted libraries from!
153
Reposted by Alex Rebert
jeffvanderstoep.bsky.social @jeffvanderstoep.bsky.social · 18/11/2025
With Rust development surpassing C++ in the Android platform in 2025, we can start making reliable comparisons. Rollback rates, code review latency, vulnerability density, and a CVE with a twist. security.googleblog.com/2025/11/rust...
security.googleblog.com
Rust in Android: move fast and fix things
Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in ...
041
Reposted by Alex Rebert
Bob Lord @boblord.bsky.social · 06/11/2025
Secure by Design software: It’s time to stop patching and start preventing. One year left before "Smashing the Stack" turns 30—let’s make it count! 🔐💪🛡️🗓️ medium.com/@boblord/29-...
medium.com
29 Years Since “Smashing the Stack”: Time to Smash Memory Unsafety Itself
This coming Saturday marks the 29th anniversary of Aleph One’s seminal Phrack Magazine article, “Smashing the Stack for Fun and Profit.”…
083
Reposted by Alex Rebert
Andrew Lilley Brinker @alilleybrinker.com · 10/11/2025
"Memory Safety for Skeptics," where I argue why memory safety is worthwhile to pursue amid competing priorities! queue.acm.org/detail.cfm?i... #rustlang
queue.acm.org
Memory Safety for Skeptics - ACM Queue
14914
Alex Rebert @ayper.bsky.social · 25/02/2025
We're joining forces with industry & academia to call for memory safety standardization: security.googleblog.com/2025/02/secu.... It's a recognition that memory unsafety is no longer a niche technical problem but a societal one, impacting everything from national security to personal privacy.
security.googleblog.com
Securing tomorrow's software: the need for memory safety standards
Posted by Alex Rebert, Security Foundations, Ben Laurie, Research, Murali Vijayaraghavan, Research and Alex Richardson, Silicon For decades,...
070
Reposted by Alex Rebert
erbbysam @erbbysam.bsky.social · 21/01/2025
🛡️💸 We've revamped our Patch Rewards Program, extending its scope and increasing rewards for security patches – with a particular focus on memory safety, including bonus multipliers! bughunters.google.com/blog/5273064...
bughunters.google.com
Blog: Level Up Your Open Source Karma (And Your Wallet) by Improving Security
This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased ...
152
Reposted by Alex Rebert
Michele Spagnuolo @miki.it · 17/11/2024
Happy to publish the effort of my last five years: Security Signals. research.google/pubs/securit...
research.google
Security Signals: Making Web Security Posture Measurable At Scale
0277
Reposted by Alex Rebert
Chandler Carruth @chandlerc.blog · 17/11/2024
Had a bunch of thoughts about the recent safety stuff, way more than fit in social media post... Blog post story time! (It's a bit of a ramble, sorry about that...) chandlerc.blog/posts/2024/1... #LLVM #Clang #MemorySafety
chandlerc.blog
Story-time: C++, bounds checking, performance, and compilers
Recently, several of my colleagues at Google shared the story of how we are retrofitting spatial safety onto our monolithic C++ codebase: https://security.googleblog.com/2024/11/retrofitting-spatial-s...
19519
Alex Rebert @ayper.bsky.social · 15/11/2024
The best part? It’s incredibly cost-effective, with an average performance overhead of just 0.3%. So there’s really no reason not to do it if you’re running C++ code :)
010
Alex Rebert @ayper.bsky.social · 15/11/2024
This improves spatial safety across Google’s services, including performance-critical components of Search, Gmail, Drive, YouTube, and Maps. We’ve already seen it disrupt a red team exercise, reduce segfaults by 30%, and improve code correctness.
110
Alex Rebert @ayper.bsky.social · 15/11/2024
Excited to share our latest blog post on memory safety! We’re tackling spatial safety in our massing C++ codebase by hardening live++ by default. It adds bounds checks to things like std::vector, preventing a fair bit of out-of-bounds vulnerabilities: security.googleblog.com/2024/11/retr...
security.googleblog.com
Retrofitting Spatial Safety to hundreds of millions of lines of C++
Posted by Alex Rebert and Max Shavrick, Security Foundations, and Kinuko Yasada, Core Developer Attackers regularly exploit spatial mem...
1278