Sign in

erbbysam

@erbbysam.bsky.social
1.1K followers 169 following 14 posts

Software security, cryptography etc

PostsRepliesMedia
Reposted by erbbysam
Cameron Blevins @cblevins.bsky.social · 03/04/2026
This is so, so well-articulated.
People call this friction "grunt work." Schwartz uses exactly that phrase, and he's right that LLMs can remove it. What he doesn't say, because he already has decades of hard-won intuition and doesn't need the grunt work anymore, is that for someone who doesn't yet have that intuition, the grunt work is the work. The boring parts and the important parts are tangled together in a way that you can't separate in advance. You don't know which afternoon of debugging was the one that taught you something fundamental about your data until three years later, when you're working on a completely different problem and the insight surfaces. Serendipity doesn't come from efficiency. It comes from spending time in the space where the problem lives, getting your hands dirty, making mistakes that nobody asked you to make and learning things nobody assigned you to learn.
97107603880
erbbysam @erbbysam.bsky.social · 08/08/2025
What's strange about go.dev/play/p/4fc3Y... 👀 Attend my presentation in the Bug Bounty Village @ DEFCON today at 5pm to learn more!
VRP @ Google -- a look inside a large self-hosted VRP
020
Reposted by erbbysam
Randall Munroe @xkcd.com · 25/04/2025
PhD Timeline xkcd.com/3081
5865978320440
erbbysam @erbbysam.bsky.social · 24/03/2025
I missed the "Top Secret//ORCON//Signal" banner, my bad
010
erbbysam @erbbysam.bsky.social · 24/03/2025
Quick question -- in Signal, how do I differentiate my EZpass scam messages from those sent by the Pentagon?
010
erbbysam @erbbysam.bsky.social · 08/02/2025
BSides CambridgeMA CFP is open!!! bsidescambridgema.org/call-for-pro... 👀🎉
bsidescambridgema.org
Call for Proposals 2025 – BSides CambridgeMA
000
erbbysam @erbbysam.bsky.social · 22/01/2025
To answer your first question -- yes, we would accept submissions for golang.org/x repos
110
erbbysam @erbbysam.bsky.social · 22/01/2025
🤦‍♂️ amazing spot. Our intention was to only remove it for one-liner changes as reflected on the rules page. We updated the blog post to match!
110
erbbysam @erbbysam.bsky.social · 21/01/2025
Good question, let me check with our team and I'll get back to you
110
erbbysam @erbbysam.bsky.social · 21/01/2025
🛡️💸 We've revamped our Patch Rewards Program, extending its scope and increasing rewards for security patches – with a particular focus on memory safety, including bonus multipliers! bughunters.google.com/blog/5273064...
bughunters.google.com
Blog: Level Up Your Open Source Karma (And Your Wallet) by Improving Security
This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased ...
152
erbbysam @erbbysam.bsky.social · 17/12/2024
🎵Should I open it? Or should I keep it sealed?
My Bitcoin wallets on Google Drive from ~2013
260
Reposted by erbbysam
Koto @kkotowicz.bsky.social · 04/12/2024
I don't often post about my work but bughunters.google.com/blog/6355265... is actually super cool thing my team is doing. These short term redteams focused on just stealing our passwords were always amazing to highlight how severely broken complex systems are. The internal writeups are so, so fun!
bughunters.google.com
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!)
The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...
0189
erbbysam @erbbysam.bsky.social · 30/11/2024
Reported, thanks for the headsup
010
erbbysam @erbbysam.bsky.social · 14/11/2024
Check out the OSS Fuzz projects scope line :) github.com/google/oss-f...
110
erbbysam @erbbysam.bsky.social · 14/11/2024
bughunters.google.com/open-source-... for fixing?
bughunters.google.com
Open Source Security Patch Rewards
The Patch Rewards program rewards proactive improvements to security in open source projects.
120
erbbysam @erbbysam.bsky.social · 10/11/2024
Going to start posting here more often. If this doesn't work out, I found a good fallback.
Digital equipment corporation inter-departmental correspondence envelope
040
erbbysam @erbbysam.bsky.social · 09/11/2024
Hello w̶o̶r̶l̶d̶ blue sky!
070