Sign in

Eric Chiang

@ericchiang.bsky.social
121 followers 122 following 43 posts

@oblique.security. Ex Google Security, CoreOS. ericchiang.github.io

PostsRepliesMedia
Reposted by Eric Chiang
Matthew Green @matthewdgreen.bsky.social · 17/05/2026
A good primer on the new Bitlocker exploit. solcyber.com/bitlocker-in...
solcyber.com
BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber
Nightmare Eclipse hates Microsoft, loves dropping 0-days.
25822
Reposted by Eric Chiang
Johan Brandhorst-Satzkorn @jbrandhorst.com · 05/05/2026
SREs hate this one YAML annotation: oblique.security/blog/the-per...
oblique.security
The performance bug hiding in our billing settings | Oblique
How we spent two months debugging Cloud Run latency, built out our tracing along the way, and learned the fix was one line of YAML.
073
Reposted by Eric Chiang
jenny (phire) @phirephoenix.com · 30/04/2026
I wrote about our team’s code review norms, which I am grateful are deeply human.
0185
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 20/03/2026
Who do I know who's going to be in town for bsides or RSA?
042
Eric Chiang @ericchiang.bsky.social · 25/02/2026
Turns out, I'm the only one who didn't know about the passkey PRF extension. Wrote up a post about using it for end-to-end encryption! oblique.security/blog/passkey...
oblique.security
Passkey PRFs for end-to-end encryption | Oblique
The passkey PRF extension lets syncable credentials do much more than login users. See how apps are using this for end-to-end encryption.
131
Eric Chiang @ericchiang.bsky.social · 10/12/2025
Bad news everyone
000
Reposted by Eric Chiang
BART @bart.gov · 20/08/2025
🚨 Tap and Ride is LIVE! 🚨 Starting today, you can pay for BART right at the fare gates with a 💳 contactless-enabled debit or credit card or use 🤳 mobile payment, like Apple Pay and Google Pay. There is zero registration or setup process required.
33811
Eric Chiang @ericchiang.bsky.social · 18/08/2025
Wrote about a fun @golang.org type trick where APIs can force clients to pass string constants as arguments. Happens to be _extremely_ useful for SQL builders! oblique.security/blog/injecti...
oblique.security
Injection-proof SQL builders in Go | Oblique
SQL builders are always one bad logic bug away from full-blown query injection. This post covers how Oblique uses Go type tricks to prevent this entire class of backend issues.
010
Reposted by Eric Chiang
authzed @authzed.com · 14/08/2025
How can you use a Terraform Provider to automate your Permission System? Well, that's what @veronicalg.bsky.social is going to tell us in this livestream later today. It's Office Hours format so bring any questions you may have. www.youtube.com/live/OlQ70bq...
youtube.com
Use Terraform Providers to Automate Your Permission System
AuthZed now has a Terraform and OpenTofu Provider for the AuthZed Cloud API! This provider automates the management of resources in AuthZed Dedicated environments: Service accounts for programma...
122
Eric Chiang @ericchiang.bsky.social · 01/08/2025
It turns out workload identity isn't a complete mess in 2025 (only a little one)? Wrote a bit about authenticating GitHub Actions identity directly using OpenID Connect.
030
Eric Chiang @ericchiang.bsky.social · 23/06/2025
Oh hey, what's this fancy new IAM company?
030
Reposted by Eric Chiang
Corey Quinn @quinnypig.com · 10/06/2025
A friend needs a Workday test instance to build something interesting. Anyone know how to get one? (A Workday instance; I kinda already know how to get a friend.)
8504
Eric Chiang @ericchiang.bsky.social · 16/05/2025
Every day I'm glad my job isn't staring into the IAM abyss of a large Cloud org. matduggan.com/iam-is-the-w...
So that's effectively the AWS story, which is terrible but at least it's possible to cobble together something that works and you can audit. Google looked at this and said "what if we could express how much we hate Infrastructure teams as a service?" Expensive coffee robots were engaged, colorful furniture was sat on and the brightest minds of our generation came up with a system so punishing you'd think you did something to offend them personally.
010
Eric Chiang @ericchiang.bsky.social · 07/05/2025
Every time you feel useless, remember that GitHub as a notifications tab
120
Eric Chiang @ericchiang.bsky.social · 07/05/2025
who needs coherent cyber policy when we excel so much at corporate ligation? www.nytimes.com/2025/05/06/t...
nytimes.com
Meta Awarded $167 Million in Damages From Israeli Cybersecurity Firm
010
Reposted by Eric Chiang
Michael Knyszek @michael.express · 02/05/2025
New experimental garbage collector for Go programs! github.com/golang/go/is...
github.com
runtime: green tea garbage collector · Issue #73581 · golang/go
Green Tea 🍵 Garbage Collector Authors: Michael Knyszek, Austin Clements Updated: 2 May 2025 This issue tracks the design and implementation of the Green Tea garbage collector. As of the last update...
212241
Reposted by Eric Chiang
Polar Signals @polarsignals.com · 01/04/2025
📣Today, we’re super excited to announce our latest product addition: Continuous Profiling for GPUs! Check out the use cases and sign up for early access on the announcement post! 🔥📈 www.polarsignals.com/blog/posts/2...
083
Eric Chiang @ericchiang.bsky.social · 26/03/2025
Scraping Kubernetes codebases for os/exec continues to pay dividends www.wiz.io/blog/ingress...
wiz.io
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
000
Eric Chiang @ericchiang.bsky.social · 24/03/2025
"middleware:middleware:middleware:middleware:middleware" is the new bloody mary zhero-web-sec.github.io/research-and...
zhero-web-sec.github.io
Next.js and the corrupt middleware: the authorizing artifact
CVE-2025-29927
000
Eric Chiang @ericchiang.bsky.social · 23/03/2025
Awesome to see Landlock making unprivileged isolation so easy. As someone who maintained bubblewrap jails, I'm hoping that this takes over user namespaces. Things like network controls are always mess there. github.com/Zouuup/landrun
github.com
GitHub - Zouuup/landrun: Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel.
Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel. - Zouuup/landrun
020
Reposted by Eric Chiang
Eric Chiang @ericchiang.bsky.social · 14/03/2025
Quick reminder:
121
Eric Chiang @ericchiang.bsky.social · 14/03/2025
"No way to see this coming" says only auth protocol with regular auth bypasses github.blog/security/sig...
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
100
Eric Chiang @ericchiang.bsky.social · 12/03/2025
"Vibe coding will ruin the quality of our codebase!" The codebase: github.com/pandas-dev/p...
A Python code comment that says "Welcome to the spaghetti factory"
110
Reposted by Eric Chiang
Frederic Branczyk @brancz.com · 02/03/2025
On my way to New York! I’ll be in there from Monday until Thursday evening, and still have some room to meet on Wednesday afternoon, anyone want to chat databases/observability/performance? Feel free to DM me!
1114
Eric Chiang @ericchiang.bsky.social · 28/01/2025
I finally read up NVIDIA Confidential Compute, so you don't have to! Surely this will make all of our AI secure ericchiang.github.io/post/confide...
ericchiang.github.io
Eric Chiang | Confidential Compute and GPUs
010
Eric Chiang @ericchiang.bsky.social · 20/01/2025
Do OSS, it'll be fun! *Ten years later and still getting reports on my day off about other people's buggy implementations*
010
Reposted by Eric Chiang
Catalin Cimpanu @campuscodi.risky.biz · 08/01/2025
According to Giraffe Security, AWS staff have somehow managed to re-introduce the same RCE vulnerability into its platform three times over the past four years giraffesecurity.dev/posts/amazon...
24010
Eric Chiang @ericchiang.bsky.social · 05/01/2025
One of the coolest pieces of security tech I read about in 2024 was PyPI's builder identity verification done by Trail Of Bits. Didn't see much fanfare in my feeds when it was published, but defiantly worth the read. blog.trailofbits.com/2024/11/14/a...
blog.trailofbits.com
Attestations: A new generation of signatures on PyPI
For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestatio…
011
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 02/01/2025
Streaming media DRM has nothing to do with TPMs and the FSF is just plain wrong: mjg59.dreamwidth.org/70954.html
34912
Eric Chiang @ericchiang.bsky.social · 25/12/2024
If the rust compiler is slow, why don't rustaceans simply rewrite it in rust?
061
Reposted by Eric Chiang
Michael Stapelberg 🐧🐹😺 @zekjur.bsky.social · 16/12/2024
The Go Blog Go Protobuf: The new Opaque API Michael Stapelberg 16 December 2024 go.dev/blog/protobu... #golang
go.dev
Go Protobuf: The new Opaque API - The Go Programming Language
We are adding a new generated code API to Go Protobuf.
02611
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 12/12/2024
Hello I wrote a thing describing how a worthwhile privacy improvement in Android had the unfortunate side effect of appearing to undermine the usefulness of key attestation: mjg59.dreamwidth.org/70630.html
0173
Eric Chiang @ericchiang.bsky.social · 12/12/2024
@mayakaczorowski.com and I are publishing the write up of our 2022 NorthSec talk on the hard parts of zero trust. Which made me wonder, how's that US executive memorandum requiring agencies to adopt ZTA by 2024? ericchiang.github.io/post/zero-tr...
ericchiang.github.io
Eric Chiang | The road to zero trust is paved with good intentions
111
Reposted by Eric Chiang
Maya Kaczorowski @mayakaczorowski.com · 10/12/2024
What keeps security leaders up at night? I interviewed 57 CISOs and security leaders to find out. The answers were surprisingly consistent: access management challenges, vulnerability management complexity, and limited SaaS visibility. Read the post: mayakaczorowski.com/blogs/what-s...
mayakaczorowski.com
What sucks in security? Research findings from 50+ security leaders
I interviewed 57 security leaders and asked them "What sucks in security?" Their top pain points were inconsistent access management, vulnerability prioritization and remediation, and obtaining SaaS l...
23116
Reposted by Eric Chiang
Matthew Green @matthewdgreen.bsky.social · 06/12/2024
This is like the Cybertruck of language features.
1192
Eric Chiang @ericchiang.bsky.social · 05/12/2024
Since it's Spotify wrapped season, reminder that Spotify allows you to request your entire listening data history. I used that data to build personalized visualizations earlier this year! ericchiang.github.io/post/spotify/
ericchiang.github.io
Eric Chiang | Analyzing Spotify stream history
010
Eric Chiang @ericchiang.bsky.social · 28/11/2024
Forcing users set a PIN is the "one weird trick" solution to all hard security problems
Google Password Manager

Create a recovery PIN
This helps you access your saved passkeys on any device
000
Eric Chiang @ericchiang.bsky.social · 10/11/2024
Apparently the Alameda county vote count is taking super long because (checks notes) CA mandated PDF as the interchange format? From @berkeleyside.bsky.social www.berkeleyside.org/2024/11/08/a...
100