Sign in

Eric Chiang

@ericchiang.bsky.social
121 followers 122 following 43 posts

@oblique.security. Ex Google Security, CoreOS. ericchiang.github.io

PostsRepliesMedia
Eric Chiang @ericchiang.bsky.social · 19/07/2026
I wrote up a package a while back after being unsatisfied with some of the other libraries. One of the core decisions is if you want to deal with attestation. It's a cool primitive, but complicates the API github.com/go-passkeys/...
github.com
GitHub - go-passkeys/go-passkeys: Passkeys support for Go
Passkeys support for Go. Contribute to go-passkeys/go-passkeys development by creating an account on GitHub.
030
Reposted by Eric Chiang
Matthew Green @matthewdgreen.bsky.social · 17/05/2026
A good primer on the new Bitlocker exploit. solcyber.com/bitlocker-in...
solcyber.com
BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber
Nightmare Eclipse hates Microsoft, loves dropping 0-days.
25822
Reposted by Eric Chiang
Johan Brandhorst-Satzkorn @jbrandhorst.com · 05/05/2026
SREs hate this one YAML annotation: oblique.security/blog/the-per...
oblique.security
The performance bug hiding in our billing settings | Oblique
How we spent two months debugging Cloud Run latency, built out our tracing along the way, and learned the fix was one line of YAML.
073
Reposted by Eric Chiang
jenny (phire) @phirephoenix.com · 30/04/2026
I wrote about our team’s code review norms, which I am grateful are deeply human.
0185
Eric Chiang @ericchiang.bsky.social · 16/04/2026
Do I have the privilege of recommending you to @ifbookspod.bsky.social or is that already on your radar? www.buzzsprout.com/2040953/epis... www.buzzsprout.com/2040953/epis...
buzzsprout.com
The Anxious Generation - If Books Could Kill
Is social media to blame for the teen mental health crisis? It's complicated!Thanks to Emily Weinstein, Amy Orben, Andrew Przybylski, Dean Burnett, Michael Mullarkey and Gideon Meyerowitz-Katz for hel...
120
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 20/03/2026
Who do I know who's going to be in town for bsides or RSA?
042
Eric Chiang @ericchiang.bsky.social · 25/02/2026
Look, I'll take being a year behind Filippo as not being too bad.
110
Eric Chiang @ericchiang.bsky.social · 25/02/2026
Turns out, I'm the only one who didn't know about the passkey PRF extension. Wrote up a post about using it for end-to-end encryption! oblique.security/blog/passkey...
oblique.security
Passkey PRFs for end-to-end encryption | Oblique
The passkey PRF extension lets syncable credentials do much more than login users. See how apps are using this for end-to-end encryption.
131
Eric Chiang @ericchiang.bsky.social · 09/02/2026
Yep! If two goroutines are blocked by sleeping the same amount of time, then synctest picks which to unblock at random: go.dev/play/p/J7XMk...
go.dev
Go Playground - The Go Programming Language
020
Eric Chiang @ericchiang.bsky.social · 16/12/2025
GCP managed certs work by pointing Cloudflare DNS records at your load balancer. Manage both through Terraform and that's hopefully not too terrible when you're spinning up services on new subdomains.
000
Eric Chiang @ericchiang.bsky.social · 10/12/2025
Bad news everyone
000
Eric Chiang @ericchiang.bsky.social · 24/09/2025
I've heard of tougher noogler projects
130
Eric Chiang @ericchiang.bsky.social · 24/09/2025
Surely someone there is smart enough to just implement 802.1x for corp devices?
140
Reposted by Eric Chiang
BART @bart.gov · 20/08/2025
🚨 Tap and Ride is LIVE! 🚨 Starting today, you can pay for BART right at the fare gates with a 💳 contactless-enabled debit or credit card or use 🤳 mobile payment, like Apple Pay and Google Pay. There is zero registration or setup process required.
33811
Eric Chiang @ericchiang.bsky.social · 18/08/2025
Wrote about a fun @golang.org type trick where APIs can force clients to pass string constants as arguments. Happens to be _extremely_ useful for SQL builders! oblique.security/blog/injecti...
oblique.security
Injection-proof SQL builders in Go | Oblique
SQL builders are always one bad logic bug away from full-blown query injection. This post covers how Oblique uses Go type tricks to prevent this entire class of backend issues.
010
Reposted by Eric Chiang
authzed @authzed.com · 14/08/2025
How can you use a Terraform Provider to automate your Permission System? Well, that's what @veronicalg.bsky.social is going to tell us in this livestream later today. It's Office Hours format so bring any questions you may have. www.youtube.com/live/OlQ70bq...
youtube.com
Use Terraform Providers to Automate Your Permission System
AuthZed now has a Terraform and OpenTofu Provider for the AuthZed Cloud API! This provider automates the management of resources in AuthZed Dedicated environments: Service accounts for programma...
122
Eric Chiang @ericchiang.bsky.social · 01/08/2025
It turns out workload identity isn't a complete mess in 2025 (only a little one)? Wrote a bit about authenticating GitHub Actions identity directly using OpenID Connect.
030
Eric Chiang @ericchiang.bsky.social · 23/06/2025
Oh hey, what's this fancy new IAM company?
030
Reposted by Eric Chiang
Corey Quinn @quinnypig.com · 10/06/2025
A friend needs a Workday test instance to build something interesting. Anyone know how to get one? (A Workday instance; I kinda already know how to get a friend.)
8504
Eric Chiang @ericchiang.bsky.social · 09/06/2025
We're doing new container runtimes in 2025? Hell yeah
150
Eric Chiang @ericchiang.bsky.social · 05/06/2025
So if I'm reading this right Step 1 - generate a private key with no forward secrecy Step 2 - upload private key to twitter (but don't worry it's protected by a low entropy PIN) Ummmmmmmmm
120
Eric Chiang @ericchiang.bsky.social · 16/05/2025
Every day I'm glad my job isn't staring into the IAM abyss of a large Cloud org. matduggan.com/iam-is-the-w...
So that's effectively the AWS story, which is terrible but at least it's possible to cobble together something that works and you can audit. Google looked at this and said "what if we could express how much we hate Infrastructure teams as a service?" Expensive coffee robots were engaged, colorful furniture was sat on and the brightest minds of our generation came up with a system so punishing you'd think you did something to offend them personally.
010
Eric Chiang @ericchiang.bsky.social · 07/05/2025
What a sicko
120
Eric Chiang @ericchiang.bsky.social · 07/05/2025
Every time you feel useless, remember that GitHub as a notifications tab
120
Eric Chiang @ericchiang.bsky.social · 07/05/2025
who needs coherent cyber policy when we excel so much at corporate ligation? www.nytimes.com/2025/05/06/t...
nytimes.com
Meta Awarded $167 Million in Damages From Israeli Cybersecurity Firm
010
Reposted by Eric Chiang
Michael Knyszek @michael.express · 02/05/2025
New experimental garbage collector for Go programs! github.com/golang/go/is...
github.com
runtime: green tea garbage collector · Issue #73581 · golang/go
Green Tea 🍵 Garbage Collector Authors: Michael Knyszek, Austin Clements Updated: 2 May 2025 This issue tracks the design and implementation of the Green Tea garbage collector. As of the last update...
212241
Eric Chiang @ericchiang.bsky.social · 05/04/2025
@mayakaczorowski.com's been using it a ton and had great things to say.
110
Reposted by Eric Chiang
Polar Signals @polarsignals.com · 01/04/2025
📣Today, we’re super excited to announce our latest product addition: Continuous Profiling for GPUs! Check out the use cases and sign up for early access on the announcement post! 🔥📈 www.polarsignals.com/blog/posts/2...
083
Eric Chiang @ericchiang.bsky.social · 27/03/2025
You're not even using nix packages? What kind of tech hipster are you?
110
Eric Chiang @ericchiang.bsky.social · 26/03/2025
Scraping Kubernetes codebases for os/exec continues to pay dividends www.wiz.io/blog/ingress...
wiz.io
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
000
Eric Chiang @ericchiang.bsky.social · 24/03/2025
"middleware:middleware:middleware:middleware:middleware" is the new bloody mary zhero-web-sec.github.io/research-and...
zhero-web-sec.github.io
Next.js and the corrupt middleware: the authorizing artifact
CVE-2025-29927
000
Eric Chiang @ericchiang.bsky.social · 24/03/2025
I really wish progressive web apps took off so every app didn't come with a chrome fork
120
Eric Chiang @ericchiang.bsky.social · 23/03/2025
Awesome to see Landlock making unprivileged isolation so easy. As someone who maintained bubblewrap jails, I'm hoping that this takes over user namespaces. Things like network controls are always mess there. github.com/Zouuup/landrun
github.com
GitHub - Zouuup/landrun: Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel.
Run any Linux process in a secure, unprivileged sandbox using Landlock LSM. Think firejail, but lightweight, user-friendly, and baked into the kernel. - Zouuup/landrun
020
Reposted by Eric Chiang
Eric Chiang @ericchiang.bsky.social · 14/03/2025
Quick reminder:
121
Eric Chiang @ericchiang.bsky.social · 14/03/2025
Was it petty? Yes. Was it necessary? Also yes.
010
Eric Chiang @ericchiang.bsky.social · 14/03/2025
Quick reminder:
121
Eric Chiang @ericchiang.bsky.social · 14/03/2025
"No way to see this coming" says only auth protocol with regular auth bypasses github.blog/security/sig...
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
100
Eric Chiang @ericchiang.bsky.social · 12/03/2025
"Vibe coding will ruin the quality of our codebase!" The codebase: github.com/pandas-dev/p...
A Python code comment that says "Welcome to the spaghetti factory"
110
Reposted by Eric Chiang
Frederic Branczyk @brancz.com · 02/03/2025
On my way to New York! I’ll be in there from Monday until Thursday evening, and still have some room to meet on Wednesday afternoon, anyone want to chat databases/observability/performance? Feel free to DM me!
1114
Eric Chiang @ericchiang.bsky.social · 28/01/2025
I finally read up NVIDIA Confidential Compute, so you don't have to! Surely this will make all of our AI secure ericchiang.github.io/post/confide...
ericchiang.github.io
Eric Chiang | Confidential Compute and GPUs
010
Eric Chiang @ericchiang.bsky.social · 20/01/2025
Do OSS, it'll be fun! *Ten years later and still getting reports on my day off about other people's buggy implementations*
010
Reposted by Eric Chiang
Catalin Cimpanu @campuscodi.risky.biz · 08/01/2025
According to Giraffe Security, AWS staff have somehow managed to re-introduce the same RCE vulnerability into its platform three times over the past four years giraffesecurity.dev/posts/amazon...
24010
Eric Chiang @ericchiang.bsky.social · 05/01/2025
One of the coolest pieces of security tech I read about in 2024 was PyPI's builder identity verification done by Trail Of Bits. Didn't see much fanfare in my feeds when it was published, but defiantly worth the read. blog.trailofbits.com/2024/11/14/a...
blog.trailofbits.com
Attestations: A new generation of signatures on PyPI
For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestatio…
011
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 02/01/2025
Streaming media DRM has nothing to do with TPMs and the FSF is just plain wrong: mjg59.dreamwidth.org/70954.html
34912
Eric Chiang @ericchiang.bsky.social · 29/12/2024
Reminds me of Go's codereview plugin, which presents a higher level "change" abstraction on top of git. Figure if you're running a large project, you've already got a PR style guide. Much easier if you can just say "use this tool to contribute" pkg.go.dev/golang.org/x...
pkg.go.dev
git-codereview command - golang.org/x/review/git-codereview - Go Packages
000
Eric Chiang @ericchiang.bsky.social · 25/12/2024
If the rust compiler is slow, why don't rustaceans simply rewrite it in rust?
061
Reposted by Eric Chiang
Michael Stapelberg 🐧🐹😺 @zekjur.bsky.social · 16/12/2024
The Go Blog Go Protobuf: The new Opaque API Michael Stapelberg 16 December 2024 go.dev/blog/protobu... #golang
go.dev
Go Protobuf: The new Opaque API - The Go Programming Language
We are adding a new generated code API to Go Protobuf.
02611
Reposted by Eric Chiang
Matthew Garrett @mjg59.eicar-test-file.zip · 12/12/2024
Hello I wrote a thing describing how a worthwhile privacy improvement in Android had the unfortunate side effect of appearing to undermine the usefulness of key attestation: mjg59.dreamwidth.org/70630.html
0173
Eric Chiang @ericchiang.bsky.social · 12/12/2024
Good news - we've increased "encryption of data both at rest and in transit" by more than 10%! I'm sure we'll finish the rest of that whole "zero trust" thing in time for the holiday freeze. www.whitehouse.gov/wp-content/u...
000
Eric Chiang @ericchiang.bsky.social · 12/12/2024
@mayakaczorowski.com and I are publishing the write up of our 2022 NorthSec talk on the hard parts of zero trust. Which made me wonder, how's that US executive memorandum requiring agencies to adopt ZTA by 2024? ericchiang.github.io/post/zero-tr...
ericchiang.github.io
Eric Chiang | The road to zero trust is paved with good intentions
111