coffeetocode Profile Banner
Patrick Thomas (@coffeetocode@infosec.exchange) Profile
Patrick Thomas (@[email protected])

@coffeetocode

Followers
2K
Following
2K
Media
213
Statuses
3K

Software engineer to security consultant, now security partner at @Netflix. Infosec pragmatist.

SF Bay Area
Joined February 2010
Don't wanna be here? Send us removal request.
@coffeetocode
Patrick Thomas (@[email protected])
9 years
"Penetration Test" is a crazy overloaded term. Important to start w/ discussion of goals and tradeoffs between testers and client team.
22
692
938
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Thanks for the #BSidesSF Semgrep workshop @enncoded @LewisArdern @onefiftyman . You packed a *ton* into 2 hours. Really appreciate the work that went into it.
1
3
12
@coffeetocode
Patrick Thomas (@[email protected])
3 years
What can we say, twitter-driven development sometimes works :) https://t.co/W12RcGwa75 Ya'll are good folks. Keep it going!
@securitytxt
security.txt (RFC 9116)
3 years
Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAANG list. 🙌
2
6
58
@coffeetocode
Patrick Thomas (@[email protected])
3 years
I love formal forecasting exercises (esp those run by @Magoo) because they really force you to slow down consider all the potentially relevant facts, and introspect your biases. FWIW I was 80% here, but I think I was undervaluing the "autopilot" nature of modern CI/CD.
@Magoo
Ryan McGeehan
3 years
That's what myself and 26 others sought to gather over the weekend. The panel we put together forecasted a 72.8% belief it would happen. Here's the spread of forecasts https://t.co/fS70r6WCNf
1
0
1
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Of the ~950 people I follow on twitter, some hacky profile scraping says that about 60 of those currently have a Mastodon link. So for me that's basically from ~0% to 15% exodus (or at least strongly hedging) in a *week*.
2
0
3
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Hah, this makes me feel so much better about my small pile of aborted "I think I should write something about..." drafts.
@troyhunt
Troy Hunt
3 years
Know how many blog posts I start writing but never finish? *HEAPS*! Sometimes the story just doesn't work out as expected, sometimes I calm down and change my mind, other times... I'm a busy guy 🤷‍♂️ Are there any here I really should finish?
0
1
2
@tqbf
Thomas H. Ptacek
3 years
I don’t think there’s a SOC2 rule against banking 50 pre-approved empty PRs for future use.
4
3
75
@coffeetocode
Patrick Thomas (@[email protected])
3 years
When looking at a big backlog of known work we want to drive, it's *so easy* to just group into themes and call it good. I can think of times I've done that which really, really would have benefitted from asking if the framing leads to an ability to confidently prioritize. 2/2
0
0
0
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Someone asked today "Is that list of 'goals' *really* a list of goals, or just a some themes of work?" I *love* that question & the insight behind it. True "goals" help prioritize among possible work, themes really don't. 1/2
1
0
2
@aboodman
Aaron Boodman
4 years
Chrome was delivered without any sprints at all. The team came in at 9 and left at 5 (figuratively, people actually kept their own ~8h schedules) every workday for a couple years like clockwork. No drama. No broken marriages, no broken families.
@hadip
Hadi Partovi
4 years
Sadly, there were divorces and broken families and bad things that came out of that. But I also learned that even at a 20,000-person company, you can get a team of 100 people to work like their lives depend on it.
67
2K
11K
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Congrats to @Resourcely! Clear, exciting product vision at that critical touchpoint of developer velocity, security, and cloud resources. Very pleased to have joined this round, and looking forward to seeing where @travismcpeak and @0xshellrider take this idea.
@Resourcely
Resourcely
3 years
Hello world! We're on a mission to make cloud security easier for users. See our funding announcement ( https://t.co/uBm6JTCAct) and blog post ( https://t.co/xXLAUz4Pes) for more details. We're #Hiring!
1
0
8
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Strong recommend for anyone thinking about sustainability, culture, and ultimately the humans in a security organization. @astha_singhal knows what she's talking about and delivers it so well. 🙌
@astha_singhal
Astha Singhal
3 years
This year I got the amazing opportunity to deliver the keynote at one of my favorite security conferences, @BSidesSF. You can now check out my talk on "Building Sustainable Security Programs" here: https://t.co/yI1ev06cF8
0
0
4
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Web timing attacks: super cool in principle, still super janky in practice. Seems like TimeTrial ( https://t.co/tVkldL3epu) and Nanown ( https://t.co/TPKkst2VPm) still best tools, but really janky to get running & require a known-good case. Anyone got suggestions? Banging my head.
1
0
0
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Strong recommend. Some great examples that improve both risk and user experience, and also give metrics that make the wins feel real.
@leifdreizler
Leif Dreizler
3 years
@workingrach and my @BSidesSF preso is uploaded to Youtube! https://t.co/ZibT9Ahvny
1
0
4
@manicode
Jim Manico from Manicode Security
3 years
Brilliant talk from @coffeetocode on bonding security to developer productivity.
1
6
20
@coffeetocode
Patrick Thomas (@[email protected])
3 years
@manicode
Jim Manico from Manicode Security
3 years
When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHavingFun
0
0
5
@manicode
Jim Manico from Manicode Security
3 years
When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHavingFun
0
4
15
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Woo! @LocoMocoSec has been on my list since it started; I'm finally here and so excited! Looking forward to meeting folks. Just hanging out today/tomorrow if anyone else in early wants to meet up!
@ropnop
Ronnie Flathers
3 years
Aloha @LocoMocoSec 😎 so excited to be here - have wanted to attend this con for a long time! Really looking forward to learning a lot, talking prodsec and meeting new friends. Anyone else gonna be here? And can’t wait to catch up @coffeetocode been too long!
3
1
13
@coffeetocode
Patrick Thomas (@[email protected])
3 years
Woot! Let's do this! I'm really looking forward to sharing this.
@LocoMocoSec
LocoMocoSec: Hawaiʻi Security Conference
3 years
Patrick Thomas, Senior Security Partner @netflix, is speaking @LocoMocoSec next week! Register now to see his talk 'Productizing Security For Leverage and Scale' on June 30th🤙 ⛵ Waikīkī Marriott Resort 🏝️ O'ahu, Hawai'i ☀️ June 27-30th 🌟 @coffeetocode
1
2
16