
John Saigle
@johnsaigle
Followers
271
Following
771
Media
7
Statuses
226
asymmetric research, prev halborn, FKA sudo
Joined June 2017
dang dude I'm gonna be out of a job real quick. I wish it had occurred to me to advise people to implement authentication.
We’re using this ourselves at @AnthropicAI. It's already caught real vulnerabilities, including a potential remote code execution vulnerability in an internal tool. With the GitHub action, we were able to fix it before it made it to production.
1
0
3
RT @lonelysloth_sec: @Ehsan1579 I usually take the opposite approach. Whenever I audit a codebase I can give a 100% guarantee that I’ll mis….
0
3
0
Bug bounty programs won't survive if they continue to be DDoS'd by LLM slop. It stops being worth the effort to triage. If you make money from bounties, or believe they're good for security, then you should refrain from and discourage slop submissions.
daniel.haxx.se
I have previously blogged about the relatively new trend of AI slop in vulnerability reports submitted to curl and how it hurts and exhausts us. This trend does not seem to slow down. On the contra...
0
0
1
RT @zack_overflow: Prior to coding agents, I used to think bike-shedding like this about code/file structure and naming was a massive waste….
0
4
0
RT @osec_io: NEW: Building on Cosmos?. We uncovered hidden bugs commonly overseen by developers, backed by real-world examples. Our latest….
osec.io
From infinite loops and map determinism to AnteHandler missteps and storage key collisions, we highlight real-world vulnerabilities and actionable advice for building safer Cosmos-based projects.
0
15
0
👀👀👀 .Alternate title: retroactively justifying all of my Informational findings.
Boredom > Beauty: Why Code Quality Is Code Security by @johnsaigle. Some of the most devastating vulnerabilities stem from complexity, inconsistency, and chaos. This post explains why predictable, well-formed code is the foundation of security.
1
1
6
RT @Montyly: Might be a hot take but “More audits, contests, or bigger bounties” is not always the best advice. What protocols often need t….
0
6
0
"gibberish".
A modern URL bar (in @diabrowser):. • Page Title not "/2025/12/seo-spam" gibberish .• Space on both sides of "/" for readability .• Hover to reveal & edit URL.• Emphasize domain for trust+security . Dia isn't just AI. It's refined browser basics too, @browsercompany style.
0
0
0