John Saigle Profile
John Saigle

@johnsaigle

Followers
271
Following
771
Media
7
Statuses
226

asymmetric research, prev halborn, FKA sudo

Joined June 2017
Don't wanna be here? Send us removal request.
@johnsaigle
John Saigle
2 days
dang dude I'm gonna be out of a job real quick. I wish it had occurred to me to advise people to implement authentication.
@claudeai
Claude
2 days
We’re using this ourselves at @AnthropicAI. It's already caught real vulnerabilities, including a potential remote code execution vulnerability in an internal tool. With the GitHub action, we were able to fix it before it made it to production.
Tweet media one
1
0
3
@johnsaigle
John Saigle
3 days
RT @vxunderground: those mfers did WHAT?
Tweet media one
0
144
0
@johnsaigle
John Saigle
3 days
if you actually cared about command injection you'd just patch it yourself.
0
0
0
@johnsaigle
John Saigle
3 days
Tweet media one
0
0
1
@johnsaigle
John Saigle
4 days
Just taking the opportunity to repost this classic
Tweet media one
@Cloudflare
Cloudflare
4 days
Perplexity is repeatedly modifying their user agent and changing IPs and ASNs to hide their crawling activity, in direct conflict with explicit no-crawl preferences expressed by websites.
0
9
55
@johnsaigle
John Saigle
25 days
RT @lonelysloth_sec: @Ehsan1579 I usually take the opposite approach. Whenever I audit a codebase I can give a 100% guarantee that I’ll mis….
0
3
0
@johnsaigle
John Saigle
25 days
Friendly reminder to devs to create a SECURITY[.]md file.
0
0
3
@johnsaigle
John Saigle
25 days
Bug bounty programs won't survive if they continue to be DDoS'd by LLM slop. It stops being worth the effort to triage. If you make money from bounties, or believe they're good for security, then you should refrain from and discourage slop submissions.
Tweet card summary image
daniel.haxx.se
I have previously blogged about the relatively new trend of AI slop in vulnerability reports submitted to curl and how it hurts and exhausts us. This trend does not seem to slow down. On the contra...
0
0
1
@johnsaigle
John Saigle
2 months
RT @zack_overflow: Prior to coding agents, I used to think bike-shedding like this about code/file structure and naming was a massive waste….
0
4
0
@johnsaigle
John Saigle
2 months
RT @osec_io: NEW: Building on Cosmos?. We uncovered hidden bugs commonly overseen by developers, backed by real-world examples. Our latest….
Tweet card summary image
osec.io
From infinite loops and map determinism to AnteHandler missteps and storage key collisions, we highlight real-world vulnerabilities and actionable advice for building safer Cosmos-based projects.
0
15
0
@johnsaigle
John Saigle
2 months
My guess is that it's a misapplication of the EVM security model to Solana:.- the bug classes aren't one-to-one.- Anchor's internals change a ton.- Solidity is a silly language that's easy to learn by pattern matching, but Rust demands a lot more understanding to get right.
0
0
6
@johnsaigle
John Saigle
2 months
PSA: Pretty much every "Solana/Anchor top vulnerabilities" checklist I've seen has numerous entries that are wrong. Either the remediations are wrong or entire bug classes are made up (perhaps hallucinated?).
5
1
23
@johnsaigle
John Saigle
2 months
👀👀👀 .Alternate title: retroactively justifying all of my Informational findings.
@asymmetric_re
asymmetric research
2 months
Boredom > Beauty: Why Code Quality Is Code Security by @johnsaigle. Some of the most devastating vulnerabilities stem from complexity, inconsistency, and chaos. This post explains why predictable, well-formed code is the foundation of security.
1
1
6
@johnsaigle
John Saigle
2 months
👀👀
Tweet media one
0
0
2
@johnsaigle
John Saigle
2 months
👀
Tweet media one
0
0
2
@johnsaigle
John Saigle
2 months
RT @Montyly: Might be a hot take but “More audits, contests, or bigger bounties” is not always the best advice. What protocols often need t….
0
6
0
@johnsaigle
John Saigle
3 months
"gibberish".
@joshm
Josh Miller
3 months
A modern URL bar (in @diabrowser):. • Page Title not "/2025/12/seo-spam" gibberish .• Space on both sides of "/" for readability .• Hover to reveal & edit URL.• Emphasize domain for trust+security . Dia isn't just AI. It's refined browser basics too, @browsercompany style.
0
0
0
@johnsaigle
John Saigle
3 months
I feel the opposite way for the most part. I really wish that Go actually was "boring" but instead there are a million hidden ways for your code panic at runtime.
@zack_overflow
zack (in SF)
3 months
The creators of the Go programming language had awful taste but great execution.
0
0
3
@johnsaigle
John Saigle
3 months
RT @_FelixsIntern: GitHub is my TikTok.
0
1
0