Ronnie Flathers Profile
Ronnie Flathers

@ropnop

Followers
6K
Following
4K
Media
176
Statuses
2K

security engr, pentester, researcher. i sometimes blog and code based on motivation/caffeine levels. Principal Security Engineer @Marqeta

Chicago
Joined October 2013
Don't wanna be here? Send us removal request.
@ropnop
Ronnie Flathers
3 years
RT @JerrinJacob26: Huge shoutout to @ropnop on this article of SOP, CORS and CSRF. I don't know how many times I ha….
Tweet card summary image
blog.ropnop.com
0
3
0
@grok
Grok
3 days
Join millions who have switched to Grok.
178
199
2K
@ropnop
Ronnie Flathers
3 years
100% best group of attendees and conversations I’ve ever had at a con. So many great people it was awesome meeting you all!.
1
0
4
@ropnop
Ronnie Flathers
3 years
Yes great talk!! Tons to unpack and think about how to “productive” security more.
@manicode
Jim Manico from Manicode Security
3 years
Brilliant talk from @coffeetocode on bonding security to developer productivity.
Tweet media one
0
1
2
@ropnop
Ronnie Flathers
3 years
RT @manicode: Brilliant talk from @coffeetocode on bonding security to developer productivity.
Tweet media one
0
6
0
@ropnop
Ronnie Flathers
3 years
RT @manicode: When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHaving….
0
4
0
@ropnop
Ronnie Flathers
3 years
Aloha @LocoMocoSec 😎 so excited to be here - have wanted to attend this con for a long time! Really looking forward to learning a lot, talking prodsec and meeting new friends. Anyone else gonna be here? And can’t wait to catch up @coffeetocode been too long!
Tweet media one
0
1
8
@ropnop
Ronnie Flathers
3 years
So this is a bad/crazy idea right? Maybe? I hacked together a valid OpenPGP entity that uses AWS KMS backed signing and encryption keys. Idea was to use PGP without actually needing to handle key data or mess with gpgagent/pkcs11
Tweet media one
Tweet media two
0
0
3
@ropnop
Ronnie Flathers
4 years
RT @amirootyet: @KringleCon @edskoudis ready when you are :)
Tweet media one
0
5
0
@ropnop
Ronnie Flathers
4 years
RT @projectsigstore: 🥳🎉 We are happy to announce that sigstore is now an @theopenssf project! 🎉🥳.
0
40
0
@ropnop
Ronnie Flathers
4 years
What's the current take on format preserving encryption (FPE)? I'm not super familiar with it, but the more I research it seems like it's probably not the best idea unless you *really really* have to?.
2
0
0
@ropnop
Ronnie Flathers
4 years
Oh this neat! Seems like this will also lead to better experience developing in a multi-module monorepo with needing something like Bazel.
0
0
1
@ropnop
Ronnie Flathers
4 years
Welp that wasn't too hard. Minisign's spec is pretty easy to implement. Can now minisign things with ed25519 keys stored in Vault (and eventually other kms's). Might opensource it if i can clean it up and generalize
Tweet media one
@ropnop
Ronnie Flathers
4 years
Before I go coding something new, has anyone used @hashicorp Vaults transit engine with ed25519 keys to output minisign compatible signatures? Seems like a great plug-in or feature to have, but I’m pretty sure it wouldn’t be too difficult to wrap the vault api if I have too….
0
0
1
@ropnop
Ronnie Flathers
4 years
RT @byt3bl33d3r: Let's try something different. The Infosec Industry is a hammer.
0
24
0
@ropnop
Ronnie Flathers
4 years
Before I go coding something new, has anyone used @hashicorp Vaults transit engine with ed25519 keys to output minisign compatible signatures? Seems like a great plug-in or feature to have, but I’m pretty sure it wouldn’t be too difficult to wrap the vault api if I have too….
0
1
2
@ropnop
Ronnie Flathers
4 years
Is there a term for something like “security through obscurity” but for just “redundant security”, or controls that look good at first glance but ultimately don’t solve anything? E.g. hashing passwords client side in a web app before sending over HTTPS to a server.
14
1
4
@ropnop
Ronnie Flathers
4 years
RT @dinodaizovi: It's great to see GCP include code examples for app-layer, client-side encryption for data stored in MySQL, including how….
Tweet card summary image
cloud.google.com
0
12
0
@ropnop
Ronnie Flathers
4 years
My company is hiring for several security roles (appsec, privacy, cloudsec) if you’re looking for a change! Awesome team and culture, and remote friendly. Come help me solve some really cool and interesting problems! Lmk if you wanna chat DMs open
Tweet card summary image
marqeta.com
Join Marqeta and empower innovation in fintech! Enjoy flexible work, top benefits, and a diverse, award-winning culture. Explore our career opportunities!
1
1
6
@ropnop
Ronnie Flathers
4 years
RT @dinodaizovi: This type of cross-tenant attack against Azure's Cosmos DB is a great example of why you should want client-side, app-laye….
Tweet card summary image
wiz.io
As part of building a market-leading CNAPP, Wiz Research is constantly looking for new attack surfaces in the cloud. Two weeks ago we discovered an unprecedented breach that affects Azure’s flagship...
0
32
0