Ronnie Flathers Profile
Ronnie Flathers

@ropnop

Followers
6K
Following
4K
Media
176
Statuses
2K

security engr, pentester, researcher. i sometimes blog and code based on motivation/caffeine levels. Principal Security Engineer @Marqeta

Chicago
Joined October 2013
Don't wanna be here? Send us removal request.
@JerrinJacob26
Jerrin Jacob
3 years
Huge shoutout to @ropnop on this article https://t.co/0P0vaY5QYd of SOP, CORS and CSRF. I don't know how many times I have referred to this blog to make sure I understand these concepts properly. Looking forward to more of these.šŸ™Œ
Tweet card summary image
blog.ropnop.com
1
3
12
@clintgibler
Clint Gibler
3 years
🚧 AWS Perimeter Mod for @steampipeio An AWS perimeter checking tool that can be used to look for resources that are: * Publicly accessible * Shared with untrusted accounts * Have insecure network configurations + more https://t.co/pzcdtxU0YN
Tweet card summary image
github.com
Is your AWS perimeter secure? Use Powerpipe and Steampipe to check your AWS accounts for public resources, resources shared with untrusted accounts, insecure network configurations and more. - tur...
0
17
34
@ropnop
Ronnie Flathers
3 years
100% best group of attendees and conversations I’ve ever had at a con. So many great people it was awesome meeting you all!
1
0
4
@ropnop
Ronnie Flathers
3 years
Yes great talk!! Tons to unpack and think about how to ā€œproductiveā€ security more
@manicode
Jim Manico from Manicode Security
3 years
Brilliant talk from @coffeetocode on bonding security to developer productivity.
0
1
2
@manicode
Jim Manico from Manicode Security
3 years
Brilliant talk from @coffeetocode on bonding security to developer productivity.
1
6
20
@manicode
Jim Manico from Manicode Security
3 years
When it literally rains on your parade at @LocoMocoSec with @ropnop @SammyHep @ndm @h4ck3rky13 and @coffeetocode #stillHavingFun
0
4
15
@ropnop
Ronnie Flathers
3 years
Aloha @LocoMocoSec šŸ˜Ž so excited to be here - have wanted to attend this con for a long time! Really looking forward to learning a lot, talking prodsec and meeting new friends. Anyone else gonna be here? And can’t wait to catch up @coffeetocode been too long!
0
1
8
@ropnop
Ronnie Flathers
4 years
So this is a bad/crazy idea right? Maybe? I hacked together a valid OpenPGP entity that uses AWS KMS backed signing and encryption keys. Idea was to use PGP without actually needing to handle key data or mess with gpgagent/pkcs11
0
0
3
@amirootyet
Pranshu Bajpai
4 years
@KringleCon @edskoudis ready when you are :)
0
5
8
@projectsigstore
sigstore
4 years
šŸ„³šŸŽ‰ We are happy to announce that sigstore is now an @theopenssf project! šŸŽ‰šŸ„³
3
40
153
@ropnop
Ronnie Flathers
4 years
What's the current take on format preserving encryption (FPE)? I'm not super familiar with it, but the more I research it seems like it's probably not the best idea unless you *really really* have to?
2
0
0
@ropnop
Ronnie Flathers
4 years
Oh this neat! Seems like this will also lead to better experience developing in a multi-module monorepo with needing something like Bazel
0
0
1
@ropnop
Ronnie Flathers
4 years
Welp that wasn't too hard. Minisign's spec is pretty easy to implement. Can now minisign things with ed25519 keys stored in Vault (and eventually other kms's). Might opensource it if i can clean it up and generalize
@ropnop
Ronnie Flathers
4 years
Before I go coding something new, has anyone used @hashicorp Vaults transit engine with ed25519 keys to output minisign compatible signatures? Seems like a great plug-in or feature to have, but I’m pretty sure it wouldn’t be too difficult to wrap the vault api if I have too…
0
0
1
@byt3bl33d3r
Marcello
4 years
Let's try something different. The Infosec Industry is a hammer. https://t.co/qF3kl365nO
12
24
58
@ropnop
Ronnie Flathers
4 years
Before I go coding something new, has anyone used @hashicorp Vaults transit engine with ed25519 keys to output minisign compatible signatures? Seems like a great plug-in or feature to have, but I’m pretty sure it wouldn’t be too difficult to wrap the vault api if I have too…
0
1
2
@ropnop
Ronnie Flathers
4 years
Is there a term for something like ā€œsecurity through obscurityā€ but for just ā€œredundant securityā€, or controls that look good at first glance but ultimately don’t solve anything? E.g. hashing passwords client side in a web app before sending over HTTPS to a server
14
1
4
@dinodaizovi
Dino A. Dai Zovi
4 years
It's great to see GCP include code examples for app-layer, client-side encryption for data stored in MySQL, including how to use the AAD in AEAD to prevent malicious replacement of ciphertexts: https://t.co/GeZPr0fBXN
Tweet card summary image
docs.cloud.google.com
1
12
48
@ropnop
Ronnie Flathers
4 years
My company is hiring for several security roles (appsec, privacy, cloudsec) if you’re looking for a change! Awesome team and culture, and remote friendly. Come help me solve some really cool and interesting problems! Lmk if you wanna chat DMs open
Tweet card summary image
marqeta.com
Join Marqeta and empower innovation in fintech! Enjoy flexible work, top benefits, and a diverse, award-winning culture. Explore our career opportunities!
1
1
6
@dinodaizovi
Dino A. Dai Zovi
4 years
This type of cross-tenant attack against Azure's Cosmos DB is a great example of why you should want client-side, app-layer encryption in your services so that your datastores primarily store ciphertext of any sensitive data: https://t.co/QEEJDmc2dC
Tweet card summary image
wiz.io
As part of building a market-leading CNAPP, Wiz Research is constantly looking for new attack surfaces in the cloud. Two weeks ago we discovered an unprecedented breach that affects Azure’s flagship...
6
32
85