Alex Rice
@senorarroz
Followers
5K
Following
2K
Media
57
Statuses
1K
founder & cto, @hacker0x01 | #blacklivesmatter
San Francisco, CA
Joined August 2013
Some people will remember Steve Jobs as the visionary designer of the iPhone. I will always remember him as this f**king guy
40
85
1K
Rest In Peace, SecDef Ash Carter.😢 Your inspiring belief in the power of diversity created opportunity for women, all genders, and a few hackers, too. Your impact will be missed but not forgotten. https://t.co/ZZOb9ctS2B
#hackthepentagon
0
1
5
Bill Gates' Trustworthy Computing Memo publication is closer to the first release of MS DOS than it is to today. ⏳
1
6
16
😢 Why do security products fail? By @Datadog CISO @eaescob - They introduce toil - Poor UX - For security, by security - Lack of measurable effectiveness Consider: - Time to decision - Think of all customer personas - Use what’s already there https://t.co/sbU1eUh6Mp
1
6
25
Most companies are not Uber this morning as a matter of luck, not skill. This could easily have been ~90% of organizations. Don’t point and laugh. It could be you next time, and it might be already.
42
313
2K
Louder, for the folks in the back 📣 "Slowing down software delivery does not help security, it hurts it"
My latest essay is a rebuttal to the recent guide published by CISA, ODNI, & NSA on "Securing the Software Supply Chain." I present my 10 main objections to its recommendations, which I believe would result only in securing the supply chain of nothing:
0
1
6
cyber security isn't important... and that's OK. This isn't a bleak rant... more a sharing of something I've known for a while... and am now accepting. If you want your assumptions of cyber security challenged, please read on! 🧵 1
57
84
442
GitLab disclosed a bug submitted by @wcbowling: https://t.co/K0Ma0VI3QB - Bounty: $33,510 #hackerone #bugbounty
3
66
340
This Sunday marks 30 years since the release of the greatest hacker movie of all time: Sneakers. I've been saving stuff I've seen about Sneakers on Twitter for literally months; a quick thread about why this movie is so timeless and links to sources for more reading.
16
164
739
🚀 To keep ahead of cybercriminals, we work with the ethical hacker community through our Bug Bounty Program & events to assist with catching bugs & identifying issues before the bad guys do—an industry best practice. Read how @Hacker0x01’s #h1702 went: https://t.co/nSWus9YTDd
2
10
78
Nobody in infosec is surprised that Twitter had unpatched servers, lax access controls, an immature SDLC, poor backups, and all of the other security debt that you'll find in most large enterprises. BUT...
13
107
957
A woman in Louisiana is being forced to carry a fetus without a skull to term. It will be dead on delivery. Because abortion is banned, she’s being forced to carry a corpse for 6 more months. Roe v Wade kept us from stories like these every day.
386
11K
53K
So… I just finished my 1st @Hacker0x01 Live Hacking event & I’m heading into another with @Bugcrowd As a program owner, hacker, & security leader… I have thoughts! Read along for some spicy bounty takes. 🚨 Like, follow, & retweet for more security content 🚨 a 🧵 1/x
5
61
431
The 2022 #H1Elite announcement is here! Every year at HackerOne, we celebrate the hacker community’s hard work by selecting 5 hackers and awarding them with the HackerOne Elite title and a special comic. Check them out below!👇🧵
1
5
86
Ever had a source code review audit as part of, or in tandem with, a web app pentest? I’d love meet up and ask a couple of questions (~15min).
1
2
6
Open, community collaboration is in our DNA. We believe Open Security is the best way to keep systems secure — allowing for further understanding of how to protect systems from cyberattacks for all who need it. Learn more here:
elastic.co
It’s time for a new paradigm in the world of cybersecurity. Rather than closed systems that show no signs of abating the ever-increasing cycle of vulnerability, intrusion, patch, and repeat, we...
1
34
128
I was finally able to disclose one of the examples from my last blog post https://t.co/pODPvDUOU9 Here's the PoC-movie from the report to Reddit:
Reddit disclosed a bug submitted by fransrosen: https://t.co/K1f1kRd7WU - Bounty: $10,000 #hackerone #bugbounty
11
105
422
I'm not sure people understand the reason having a functional, capable, independent, dedicated cybersecurity incident investigation body could be of great benefit. To put it one way... The neverending stream of cybersecurity breaches is, in a sense, caused by lies.
18
49
232