Native Angeleno. Native American. Human. AR/VR/Smart-Devices Security & Privacy @ Reality Labs

Joined October 2014
535 Photos and videos
Pinned Tweet
Invest in product security, not security products.
2
34
69
Replying to @head_tennis
@head_tennis can you please just make the Gravity Pro in a 16x19 pattern? Been 5 years and 3 gravity models where I can’t even customize the gravity mp or pro to what I need. My old graphene speed MP is just a 13 year old version of the gravity pro mold in 16x19 string pattern
1
178
You’ve made this in pro stock, but I can’t find any. I’ve tried the gravity pro in 18x20 and weight/balance modified the gravity mp but the thicker beam and 16x20 don’t work. New gravity tour is close but I need 100 sq in head, not 98
213
Looking forward to meeting some fellow Infosec leaders over the next couple days while GDC is going on in San Francisco. If you're there and would like to meet, let me know!
181
thenak@threads.net retweeted
12 Sep 2023
Time for an Arm-twist! CVE-2023-4039 Tom Hebb (Meta red team) and I discovered an 0day in GCC (for AArch64 targets) during my Arm exploitation training. It renders stack canaries against overflows of dynamically-sized variables useless. github.com/metaredteam/exter…
11
158
634
143,629
thenak@threads.net retweeted
21 Mar 2023
It is with profound sadness that we mourn the loss of our friend and mentor, @aloria. Kelly had an indomitable spirit, and our world is a bit darker without her.
260
255
981
536,755
thenak@threads.net retweeted
25 Jan 2023
These fish committed credit card fraud while playing Pokémon. 💳🐟🐟🐟🐟
205
8,737
37,546
4,227,160
thenak@threads.net retweeted
27 Jan 2023
Wow, holy shit this is far away from anything else I’ve seen. Insane. Google basically solved AI music: google-research.github.io/se…

120
556
3,366
999,704
thenak@threads.net retweeted
27 Jan 2023
#enigma2023 is a wrap! Awesome seeing everyone, thanks for the opportunity to talk about hard problems in hardware privacy and to all the amazing speakers for sharing your ideas. Thanks @enigmaconf for hosting a top notch event ❤️. usenix.org/conference/enigma…

2
1
402
thenak@threads.net retweeted
7
41
158
23,135
Sad to have had to miss this (my favorite con) at the last minute... But there are awesome people you should meet in my place if you're around. Say hi to @sirus or @rootfoo (presenting Thursday) if you're around! #enigma2023
A snapshot from our opening session at #enigma2023: The Emperor's New Clothes: Location Data and the Promise of Anonymization.
2
4
585
thenak@threads.net retweeted
5 Jan 2023
CircleCI Security Alert [4 Jan. 2023] We strongly recommend all CircleCI customers rotate secrets stored on our system. Read more: circleci.com/blog/january-4-…
16
551
577
407,508
thenak@threads.net retweeted
I resigned from Meta, and my internal post got leaked to the press, resulting in some fragmented quotes. Here is the full thing: facebook.com/permalink.php?s…
577
2,601
21,808
7,777,510
Hmm, interesting
2
155
Even my backup plan for Mastodon is blocked??
2
8
409
thenak@threads.net retweeted
15 Dec 2022
We also just published new payout guidelines for different bug categories, ranging as high as $300K, making our program one of the highest-paying in the industry. about.fb.com/news/2022/12/me… (6/6)
2
2
12
thenak@threads.net retweeted
14 Dec 2022
Scoop: InfraGard, a program run by the U.S. Federal Bureau of Investigation (FBI) to build cyber/physical threat info sharing partnerships w/ the private sector, this week saw its database of contact information on more than 80,000 members go up for sale. krebsonsecurity.com/2022/12/…
37
382
708
thenak@threads.net retweeted
LinkedIn really flies under the radar as the social media platform that’s absolutely the most unhinged
2,144
21,300
226,580
thenak@threads.net retweeted
A buddy who's interested in end-to-end encryption (E2EE) but hasn't done one of these projects in the very messy place which is the real world happened to ask me this morning about pitfalls which might not be obvious. So here's a partial list in the hopes that it's helpful. 🧵
23
288
1,421
Mastodon would be easier to at least try out if there were a low friction option to import or even find folks I already follow on Twitter. Afaict, no such feature exists
2
1