CipherStash founder, cryptography nerd, Rust zealot.

Joined May 2008
540 Photos and videos
I pointed Claude Fable at a major update of one of our crypto libs over night. It more than quadrupled encrypt performance and found an obscure encrypt-side timing security flaw that exists in our scheme as well as all of the current published ORE schemes in the literature. Mind blown. ...and now Fable has been disabled.
1
5
416
I love this! Great move from the @prisma team
Jun 10
Agents changed how fast we can build software But shipping still feels slower than it should, because your app, database, deploys, logs, and previews all live in different places Prisma Compute is our next step toward bringing that whole loop together
2
11
2,100
Most Postgres hardening guides are checklists in no particular order. Attackers don't probe in no particular order. Here's how to secure a Postgres database in the sequence an attacker would actually work through it 🧵
1
2
182
The fix: encrypt in the application, so Postgres never holds plaintext or key material. The catch was always search. WHERE email = ? dies on random ciphertext. Encrypted indexes solve it: the planner uses them like any other index. A pg_dump shows ciphertext. Nothing else.
1
2
30
Doors five and six: backups (a complete copy of your database with none of its access controls) and unapplied patches (a door you know is open, and so does everyone else). Work through the doors in order. The attacker will. Runnable commands for all six: dev.to/cipherstash/securing-…
19
I've been a big Prisma fan for years. Prisma Next looks like a genuine step up. And to have @cipherstash directly integrated is *Next* level.
May 21
CipherStash Prisma Next integration just shipped 🚀 Add cipherstash.EncryptedString() to your contract for searchable encryption. Encrypted data stays queryable, your rules live in the contract & plaintext only appears when you explicitly decrypt it. pris.ly/cipherstash-p-blog
1
4
167
Dan Draper retweeted
In the long run I think software gets more secure out of necessity, but the in between is a scary time period where everyone is just CONSTANTLY getting hacked
13
8
245
16,262
Dan Draper retweeted
I tried to make sense of the backdoor mechanism this time and summarized it in a one-page overview. 😵‍💫 There's obviously more technical detail to uncover, but you'll get a general understanding of the complexity and the stealthy mechanisms used to remain undetected. 🧐 Thanks to @AndresFreundTec for his insight into this and a shoutout to these researchers if you want to learn more about the backdoor 🙏👇 - gist.github.com/smx-smx/a611… by SMX - bsky.app/profile/filippo.aby… by @FiloSottile - github.com/amlweems/xzbot by @amlweems - github.com/karcherm/xz-malwa… by Karchem - research.swtch.com/xz-script by Russ Cox - github.com/0xlane/xz-cve-202… by 0xlane And of course, all the others previously mentioned and those who contributed to the analysis. #xz #infosec
8
63
210
11,497
Dan Draper retweeted
28 Aug 2023
In the wake of FTX, SVB, Medibank and Optus data hacks, how do we move forward? Join @RaajRayat (Investment Manager, AirTree) as he discusses best practice for treasury management and cyber security with a panel of experts from the AirTree family 🌳 🎟️: intersektfestival.com/regist…
1
6
1,018
Trying to do some tricky stuff in SQL server so I asked ChatGPT. It recommended that I use PostgreSQL. Can't say I disagree!
1
3
360
Dan Draper retweeted
Apparently I'm moving back to Sydney (finally). And officially house hunting Since this has worked insanely well before, Twitter friends, if you know of anyone looking for a roomie please let your girl know!
6
4
25
3,916
Ugh. Sick. Whyyyyyyy
255
Dan Draper retweeted
This is weird to say out loud, but I actually am kinda an expert in rate limiting, so I'm gonna explain some stuff. About half of incidents in large-scale production systems involve having more requests than you can serve. There are two categories of this kind of incident:
142
1,849
9,197
2,565,789
9x out of 10, CopilotX is bang-on! The other time I'm like wuuuut. So basically the same as the typical engineer 🤣
2
309