Joined September 2007
8 Photos and videos
May 28
The wins of infosec as a field are under discussed, what else goes on this list? libber.org/society_level_inf…

1
34
Apr 27
Golden opportunity to convert this vulnpocalypse hype into properly funding vuln mgmt (the least exciting, often most lacking part of a security program) This is our chance as an industry!
3
1
7
971
9 May 2025
An excellent writeup of what makes data "sensitive" and what that means for security and privacy strategicsec.substack.com/p/…

141
19 Mar 2025
The differences between performing privacy and security work in a big company for my fellow computer security people. collingreene.com/security_an… I'm still newer to privacy work so this is my "most likely to be wrong" writeup, feedback welcome

5
314
18 Dec 2024
Compliance is different from security: collingreene.com/compliance.…

1
1
12
1,006
2 Sep 2022
Thoughts on how to maximize success as an infosec team that needs to roll out changes people may not like - collingreene.com/communicati…

3
22
1 Sep 2022
Shift left in 60 seconds - libber.org/shift_left_in_60_… I've had success with shift left as a central strategy of infosec teams for the last n years and attempted a tl;dr of it without marketing fluff

1
11
20 Jul 2022
1/ We just published our first Bug Bulletin, the spot where we aim to share cool bugs we found in our own and external code, and how we found them engineering.fb.com/2022/07/2… 🧵
4
79
325
20 Jul 2022
2/Our first report includes cool bugs found by our Red Team X, Bug Bounty team and ProdSec. I’m excited to see our teams’ work out there and shared with the security community. I am also happy to see cool work by our #BugBounty researchers shared cc @samm0uda @phwd_
2
16
20 Jul 2022
3/ Our goal with these is to celebrate bug hunting and share our lessons with the larger security community. This is our 1st Bug Bulletin and we welcome feedback on how we can make if more useful and informative
1
13
22 Nov 2021
Infosec celebrated at a college football game, a first? @nudehaberdasher where is the cruise pitt collab? :)
So the coolest thing happened today. @UofMaryland invited my students Kevin Bock, Kyle Hurley, and me onto the field for winning the @USENIXSecurity / Facebook Internet Defense Prize!
1
2
14
5 Oct 2021
Outages won't stop facebook awarding money to good security work, here are this years 3 winners of the internet defense prize: usenix.org/blog/facebook-and…

3
20
collin retweeted
I'll be presenting "Teaching an old dog new tricks: Reusing security tools in novel domains" at #Enigma2022 in Santa Clara, February 1–3, 2022. It provides case studies of how security tools like Pysa have been used in non-security applications at Facebook bit.ly/enigma2022
1
1
7
29 Sep 2021
Open sourcing our 3rd and most recent homegrown static analysis, this time for mobile/java: engineering.fb.com/2021/09/2…

12
42
9 Jul 2021
Two folks on the Facebook product security team are presenting on our language-spanning security static analysis work. blackhat.com/us-21/briefings… We are always hiring, SEA, MPK, NYC, LON: facebook.com/careers/v2/jobs…

2
19
24 Apr 2021
Be well @dakami, RIP One of the purest humans I've ever met. You embodied the best of [hacking, curiosity, fellowship]. The vista pentest summer was one of the best of my life. Even as you mercilessly crushed us at streetfighter2 literally one-handed x.com/dakami/status/12140132…

6 Jan 2020
Replying to @dakami
This thread is absolutely a love letter to everything I’ve treasured, being an Infosec nerd. A *lot* of people were kinder than they had to be. I’m proud to say I did everything I knew to return the favor, and not ashamed to admit I didn’t always know how. But I can document :)
2
26
collin retweeted
For those attending @pycon (it's too late to sign up!), check out the out the talk @the_st0rm and I are giving on the myriad of APIs that can enable remote code execution in Python: us.pycon.org/2021/schedule/p… These examples were originally compiled as a part of our work on Pysa.

1
7
16
19 Nov 2020
wired.com/story/facebook-mes… A decade of facebook bug bounty. 130,000 reports, 6,900 valid, 11.7million paid out. An incredible team of folks lead this program now - it started in a basement and with us taking weekly trips to western union to send money orders to fulfill bounties.
7
42
9 Oct 2020
Two improvements to the Facebook bug bounty: HackerPlus our loyalty program (facebook.com/BugBounty/posts…) and Facebook Bug Description Language (FBDL, facebook.com/BugBounty/posts…) a way to represent the repro of a bug for ease of understanding and increased payouts.

24
99