Dylan (@insecurenature) 's Twitter Profile
Dylan

@insecurenature

Security researcher, public speaker and founder.

Forbes 30 Under 30

Truffle Security @trufflesec

Github.com/dxa4481

Prev @Netflix

ID: 1282920360015327233

linkhttps://TruffleSecurity.com calendar_today14-07-2020 06:10:45

997 Tweet

3,3K Followers

230 Following

Truffle Security (@trufflesec) 's Twitter Profile Photo

We scanned 400TB of DeepSeek’s training data & found: 🚨 ~12K live API keys & passwords 🌐 2.76M affected pages 🔄 One key appeared 57K+ times 🔑 219 secret types (AWS root keys, Slack webhooks, etc.) 🔗 Full research: trufflesecurity.com/blog/research-…

We scanned 400TB of DeepSeek’s training data & found:

🚨 ~12K live API keys & passwords 
🌐 2.76M affected pages
🔄 One key appeared 57K+ times
🔑 219 secret types (AWS root keys, Slack webhooks, etc.)
🔗 Full research: trufflesecurity.com/blog/research-…
a16z (@a16z) 's Twitter Profile Photo

AI-generated code is scaling fast, but code security is often a function of how a model is trained. This can create hidden risks for companies, says @insecurenature Truffle Security Co-Founder and CEO. Alignment around security best practices can be a challenge, so instead of waiting

Truffle Security (@trufflesec) 's Twitter Profile Photo

🔥 You can now add TruffleHog to Burp Suite! 🌐 Install it directly from the BApp Store 🔍Scan web traffic for live, verified credentials—active & exploitable Because secrets don’t just leak in code… 😬 Big Thanks to PortSwigger ! 🙌 🔗trufflesecurity.com/blog/introduci…

🔥 You can now add TruffleHog to Burp Suite!

🌐 Install it directly from the BApp Store
 🔍Scan web traffic for live, verified credentials—active & exploitable

 Because secrets don’t just leak in code… 😬

Big Thanks to <a href="/PortSwigger/">PortSwigger</a> ! 🙌

🔗trufflesecurity.com/blog/introduci…
Dylan (@insecurenature) 's Twitter Profile Photo

A couple of years ago I co-presented with Whitney Merrill how sensitive bug bounty hunter accounts can be, especially active hunters with years of file attachments and POC data. Today bugcrowd is mandating 2fa on all accounts: bugcrowd.com/blog/bugcrowd-… Definitely a positive change.

Dylan (@insecurenature) 's Twitter Profile Photo

Tomorrow I'll be speaking at BSidesSF at 11:15am. The topic? Aligning light weight AI models to become self replicating ransomware worms. Join me on the IMAX.

Dylan (@insecurenature) 's Twitter Profile Photo

I shared an Uber ride with Feross and I thought his new reachability analysis tool (Socket) was neat. So I pulled out my phone and asked him to repeat say it again on camera

Dylan (@insecurenature) 's Twitter Profile Photo

I asked Maya Kaczorowski (former Senior Director GitHub) about her thoughts about GitHub's identity system. Personally I think managing identity in GitHub is clear as mud.

Dylan (@insecurenature) 's Twitter Profile Photo

The fall of the empire did NOT depend on the rebellion. Obi-Wan used Luke to turn Vader against the Emperor. The death star didn't need to explode. Luke didn't need to meet the rebellion.

Dylan (@insecurenature) 's Twitter Profile Photo

This is WILD. When you opt out of ad tracking this website makes you check a box saying: "I acknowledge cookies need to be deleted from my browser to remove tracking." Ad tracker opt-out is a GDPR requirement. Forcing the user to delete their cookies is...

Truffle Security (@trufflesec) 's Twitter Profile Photo

🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub. 🔗A guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-pos…

🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub.

🔗A guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-pos…