caseyjohnellis·Feb 8For the Love of the Game: DistrictCon’s Year 1 JunkyardNotes from judging DistrictCon’s Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA…
caseyjohnellis·Mar 9, 2025The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851There’s a recurring theme in the world of security, whether physical or digital: the assumption of invulnerability. It’s a dangerous…
caseyjohnellis·May 8, 2021On Project Zero’s 90+30 vulnerability disclosure policy changesI was asked a few questions by Lindsay O’Donnell of the awesome Decipher Bureau regarding Google Project Zero’s changes to their default…
caseyjohnellis·Mar 28, 2021My “office” setuptl;dr: If you want the tech list, jump straight to the middle. The front is about how choices were made and what I was optimizing for, and…
caseyjohnellis·Mar 8, 2021NIST: Vulnerability Disclosure as a Requirement for Every OrganizationThe NIST Cybersecurity Framework is a set of policies meant to help the private sector in strengthening their cybersecurity readiness and…
caseyjohnellis·Oct 7, 2020NIST SP 800–53 R5 adds Vulnerability Disclosure Programs to Federal Security and Privacy Controls |…What are the changes?
caseyjohnellis·Sep 30, 2020Information Asymmetry and the 1950s Nuclear BountyThe idea of a bounty (or, more specifically, payment-for-success incentives designed to reduce information asymmetry) predate…