@roland.zone

go (the language) security team lead 🔥💻🔥

can someone just break ecc already so we can stop having this annoying fight on the ietf tls wg mailinglist

Bild

somewhat ironic that everyone is posting about how perelman is the only human to have solved a millennium prize problem when one of the main reasons he rejected the prize was because it ignored the work done by hamilton

i think all football shirts should be required, by law, to have a proper shirt collar. they just look better. thanks for coming to my ted talk

fifa collapsing the second it even looks in the direction of private equity is just... beautiful, a+ story writing, my compliments to the chef

excited to talk about the (mostly) boring vulns we have, with a slight digression about how LLMs have completely turned the way vulns are found upside down 🙃

GopherCon@gophercon.com · 3mo ago

If Go is memory-safe, where do its vulnerabilities come from? 🔒 Go Security Team Lead @roland.zone shares how the Go team identifies, responds to, and learns from vulnerabilities across the Go ecosystem. Discover what those lessons mean for building more secure Go software. 🎟️ gophercon.com

If Go is memory-safe, where do its vulnerabilities come from? 🔒 Go Security Team Lead @roland.zone shares how the Go team identifies, responds to, and learns from vulnerabilities across the Go ecosystem. Discover what those lessons mean for building more secure Go software. 🎟️ gophercon.com

Bild

i'm sorry, i have zero interesting in consuming a "companion podcast", i'd like to watch your slop tv show, derive my own opinions, and then immediately forget everything about it 30 minutes later

did something very silly, may have some at gophercon this year if you ever sent us a vulnerability report or contributed to Go crypto (or are just nice to me) thanks to @ljamesart.bsky.social who did the great art!

Bild

i have opinions about the ffmpeg security thing but i'm not going to post them, for my own sanity (but i am posting about not posting about it)

I recently passed my 5 year anniversary at Google on the Go team (thanks to them for reminding me), which also means it's been about 10 years since I first joined the Let's Encrypt team. It's been amazing to see the projects grow over those years, and I couldn't be prouder to have worked on them.