Interested in web application security. Security Engineer at Facebook. My tweets do not reflect the opinions or views of my employer.

Neal Poole retweeted
Congratulations, Brown CS Class Of 2020! It gives us a lot of happiness to share the following celebrations of our 2020 graduates, including a special video from our faculty. We've never been prouder to be part of the @BrownCSDept community. cs.brown.edu/people/2020grad…
1
8
55
Neal Poole retweeted
At #realworldcrypto, @JonMillican just announced definitively that @Facebook will ship end-to-end encryption in Messenger. Bold. No timeline was provided, however.
2
15
43
Neal Poole retweeted
Writeup on how I made $40,000 breaking the new Chromium Edge using essentially two XSS flaws. leucosite.com/Edge-Chromium-…
25
447
1,108
Neal Poole retweeted
We are expanding the scope of our bug bounty program again, facebook.com/notes/facebook-… 3rd party apps, after user approval, have limited access to facebook user data. They must be responsible stewards of that data and this further encourages that.
3
12
52
Neal Poole retweeted
Several coworkers and I put up a proposal / demo on privacy preserving reporting on third parties using blind signatures github.com/siyengar/private-…. There are a surprising number of fun sub-problems to solve along the way. We'd love feedback @taubeneck @ajknox_ @bedfordsean.
1
9
18
Neal Poole retweeted
Zoncolan THE static analysis tool used to protect Facebook m-cacm.acm.org/magazines/201… The main project I've been working on for the last 3 years to enable engineers to move fast with secure code Tldr * Analysing ~100M LoC in ~30 mns * Detecting ~40% of FB severe > any other system
2
22
82
Neal Poole retweeted
This is cool. SDLC feedback loops at scale. "Bugs that Matter" (1) Stats on crashes and other errors that happen in production. (2) A "bug bounty" program, where people outside the company can report vulnerabilities (3) Internal tracking the most severe bugs (SEV) that occur.
Zoncolan THE static analysis tool used to protect Facebook m-cacm.acm.org/magazines/201… The main project I've been working on for the last 3 years to enable engineers to move fast with secure code Tldr * Analysing ~100M LoC in ~30 mns * Detecting ~40% of FB severe > any other system
1
2
7
Neal Poole retweeted
Startups keep asking us how to sign JSON objects and @lvh got sick of re-explaining and wrote this. latacora.micro.blog/2019/07/…
4
24
73
Neal Poole retweeted
Facebook's CTF starts tomorrow, bit.ly/2HPrxS9. You can sign up and play here: fbctf.com. There's monetary prizes for the top 3 teams, but if you place in the top 50 you'll receive some of the best swag I've ever created.
11
99
223
Neal Poole retweeted
We just announced Facebook CTF! Come play :) facebook.com/notes/facebook-…
1
34
72
Neal Poole retweeted
I'm very excited to announce that I will be joining @facebook as a security engineer soon. Shoutout to @Hacker0x01 for the real world security experience which no doubt helped me land the interviews. I look forward to being on the other side of screen evaluating incoming reports.
61
24
519
At first sight this sounds like a terrible idea, but in fact there's peer reviewed research on measuring the security-usability tradeoff in correcting password typos, and it turns out it makes a lot of sense to do this. cs.cornell.edu/~rahul/papers… Screenshot HT @amunchbach
13
153
385
Great new post about the work that we do on the security team at Facebook (yay @libber): newsroom.fb.com/news/2019/01…
2
23
61
Neal Poole retweeted
What annoys me most about the @nytimes #Facebook "Private Messages" story launched & everyone is copying, is that once cooler heads look into it, it will be seen as a storm in a teacup, newspapers will rage at regulators for contradicting them, & civil society will look stupid.
1
4
13
Replying to @MarriottBonvoy
@MarriottRewards I stayed at the JW Marriott Miami in October. Got an email last Fri. It said they couldn’t charge my card and I needed to email (a random email domain) or fax them my CC info. Talked to a rep who confirmed the options...
1
1
...So I sent the fax to the number provided. And now I’m told they gave me the wrong number and can’t get a straight answer about what happened to my data. Help?
6
Replying to @mattblaze
Vote for Pedro! Check out Pedro Canahuati (@mepedroc): nitter.net/mepedroc?s=09
1
10
Neal Poole retweeted
If you've been logged out of your account and asked to sign back in, it’s because we've discovered a security issue and are taking immediate action to protect people on Facebook. Learn more newsroom.fb.com/news/2018/09…
450
1,928
2,046
Neal Poole retweeted
Heads up regarding FB breach response. You may see some companies logging out users forcefully, similar to how Facebook responded. This does *not* indicate that other websites were breached. /1
1
15
22
Neal Poole retweeted
ironically, FB's "View As" feature is one designed to *help* people ensure content on their profile is private/secure. (it lets you see what content on your profile someone else can see and double-check it's not more than you intended!)
1
20
87