Heather Adkins
argv.bsky.social
Heather Adkins
@argv.bsky.social
3.6K followers 140 following 43 posts
VP Security at Google. Co-Chair Cybersafety Review Board, Co-Author Building Secure and Reliable Systems. r00t. Medieval historian.
Posts Media Videos Starter Packs
Stop what you’re doing and read this… don’t get surprised by what’s coming. It’s time to rethink everything you’re doing on cyber defense. H/T to Gadi and Bruce for partnering on this opinion piece. www.csoonline.com/article/4069...
Today as part of our commitment to transparency in this space, we are proud to announce that we have reported the first 20 vulnerabilities discovered using our AI-based "Big Sleep" system powered by Gemini — goo.gle/bigsleep
Google Issue Tracker
goo.gle
Today @Google Project Zero announced a new trial policy: Reporting Transparency. We’ll now share when we report a security vuln to a vendor within 1 week including products + deadlines. Goal: shrink the patch gap + drive faster, safer updates for users: googleprojectzero.blogspot.com/2025/07/repo...
Policy and Disclosure: 2025 Edition
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...
googleprojectzero.blogspot.com
Some excellent work by @craiggidney.bsky.social that reduces the number of qubits (in a quantum computer) required to break RSA by 20-fold. If you don’t have a migration plan to safe algorithms, now is the time to start one!
I'm often asked if I'll redo the 2019 quantum factoring estimate. Denser storage by yokes, smaller magic factories by cultivation, slimmer approx arithmetic by Chevignard et al… surely the cost is lower now?

Yes, it's lower now.

security.googleblog.com/2025/05/trac...

arxiv.org/abs/2505.15917
It is still worth it to get a credit card that earns miles. Then you can spend those miles on buying an upgraded fare.
It’s not worth it to play the airline status game anymore. There are too many high-status fliers and the airlines are now making it harder to get it. There are no guarantees beyond paying for a business/first class ticket.
There’s no better time for it… I feel like we are on the edge of another historical precipice where someone is hailing a new age of greatness whereby we will toss aside what we know now in favor of a perceived gleaming future. 🤮
Concur. I could see myself accidentally chatting with the wrong ppl from my contacts, getting them confused between one another. The usability is really poor.
How do you like the polestar?
We will have memory safety… it will take many steps forward, over the long haul. Here’s an update from Chrome on replacing FreeType with a Rust based alternative. developer.chrome.com/blog/memory-...
Memory safety for web fonts  |  Blog  |  Chrome for Developers
Learn how and why the Chrome team has replaced FreeType with Skrifa.
developer.chrome.com
I can’t believe it’s already been 5 years… wow.
Need to do the reciprocal benefits for Russia. They get all the rest too.
Everyday is a good day to patch.
So often, I see design docs and product pitches reference shoddy news articles, Wikipedia, etc and not apply the kind of scrutiny and skepticism Pat and Adam do. We need a solid repo of material. 2/2
While listening to @patrick.risky.biz and @metlstorm.risky.biz on this week’s risky biz podcast I dreamt up a nice retirement project: “Case Studies for Security Engineering”. Highly curated technical descriptions of incidents written in such a way that solutioneers can understand attacks. 1/2
Always easier to be objective (and less stressful) if it was someone else’s incident :-)
Ever wake up in the morning and think to yourself: wish I could do an official review of that incident. 👀
Exceptionally good analysis of the current geopolitical discussion re: Ukraine and Russia negotiations. x.com/nicholadrumm...
x.com
x.com
It's #WorldPasswordDay!! At @Google we're celebrating the journey on deprecating passwords! We're happy to report passkeys have been used 1B+ times across 400M Google Accounts. We're also sharing how we'll use them to protect high risk users: blog.google/technology/s...
Passkeys, Cross-Account Protection and new ways we’re protecting your accounts
For World Password Day, we’re sharing updates to passkeys across our products and sharing more ways we’re keeping people safe online.
blog.google