惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园_首页
小众软件
小众软件
美团技术团队
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
U
Unit 42
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗

Meta Tech Podcast

Meta Tech Podcast: BONUS: Send Us Your Questions About Engineering at Meta Meta Tech Podcast: 87: Everything is Power: Battery Life Engineering for AI Glasses Meta Tech Podcast: 86: A Hard Cell: Engineering Ultra-Narrow Batteries for AI Glasses Meta Tech Podcast: 85: Reel Friends: Building Social Discovery that Scales to Billions Meta Tech Podcast: 84: Trust But Canary: Configuration Safety at Scale Meta Tech Podcast: 83: Patch Me If You Can: AI Codemods for Secure-by-Default Android Apps Meta Tech Podcast: 82: CSS at Scale with StyleX Meta Tech Podcast: 81: From Zero to Polish: Building Meta Ray-Ban Display Meta Tech Podcast: 80: Lowering emissions with the Open Compute Project Meta Tech Podcast: 79: Building Android apps in Meta’s monorepository with Buck2 Meta Tech Podcast: 78: Generating 3D Worlds with AI Meta Tech Podcast: ARCHIVE: What it's like to write code at Meta Meta Tech Podcast: 77: How to build a generic neuromotor interface Meta Tech Podcast: 76: From C to Rust on Mobile Meta Tech Podcast: 75: Open-sourcing Pyrefly - A faster Python type checker written in Rust Meta Tech Podcast: 74: Taking the plunge - The engineering journey of building a Subsea Cable Meta Tech Podcast: 73: Mobile GraphQL at Meta in 2025 Meta Tech Podcast: 72: Multimodal AI for Ray-Ban Meta glasses Meta Tech Podcast: 71: Translating Java to Kotlin at Scale Meta Tech Podcast: 70: Jetpack Compose at Meta Meta Tech Podcast: 69: To type or not to type — measuring productivity impact with DAT Meta Tech Podcast: 68: How to Build a Mixed Reality Headset Meta Tech Podcast: 67: Measuring Developer Productivity with Diff Authoring Time Meta Tech Podcast: 66: Inside Bento - Serverless Jupyter Notebooks at Meta Meta Tech Podcast: 65: Getting Ready for Post-Quantum Cryptography Meta Tech Podcast: 64: Caddy - Building the next generation of CAD software for Mixed Reality Meta Tech Podcast: 63: The key to a happy Rust/C++ relationship Meta Tech Podcast: 62: Building Threads for Web Meta Tech Podcast: 61: Image Quality Improvements at Scale Meta Tech Podcast: 60: Simplified Executable Deployment with DotSlash
Meta Tech Podcast: 53: Offensive security at Meta’s Red T...
2023-06-29 · via Meta Tech Podcast

Jun 29, 2023

Red Team X is a security team at Meta that is responsible for finding and exploiting vulnerabilities in third-party products that could impact Meta's own security. The team acts as a hybrid between a traditional red team, which focuses on probing their own organisation's systems and products for vulnerabilities, and an elite bug-hunting group.

The team was founded by Vlad I. in 2020 when the pandemic and the sudden shift to Work From Home challenged various previously-held assumptions about security.

In his discussion with Pascal, Vlad explains the roles of different security teams within Meta, how they go about prioritising the highest-impact targets to exploit and how they work with vendors to ensure not just Meta but the entire world benefits from the fixes produced.

Got feedback? Send it to us on Twitter (https://twitter.com/metatechpod), Instagram (https://instagram.com/metatechpod) and don’t forget to follow our host @passy (https://twitter.com/passy and https://mastodon.social/@passy). Fancy working with us? Check out https://www.metacareers.com/.

Links:

Timestamps:

  • Intro 0:06

  • Vlad Intro 1:55

  • Red Teaming 2:43

  • Staying up-to-date 6:34

  • Different team colours 10:02

  • Defence-in-depth 12:44

  • Red Team X 15:57

  • Hardware v Software 19:43

  • Focus areas 21:29

  • Prioritising requests 22:44

  • Notable RTX Disclosures 26:05

  • Vulnerability disclosure policy 28:52

  • Getting into offensive security 38:48

  • Outro 40:51