He wrote the first reliable remote kernel exploit for a Linux Wi-Fi driver, then spent a career on the other side of that trade — building the sandbox that boxes an attacker in. So when an anonymous crew put him on a list of "notable whitehats" it claimed to have owned on the eve of Black Hat 2009, next to Kevin Mitnick and Dan Kaminsky, the joke was on the joke: the man they name-checked to prove the industry could not defend its boxes had, by then, done more than almost anyone to make the boxes defensible. This is a short file. The drama is thin. The record is not.
The recent focus on sandboxes (Chrome, Office) makes the kernel an even more interesting target.
Julien Tinnes and Tavis Ormandy, "There's a Party at Ring0, and you're invited" (2010) — the whole modern attack-surface argument in one line: harden the application and the fight moves down to the kernel
WHO
Julien Tinnes — French vulnerability researcher; formerly Orange Labs / France Telecom R&D, "currently working at Google" by his own homepage FACT
SCENE
Disclosure-era kernel and sandbox researcher — a builder in the same generation as figures like Solar Designer and Aleph One; frequent co-author with Tavis Ormandy
THE WORK
First reliable 802.11 remote Linux kernel exploit (MadWiFi, CVE-2006-6332, with Laurent Butti); Metasm assembler/disassembler folded into Metasploit 3; the ptrace / kernel attack-surface research; and the seccomp-bpf next-generation Linux sandbox for Chrome and Chrome OS at Google
THE DRAMA
Named by ZF0 ("Zero for 0wned") among the "notable whitehats" it claimed to have owned in its July 2009 issue 5, alongside Kevin Mitnick and Dan Kaminsky (see Crew Rivalries). That is the whole of it
STATUS
STILL BUILDING — defense-side lifer; no criminal record, none implied
This file is short on purpose. Julien Tinnes belongs on troll.fan for exactly one reason — a 2009 zine put his name on a list — and honesty demands that the reason be kept in proportion to itself. The interesting thing is not the owning. It is the arc around it: a researcher who proved, at 802.11 range, that a kernel driver could be popped from across the room, and who then went and built the mitigations that make the next pop harder. The drama is a footnote. The work is the story.
the drama timeline
ACT I — THE REMOTE KERNEL BUG (2006–2007)
Before he was a name on anyone's list, he was the coder who turned a Wi-Fi driver flaw into the first reliable remote kernel exploit on Linux.
2006–07
MadWiFi — CVE-2006-6332
Through Wi-Fi fuzzing, Tinnes and Laurent Butti find and exploit a buffer overflow in the MadWiFi Linux kernel driver — documented as the first reliable 802.11 remote kernel stack overflow under Linux. The exploit is reliable, does not crash the wireless stack, and can hit the same target repeatedly. The technique and their broader 802.11 driver work are written up in a peer-reviewed journal and presented at SSTIC 2007 and hack.lu.
His Metasm Ruby assembler/disassembler is integrated into Metasploit 3 — the kind of quiet toolchain contribution that ends up in everybody's kit without anybody's name attached. By this point the résumé reads like a working exploit developer's: kernel bugs, tooling, teaching security at French engineering schools on the side.
On the eve of Black Hat, an anonymous crew dumped roughly 75,000 passwords and named its "notable whitehats." He was one of three headliners. It is the entirety of the drama, so here it is, in proportion.
JUL 2009
ZF0 issue 5 — "notable whitehats"
ZF0 ("Zero for 0wned") opens its fifth and final issue with a boast: "We hacked notable whitehats Kevin Mitnick, Dan Kaminsky, and Julien Tinnes, among others." The zine sketches him as "a french security expert" who "works for Google," singles out the MadWiFi kernel bug as his best-known work, and — grudgingly, for ZF0 — concedes "some solid work, especially some good blog posts." The dump landed with the rest of the ~75,000-password haul, timed to embarrass the industry while it gathered in Las Vegas. Contemporaneous coverage recorded it as "Security Gurus 0wned by Black Hats."
The other two names on the marquee were the world's most famous security consultant and the researcher who had just saved the internet's DNS — Kevin Mitnick and Dan Kaminsky, both owned in the same wave. Being dumped alongside them was, if anything, a backhanded certification that Tinnes had arrived. The zine's actual thesis — that the industry's decorated names sat on soft boxes — is argued at length on the Crew Rivalries file; here it is enough to note that Tinnes was collateral in a stunt aimed at the whole guild, not the point of it.
A year later he was back on the offense, but pointed at the layer everyone else was neglecting: as applications got sandboxed, the kernel became the door.
MAR 2010
"There's a Party at Ring0"
With Tavis Ormandy, Tinnes presents "There's a Party at Ring0, and you're invited" at CanSecWest (and Black Hat USA), surveying Linux and Windows kernel bugs usable for privilege escalation. The argument — captured in the line quoted up top — is that hardening applications with sandboxes simply relocates the fight to the kernel, so the kernel's attack surface is now the thing that matters. It is a piece of offense research whose whole purpose is to tell defenders where to look next.
Ormandy and Tinnes, "There's a Party at Ring0, and you're invited" — the kernel-attack-surface talk. The offense researcher mapping the exact terrain he would spend the next years fencing off.
ACT IV — THE SANDBOX (2012–)
Then he built the fence. At Google, Tinnes helped ship the mitigation that turns "the kernel is the door" from a warning into a much smaller door.
2012
seccomp-bpf — the next-generation Linux sandbox
Tinnes writes up Chrome's next-generation Linux sandbox on his own blog and on the Chromium Blog, built on seccomp-bpf — filtering the system calls a renderer may make so that even a compromised process can barely reach the kernel. The work (with Chris Evans, Jorge Lucangeli Obes, Markus Gutschke and Adam Langley) narrows the very attack surface "Party at Ring0" had mapped. Same researcher, both ends of the exploitation lifecycle: find the way in, then wall it off.
The through-line from the 2006 remote kernel bug to the incorporated sandbox is unbroken: exploit developer to mitigation author, all inside Google's security-research generation — the same era and orbit as Project Zero, without the file asserting membership. No indictment, no plea, no scandal. The only thing anyone ever "did" to Julien Tinnes was print his name in a zine.
The zine's case: ZF0 put Tinnes on its "notable whitehats" list precisely because he was a Google security researcher with a public profile — exactly the kind of decorated name it existed to embarrass. Its thesis, applied to the whole roster, was that the industry's celebrities left mail and work data on internet-facing boxes a motivated attacker could walk into. That the dump happened is documented in the published zine and contemporaneous press [4].
And offense cuts both ways: he wrote a reliable remote kernel exploit and a survey of kernel bugs for privilege escalation. The tools and techniques are dual-use by nature, and the halo of "defender" does not un-write the exploits.
Being named is not being guilty of anything: ZF0's list was a stunt aimed at the guild, and Tinnes was one line in it. There is no allegation of misconduct against him — only that someone else claimed to have accessed a box. Even the zine conceded his "solid work" and "good blog posts" [1].
Dual-use is the whole discipline: the researcher who can pop a kernel driver from Wi-Fi range is exactly the one you want designing the sandbox. Tinnes did both, in public, and the offense research he published pointed defenders straight at the layer he then helped harden [2][3].
The record is a builder's: MadWiFi, Metasm-into-Metasploit, the ptrace and kernel attack-surface work, seccomp-bpf for Chrome and Chrome OS. Decades of it, sourced to his own site and to Google's engineering blogs, with no criminal record and none implied [2].
YOU DECIDE
There is almost nothing to decide, which is the honest verdict. Strip away the one zine mention and Julien Tinnes is a working vulnerability researcher with a clean sheet and a long list of contributions on both sides of the exploitation lifecycle. He earns a file here only because a 2009 crew wanted a famous name and he had become one — and the file's duty is to say so without inflating it into a scandal it never was.
The archive keeps the zine that named him. It also keeps the exploit, the paper, and the sandbox — which is the longer list by far.
evidence locker
PRIMARY / REFERENCE
ZF0 issue 5 ("Zero for 0wned")ATTRIBUTED — the July 2009 zine naming "notable whitehats Kevin Mitnick, Dan Kaminsky, and Julien Tinnes" (intro) and its section on Tinnes. Self-published, so a FACT that ZF0 wrote it; the owning claim is theirs. Held in the local mirror at research/zines/zf0-5.txt (intro l.84–86; Tinnes section from l.25860).
troll.fan/crew-rivalries.html
cr0.org — homepage of Julien TinnesFIRST-PARTY — his own statement of employer (Google), prior role (Orange Labs / France Telecom R&D), teaching, and research: MadWiFi (CVE-2006-6332), Metasm-in-Metasploit-3, 802.11 fuzzing, OpenSSL/Debian work.
cr0.org
The standard. Julien Tinnes is a living, respected researcher, and his contributions — the MadWiFi remote kernel exploit, Metasm in Metasploit 3, the kernel attack-surface research, and the seccomp-bpf Chrome sandbox — are stated at full strength and sourced to his own site, the CVE/exploit records, a peer-reviewed paper, and Google's engineering blogs. The only "drama" is that ZF0 named him among the whitehats it claimed to have owned in 2009; that claim is quoted from the published zine and attributed to ZF0, kept in proportion and never adopted as our voice. He is not asserted to be a member of Project Zero. No criminal conduct is alleged because none exists. If a line here couldn't survive scrutiny, it wouldn't be on the page.