THOMAS PTACEK

He co-founded one of the most respected software-security firms in America — a shop that audited everyone else's code, evangelized disclosure, and built hiring CTFs to harvest the next generation of talent. Then, in July 2009, Matasano's own website got popped and dumped to the Full Disclosure mailing list, with the firm's own disclosure sermons pasted at the top of the defacement. This file is not about whether Ptacek is good at his job; by every public measure, he is. It is about the oldest joke in the industry: the people who grade the class eventually get graded back.

I work on crypto the way other vulnerability researchers work on iOS, or on Windows kernel vulnerabilities.

Thomas Ptacek, describing his own adversarial approach to cryptography — sockpuppet.org/me

WHO
Thomas H. Ptacek — security researcher and software developer; in the field since 1995 FACT
SCENE
Secure Networks (the industry's first commercial vuln-research lab), then co-founder of Matasano Security, Latacora, and Starfighter; now at Fly.io. Prolific voice on Hacker News (tptacek)
THE DRAMA
Matasano made its name auditing and grading everyone else's security — and in July 2009 got publicly owned itself, the dump posted to Full Disclosure with the firm's own disclosure-evangelism quoted back at it. The irony, not a verdict
RECORD
Matasano founded 2005; acquired by NCC Group on Aug 2, 2012 for £8.4M (~$13M). Co-author, with Timothy Newsham, of the landmark 1998 paper on eluding intrusion detection FACT
STATUS
ACTIVE — SHIPPING AT FLY.IO — still building, still posting, still respected

This is not an accusation, and it is not a competence file. Thomas Ptacek is a working, well-regarded security researcher whose technical contributions — a paper that reshaped how the industry thinks about intrusion detection, a set of crypto challenges that trained a generation — stand on their own. The through-line here is narrower and more human: a firm that built a brand on telling everyone else where their security was weak had a bad week in July 2009, and the internet, which never forgets a firm graded itself, kept the receipt. We keep it too — as the documented irony it was, and nothing more.

the drama timeline

ACT I — THE CRITIC'S TOOLKIT (1995–2005)

Before the firm, the paper. Ptacek learns the trade at the industry's first commercial vulnerability lab and co-writes the document that teaches a generation how intrusion detection fails.

  1. 1995–98

    Secure Networks, and the IDS paper

    Working in software security since 1995, Ptacek joins Secure Networks — by his own account "the industry's first commercial vulnerability research lab." In January 1998 he and Timothy Newsham publish Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection, which shows that an IDS cannot reliably match what the destination host actually sees. It becomes one of the most-cited papers in network security.

  2. 2005

    Matasano is founded

    Ptacek co-founds Matasano Security — "one of the original three founders," with Dave and Jeremy — a boutique that does penetration testing, reverse engineering, and source-code review for vendors and enterprises. Its stock-in-trade is finding, and publishing, the flaws in other people's software.

ACT II — GRADING THE INDUSTRY (2005–2009)

Matasano becomes the shop that grades everyone — and preaches disclosure while doing it. That posture is the setup; the punchline arrives in Act III.

  1. 2005–09

    Audit everyone; evangelize disclosure

    The firm's public stance, as its own site put it (and as the attackers would later gleefully quote back): "Matasano publishes vulnerabilities. We think it's the right thing to do... We are evangelists for disclosure." Matasano also built talent pipelines from the practice — hiring CTFs and crypto exercises that doubled as recruiting. Grading the class, and drafting from it.

  2. JUL 2008

    The DNS bug leaks — from Matasano's own blog

    A year before the defacement, the grievance. In July 2008 Dan Kaminsky went public with a fundamental DNS cache-poisoning flaw and asked researchers to hold the details until his Black Hat talk. Someone at Matasano posted those details on the firm's blog — then pulled the post down. Per Wired, the firm drew "heavy criticism from other security researchers who accuse Matasano of irresponsible disclosure and of trying to get publicity by stealing attention from Kaminsky's Black Hat talk." Ptacek, who had earlier doubted the bug and recanted after Kaminsky briefed him privately, was not the employee whose name was on the post — but as founder he apologized publicly. It is the concrete grievance the anti-sec crowd would throw back a year later.

  3. 2008–09

    King of the security blogs — and a mark for it

    By the late 2000s Ptacek was, in the scene's own telling, "the king of the security blog scene" — a prolific voice whose commentary made Matasano a lightning rod. ZF0 handed the firm its parody "Biggest Time Wasting Whitehat Blog" award, needling the "endless Internet debates" on the Matasano site, and recounted an earlier scrap in which the pseudonymous GOBBLES "took offense and smacked him down," after which (ZF0 says) Ptacek redirected his energy into Wikipedia, campaigning to delete dubious "hacker" biographies — a project the zine grudgingly conceded he was "100% right" to pursue. And the tell that this was sport, not a hit: ZF0 itself wrote that Ptacek and Matasano "were not targets, just examples."

ACT III — "MATASANO CREAMPIE" (JULY 2009)

The firm that grades everyone gets graded. On July 25, 2009, its website is defaced and a dump lands on the Full Disclosure list — the same wave of "anti-sec" attacks on security researchers that a week later would hit Dan Kaminsky and Kevin Mitnick.

  1. JUL 25, 2009

    The dump hits Full Disclosure

    An anonymous post titled "Matasano Creampie" appears on the Full Disclosure mailing list, opening with a taunt at "whitehats," pasting Matasano's disclosure-evangelism marketing back at it, and claiming a walk-in through a non-root account. The firm's website was defaced; a mirror was posted publicly. The intrusion is real and dated; the swagger inside the post is the attackers'.

  2. JUL 25–27, 2009

    "Even the pros are vulnerable"

    Independent coverage follows. On Sucuri's blog, David Dede calls Matasano "one of the top security web sites with an amazing group of professionals," declines to assert a cause — "My guess: it was either a weak password from some of their web designers or a web application bug" — and pointedly doubts a zero-day was involved. Hacker News files it under the headline the whole industry felt: "Matasano hacked. A humbling lesson, even the pros are vulnerable."

  3. AUG 2009

    Context: the anti-sec wave

    Matasano was not alone. The July defacement sat inside a 2009 "anti-sec" campaign against the security industry that, weeks later, dumped the private mail and chat logs of Dan Kaminsky and Kevin Mitnick in the ZF05 zine. Being popped that summer put Matasano in crowded, senior company — a fact the defense column leans on, hard.

  4. JUL–AUG 2009

    The anti-sec bloc names him

    The defacement was not a random pop — it landed inside a named campaign. The very same ZF0 #5 zine that dumped Kaminsky and Mitnick that summer opened with a manifesto that put Matasano and Ptacek in its sights by name: the scene was "fucked," it wrote, because "you have Matasano harvesting talent and critiquing everyone, and then Ptacek can only announce the release of... a graphical firewall management client." Days after the site was popped the zine gloated — "Look at Matasano. 0wned to fuck just a couple of days ago" — and handed the firm a parody "least trustworthy whitehats" award, citing the 2008 DNS-bug leak as its case. This is the anti-sec bloc's contempt for the disclosure industry, aimed at a named man. It is their charge sheet, not ours.

ACT IV — POACHER STAYS GAMEKEEPER (2012– )

The breach did not dent the trajectory. Three years later the firm sells for eight figures, and Ptacek keeps building the tools the next cohort learns on.

  1. AUG 2, 2012

    NCC Group buys Matasano

    NCC Group acquires Matasano for £8.4M (~$13M), with the firm reporting roughly $5M revenue for the year and continuing as "Matasano, an NCC Group company." Whatever July 2009 was, it was not fatal — the market valued the practice, not the defacement.

  2. 2012–

    Cryptopals, Latacora, Fly.io

    Ptacek keeps shipping: the Matasano Cryptopals Challenges ("7 sets of 8 cryptographic challenges each based on real-world crypto flaws"), the Microcorruption hiring CTF, then co-founding the consultancy Latacora, and now developer work at Fly.io — while remaining one of the most prolific and quotable voices on Hacker News. Poacher, gamekeeper, and permanent commentator, all at once.

both sides, on the record

The irony is real, and it was public: a firm whose entire pitch was finding other people's flaws — and which called itself an "evangelist for disclosure" — had its own site defaced and mirrored to a public mailing list, with that very marketing copy quoted back at it. The scene did not invent the joke; Matasano's own words wrote the punchline [3].

Graders get graded: when your brand is the report card, an "even the pros are vulnerable" headline lands harder. That is not unfair; it is the deal you take when you audit the industry for a living [5].

It was personal, and it was named: this was not blind vandalism. The ZF0 #5 manifesto singled out "Matasano harvesting talent and critiquing everyone" and Ptacek by name, and the anti-sec crowd had a concrete grievance to point at — the July 2008 episode in which Matasano's blog spilled Kaminsky's DNS bug ahead of his talk [13] [15].

A website is not a practice: the compromise was of a public web server, and the only cause ever floated in print was Sucuri's speculation of "a weak password... or a web application bug" — explicitly a guess, with the zero-day theory doubted. No harm to client engagements was ever established, and nothing here reflects on the quality of Matasano's actual security work [4].

Everyone got popped that summer: Matasano was one name in a broad 2009 anti-sec campaign that also dumped Kaminsky and Mitnick. In that company, a defacement is a war story, not a disqualification [6].

Even the zine said he wasn't the target: ZF0 #4 itself wrote that Ptacek and Matasano "were not targets, just examples," and Wired's own account of the 2008 leak records that Ptacek did not write the offending blog post and apologized once it appeared. Being named in a manifesto is not being guilty of anything [14] [13].

The work stands on its own: the 1998 intrusion-detection paper, the Cryptopals challenges that trained a generation, Microcorruption, and a firm the market bought for ~$13M three years later — the record of contribution dwarfs one bad week [1] [7].

YOU DECIDE

Strip the schadenfreude and there is no scandal here — just an industry running its favorite gag on one of its own. A respected researcher co-founded a firm that graded everyone's code; the firm's website got popped once, in the summer of 2009, on the same wave that took Kaminsky and Mitnick; the firm sold for eight figures three years later; and the man kept building the tools the next cohort learns on. The defacement is a documented fact. It is not a verdict on his skill, and we do not offer it as one.

The archive does not gloat. It keeps the marketing copy — and the mailing-list post that quoted it back.

evidence locker

PRIMARY / FIRST-PARTY

  1. sockpuppet.org — Thomas Ptacek's own bio FACT — first-party: "security researcher and a software developer," in the field "since 1995"; co-founder of Matasano (with Dave and Jeremy) and Latacora; developer at Fly.io; Secure Networks; the Cryptopals challenges and Microcorruption; his crypto-as-vuln-research posture. sockpuppet.org/me
  2. Hacker News — profile: tptacek ATTRIBUTED — his long-running, prolific commenting account, corroborating the "combative, quotable presence" characterization in his own venue. news.ycombinator.com/user?id=tptacek

THE 2009 EPISODE

  1. Full Disclosure — "Matasano Creampie" (Jul 25, 2009) ATTRIBUTED — the primary, ANONYMOUS, attacker-authored dump: taunts at "whitehats," Matasano's own disclosure-evangelism marketing quoted verbatim, and claimed intrusion details. Internal claims are the attackers'; the dated public defacement is corroborated below. seclists.org/fulldisclosure/2009/Jul/388
  2. Sucuri — "Matasano.com hacked" ATTRIBUTED — independent corroboration of the July 25, 2009 defacement; David Dede calls Matasano "one of the top security web sites," frames the vector only as a guess ("a weak password... or a web application bug"), and doubts a zero-day. blog.sucuri.net/2009/07/matasano-com-hacked.html
  3. Hacker News — "Matasano hacked. A humbling lesson, even the pros are vulnerable." ATTRIBUTED — the industry's contemporaneous framing; links to the Full Disclosure post. news.ycombinator.com/item?id=723798
  4. Darknet — "Dan Kaminsky & Kevin Mitnick Hacked" CONTEXT — the wider 2009 anti-sec / ZF05 wave against the security industry; establishes that senior researchers were targeted the same summer. Does not itself tie Matasano to that dump. darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked

RECORD & CONTRIBUTION

  1. SecurityWeek — "Matasano Security Acquired by NCC Group for $13 Million" FACT — acquisition Aug 2, 2012, £8.4M (~$13M); Matasano founded 2005; penetration testing, reverse engineering, source-code review. securityweek.com/matasano-security-acquired-ncc-group-13-million
  2. Ptacek & Newsham (1998) — Insertion, Evasion, and Denial of Service FACT — the landmark IDS-evasion paper, Secure Networks, January 1998 (PDF). users.ece.cmu.edu/~adrian/731-sp04/readings/Ptacek-Newsham-ids98.pdf
  3. Hacker News — Ptacek on founding Matasano ATTRIBUTED — his own account (as tptacek) confirming he founded Matasano and its NCC Group acquisition. news.ycombinator.com/item?id=9372075

CONTEXT & CROSS-LINKS

  1. troll.fan — Phiber Optik CROSS-LINK — the poacher-to-gamekeeper arc the scene runs on repeat. troll.fan/dossiers/phiber-optik.html
  2. troll.fan — DEF CON CROSS-LINK — the conference-and-CTF circuit Matasano recruited and competed on. troll.fan/dossiers/defcon.html
  3. troll.fan — Crew Rivalries CROSS-LINK — the anti-sec-vs-whitehat feud that framed the 2009 wave. troll.fan/crew-rivalries.html

THE ANTI-SEC ANIMUS

  1. Wired — "Details of DNS Flaw Leaked; Exploit Expected by End of Today" (Jul 2008) FACT — Matasano's blog posted the details of Kaminsky's DNS cache-poisoning bug ahead of his Black Hat talk, then pulled the post; other researchers accused the firm of "irresponsible disclosure." Explicitly notes that founder Ptacek was NOT the post's author, had earlier doubted the bug and recanted privately, and apologized publicly. wired.com/2008/07/details-of-dns
  2. Zero For 0wned #4 (Exploit-DB mirror) ATTRIBUTED — the anti-sec zine's parody "Biggest Time Wasting Whitehat Blog" award to Matasano, the "king of the security blog scene" framing and GOBBLES scrap, and ZF0's own caveat that Ptacek and Matasano "were not targets, just examples." All characterizations are the zine's, attributed to its anonymous authors. exploit-db.com/ezines/…/ZF0/
  3. Zero For 0wned #5 (Exploit-DB, paper 12892) ATTRIBUTED — the same July 2009 zine that dumped Kaminsky and Mitnick; its manifesto names "Matasano harvesting talent and critiquing everyone" and Ptacek directly, it gloats over the fresh defacement ("0wned to fuck just a couple of days ago"), and its parody "least trustworthy whitehats" award cites the 2008 DNS-bug leak. Anti-sec animus, attributed to ZF0. exploit-db.com/papers/12892
The standard. Thomas Ptacek is a living, active security professional, and this file is held to the higher bar that demands. The biographical spine — Secure Networks, the 1998 paper, founding Matasano, the NCC Group acquisition, Latacora, Fly.io — is documented and, where possible, first-party. The one "drama," the July 2009 defacement, is stated as the documented, publicly-corroborated event it was; its cause is presented only as Sucuri's explicit speculation, never asserted; the swaggering internal claims are labeled as the anonymous attackers' own. His contributions and reputation are given at full strength. Nothing here is offered as a verdict on his competence or character, and nothing beyond the public record is asserted. If a line couldn't survive scrutiny, it wouldn't be on the page.