Giter Site home page Giter Site logo

Adam Strickland ([email protected])

Technical problem solver with expertise in web and native app security and networking protocols. Technologies I know:

I like to say that if it uses HTTP, I can hack it! I can quickly examine a network trace (for example, using Burp Suite) and understand how a web or native application ticks.

My Work

Applied Cryptography

  • Demonstrated how to sign Elliptic-Curve JWTs with the openssl CLI
  • Contributed JWT authentication functionality to an Openid Connect library

Authentication Systems

  • Contributed to a FIDO/WebAuthn library that bridges OpenSSH with Windows Hello
  • Identified a broken authentication issue in one of my company's integrations. I used my knowledge of crpytography to exploit an encryption system

RESTful Web Services

  • Updated the Swagger/OpenAPI spec for the CDS Hooks REST API
  • Implemented an example CDS Hooks service for my company's use in demos (hosted in pipedream)

CSRF Protection

  • Identified a login CSRF attack at my company, and prevented us from pushing the code to production
  • Added a CSRF protection example to an Openid Connect Library after a throrough conversation with library maintainers on the scope of CSRF attacks against the library

Session Management

  • Discovered and fixed an issue with an Openid Connect library, where sessions didn't work embedded in an iframe
  • Added testing for a feature of the express-session library

Adam Strickland's Projects

api icon api

CDS Hooks Swagger API

dcr-client-subspace icon dcr-client-subspace

An example single-page-app for using runtime dynamic client registration against Subspace

docs icon docs

CDS Hooks website & specification

fhiruser-ui icon fhiruser-ui

A UI for interacting with fhir servers starting from access token response payloads

jwt-extern-key icon jwt-extern-key

A list of strategies and examples for signing JSON Web Tokens (JWTs) using a private key in a separate, trusted memory location.

node-bulk-fhir icon node-bulk-fhir

A nodejs client for the FHIR Bulk Data Access (Flat FHIR) profile

openssh-sk-winhello icon openssh-sk-winhello

A helper for OpenSSH to interact with FIDO2 and U2F security keys through native Windows Hello API

puri-fhir icon puri-fhir

A JS functional programming library for working with FHIR resources, based on the purify-ts library.

smart-express-demo icon smart-express-demo

An example express app supporting SMART on FHIR. Supports multiple browser tabs protected by cookies

sof-oidc-example icon sof-oidc-example

An example application demonstrating an EHR Launch using the express-openid-connect SDK

ssl-kill-switch2 icon ssl-kill-switch2

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.