Thomas H. Ptacek is an American security researcher and software developer who has spent three decades moving between two postures: breaking software and teaching the people who build it. He co-founded Matasano Security in 2005, sold it to NCC Group in 2012, co-founded the startup-security firm Latacora, built the cryptographic challenges that became Cryptopals, and co-founded Starfighter — a short-lived, influential attempt to replace engineering hiring with games. Since roughly 2020 he has been a developer at Fly.io, and since 2025 one of the industry's most-quoted essayists arguing that LLM agents have permanently changed programming.
From vulnerability research to Matasano
Ptacek's career starts in the first generation of commercial security research. He has worked in software security since 1995 and was a member of what he calls the industry's first commercial vulnerability research lab, at Secure Networks, where much of his work concerned intrusion detection. In 1998 he and Timothy Newsham published "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection," the paper that defined IDS evasion. He later carried that work onto the Black Hat stage, presenting on intrusion detection evasion, flaws in data-loss-prevention products, detection of hardware virtualized rootkits, and cryptographic attacks on software crypto.
In 2005 he co-founded Matasano Security with Dave Goldsmith and Jeremy Rauch. The firm sold penetration testing, reverse engineering, and source code review to blue-chip clients, and its Chargen blog became a public voice for applied security — most famously Ptacek's 2007 "Enough With The Rainbow Tables," which argued that salting already defeats rainbow tables and that real password storage needs deliberately slow password hashes. Telling Brian Krebs in 2012 that "nobody gets this right," he diagnosed the underlying problem: generalist developers are asked to build cryptographic systems they were never trained for. NCC Group acquired Matasano in August 2012 for up to £8.4 million; he describes the firm at sale as one of the largest software security companies in the US. In 2014, Ars Technica reported him as technical lead for Phase II of the crowdfunded TrueCrypt audit.
Games as instruments
The thread that runs through his companies is hiring. Ptacek ran hiring at Matasano and, briefly, at NCC, and concluded that interviews and resumes systematically misprice talent — they measure confidence, not capability. Matasano's answer was work samples: the crypto challenges, a set of exercises that teach real attacks on real cryptography, which began as a hiring filter and became the public Cryptopals Crypto Challenges, now maintained by Sean Devlin with NCC Group's cryptography team. With Square, Matasano built Microcorruption, an embedded-security CTF that teaches memory-corruption exploitation on an idealized MSP430.
In March 2015 he published "The Hiring Post," his fullest argument that developer interviews are a market failure, and three days later he, Patrick McKenzie, and Erin Ptacek announced Starfighter: a company whose CTF games would measure rare programming skills and route top players to employers. Its flagship game Stockfighter shipped publicly in December 2015, but the contingency-recruiting business never hummed, and the company wound down in 2016. The experiment was a commercial failure and a cultural success: work-sample hiring arguments now quote him reflexively.
Latacora, essays, and public argument
After the NCC years he co-founded Latacora with Erin Ptacek and Jeremy Rauch, a firm that embeds ongoing security teams inside startups rather than selling point-in-time assessments. Through it he published two of his most-cited stances: "Cryptographic Right Answers," his 2015 list of opinionated defaults — NaCl/libsodium, AEAD constructions, slow password KDFs — and "Stop Using Encrypted Email" (2020), a sustained attack on encrypted email as practiced. His sockpuppet.org essays take similar swings at industry orthodoxy, from "Against DNSSEC" to "Applied Cryptography Engineering," a critique of the Schneier classic as a dangerous instruction manual.
He argues in public constantly: as tptacek he is one of Hacker News's highest-karma commenters, and since 2021 he has co-hosted the Security Cryptography Whatever podcast with Deirdre Connolly and David Adrian. In February 2025 he described testifying as an expert witness in a Cook County FOIA trial, explaining to a judge why Chicago's parking-ticket database schema was "the product of an attack, not one of its predicates."
Fly.io and the LLM turn
At Fly.io he is simply a developer — his bio's words — working on platform internals and writing engineering posts on WireGuard networking and token design. Then, in June 2025, "My AI Skeptic Friends Are All Nuts" made him the loudest credible voice for LLM-assisted programming: the skeptics' arguments are unserious, the tools already do real work, and you remain responsible for what you merge to main. He followed it with "You Should Write An Agent," which reduces a working agent to a loop and a tool call, and in March 2026 with "Vulnerability Research Is Cooked," arguing that agents will industrialize exploit development — that the industry was protected partly by a scarcity of elite attention which no longer holds.
What the record does not settle
The public record is strong on what he built and argued, thin on biography. There is no Wikipedia article; the Wikidata item is sparse; his birth date and education do not appear in the cited sources. His Fly.io start date and Latacora's founding year are only approximately documented, and "one of the largest software security firms in the US" is his own characterization. The index preserves those seams rather than smoothing them over.
This index was compiled from public sources and does not imply the subject's endorsement. Citations live in the packet's source catalog.