lily anne hall curriculum vitae

personal

Pronouns they/them
CV lilyanne.me
Email lily.anne.hall@protonmail.com
Github github.com/tacticalchihuahua

I’m a security researcher with an extensive background in distributed systems, digital privacy and applied cryptography. I have worked with Zcash, MetaMask, Ethereum Foundation, Blockstack and others.

professional experience

Security Researcher 2017-present

Independent Contractor/Consultant

Developed security tools, code reviews, audits, pen tests and system design reviews while consulting for private clientele.

Senior Engineering Manager 2022-2023

Spruce Systems

Acted as a technical advisor and engineering manager to a team of six engineers responsible for Sign-in-with-Ethereum (SIWE). Established testing practices and security best practices.

Senior Engineering Manager 2020-2022

Eaze

Managed the consumer engineering department which included the web, mobile, and payments teams. Developed hiring rubrics, progression criteria and operational practices. Led the security working group – a cross-functional team responsible for organizational and application security practices.

Security Researcher 2017-2020

Least Authority (contract)

Conducted dozens of research and auditing projects for an ensemble of privacy focused technology projects. Authored reports and blog posts. Worked directly with clients to remediate vulnerabilities.

Principal Software Engineer, Architect 2015-2017

Storj Labs

Implemented the Storj protocol per its initial prototype specification. Co-authored the protocol specification for its first major stable release. Acted as the open-source project’s core developer and community liaison.

Staff Software Engineer, R&D 2012-2015

BitPay

Co-authored the second major release of the Merchant API and the first major release of the Payroll API – both designed with a capabilities-based security model. Led the research and development team to build internal tools and contribute to open source projects Bitcore, Bitauth and Copay

Presentation Layer Architect 2012

Razorfish

Senior Software Engineer 2010-2012

Bridgevine

Interface Engineer 2009-2010

LBi/Digitas

published research

TRON: Protocol Security Audit 2020

lilyanne.me/research/TRON/LeastAuthority-TRON-Protocol-Audit-Report.pdf

MetaMask: Lavamoat Plugin System Security Audit 2019

lilyanne.me/research/MetaMask/LeastAuthority-MetaMask-Plugin-System-LavaMoat-Audit-Report.pdf

MetaMask: Capnode Permissions System Security Audit 2019

lilyanne.me/research/MetaMask/LeastAuthority-MetaMask-Permissions-Capnode-Audit-Report.pdf

MetaMask: Mobile Wallet Security Audit 2019

lilyanne.me/research/MetaMask/LeastAuthority-MetaMask-Audit-Report.pdf

Blockstack: Stacks Investor Wallet Security Audit 2019

lilyanne.me/research/Blockstack/LeastAuthority-Blockstack-Wallet-Audit-Report.pdf

Cosmos: SDK Security Audit 2019

lilyanne.me/research/Cosmos/LeastAuthority-Cosmos-SDK-Audit-Report.pdf

Ethereum Foundation: ProgPow Algorithm Security Audit 2019

lilyanne.me/research/EthereumFoundation/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf

Zcash: Sapling Implementation Security Audit 2019

lilyanne.me/research/Zcash/LeastAuthority-Zcash-Sapling-Implementation-RPC-Interface-Updated-Audit-Report.pdf

Zcash: Overwinter Specification and Implementation Security Audit 2018

lilyanne.me/research/Zcash/LeastAuthority-Zcash-Implementation-Analysis-and-Overwinter-Specification.pdf

Storj: a peer-to-peer cloud storage network 2016

lilyanne.me/research/Storj/Storj.Whitepaper.V2.pdf

leadership & advisory roles

Counterpoint Hackerspace 2014-2019

Executive Director

Co-founded a hackerspace in Atlanta, GA. Managed operational logistics, curriculum, and hosted a weekly counter-surveillance and threat modeling workshop.

Fluence Labs 2017-2018

Technical Advisor

Consulted during the early design phase to identify potential attack vectors related to the overlay network structure, incentive model and scalability concerns.

grants & scholarships

Open Technology Fund, Red Team Labs (research grant) 2018

Onion Routed Cloud, Author

Awarded a research grant to fund a third party security audit of my open source privacy software project, Onion Routed Cloud (ORC).

Art Institute of Atlanta (scholarship) 2007

National Scholarship Competition, Digital Filmmaking

Awarded first place in Ai’s National High School Scholarship competition for two short films that I wrote, directed, and edited.

public speaking

BlockCon 2017

Santa Monica, CA

Participated in a panel interview with representatives from Sia and Tahoe-LAFS about the state and future of decentralized scloud storage.

LibrePlanet 2017

MIT, Cambridge, MA

Spoke about the ecological impact of proof-of-work systems and made an appeal for various alternatives.

NodeSummit 2016

San Francisco, CA

Spoke at NodeSummit about Storj and gave a live demonstration of one of the first decentralized cloud systems using distributed ledger technology.

ConnectJS 2014

Atlanta, GA

Spoke at a conference for JS developers about using server-side JavaScript to implement a peer-to-peer consensus algorithm.

skills

languages JavaScript + Node.js, C++, Python, Rust, Lua, Solidity, Bash, HTML, CSS
software Asynchronous Programming, Distributed Systems Design, API Design, Security Best Practices, Reverse Engineering

references

Available upon request