This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Shmoo Group | |
|---|---|
| Name | Shmoo Group |
| Formation | 2000s |
| Type | Security research collective |
| Headquarters | United States |
| Fields | Information security, cybersecurity, vulnerability research |
Shmoo Group The Shmoo Group is an informal collective of security researchers, computer scientists, and information technology practitioners focused on vulnerability research, penetration testing, and defensive analysis. Founded in the early 2000s by participants drawn from conferences and security community networks, the group has engaged with topics ranging from network protocol analysis to hardware security and privacy engineering. Its members have interacted with organizations and events across the technology industry, academia, and open source communities.
The origins trace to meeting and collaboration among attendees at events like Black Hat USA, DEF CON, and RSA Conference, with early intersections involving contributors active in projects associated with CERT Coordination Center, Open Web Application Security Project, and Electronic Frontier Foundation. Over time, members published work intersecting with research at institutions such as Massachusetts Institute of Technology, Carnegie Mellon University, Stanford University, and University of California, Berkeley. The group’s timeline includes participation alongside actors from companies like Google, Microsoft, Cisco Systems, and Intel Corporation, and dialogues involving standards bodies such as the Internet Engineering Task Force and Institute of Electrical and Electronics Engineers.
Membership is informal and fluid, often including affiliated researchers associated with SANS Institute, Symantec, Kaspersky Lab, Palo Alto Networks, and CrowdStrike. Participants have backgrounds linked to labs at Bell Labs, Lawrence Livermore National Laboratory, and Sandia National Laboratories, and professional histories involving firms like IBM, Apple Inc., Amazon Web Services, Oracle Corporation, Facebook (Meta Platforms), and Nokia. Individuals often cross-collaborate with nonprofit groups such as Center for Democracy & Technology, OpenSSL Software Foundation, and Mozilla Foundation. The organization lacks formal governance, mirroring cooperative practices seen at Linux Foundation-affiliated projects and Apache Software Foundation working groups.
The collective has contributed to areas spanning cryptography implementations, secure coding practices, and embedded systems analysis, producing work referenced alongside studies from National Institute of Standards and Technology, European Union Agency for Cybersecurity, and academic publications in venues like USENIX, ACM SIGCOMM, IEEE Symposium on Security and Privacy, and NDSS Workshop. Their analyses have intersected with protocols and platforms including TCP/IP, Bluetooth, Wi‑Fi Alliance standards, and Industrial Control Systems components used by companies such as Siemens and Schneider Electric. Contributions also relate to tooling and methodologies comparable to Metasploit Framework, Burp Suite, Valgrind, and Ghidra, and to disclosure practices resonant with the Coordinated Vulnerability Disclosure model advocated by FIRST.
Members have presented findings at conferences including CanSecWest, BSides San Francisco, ShmooCon, Hack.lu, HITB, and REcon. Projects have examined vulnerabilities tied to platforms like Android (operating system), iOS, Windows NT, and Linux kernel, and to hardware platforms from ARM Holdings and Intel Corporation. Collaborative efforts addressed topics such as side-channel attacks, firmware analysis, secure boot mechanisms, and telecommunications infrastructures involving vendors like Ericsson, Huawei, and Nokia. Events linked to the collective’s work overlapped with disclosures seen at Project Zero, Zero Day Initiative, and coordinated responses involving US-CERT and European Cybercrime Centre.
The group’s informal outputs influenced practices in vulnerability disclosure policy and informed curriculum at programs like those at Georgia Institute of Technology and University of Illinois Urbana‑Champaign. Their collaborations reinforced ties between practitioners from cybersecurity startups and public institutions such as Department of Homeland Security components and Defense Advanced Research Projects Agency. The group’s ethos shaped community norms reflected in open source security tooling and inspired spin-off initiatives and working groups within security research venues, contributing to a lineage of collaborative research alongside entities like Mitre Corporation and National Security Agency research labs.
Category:Information security groups Category:Computer security organizations