Bart De Water is a software engineer based in Montreal with 13 years of experience building secure, high-performance back-end systems. Currently at Thatch, he brings deep Ruby expertise demonstrated by contributions to core projects like ruby/ruby, rails/rails and performance-focused work on fast-ruby. He has a strong security pedigree—improving OpenSSL integrations and implementing constant-time comparison functions to mitigate timing attacks. His contributions to payment libraries such as Active Merchant and offsite_payments show practical experience with gateway integrations and real-world reliability concerns. Known for benchmarking and pragmatic optimizations, he blends careful measurement with maintainable refactors and documentation improvements. Trained at The Hague University of Applied Sciences, he pairs a disciplined engineering approach with a curiosity for low-level cryptographic and performance details.
A simple and unified API to handle dozens of different offsite payment pages.
Role in this project:
Back-end Developer
Contributions:5 releases, 2 reviews, 33 commits in 1 year 5 months
Contributions summary:Bart primarily focused on maintaining and updating the `offsite_payments` library. Their contributions include updating the library version, fixing an issue related to string comparison, and improving the BitPay integration by removing an error swallowing pattern. Additionally, they made changes to the Sage Pay and Paytm integrations, likely to address bugs or improve functionality. Their work suggests a focus on payment gateway integrations and library maintenance.
Provides SSL, TLS and general purpose cryptography.
Role in this project:
Security Engineer
Contributions:3 reviews, 20 commits, 18 PRs in 3 years 2 months
Contributions summary:Bart contributed significantly to the security and functionality of the OpenSSL library. Their primary contributions involved implementing and refining constant-time comparison functions like `OpenSSL.memcmp?` and `OpenSSL.fixed_length_secure_compare` to mitigate timing attacks. They also addressed potential security vulnerabilities by renaming a function related to secure comparison and adding `OpenSSL.secure_compare` which employs SHA-256 hashing. Furthermore, the user improved the library's usability by adding Marshal support to various X509 objects.
cryptographysslopensslcruby
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.