Samy Amkar is a seasoned security-focused technologist and repeat founder with 15 years of experience building startups and offensive security tooling from Los Angeles. As Co-Founder of Openpath Security (acquired by Motorola Solutions) and earlier Fonality, he blends product leadership with deep, hands-on engineering. His open-source work on high-profile security projects like poisontap, usbdriveby and evercookie demonstrates uncommon expertise in USB/HID exploitation, browser persistence techniques, and practical privacy/compatibility hardening. Samy pairs full-stack development instincts with pragmatic threat modeling, often addressing cross-platform quirks to make exploits or defenses reliably operational. He also advises robotics and consumer-focused teams, bringing an operator’s mindset to product security and acquisition-stage outcomes.
Produces persistent, respawning "super" cookies in a browser, abusing over a dozen techniques. Its goal is to identify users after they've removed standard cookies and other privacy data such as Flash cookies (LSOs), HTML5 storage, SilverLight storage, and others.
Role in this project:
Full-stack Developer
Contributions:61 commits, 11 PRs, 19 pushes in 7 years 2 months
Contributions summary:Samy contributed to the evercookie project by adding features and making code changes to enhance its functionality. They implemented silverlight, window.name and standard cache support. Additionally, the user addressed issues with etag handling, cache mechanisms, and dependencies within the Javascript code, improving the project's overall reliability. The changes involved modifications to both the client-side JavaScript and the server-side PHP files, reflecting a full-stack approach.
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js.
Role in this project:
Security Engineer
Contributions:25 commits, 12 PRs, 23 pushes in 2 years
Contributions summary:Samy appears to be focused on the security aspects of the `poisontap` project. They made modifications to the injected Javascript files, likely to prevent the code from pointing to the developer's server, and ensuring the injected scripts executed correctly in different browsers. They also modified the USB configuration to potentially increase compatibility across different operating systems. The commits demonstrate a concern for the project's operational functionality and user privacy.
pi-zeroprotecteddropspassword-protectedusb
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.