Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

AppSec stof :verified:

@stof@ioc.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on ioc.exchange

#father #husband #bootstrap #founder #snowboarding #hiking #surfing #kayak #music #ancienthistorybuff #astronomybuff #coder #security #researcher #curious of everything else interesting

In that order regardless of online representations

0 Followers
28 Following
20 Posts
Joined November 21, 2022
Trivial Security:
https://www.trivialsec.com/
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

@doot@glitterkitten.co.uk Carbon and Macadamia chiilin outside

18
1
3
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

I totally forgot about that "hollywood" command :tux: :terminal:
A little hacker in the making

3
0
2
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

“Knock, knock. Who’s there?” very long pause… “Java.”

https://docs.aws.amazon.com/lambda/latest/dg/snapstart.html​
#java #aws #sre #reinvent #reinvent2022

docs.aws.amazon.com
3
0
1
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

What a headline!
VPN "less Secure Network Access"
https://aws.amazon.com/blogs/aws/aws-verified-access-preview-vpn-less-secure-network-access-to-corporate-applications/

Let the pic do the talking
#aws #vpn #cybersecurity

aws.amazon.com
2
0
1
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

There's a 'grain' of truth in every joke

#AWS fine-grained permissions and #authorization is no joke

Or is it?
https://aws.amazon.com/verified-permissions/

Any practitioner can tell you that #authz is entirely about 'actions', guess what the one thing about AWS #IAM they didn't include in this service derived from IAM policy document format and #API?..

ioc.exchange
1
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

For me personally, cloud security isn’t a worry. My data is such a mess that no one would find anything anyway

Worked for Medibank!

https://aws.amazon.com/blogs/aws/preview-amazon-security-lake-a-purpose-built-customer-owned-data-lake-service/
#aws #datalake #cybersecurity #datasecurity

aws.amazon.com
1
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

Why are mausoleums the the best place to store sensitive information?

Their contents are encrypted at rest

https://aws.amazon.com/blogs/aws/announcing-aws-kms-external-key-store-xks/

#aws #pki #crypto #encryption

aws.amazon.com
1
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

99 little bugs in the code,
99 little bugs,
Take one down, patch it around,
142 little bugs in the code
https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-ec2-enables-patching-guest-operating-system-application-replace-root-volume/

#aws :calculator: :crazy:
#PatchYourShit :blobpeek: :microsoft:
#patchmanagement :git: :terminal: :ablobfoxbongo:

aws.amazon.com
1
0
5
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

@LitMoose@infosec.exchange as a couch surfer I can relate

The issue is the same thing we face with #AI #ML

The #developer coded with unconscious bias

Then the company shipped it with no employee caring what the company software actually looks like, they simply don't care enough to even use the things they sell that pays their wages

Work ethics have been this way for as long as I've been working, and I expect the next 24+ years will be no different

ioc.exchange
1
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 47mo ago
Replying to
@Blubberbub@vis.social you're trying to make a point about assurance that data won't leave the browser, CORS provides no such assurance of that no matter how you designed the fetch/xhr to gain it in the first place, thats (CORS) is the opposite direction..
1
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

@jerry@infosec.exchange a lot of 1.2, even some 1.1, ciphers are fine
Disabling an entire protocol is what bad security tools and uneducated people tell you
Just serve a set of ciphers not known to be weak and a few other tweaks like SCSV and DNSSEC, also if you're going to be relying on those nasty ACME issued DV certs maybe use your own CSR and at least get a v3 with must staple flag
TLS has too many knobs and levers....

0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

@jerry@infosec.exchange its mine, link in the bio
The pic mentions CBC which obviously isn't TLS1.3
and my message talked about bad actors using the least secure methods available, which is what the tool looks for too
Happy to go offline to chat, you don't seem to be paying attention to the details so whenever you're ready, happy to help you out if i can too, no drama

0
1
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

@jerry@infosec.exchange as many others have pointed out, that's not a high confidence report

Besides, bad actors don't negotiate the 'best' available, they connect with the most exploitable option

My tool wasn't too impressed either

0
1
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 45mo ago

My #NewYear2023 resolution
1920x1080 as usual :blobpats:

Maybe an upgrade is due :battery_broken:
This will be a hand-me-down or dedicated :kali_linux_r:

ioc.exchange
0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

🪰🪲
We added bugs to our home page (on purpose)
🪰🪲
https://www.trivialsec.com/
🪰🪲
Keep or exterminate?
🪰🪲🪰🪲🪰🪲

trivialsec.com
0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

Today, after years of coding, I made my first money as a Programmer

I sold my laptop

Meanwhile my code is used by the largest and most profitable businesses, and they call it;
https://aws.amazon.com/about-aws/whats-new/2022/11/aws-supply-chain-preview/
#aws #opensource #sca #sbom

Amazon Web Services, Inc.

Announcing AWS Supply Chain (Preview) - AWS

Discover more about what

0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 46mo ago

#stargate has it all
Adventure
Dry humour
Space
Ancient history (mythology mostly)
Action scenes
Witty
Short stories
Loooong story arcs
Interesting characters
Clever twists
Love interest
Self detrimental humour
Oh the puns!

ioc.exchange

IOC.exchange

0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 47mo ago

@cvwise@infosec.exchange i have an Arch box here with some pretty similar period ports, isolated in all known ways to access it remotely doing backups pull-style. Very reliable
Old hardware never looses usefulness

infosec.exchange

cvw (@cvwise@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 47mo ago

Do you collect #vulnerabilities?
What do you do next?
Alert a #developer channel?
Store in excel
Keep in #DevOps pipeline logs
Review in a vulnerability management process
Report with pretty graphs and scream at dev teams to patch the fraking software faster?
Really, what works for you, actually works?

ioc.exchange

IOC.exchange

0
0
1
0
Open post
AppSec stof :verified: @stof@ioc.exchange
· 47mo ago
Replying to
@Blubberbub@vis.social i think you mean CSP, because CORS is only for those who control both client and server on different origins, and a twitter scenario with CORS would not make sense. CSP however gives us confidence if it defines explicitly what external APIs will work, everything else will be blocked (except plugins)
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:13:48 UTC