@onlipoi https://t.co/AWk46e7IW3
hocam gonderdiginiz bu parca sanirim yenilenmis (remanufactured) bir urun, soyle bir bakindim da egr sogutucuyu burada daha ucuza temin edebiliyorsunuz
"We often sweat life's big decisions, but it's the little decisions that matter the most -- the ones we make thousands of times a day, often without even realizing it. The big decisions are the inevitable result of those small decisions."
https://t.co/8W7A7aUZWI
I spent 12 years at Amazon in leadership, and I spent 12 years repeatedly fighting off efforts to measure (and improve) our engineer's efficiency.
Below is my general view.
Recently, I discovered a DOMPurify bypass in the case of CUSTOM_ELEMENT_HANDLING and FORBID_CONTENT options usage ⏭️
This issue isn't a big deal as it doesn't involve a default configuration bypass. However, I thought it was interesting to document it 👇
https://t.co/WLdH5sgXB0
Saatlerinizi ayarlayin!⏰ 5 Mart'da Ankara'da yine harika iki konusmaciyla yeni bir seyler ogrenecegiz. Ev sahibimiz @AnkaraTekmer e cok tesekkurler! Konusmacilarimiz @emirilhan ve @cesrinzade'ye cok tesekkur ederiz.
https://t.co/6Uff7E5lwx
🚀 New Blog Post: 🚀
"Bitwarden Heist - How to Break into Password Vaults without Using Passwords"
🔥 Join us as we dive deep into biometric auth using Windows Hello in the popular password manager Bitwarden and how to exploit it 🔥
https://t.co/nreZtAVayN
#bitwarden#infosec
Periodic reminder that if you discuss CAP theorem, ACID transactions or consistency and availability in distributed systems in general, you can freely refer to the previous body of knowledge.
This includes papers, as well as trustworthy less formal explanations.
When I was working at Google 10 years ago, 3 engineers would get together to solve a very hard problem in 6 months without distraction from anyone, then get the sponsorship of 1-2 people from leadership to turn it a real thing and slowly grow the team.
"The best security work is happening as close as possible to the engineering field work, building and developing products. That's the cheapest and most effective place to make good security decisions."
👆 GitHub's Mike Hanley on his dual-role as CSO and SVP/ Engineering
Securely hosting active and inactive user data is a fairly complex task (in particular in the light of third-party cookie deprecation). Read how @ddworken and @terjanq achieved this at Google by leveraging new web platform (security) features.
https://t.co/nRUcRjJkZ7
We’re a company with deep connections to Turkey, and our hearts go out to our Turkish colleagues and those affected by the devastating earthquake.
Please support the relief efforts by donating to a reputable nonprofit organization in the list below. 🙏🇹🇷
https://t.co/Inm2MbPb2T
#BSidesLV This is my first time joining BSides LV and I love it! Lots of good talks today and it looks like I'll be running from one hall to another all day.
.@Volexity discovers zero-day exploit impacting all current versions of Atlassian Confluence Server and Data Center. Attackers deploy in-memory Java implant to evade detection. Read more in our latest blog post: https://t.co/aCSwnSUfj8 #DFIR#ThreatIntel#InfoSec
I strongly believe that all managers in a technical area must be technically excellent.
Managers in software must write great software or it’s like being a cavalry captain who can’t ride a horse!
Welp. It’s the crypto bug of the year. Mark it down for April. Java 15-18 ECDSA doesn’t sanity check that the random x coordinate and signature proof are nonzero; a (0,0) signature validates any message. Breaks JWT, SAML, &c. https://t.co/t2WgnS0g3A