@MathisHammel OWASP API 10 référence celle là https://t.co/O0wQQmhyAD. Un must à connaitre pour qui veut designer des APIs Web! Et éviter ce genre de faille grossière :/
If you haven't seen the Microsoft OAuth vulnerability yet, you need to check it out. #nOAuth
Anyone in the world is able to access your apps AS YOU with MS OAuth if the app is configured to use email as the account identifier.
Next tweet contains a video demo:
Do NOT. I repeat. Do NOT remove curl.exe from your Windows System32 folder to silence a (stupid) security scanner. It will lead to tears and sorrows.
And if you do, please don't ask *me* for help when you've broken your Windows install. I can't fix that.
As we scale systems, it's essential to realize the impact of all the components in our systems and how they interact. For example, load balancers usually come into play once we scale beyond one server being able to serve requests reliably.
"As geeks we now seem to be stuck in a perpetual anti-hype cycle, where Silicon Valley ... sell[s] the world on a new 'disruptive' thing and all of the sane people have to point out why that thing does not and can never do what is promised of it."
https://t.co/EbMIdOnXEo
@Joyce_Stack I would say UX, API formats concepts and API specs. API designers need to understand what are the goals of their consumers and know how to interact with them
#Netflix has unveiled the details of its new anti-#PasswordSharing policy, detailing a suite of complex gymnastics that customers will be expected to undergo if their living arrangements trigger @Netflix's automated enforcement mechanisms:
https://t.co/Kk5ANPumOs 1/
The top productivity hack in software development is to build foundations that are dependable enough that you can keep building on top without having to go back and modify them as you go. 100x time saver.
When it comes to Staff Engineer or Principal Engineer roles, expectations can - and do! - wary wildly between companies.
While this should not be surprising for any leadership role, those changing positions for the first time as a Staff+ engineer can be caught off-guard.
I've been covering bad parts of the internet for long time now.
For years, there was one site extremist researchers warned me not to cover because publicizing it would be dangerous.
But it's time people know KiwiFarms—and how they're chasing political enemies around the world.
I've never felt so conflicted about an emerging technology as AI text-to-image models, which are so immediately fun to play with, but raise so many ethical questions, it's hard to keep track of them all. https://t.co/xFYD2ZD4PN