Adam Langley

7K posts

Adam Langley banner
Adam Langley

Adam Langley

@BuildHackSecure

Ethical Hacker & Fullstack Dev | Helping thousands learn to hack ethically & build secure apps | CTO @hackinghub_io | Director @bsidesexeter

Exeter, England Katılım Şubat 2015
775 Takip Edilen9.9K Takipçiler
Adam Langley retweetledi
Scott Helme
Scott Helme@Scott_Helme·
Honestly this should be a national scandal. The river I used to play in as a kid is now so polluted that my kid can’t play in it. bbc.co.uk/news/articles/…
English
1
1
14
1.1K
TryHackMe
TryHackMe@tryhackme·
The grid has spoken.
TryHackMe tweet media
English
11
3
38
3.3K
STÖK ✌️
STÖK ✌️@stokfredrik·
After trying to renovate the old camper I bought last summer only to realize I suck at fiberglass work and that it was water damaged. The only viable option for me, was to order a new one that matched my needs. so got myself a custom euro built dux explorer 240 camper, with diesel heating, diesel stove, compost toilet, heated water tanks and a solar setup that allows me to be offgrid for very long periods of time (all year around). This setup combined with the power of the ford ranger wildtrack 2025 with airbags and true 4x4, opens up endless possibilities and is going to be a great companion when I’m going explore the northern parts of Scandinavia the upcoming season. And yes, semlan is cute and hungry.
English
5
1
52
3.6K
Joseph Thacker
Joseph Thacker@rez0__·
we're mopping up the internet one submission at a time
English
4
0
31
2.9K
Adam Langley retweetledi
Adam Langley
Adam Langley@BuildHackSecure·
Why are API keys not bound to an IP address allow list? I never see this option available in API services. Failing that, you should also receive an email whenever a new IP address attempts to use your API key. API keys should double up as canary tokens.
English
31
18
216
25.4K
freakyclown
freakyclown@_Freakyclown_·
Feast your eyes on this abomination of a UX - it’s so overwhelming it has to shared!
English
5
0
6
1.1K
Adam Langley
Adam Langley@BuildHackSecure·
@schuyler_t @TweetEagle1 @francip Ah right maybe it's changed, just remember hearing something a few years ago that people were really locked into suppliers and had little to no choice. But that 2 gig both way sounds amazing! Only things I could of dreamt of back in the 90s with a dial up haha
English
0
0
0
24
Schuyler Thompson
Schuyler Thompson@schuyler_t·
@BuildHackSecure @TweetEagle1 @francip Very much depends where you are, but I’d say that’s the median experience yes. In Seattle there’s 4 or 5 different options but availability varies by neighborhood. My first gig connection was from an ISP that only served apartment buildings/condos.
English
1
0
0
17
Schuyler Thompson
Schuyler Thompson@schuyler_t·
@BuildHackSecure @TweetEagle1 @francip I think they did with a business plan, they’re also switching away from PPPoE to DHCP (“IPoE”) so it might get more stable with that. I switched to Comcast last year because they offered 2 gig symmetric for $10 less than I was paying.
English
1
0
0
46
Adam Langley
Adam Langley@BuildHackSecure·
@juliknl I didn’t say keys should only be used from prod. And like I said my post did have a subconscious focus on dev machines. I never said whitelisting for all tokens, I just want options.
English
0
0
0
39
Julik Tarkhanov
Julik Tarkhanov@juliknl·
Why should keys be only usable from prod, and not from, say, development machines? Leaks of PATs are an orthogonal issue - it's handy when services notify that "$usage of your token just occurred from $ip and it did $action" but whitelisting for all tokens feels like extreme overkill
English
1
1
1
92
Adam Langley
Adam Langley@BuildHackSecure·
Well I can confidently say after crunching all the numbers that all developers that have been working for between 5 - 10 years have less job satisfaction due to AI, feel free to use and quote my indepth research.
Adam Langley tweet media
Adam Langley@BuildHackSecure

I'm interested what effect AI has had on job satisfaction for Software Engineers and Developers, and whether there's any correlation with years of experience. I'd love to get many responses, so please share post. I'll share the results in a few days. forms.gle/tnqVmAxzr4x5eR…

English
1
0
2
750
Adam Langley
Adam Langley@BuildHackSecure·
@rad9800 Yeah agreed, it's definetly not a perfect solution but I'd like the option. And I'm sure there's a lot of people in my situation as a WFH dev who uses a lot of API keys and doesn't really change IP addresses.
English
0
0
2
73
Rad
Rad@rad9800·
humbly, the illusion of security (if an option). if I've learnt one thing, if there is a way to fuck up users will do so. if it was enforced, great - an anti-fuck up, but high-friction. secrets as is, should not be solved with bandaids. I like the idea, but it does seem like a tarpit!
English
1
0
1
51
Adam Langley
Adam Langley@BuildHackSecure·
@just_infosec_ @francip Yeah, I think even at least something alerting you that your IP address is being suddendly used in a different country.
English
1
0
0
165
SS
SS@just_infosec_·
@BuildHackSecure @francip I always wanted this IP whitelisted approach, but: Whenever IP changes, someone else is whitelisted. In big orgs, Operationally it takes time to get the new IP whitelisted. In case of corporate vpn gateway IP, a lot of people share the same public IP
English
1
0
0
138
Adam Langley
Adam Langley@BuildHackSecure·
@fwrnr @rad9800 Haha literally going to respond back with "have you heard of a JOIN statement" I think it would be minuscule, if a dev complained about it I'd ask to see their code and in 5 minutes probably save even more compute from somewhere else by improving a statement or adding an index.
English
0
0
0
31
Adam Langley
Adam Langley@BuildHackSecure·
@shuv1337 Ah yeah, I've been caught out a couple of times with all of the IP ranges not been publically kept upto date.
English
0
0
2
201
shuv
shuv@shuv1337·
@BuildHackSecure i restrict keys by ip whenever possible but it's a royal pain for cloud > cloud stuff. just pray your provider publishes an accurate and updated egress list. still worth the pain whenver it's doable though
English
1
0
2
253