Sabitlenmiş Tweet
ray
7.4K posts

ray
@Raybeorn
Life Coach, Conspiracy Theorist, and Absurdist. I do AppSec in my non-spare time for money. My opinions are now your opinions, but at least you are now right!
The Wasteland Katılım Mart 2012
318 Takip Edilen582 Takipçiler

She’s naughty, I’m nice!
I love Lacey @koronkowy- we were mutuals for like 6 years before I met her IRL 🥲
She’s available and looking for work by the way- who’s hiring for technical sales roles in cyber?
If you don’t have anything, it would mean a lot if you could RT !

English

“AMA - I built a cybersecurity agency in a week, so you can totally trust me and hand over your source to an unknown entity”
Folks, just use the god damn OSS security tools out there and make good design decisions.
Shipping fast doesn’t need to compromise security.
Simon@soeckly
I just launched my new project shipsecu.re 🎊 After all the Marc Lou drama, I decided to build a cybersecurity agency focused on helping indie devs and startups stay secure.
English

@thatsjet @shehackspurple I have been using software for a long time, i can’t say that things have gotten worse but it hasn’t gotten better. The business incentives aren’t there
English

@shehackspurple I think it is dependent on the development culture. Some might need more security support others might need less
English

@glumGPT @BSidesPDX The badge is pretty cool tho. Gotta love the squach themes they always provide
English

@Raybeorn Everyone is in security, but across a variety of domains. A good portion are focused on code security/devs.
English

Call for data for the next @OWASPTop10 ! At @owasp global AppSec in San Francisco! With @sec_tigger 🥳

English

@sec_tigger @0xTib3rius @shehackspurple @OWASPTop10 @owasp Hey avi, the data is there for anyone to look at? If so, then someone could make a top 10 vuln list if they wanted?
English

@0xTib3rius @sec_tigger @shehackspurple @OWASPTop10 @owasp Do you work with a lot of devs directly? I do, i prefer this approach better compared to the 2013 version which was calling out specific vulns. But i could be wrong
English

@0xTib3rius @sec_tigger @shehackspurple @OWASPTop10 @owasp It literally says top 10 web application security risks. No where does it say the top 10 vulns on their page ( with a quick ctrl + f search )
English

@0xTib3rius @sec_tigger @shehackspurple @OWASPTop10 @owasp That is why it doesn’t have 11 items on it
English

@0xTib3rius @sec_tigger @shehackspurple @OWASPTop10 @owasp It’s an awareness doc for devs about things they should be concerned about. I think it kinda has just out grown being about vulns. When it was about vulns it wasn’t very helpful to people actually fixing shit. Plus who fucking cares.
English

With respect, that makes no sense. The issue isn't data collection, it's how you process it and decide to generate the Top 10.
You used to have actual vulnerabilities in the Top 10. Now it's mostly categories of vulnerabilities.
It's not a "Top" 10 anymore, it's 10 categories that cover 99.99% of vulns, if not 100%, thanks to "Insecure Design".
Make it an actual Top 10 again.
English

@endingwithali I think just changing the admin password is enough. Most people should be fine.
English

