ray

7.4K posts

ray banner
ray

ray

@Raybeorn

Life Coach, Conspiracy Theorist, and Absurdist. I do AppSec in my non-spare time for money. My opinions are now your opinions, but at least you are now right!

The Wasteland Katılım Mart 2012
318 Takip Edilen582 Takipçiler
Sabitlenmiş Tweet
ray
ray@Raybeorn·
So I have a mastodon account now. I haven't really been using Twittter much lately. hit me up @raybeorn" target="_blank" rel="nofollow noopener">infosec.exchange/@raybeorn
English
0
0
1
0
glum
glum@glumDumpling·
She’s naughty, I’m nice! I love Lacey @koronkowy- we were mutuals for like 6 years before I met her IRL 🥲 She’s available and looking for work by the way- who’s hiring for technical sales roles in cyber? If you don’t have anything, it would mean a lot if you could RT !
glum tweet media
English
13
57
125
16.9K
ray
ray@Raybeorn·
@Jo3Ram But yeah secure design decisions are key
English
0
0
0
28
ray
ray@Raybeorn·
@Jo3Ram OSS usually requires a lot of time to set up properly. Most need rotisserie gold solutions, just set it and forget it
GIF
English
1
0
0
29
Joe Christian
Joe Christian@Jo3Ram·
“AMA - I built a cybersecurity agency in a week, so you can totally trust me and hand over your source to an unknown entity” Folks, just use the god damn OSS security tools out there and make good design decisions. Shipping fast doesn’t need to compromise security.
Simon@soeckly

I just launched my new project shipsecu.re 🎊 After all the Marc Lou drama, I decided to build a cybersecurity agency focused on helping indie devs and startups stay secure.

English
1
0
1
144
ray
ray@Raybeorn·
@thatsjet @shehackspurple I have been using software for a long time, i can’t say that things have gotten worse but it hasn’t gotten better. The business incentives aren’t there
English
0
0
2
25
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
What should the ratio be between software developers and security professionals?
English
4
0
4
1.1K
ray
ray@Raybeorn·
@shehackspurple I think it is dependent on the development culture. Some might need more security support others might need less
English
0
0
1
28
ray
ray@Raybeorn·
@Jo3Ram Its very rare where there is a product out there that surprises me
English
0
0
1
14
Joe Christian
Joe Christian@Jo3Ram·
I’m very much in-tune with the vendor space. If I want your stuff, I will come to you. If not, pestering me to the limit will make me forever resent your company regardless of how much I like the product.
English
1
0
1
47
Joe Christian
Joe Christian@Jo3Ram·
Look, Semgrep is cool and I have a lot of respect for my friends that work there. I also get the sales environment is difficult. If I didn’t respond to the previous 7 emails and my peers didn’t respond, calling my personal phone 7+ times was irreparable. Leave me alone.
English
1
0
0
87
ray
ray@Raybeorn·
@glumGPT @BSidesPDX The badge is pretty cool tho. Gotta love the squach themes they always provide
English
1
0
2
89
glum
glum@glumDumpling·
Who’s going to @BSidesPDX ?
English
2
0
3
1.2K
ray
ray@Raybeorn·
@Jo3Ram I’ll hit you up next week and we can figure something out
English
1
0
0
68
Joe Christian
Joe Christian@Jo3Ram·
@Raybeorn Everyone is in security, but across a variety of domains. A good portion are focused on code security/devs.
English
1
0
0
14
Joe Christian
Joe Christian@Jo3Ram·
InfoSec Peeps: I’m planning on putting together a speaker series at my org where I want to invite experts from the outside to give their opinions on a domain space that they operate in. Any topic, just no vendor pitches. If that’s something that interests you, send me a DM 📧
English
1
0
2
205
ray
ray@Raybeorn·
@Jo3Ram Is it devs or security people or both?
English
1
0
0
54
ray
ray@Raybeorn·
@0xTib3rius @sec_tigger @shehackspurple @OWASPTop10 @owasp It’s an awareness doc for devs about things they should be concerned about. I think it kinda has just out grown being about vulns. When it was about vulns it wasn’t very helpful to people actually fixing shit. Plus who fucking cares.
English
1
0
3
78
Tib3rius
Tib3rius@0xTib3rius·
With respect, that makes no sense. The issue isn't data collection, it's how you process it and decide to generate the Top 10. You used to have actual vulnerabilities in the Top 10. Now it's mostly categories of vulnerabilities. It's not a "Top" 10 anymore, it's 10 categories that cover 99.99% of vulns, if not 100%, thanks to "Insecure Design". Make it an actual Top 10 again.
English
2
0
3
103
ray
ray@Raybeorn·
@endingwithali I think just changing the admin password is enough. Most people should be fine.
English
0
0
1
98
ali
ali@endingwithali·
When you set up a new home router, what are some of the first things you do to secure it (beyond changing the password)? (PS its for a video)
English
206
23
621
129.3K