Stanley Zheng

3.4K posts

Stanley Zheng banner
Stanley Zheng

Stanley Zheng

@stanzheng

mostly about cloud, civic tech, and nyc he/him software engineer and civil servant @recursecenter alumn 2016/19. building @gohyperdrive

New York, USA Katılım Mayıs 2011
1.1K Takip Edilen1.1K Takipçiler
Sabitlenmiş Tweet
Stanley Zheng
Stanley Zheng@stanzheng·
So I guess we're migrating to 🐦 => mastodon 🦣 HMU: @stanley" target="_blank" rel="nofollow noopener">mastodon.social/@stanley
English
0
0
3
0
Stanley Zheng retweetledi
Hillai Ben-Sasson
Hillai Ben-Sasson@hillai·
We found a public AI repo on GitHub, exposing over 38TB of private files – including personal computer backups of @Microsoft employees 👨‍💻 How did it happen? 👀 A single misconfigured token in @Azure Storage is all it takes 🧵⬇️
Hillai Ben-Sasson tweet media
English
54
582
3.2K
1.1M
Stanley Zheng retweetledi
Wiz
Wiz@wiz_io·
For more details about this exposure, as well as a breakdown of potential risks and recommendations in using SAS, read the full blog post by @hillai 👇 wiz.io/blog/38-teraby…
English
5
62
206
89K
Byung
Byung@byungkrs·
My dream gig is reviewing PRs and leaving feedback without attending more than 1.5 hour of meeting per day.
English
1
0
2
42
Stanley Zheng retweetledi
Cloudflare
Cloudflare@Cloudflare·
On Sunday, July 9, 2023, early morning UTC time, we observed a high number of DNS resolution failures — up to 7% of all DNS queries across the Asia Pacific region. Here's what happened: cfl.re/44CUS9J
English
2
11
29
11.6K
Rolex Jodieres
Rolex Jodieres@Rolex_Jodieres·
@nycgov You pay for your check mark, as much as you want to collect taxes. Lead by example. Imagine if people/businesses would not want to pay their own taxes to the government. Besides, the government collects taxes from Twitter too. Your ego becomes a hindrance to your way of service.
English
1
0
1
231
Stanley Zheng retweetledi
follow @bencollins on bluesky
follow @bencollins on bluesky@oneunderscore__·
Curious how many people actually signed up for Twitter Blue yesterday and today? Well, I've got the numbers and I'll be telling them to @JoyAnnReid on MSNBC in ten minutes. Here's a hint: They were net +28 between signups and cancellations. Not 2,800. Twenty-eight.
English
655
3.9K
23.4K
7.5M
Stanley Zheng
Stanley Zheng@stanzheng·
@noneck lawful evil, find nearby dock and redock it. i do it with abandoned bikes I find in neighborhoods / damaged.
English
1
0
0
46
Stanley Zheng retweetledi
Simon Aarons
Simon Aarons@ItsSimonTime·
Introducing acropalypse: a serious privacy vulnerability in the Google Pixel's inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout!
Simon Aarons tweet media
English
128
2.5K
8.4K
2.1M
Stanley Zheng
Stanley Zheng@stanzheng·
@bettersafetynet @N3bberz within reason plausible they setup some auth and network connectivity between work <-> home-setup (whether or not they should have). i'd like to think this explaination than a a very senior tenured eng installed plex and directly doing work on an insecure home server as a norm.
English
0
0
1
132
Stanley Zheng
Stanley Zheng@stanzheng·
@bettersafetynet @N3bberz i was wondering this to but i know who people run thin clients as their computer but remote into a more beef home setup. (especially in the chaos of M1 macs and arm setups). it could be a case then the network connectivity or sensitive workloads were being done on their homebox
English
1
0
1
140
Mick Douglas 🇺🇦🌻
Mick Douglas 🇺🇦🌻@bettersafetynet·
Just so I'm tracking this... They used plex to get on the admin's home machine... but then the admin did what? VPN into work while a keylogger was running? There's a lot of orgs that have that problem, right? Is the fix here never VPN in from non-corp hardware?
MG@_MG_

It was Plex. They exploited Plex to get into the home network, installed a keylogger on a home laptop, and got the corp vault password because the home laptop was logging into it. Targeted high value employee shortly after the initial breach of LastPass. arstechnica.com/information-te…

English
56
28
304
98.5K
Stanley Zheng retweetledi
MG
MG@_MG_·
New details on the 2nd LastPass incident are fun: - got into Sr DevOp's home via vuln media software - installed keylogger - got master pass to corp vault (seemingly because it was being accessed from home computer) Cool to see that LastPass is sharing this level of detail. Most companies are vulnerable to an attack like this. Main post: support.lastpass.com/download/lastp… Incident 1 details: support.lastpass.com/help/incident-… Incident 2 details: support.lastpass.com/help/incident-…
English
25
329
1.3K
343.9K
Stanley Zheng
Stanley Zheng@stanzheng·
@vedant_6 working for large municipal government (nyc) this is totally written into the policy. (otherwise its viewed as stealing from tax payers / wage theft 🤷‍♂️) it is bureacratic but rarely enforced but there are policy endorsed permissions slips to verify tardiness by train delay.
English
0
0
0
609
Vedant
Vedant@vedant_6·
This is an indication that it's time to leave.
Vedant tweet media
English
57
25
688
123.1K
Stanley Zheng
Stanley Zheng@stanzheng·
@EricJorgenson doing the math. quantified revenue/society impact ---- divided by --- # of people x The biggest number that is close to 1 for organizations of 2 or more. goes against the definition of an "organization"to count a single person. If a person counts then biggest number >=1 ?
English
0
0
0
117
Eric Jorgenson 📚 ☀️
Eric Jorgenson 📚 ☀️@EricJorgenson·
What organization do you think has the highest % of extremely competent individuals?
English
119
5
116
87.7K
Stanley Zheng retweetledi
Architecture Notes
Architecture Notes@arcnotes·
Your app is getting better. It has more features, more active users, and every day it collects more data. Your database is now causing the rest of your application to slow down.
Architecture Notes tweet media
English
17
161
713
91.6K
Stanley Zheng retweetledi
Amelia Wattenberger 🪷
Amelia Wattenberger 🪷@Wattenberger·
so excited to share with you all: a new @GitHubNext addition to Copilot Labs... ✨ Code Brushes ✨ We wondered how we could make editing your code feel as tactile and easy as paint with a brush in Photoshop? writeup: githubnext.com/projects/code-… and 🧵
Amelia Wattenberger 🪷 tweet media
English
74
417
2.9K
970.3K