Lars

2K posts

Lars

Lars

@bob5ec

#LangSec conspirator eleminating injection vulnerabilities, #DevSecOps practitioner authoring #SecurityBelts and #ThreatModeling security architecture.

Katılım Ocak 2012
308 Takip Edilen207 Takipçiler
Sabitlenmiş Tweet
Lars
Lars@bob5ec·
Summing up the root cause of input-based security vulnerabilities dev.to/bob5ec/the-roo…
English
1
3
4
0
Lars
Lars@bob5ec·
@OwaspSAMM goes Everything as code. Model driven Security as a way to improve Security Engineering.
Lars tweet media
English
0
0
0
6
Lars
Lars@bob5ec·
I had a great time meeting the @OwaspSAMM Community. Lots of like-minded people! TIL: OWASP SAMM is for people running an #AppSec program. Target groups are not Developers or Security Champions. Hence OWASP DSOMM and Security Belts need to be there to support these target groups.
English
0
1
1
58
Lars
Lars@bob5ec·
Greetings from Lisbon. Looking forward to @OwaspSAMM User day and @owasp AppSec Global.
Lars tweet media
English
0
0
0
47
Lars
Lars@bob5ec·
@4k3nd0 Sorry, but not sorry. I still wonder how to identify the archetypes in day-to-day life.
English
0
0
0
5
Akendo
Akendo@4k3nd0·
@bob5ec Stop being in my head! I was just thinking about this diagram.
English
1
0
0
18
Lars retweetledi
I Am Devloper
I Am Devloper@iamdevloper·
There should be a reality show where project managers try to meet outrageous deadlines while developers keep introducing new features.
English
7
55
342
35.1K
Lars
Lars@bob5ec·
For everyone who is improving security culture, ui-patterns.com might be an awesome source of inspiration for fundamental patterns that can be applied.
English
0
0
0
44
Lars retweetledi
Rami McCarthy
Rami McCarthy@ramimacisabird·
I just launched a new post with @clintgibler over on tl;drsec, check it out! When I read Wiring the Winning Organization (@RealGeneKim, @StevenJSpear), I spent the whole time trying to map the concepts to Security 1/2
Rami McCarthy tweet media
English
1
10
28
2.9K
Lars retweetledi
TROOPERS Conference
TROOPERS Conference@WEareTROOPERS·
We just published an almost complete list of talks that have been accepted for #TROOPERS24. Thanks to all of you who participated in the CFP! So many excellent submissions. We really had a hard time to decide which will fit best for this year! troopers.de/troopers24/tal…
English
0
17
36
37.5K
Abhay Bhargav
Abhay Bhargav@abhaybhargav·
An underrated aspect of AppSec and Secure Coding is not exposing the insecure functionality in the first place. Let's say you have a XML parsing library that may be used by devs wrongly/insecurely. By disabling certain functions in the library, its not vulnerable to XML Injection anymore Instead of constantly training them to figure out security params, having a wrapper library (custom) that automatically disables insecure functionality is way more effective. It's: * easier to use * easier to enforce (in SAST, CI, SBOM, etc) * easier to train on * reduces cognitive load for devs in the long run * and more secure Keep it simple.
English
2
3
16
1.4K
Lars
Lars@bob5ec·
@abhaybhargav 100%! And now expand this idea to functionality of programming languages that is dangerous to use, i.e. string concatenation. If we would be able to remove that and create an abstraction for generating output all injections would be gone.
English
0
0
0
37
Lars retweetledi
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
What is this? Wrong answers only
Daniel Cuthbert tweet mediaDaniel Cuthbert tweet media
English
19
1
2
2.6K