Koen Rouwhorst

45 posts

Koen Rouwhorst

Koen Rouwhorst

@koenrh

Security at @framer. I build and break things on the internet.

Amsterdam, The Netherlands Katılım Şubat 2009
74 Takip Edilen2.8K Takipçiler
Koen Rouwhorst
Koen Rouwhorst@koenrh·
For your business-critical domains, move to a well-established registrar that supports registry locks (CSC, MarkMonitor, Cloudflare). Configure multi-party authorization for unlocking, so no single individual can approve changes. Use role-based contacts, not personal emails. Enforce phishing-resistant MFA. And set auto-renewal with a multi-year buffer. These controls have been around for many years. They are just underused.
English
0
0
6
113
Koen Rouwhorst
Koen Rouwhorst@koenrh·
You can easily check this for your own domains. Do a whois lookup and check the domain status fields. Statuses starting with "client" (e.g. clientTransferProhibited) are set by the registrar and can be removed by the registrar. Statuses starting with "server" (serverDeleteProhibited, serverTransferProhibited, serverUpdateProhibited) are set by the registry and can only be removed through the out-of-band process described above.
Koen Rouwhorst tweet media
English
1
0
4
95
Koen Rouwhorst
Koen Rouwhorst@koenrh·
Domain registrars may be one of the most overlooked single points of failure in our stack. We spend serious time and resources securing our cloud infrastructure and workloads, but our domain registrars rarely get the same level of scrutiny. Even though our domains underpin everything we operate. 🧵
English
1
4
12
319
Koen Rouwhorst
Koen Rouwhorst@koenrh·
All @framer emails now show a verified logo and blue checkmark in supporting inboxes like Gmail. Here is what is behind that little checkmark. 🧵
Koen Rouwhorst tweet media
English
7
2
74
4.4K
Koen Rouwhorst
Koen Rouwhorst@koenrh·
All @framer emails now show the verified logo across Gmail, Apple Mail, Fastmail, and Yahoo. This is first and foremost a nice trust signal for our users. When an email claims to come from Framer, the verified logo lets them know at a glance that it actually does.
English
1
0
4
427
Koen Rouwhorst
Koen Rouwhorst@koenrh·
The standard method for organization validation is a phone call to a publicly listed phone number. Framer is a remote-first company. We are incorporated in the Netherlands and have an office there, but no fixed phone line. So we asked legal to draft a legal opinion letter to establish a non-listed number for verification. That got rejected because our counsel was not registered with the local bar association in the required jurisdiction. 🙃 The certificate authority eventually fell back to sending a physical postal letter with a verification code to our physical address listed on Dun & Bradstreet. Yes, we used snail mail to verify our identity for email!
English
1
0
3
411
Koen Rouwhorst
Koen Rouwhorst@koenrh·
This setup is not about being unreachable. It is about being available for the right people and the right work, at the right time, with a brain that is fully present. Quiet by default, across every channel. Distractions stay out. Exceptions have to earn their way in. What is left is focus time, and the space to build and ship.
English
0
0
4
106
Koen Rouwhorst
Koen Rouwhorst@koenrh·
Phone Same pattern as calendar and email. Default off, exceptions earn their way in. Focus mode is always on. Only contacts marked as favorite get through: family, friends, close colleagues, leadership. App notifications are mostly off. PagerDuty is the only exception, for real (security) incidents. Everyone else can wait.
English
1
0
3
124
Koen Rouwhorst
Koen Rouwhorst@koenrh·
We are a company of makers and doers. A small team building and running a serious product, with real traction and big ambitions. We have high standards, little hierarchy, and lots of autonomy. Every engineer is expected to make an impact, and none of that works without protected focus time. That means ruthlessly cutting distractions. Here is how I do that as a security engineer at @framer, across email, calendar, Slack, and phone.
English
2
0
14
819