Ron Perris

616 posts

Ron Perris

Ron Perris

@ronperris

Talks about secure coding and conferences near beaches. 🌴 @locomocosec

Katılım Mart 2008
4 Takip Edilen839 Takipçiler
Ron Perris
Ron Perris@ronperris·
I felt a sense of relief today, knowing humans are not on the hook to solve so many problems alone anymore.
English
0
0
1
68
Ron Perris retweetledi
Jeremiah Grossman
Jeremiah Grossman@jeremiahg·
New startup has been founded! $12.5M seed round led by Ballistic Ventures. Vulnerability management — everyone knows it’s broken. With ~50% of breach losses originating for remotely exploited vulns, "fixing" this one area will have the greatest impact on cybersecurity. Thank you to everyone who supported us. It means the world.
Root Evidence@rootevidence

We’re excited to announce Root Evidence, a company solving vulnerability management by focusing on the <1% that actually cause breach loss. Built by the team behind WhiteHat and Bit Discovery, Root Evidence is launching with $12.5M in funding led by Ballistic Ventures. Proof over probability. Fix what’s real. Read the full press release: rootevidence.com/news/root-evid…

English
3
5
18
2K
Ron Perris
Ron Perris@ronperris·
@JoshCGrossman @manicode I think we agree that Risk-Based Authentication is a real thing. Not sure if you were replying to me or Jim, so sorry if I’m crossing wires here. This reminds me, I need to dig into 5.0. Love the ASVS. 👏
English
0
0
2
42
Josh Grossman 👻 (tghosth)
Josh Grossman 👻 (tghosth)@JoshCGrossman·
@ronperris @manicode Not sure I understand your point, it is mandating what is commonly known as risk based or adaptive authentication. Googling those phrases indicates this is a well established practice. Certainly not easy to implement but that is why it is a level 3 control.
English
3
0
0
83
Jim Manico from Manicode Security
Does anyone have thoughts on this ASVS 5.0 requirment? 8.2.4 Verify that adaptive security controls based on a consumer's environmental and contextual attributes (such as time of day, location, IP address, or device) are implemented for authentication and authorization decisions, as defined in the application's documentation. These controls must be applied when the consumer tries to start a new session and also during an existing session.
English
1
3
5
827
Ron Perris
Ron Perris@ronperris·
@liran_tal Great point though, Vibe coding of examples for coding concepts you are exploring can rapidly improve your learning cycle.
English
1
0
1
34
Liran Tal
Liran Tal@liran_tal·
@ronperris aaaaah yes I'm just now noticing the typo 😆 thanks Ron!
English
1
0
1
16
Liran Tal
Liran Tal@liran_tal·
I think there is a deep misunderstanding of how earning works. The more you'll spend time vibe coding, the more you'll learn about code.
English
2
0
2
284
Ron Perris
Ron Perris@ronperris·
@liran_tal API doesn't have what? The value for the base url of the current document?
English
1
0
0
23
Liran Tal
Liran Tal@liran_tal·
@ronperris Ron, if you had to support URLs (https://...) as well as plain paths (/images/picture.jpg or avatar.png) as an input from the user, what would be your strategy to ensure there's no XSS payloads? new URL('avatar.png') will throw, but it is a legitimate input for href or img src
English
1
0
0
54
Liran Tal
Liran Tal@liran_tal·
What if I told you that parsing URLs from user input, especially from Markdown content, can be a security risk? nodejs-security.com/blog/how-to-pa… Here is how URL parsing logic an be bypassed and what you need to know to handle it in a secure way
English
2
0
3
227
Ron Perris retweetledi
ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ 🛡️
One of the biggest impacts of AI that goes kind of unnoticed is that we’re about to see an explosion of poorly built applications. Specifically, applications built completely by AI with no thought of security whatsoever. 🧵
ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ 🛡️ tweet media
English
9
19
105
11.2K
Ken Johnson
Ken Johnson@cktricky·
Hello 2025!!! 🥳 @sethlaw and I are starting the year off with our new and improved "Harnessing LLMs for AppSec", course. It will be held virtually on Jan 23 & 24. Anyone is free to register and is highly recommended for novice to intermediate skill sets. training.absoluteappsec.com
English
2
0
6
509
Ron Perris
Ron Perris@ronperris·
@manicode @semgrep F1 scores of up to 14.1% F1 = 2TP / (2TP + FP + FN) TP = True Positives FP = False Positives FN = False Negatives
English
0
0
1
52
Ron Perris
Ron Perris@ronperris·
@dcuthbert @MKBHD Someone explained cyber security products to me the other day in a fascinating way, “Comfort from Purchase - Fear of Loss = Value Provided”. It’s all emotional.
English
0
0
1
53
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
What we really need is @MKBHD-like being reviewing security products and services No bullshit. Just honest reviews
English
12
0
40
3.1K
Matt Johansen
Matt Johansen@mattjay·
I've found that I need a minimum window of 3-4 hours to really even consider working on a coding project. I get these little 30-60 minutes throughout my day if I'm lucky and it really isn't good enough to ramp up/down or troubleshoot and get anything done.
English
5
1
34
2.7K