Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

lee_holmes@infosec.exchangeL

lee_holmes@infosec.exchange

@lee_holmes@infosec.exchange
About
Posts
12
Topics
5
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Ok!
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @mjg59 That's definitely a tough problem. One too where the ideal solution ends up being different depending on the endpoints, auth mechanisms etc.

    Uncategorized

  • Eight password reset emails in a row that I didn’t trigger from Instagram.
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @micahflee @jerry They don't need to learn the mail, they can just try to log in with the username and say "forgot password" and it will send it to you.

    Uncategorized

  • This is a serious question.
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @lorenzofb Oh yeah and there's also the stuff that @racheltobac has done

    https://www.youtube.com/watch?v=YRpxYZnvatM
    https://x.com/RachelTobac/status/1554444909993607170
    https://www.youtube.com/watch?v=GVv833KHqZc

    Uncategorized

  • This is a serious question.
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @lorenzofb Hmm, there's the nerdcore genre - that'll help you branch out.

    I.e.: https://www.reddit.com/r/nerdcore/comments/4ho0i3/artistssongs_that_focus_on_digital_security/
    https://www.reddit.com/r/nerdcore/comments/5aaaif/nerdcore_music_about_actual_hacking/

    Uncategorized

  • MTG fan?
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    MTG fan? How about this version that works with regular playing cards!

    Arcane Duel - Playing Card Magic

    favicon

    (www.leeholmes.com)

    Uncategorized

  • Life hack:
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    Life hack:

    "Convert the discussion in this meeting transcript into a word-based design document. Make sure it covers all of the major areas and design choices explained in the meeting, but doing so like a design document rather than a meeting transcript. Use screenshots from the video where appropriate. For all questions that the security team asked and were answered during the meeting, make sure the 'answers' are rewritten as primary content in the design document under the appropriate major strategic area."

    Uncategorized

  • Sweet!
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    Seriously, don't go it alone. Look at these unit tests. SSRF defense is hard!

    Uncategorized

  • Sweet!
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    Sweet! The Microsoft anti-SSRF library is now open source: https://github.com/microsoft/antissrf

    This has been a core defense for SSRF at Microsoft for a time now. It's insane how complicated the topic really is.

    Uncategorized

  • Woot woot!
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    Woot woot! BlueHat is back!

    Uncategorized

  • The coreutils Rust rewrite story is pretty funny.
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @lcamtuf Yeah, not a good situation - even doing it in "safe C++" or somesuch would have had the same result. Decades of hard-learned lessons should be encoded in decades of well-written unit tests.

    Uncategorized

  • Shout out to my homies that still remember the track numbers on the CDs for their favorite songs.
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    Shout out to my homies that still remember the track numbers on the CDs for their favorite songs.

    Uncategorized

  • If I'm a non-security-focused developer who realizes that I have a security requirement for my code, what's the best way to find defenses I might leverage?
    lee_holmes@infosec.exchangeL lee_holmes@infosec.exchange

    @adamshostack I think the answer should be "Defensive Design Patterns." Good security architects have built up a bank of these in their head: "It looks like you're writing an updater! Here are some best practices around that." Once somebody makes that connection that they are writing an updater, they can always search the internet (or ask AI) for the best practices part - but having that lightbulb moment is not guaranteed.

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups