|
Michael Helwig
@
c0dmtr1x
Augsburg, Deutschland
|
|
Making Software more Secure. Currently busy building SSDLCs.
|
|
|
928
Tweetovi
|
682
Pratim
|
604
Osobe koje vas prate
|
| Tweetovi |
|
Michael Helwig
@c0dmtr1x
|
31. sij |
|
It’s an interesting book, I actually read that when studying, but has there been any further academic discussion on this research? I never figured out if it could be true or is just too absurd...
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
20. sij |
|
Okay so I figured out yesterday that I could use PyCharm with Vim keybindings in the editor and it is absolutely awesome...
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Inon Shkedy
@InonShkedy
|
3. sij |
|
After several months of hard work, hours spent on research and discussions with our amazing @owasp community, we’re excited to announce the official release of the OWSP Top 10 for APIs
github.com/OWASP/API-Secu… pic.twitter.com/grSg16QuwT
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
2. sij |
|
Seems you can get a Ubuntu Desktop with VirtualBox running in Azure easily (thanks to Azure's nested virtualization support - didn't work in AWS due to HVM, couldn't install vbox dkms). pic.twitter.com/GvOHPngn8G
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
14. pro |
|
It is a challenge to adapt sdlc to agile,devops and ci/cd, yes, but if you look at modern interpretations -what netflix does or also owasp materials - I think appsec security people get it, just not necessarily the enterprise architects or auditors that have no background in dev.
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
14. pro |
|
Auditors mostly don’t understand sdlcs or appsec and can hardly tell the difference between hashing and encryption. I find SDLC/SDL actually less confusing and more comprehensive as the term devsecops, but yes, it sounds oldfashioned. If it is depends on people, not the term.
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
19. stu |
|
I usually use DevSecOps to refer to the automation part of an SSDLC / SDL - foremost security in CI/CD. But there is the Ops part as well and so much more that you actually need a wholesome application security strategy, and it becomes a full blown SSDLC quickly.
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Lorenzo [BRB👋]
@lorenzofb
|
17. stu |
|
New: Infamous hacker Phineas Fisher offers $100,000 as a “Hacktivist Bug Hunting Program” for hacks against spyware companies like NSO, banks, or oil companies.
vice.com/en_us/article/…
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
10. stu |
|
When a book by @SibylleBerg already starts to scare you because of the related search results... pic.twitter.com/BDBFOPRtK8
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
OWASP Mobile Security Testing Guide
@OWASP_MSTG
|
2. lis |
|
Want more training apps? We hear you! We just released the MSTG-Android-Java & MSTG-Android-Kotlin for Android and the MSTG-JWT app for iOS. Come and check it out at github.com/OWASP/MSTG-Hac… ! With special thanks to @bsd_daemon, @kongwenbin, @nikhil, and @ryantzj!
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Jeremiah Grossman
@jeremiahg
|
27. ruj |
|
We live in a world where we need software to protect software from software.
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
16. ruj |
|
@elbsides has been an awesome event with a lot of great talks and a flawless organization! Had a good time and a lot of inspiring conversations. Thanks to all the people who made this possible! twitter.com/elbsides/statu…
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
16. ruj |
|
Thanks! Yes I think so, you can also dm me and I send you tomorrow :)
|
||
|
|
||
|
Michael Helwig
@c0dmtr1x
|
15. ruj |
|
Looking forward to @Elbsides tomorrow, I am sure it will be awesome! 😎 Let this be the start of a cool new security conference in Hamburg! 🎉 twitter.com/elbsides/statu…
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Nick Sullivan
@grittygrease
|
6. ruj |
|
DNS-over-HTTPS will be rolled out by default in Firefox for U.S. users starting at the end of September 2019. Firefox will default to using Cloudflare's 1.1.1.1 at first, but that may change if other resolvers adopt a comparably strong privacy policy.
blog.mozilla.org/futurereleases…
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Elbsides
@elbsides
|
27. kol |
|
Less than three weeks until @elbsides is happening in Hamburg - very much looking forward to bringing the #infosec community closer together, listening to great ideas and talks, have lively discussions and plenty of networking. bit.ly/30sHG6u
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Dino A. Dai Zovi
@dinodaizovi
|
11. kol |
|
My #blackhat keynote (youtu.be/v1_mMO30Mxw) in a tweet thread.
I spent years focusing on the technical offense: red teaming, pen-testing, and security research. I felt that it wasn’t having enough impact, so pivoted to defensive security engineering.
I learned 3 key lessons:
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
polylog
@pspacecomplete
|
7. srp |
|
Our program for @Elbsides 2019 is live 🎉
Take a look, tickets will become available during the coming days.
2019.elbsides.de/programme.html
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Elbsides
@elbsides
|
6. srp |
|
Moin - have a look at the awesome program for our first @elbsides in Hamburg 2019.elbsides.de/programme.html Tickets will be made available next week
|
||
|
|
||
| Michael Helwig proslijedio/la je tweet | ||
|
Rasmus Tonboe
@RasmusTonboe
|
14. lip |
|
@SteffenMalskaer got the difficult task of retrieving our oceanographic moorings and weather station on sea ice in North West Greenland this year. Rapid melt and sea ice with low permeability and few cracks leaves the melt water on top. pic.twitter.com/ytlBDTrVeD
|
||
|
|
||