Companies like Klarna and Afterpay are just high tech payday loan companies. The fact that they are offering deferred payments for food delivery services like DoorDash is disgusting.
17.04.2025 17:14 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0@troymarshall.bsky.social
Product Security | Privacy | AI Safety | Digital Trust
Companies like Klarna and Afterpay are just high tech payday loan companies. The fact that they are offering deferred payments for food delivery services like DoorDash is disgusting.
17.04.2025 17:14 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0This might be the best thing on the internet right now. Step away from the political doom scrolling and enjoy this awesome video.
youtu.be/BI_ovUgXC5U?...
I have the tools and knowledge to build a backyard shed but that doesnโt make me a builder.
Likewise, the ability to write some useful code doesnโt make someone, or something, a software engineer.
Thereโs a lot more to building secure, resilient, maintainable software than writing code.
โSoftware engineering is not writing code.โ
Generative AI tools are making coding accessible to everyone but that doesnโt mean software engineers are going to be out of a job anytime soon.
serce.me/posts/2025-3...
Are you securing data and workloads on AWS and wondering when to use Service Control Policies (SCP) vs Resource Control Policies?
www.fogsecurity.io/blog/underst...
Regardless of your politics, everyone should be concerned about the complete lack of operational security in this case.
24.03.2025 22:46 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Lots of attention on the GitHub action supply chain attack this weekend. Is this the source of the tj-actions/changed-files compromise?
If youโre a GitHub user, time to check if youโre using reviewdog/action-setup.
#supplychainsecurity #github
www.wiz.io/blog/new-git...
You canโt have your cake and eat it too.
ISPs donโt want to be regulated as common carriers but want the protections from state regulators that the designation would provide.
arstechnica.com/tech-policy/...
Good for Apple not caving. However, not so good for the British people.
www.bleepingcomputer.com/news/securit...
Being brilliant at the basics should be the foundation of EVERY security strategy in every organization. If you arenโt doing things like asset management, patching, and IAM well how do you expect to protect against 0-day exploits?
28.12.2024 17:59 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Donโt make it an either or proposition. We should do both. Some kids will excel in college but others need a different path. Weโve focused a lot in the US on the college route and weโve lost most effective paths to skilled trade careers.
28.12.2024 17:01 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Is OSS is dying?
Elasticsearch, Redis, Terraform, and now Semgrep are just a few of the projects that have moved to a more restrictive licensing model in recent years.
What does this trend mean for the future of OSS?
Never trust AI to protect your money!
This was a neat challenge. Congrats to the winner!
www.msn.com/en-us/money/...
Thereโs a lot of new OSS data science tools tools being released targeting genAI users. Beware, some tools are not what they seem.
#ai #supplychainsecurity #pypi #python
www.cysecurity.news/2024/11/mali...
Itโs not often I find myself wishing for government regulation but I sure would like a single standard in the USA. Managing compliance with differing state laws is difficult to say the least.
21.11.2024 16:48 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Iโve got 6 or so domains I just continue to pay for each year. I refuse to kill the dream that caused me to purchase in the first place!
21.11.2024 16:46 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0If youโve tried GitHub Copilot in the past and werenโt impressed, you should check it out again. The addition of new models like Claude Sonnet and OpenAI o1 models are a huge upgrade!
#GitHub #Copilot #SoftwareEngineering #GenAI
Like many things, it was better 30 years ago. Youโre not missing anything.
21.11.2024 02:18 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Apple has patched vulnerabilities in JavaScriptCore and WebKit. Get those iOS and MacOS devices.
www.malwarebytes.com/blog/news/20...
Two CWEโs are new to the list and also tied for largest jump at 13 spots: CWE-200, Exposure of Sensitive Information to an Unauthorized Actor and CWE-400, Uncontrolled Resource Consumption.
21.11.2024 00:58 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0MITRE has released the 2025 edition of the CWE Top 25 Most Dangerous Software Weaknesses List.
2024 has seen XSS overtake Out-of-Bounds Write vulnerabilities for top spot on the list.
cwe.mitre.org/top25/archiv...
If youโre using one of these D-Link routers, itโs time to upgrade. Donโt forget those routers you might have setup for friends and family too!
EOL in May 2024:
DSR-150
DSR-150N
DSR-250
DSR-250N
DSR-500N EOL 9/2015
DSR-1000N EOL 10/2015
www.theregister.com/2024/11/20/d...
In a surprising bit of news, a vulnerability has been discovered in a Wordpress plug-in for *checks notes* security.
Wordpress security plug-in. The very definition of an oxymoron.
www.bleepingcomputer.com/news/securit...
How so you suppose they figured Chrome could fetch $20 billion? Without the advertising money, how do you monetize the browser?
20.11.2024 23:51 โ ๐ 0 ๐ 0 ๐ฌ 2 ๐ 0How can this be stopped? Sure, the FTC might stop some sales of this data but only be the more โlegitโ data brokers. The ones that are unknown or simply nation state threat actors still have the capability to collect this data.
20.11.2024 18:59 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0How do you realistically solve this? Iโve thought about getting rid of my smart phone to reduce my own footprint but the logistics of that are difficult. Should we ban folks in sensitive roles from having devices and bringing them into installations?
20.11.2024 17:03 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0If youโre like me and just getting started on Bluesky, these starter packs are a great way to get started filling your feed with relevant content.
20.11.2024 16:55 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Hello, Bluesky!
20.11.2024 15:07 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0