Troy's Avatar

Troy

@troymarshall.bsky.social

Product Security | Privacy | AI Safety | Digital Trust

382 Followers  |  338 Following  |  28 Posts  |  Joined: 20.11.2024  |  2.2298

Latest posts by troymarshall.bsky.social on Bluesky

Companies like Klarna and Afterpay are just high tech payday loan companies. The fact that they are offering deferred payments for food delivery services like DoorDash is disgusting.

17.04.2025 17:14 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Gen Z writes our marketing script
YouTube video by Prince William Public Libraries Gen Z writes our marketing script

This might be the best thing on the internet right now. Step away from the political doom scrolling and enjoy this awesome video.

youtu.be/BI_ovUgXC5U?...

17.04.2025 17:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I have the tools and knowledge to build a backyard shed but that doesnโ€™t make me a builder.

Likewise, the ability to write some useful code doesnโ€™t make someone, or something, a software engineer.

Thereโ€™s a lot more to building secure, resilient, maintainable software than writing code.

06.04.2025 14:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
There is no Vibe Engineering This article explores the relationship between vibe coding and software engineering.

โ€œSoftware engineering is not writing code.โ€

Generative AI tools are making coding accessible to everyone but that doesnโ€™t mean software engineers are going to be out of a job anytime soon.

serce.me/posts/2025-3...

06.04.2025 14:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Understanding RCPs and SCPs in AWS: Choosing the Right Policy for your Security Needs Using both AWS Service Control Policies and Resource Control Policies can improve security and data perimeters within your cloud infrastructure. AWS recently released RCPs in late 2024, and this post ...

Are you securing data and workloads on AWS and wondering when to use Service Control Policies (SCP) vs Resource Control Policies?

www.fogsecurity.io/blog/underst...

06.04.2025 13:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Regardless of your politics, everyone should be concerned about the complete lack of operational security in this case.

24.03.2025 22:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub Action supply chain attack: reviewdog/action-setup | Wiz Blog A supply chain attack on tj-actions/changed-files leaked secrets. Wiz Research found another attack on reviewdog/actions-setup, possibly causing the compromise.

Lots of attention on the GitHub action supply chain attack this weekend. Is this the source of the tj-actions/changed-files compromise?

If youโ€™re a GitHub user, time to check if youโ€™re using reviewdog/action-setup.

#supplychainsecurity #github

www.wiz.io/blog/new-git...

19.03.2025 00:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ISPs fear wave of state laws after New Yorkโ€™s $15 broadband mandate When the FCC isnโ€™t regulating, states have more power to impose broadband laws.

You canโ€™t have your cake and eat it too.

ISPs donโ€™t want to be regulated as common carriers but want the protections from state regulators that the designation would provide.

arstechnica.com/tech-policy/...

24.02.2025 17:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Apple pulls iCloud end-to-end encryption feature in the UK Apple will no longer offer iCloud end-to-end encryption in the United Kingdom after the government requested a backdoor to access Apple customers' encrypted cloud data.

Good for Apple not caving. However, not so good for the British people.

www.bleepingcomputer.com/news/securit...

21.02.2025 22:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Being brilliant at the basics should be the foundation of EVERY security strategy in every organization. If you arenโ€™t doing things like asset management, patching, and IAM well how do you expect to protect against 0-day exploits?

28.12.2024 17:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Donโ€™t make it an either or proposition. We should do both. Some kids will excel in college but others need a different path. Weโ€™ve focused a lot in the US on the college route and weโ€™ve lost most effective paths to skilled trade careers.

28.12.2024 17:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Is OSS is dying?

Elasticsearch, Redis, Terraform, and now Semgrep are just a few of the projects that have moved to a more restrictive licensing model in recent years.

What does this trend mean for the future of OSS?

14.12.2024 15:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
MSN

Never trust AI to protect your money!

This was a neat challenge. Congrats to the winner!

www.msn.com/en-us/money/...

02.12.2024 18:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
CySecurity News - Latest Information Security and Hacking Incidents: Malicious Python Packages Target Developers Using AI Tools This incident points to risks in downloading unverified packages of open source, more so when handling emerging technologies such as AI.

Thereโ€™s a lot of new OSS data science tools tools being released targeting genAI users. Beware, some tools are not what they seem.

#ai #supplychainsecurity #pypi #python

www.cysecurity.news/2024/11/mali...

26.11.2024 19:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Itโ€™s not often I find myself wishing for government regulation but I sure would like a single standard in the USA. Managing compliance with differing state laws is difficult to say the least.

21.11.2024 16:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™ve got 6 or so domains I just continue to pay for each year. I refuse to kill the dream that caused me to purchase in the first place!

21.11.2024 16:46 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If youโ€™ve tried GitHub Copilot in the past and werenโ€™t impressed, you should check it out again. The addition of new models like Claude Sonnet and OpenAI o1 models are a huge upgrade!

#GitHub #Copilot #SoftwareEngineering #GenAI

21.11.2024 16:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Like many things, it was better 30 years ago. Youโ€™re not missing anything.

21.11.2024 02:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Update now! Apple confirms vulnerabilities are already being exploited | Malwarebytes Apple has released security updates that look especially important for Intel-based Macs because they are already being exploited in the wild.

Apple has patched vulnerabilities in JavaScriptCore and WebKit. Get those iOS and MacOS devices.

www.malwarebytes.com/blog/news/20...

21.11.2024 02:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Two CWEโ€™s are new to the list and also tied for largest jump at 13 spots: CWE-200, Exposure of Sensitive Information to an Unauthorized Actor and CWE-400, Uncontrolled Resource Consumption.

21.11.2024 00:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CWE - 2024 CWE Top 25 Most Dangerous Software Weaknesses Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.

MITRE has released the 2025 edition of the CWE Top 25 Most Dangerous Software Weaknesses List.

2024 has seen XSS overtake Out-of-Bounds Write vulnerabilities for top spot on the list.

cwe.mitre.org/top25/archiv...

21.11.2024 00:58 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
D-Link says replace vulnerable routers or risk pwnage Vendor offers 20% discount on new model, but not patches

If youโ€™re using one of these D-Link routers, itโ€™s time to upgrade. Donโ€™t forget those routers you might have setup for friends and family too!

EOL in May 2024:
DSR-150
DSR-150N
DSR-250
DSR-250N

DSR-500N EOL 9/2015
DSR-1000N EOL 10/2015

www.theregister.com/2024/11/20/d...

21.11.2024 00:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security plugin flaw in millions of WordPress sites gives admin access A critical authentication bypass vulnerability has been discoveredย impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions.

In a surprising bit of news, a vulnerability has been discovered in a Wordpress plug-in for *checks notes* security.

Wordpress security plug-in. The very definition of an oxymoron.

www.bleepingcomputer.com/news/securit...

21.11.2024 00:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

How so you suppose they figured Chrome could fetch $20 billion? Without the advertising money, how do you monetize the browser?

20.11.2024 23:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

How can this be stopped? Sure, the FTC might stop some sales of this data but only be the more โ€œlegitโ€ data brokers. The ones that are unknown or simply nation state threat actors still have the capability to collect this data.

20.11.2024 18:59 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

How do you realistically solve this? Iโ€™ve thought about getting rid of my smart phone to reduce my own footprint but the logistics of that are difficult. Should we ban folks in sensitive roles from having devices and bringing them into installations?

20.11.2024 17:03 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If youโ€™re like me and just getting started on Bluesky, these starter packs are a great way to get started filling your feed with relevant content.

20.11.2024 16:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hello, Bluesky!

20.11.2024 15:07 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@troymarshall is following 20 prominent accounts