Koto's Avatar

Koto

@kkotowicz.bsky.social

Security ninja wannabe / board game geek / photon catcher

1,537 Followers  |  429 Following  |  18 Posts  |  Joined: 16.11.2024  |  2.0507

Latest posts by kkotowicz.bsky.social on Bluesky

Just when you think CVEs cannot get more ridiculous... ๐Ÿคฃ

25.01.2025 19:35 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Interesting. I wonder what's the motivation for projects to opt-in to this, and how many did already. Sounds like it would incur prohibitive costs on the company and the bug hunter (explaining technical security bugs to lawyers is orders of magnitude more involved than to security engineers).

23.01.2025 10:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
I wake up in the morning.
I sit at my computer.
The internet screams at me that the world is on fire.
I am overwhelmed by the deluge of bad news and faceplant in front of the computer.

I wake up in the morning. I sit at my computer. The internet screams at me that the world is on fire. I am overwhelmed by the deluge of bad news and faceplant in front of the computer.

I would like this comic I drew in 2017 to stop being relevant pleeeaaaaase

14.01.2025 17:21 โ€” ๐Ÿ‘ 31095    ๐Ÿ” 6504    ๐Ÿ’ฌ 66    ๐Ÿ“Œ 304
Preview
Is Telegram really an encrypted messaging app? This blog is reserved for more serious things, and ordinarily I wouldnโ€™t spend time on questions like the above. But much as Iโ€™d like to spend my time writing about exciting topics, somโ€ฆ

Telegram: not an encrypted messaging app ;) blog.cryptographyengineering.com/2024/08/25/t...

07.01.2025 17:41 โ€” ๐Ÿ‘ 6    ๐Ÿ” 7    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bombs in train firmware?
IBAN for donations is available here:
www.ccc.de/en/updates/2...

Talks for context
media.ccc.de/v/37c3-12142...
streaming.media.ccc.de/38c3/relive/...

28.12.2024 09:29 โ€” ๐Ÿ‘ 36    ๐Ÿ” 18    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

Do I hear CSP? :)

10.12.2024 09:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Chestertonโ€™s Fence: A Lesson in Thinking A core component of making great decisions is understanding previous decisions. If we donโ€™t understand how we got โ€œhere,โ€ we run the risk of making things much worse.

TIL about Chersterton's Fence fs.blog/chestertons-... - it puts a nice label to an intuition that I find very useful to apply in practice - from refactoring code, through process engineering. Understand first why the mess exists, in that form, before attempting to clean it up and revolutionize.

10.12.2024 08:45 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

To this day I think my demise will be through some npm shenanigans. And it's fair, I deserve it. It should Javascript->RCE.

04.12.2024 20:50 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!) The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...

I don't often post about my work but bughunters.google.com/blog/6355265... is actually super cool thing my team is doing. These short term redteams focused on just stealing our passwords were always amazing to highlight how severely broken complex systems are. The internal writeups are so, so fun!

04.12.2024 19:00 โ€” ๐Ÿ‘ 18    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
transliterate.js Translate any JavaScript code to foreign writing systems. Created by Martin Kleppe aka @aemkei.

Pro tip for if you have XSS but you can only use upper case:

aem1k.com/transliterat...

transliterate.js by @aemkei.bsky.social works great!

04.12.2024 10:06 โ€” ๐Ÿ‘ 21    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

There's no such thing as a "9.2" or "9.8" vulnerability. There's more science in Pitchfork's 0.0-10.0 album rating scale than in CVSS. I am completely serious. Pitchfork reviewers actually put their reviews in context with previous reviews by the artist. That's how bad CVSS is: worse than Pitchfork.

27.11.2024 00:57 โ€” ๐Ÿ‘ 46    ๐Ÿ” 10    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 1
Modern solutions against cross-site attacks Modern solutions against cross-site attacks

Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.

27.11.2024 07:50 โ€” ๐Ÿ‘ 34    ๐Ÿ” 19    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
research!rsc: Running the โ€œReflections on Trusting Trustโ€ Compiler

Not sure how I missed that, but we now actually have Ken Thompson's C compiler backdoor code from the classic "Reflections on Trusting Trust". An excellent writeup by @swtch.com - research.swtch.com/nih.

27.11.2024 09:17 โ€” ๐Ÿ‘ 9    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Interesting choice! Most, myself included, prefer Blindsight. Both are really good though, still waiting for the grand finale that will likely never come :)

25.11.2024 19:10 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :)
bsky.app/profile/jame...

25.11.2024 13:09 โ€” ๐Ÿ‘ 57    ๐Ÿ” 16    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

For posterity - nope, it does not :/

21.11.2024 22:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
a photo of a building at break of dawn, high contract, with bright windows.

a photo of a building at break of dawn, high contract, with bright windows.

1..2..3 testing testing. Does BlueSky support UltraHDR images?

21.11.2024 22:53 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
CVEs of SSH A talk about recent high-profile issues related to the SSH ecosystem.

We're doing a cool online talk tomorrow btw โ€“ hexarcana.ch/workshops/cv...

20.11.2024 19:11 โ€” ๐Ÿ‘ 21    ๐Ÿ” 8    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

You totally should rename it to Cevisshe :)

21.11.2024 08:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@webappsec.dev has go.bsky.app/Uf8dZhz, it's a good one.

21.11.2024 06:25 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

This hit close to home.

20.11.2024 04:29 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Exploring the DOMPurify library: Bypasses and Fixes. Tags:Article - Article - Web - mXSS Exploring the DOMPurify library: Bypasses and Fixes

Read this! Beautiful blog post, and so much to learn from it

mizu.re/post/explori...

15.11.2024 17:30 โ€” ๐Ÿ‘ 19    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Maybe, but that metric is not likely even correlated to 'most commonly exploited'.

18.11.2024 13:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Time to make some smart introductory websec post here, no? I guess all I have is:

Hello world, good bye XSS?

17.11.2024 12:38 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

not yet, no.

17.11.2024 12:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

bsky.app/profile/kkot... ? Half of who I follow are web security personas, you'll recognize most of them :)

17.11.2024 11:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here ๐Ÿ™‚
go.bsky.app/Uf8dZhz

17.11.2024 10:12 โ€” ๐Ÿ‘ 56    ๐Ÿ” 25    ๐Ÿ’ฌ 16    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Photos from a stroll through Atarazanas Food Market in #malaga - it turned out to be an extremely vibrant, colorful, lively place.

#photography

17.11.2024 10:45 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

If you're into web security take a look at my LocoMocoSec keynote slides from this summer about "Google's Recipe for Scaling (Web) Security": speakerdeck.com/lweichselbau...

16.11.2024 22:29 โ€” ๐Ÿ‘ 21    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@kkotowicz is following 20 prominent accounts