MFA will be requiered by default for OWASP ASVS Level 2. And so will device-bound passkeys/eIDAS-LoA3/NIST-AAL3 for ASVS Level 3.
If your app don’t, you better have a really good reason for it or take it off the internet.
github.com/OWASP/ASVS/b...
08.05.2025 18:26 — 👍 13 🔁 5 💬 0 📌 1
Oder ein Jodeldiplom. Da macht man auch mal was für sich. 😀
31.03.2025 10:37 — 👍 2 🔁 0 💬 0 📌 0
State of Threat Modeling (SOTM) 2024 Survey
Welcome to the first-ever State of Threat Modeling (SOTM) Survey!
What is the SOTM Survey?
The SOTM Survey is part of the research for the first community-driven State of Threat Modeling (SOTM) Repor...
The Threat Modeling Connect community are launching the first-ever community-driven State of Threat Modeling (SOTM) Report, led by @rewtd.bsky.social
and Dave Soldera, and we’d love your input!
docs.google.com/forms/d/e/1F...
The survey will take 15-20 minutes to complete.
#cybersec #infosec
14.03.2025 09:20 — 👍 21 🔁 15 💬 0 📌 0
Lass mich raten: Viele Finanzinstitute? Könnte von DORA kommen. Dann geht es vermutlich um den potentiellen Umstieg von einem Anbieter zu einem anderen und nicht um "raus aus der Cloud".
13.03.2025 08:09 — 👍 0 🔁 0 💬 0 📌 0
Das klingt alles so absurd nach Verschwörungstheorie. Würden sich der Typ und seine Kumpels nicht seit Jahren öffentlich dokumentiert dazu äußern, ich würde kein Wort glauben.
03.03.2025 08:26 — 👍 2 🔁 0 💬 0 📌 0
"führen zum mutmaßlichen Anführer. Sie erzählen die aberwitzige Story seiner Flucht vor dem Gesetz."
03.03.2025 08:13 — 👍 4 🔁 1 💬 0 📌 0
Trump kündigt KI-Sicherheit auf, stoppt Umweltschutz und Infrastruktur
Der neue US-Präsident macht dutzende Erlässe seines Vorgängers rückgängig und bremst so Innovation. Also braucht es mehr Energie, die Öl und Gas bringen sollen.
Trump kündigt #KI-Sicherheit auf, stoppt #Umweltschutz und #Infrastruktur
"Der neue US-Präsident macht dutzende Erlässe seines Vorgängers rückgängig und bremst so Innovation. Also braucht es mehr Energie, die Öl und Gas bringen sollen." www.heise.de/news/Trump-k...
21.01.2025 06:18 — 👍 13 🔁 4 💬 0 📌 0
You seem to take the conversation serious. That's ok.
This has been discussed a lot and led to NIST recommending not to change anymore. Bottom line: changing leads to bad passwords and also you never know when a password is compromised. So you would need to change it every day.
08.01.2025 08:45 — 👍 4 🔁 0 💬 1 📌 0
Or with the words from Garth in Wayne's World: "It's like a new pair of underwear: At first, it's constrictive, but after a while it becomes a part of you."
08.01.2025 08:42 — 👍 1 🔁 0 💬 0 📌 0
When shit goes down?
08.01.2025 08:40 — 👍 0 🔁 0 💬 1 📌 0
The other day I found my son browsing the internet. To my horror he was browsing various forums on the dark web.
„What the hell are you doing??!“ I asked.
„I forgot my password, so I am trying to find it“, he replied.
31.12.2024 11:51 — 👍 49 🔁 5 💬 5 📌 1
:-(
Das ist ja furchtbar. Ich wünsche allen Freunden und der Familie viel Kraft
08.12.2024 07:26 — 👍 1 🔁 0 💬 0 📌 0
Da war wohl einer besoffen. Oder zwei.
28.04.2024 11:09 — 👍 1 🔁 0 💬 0 📌 0
8-bit-old guy. Tech, Security, Politics, Metal, Electro, Games. Not necessarily in this order.
🔥 Loves to talk about privacy and threat modeling
💡 LINDDUN privacy threat modeling
✨ Privacy engineer
👩💼 Manager Cyber & Privacy
I accidentally became the CISO. I didn't want this job, but the job chose me. I'm scared, and I want to go home.
https://www.accidentalciso.net
Project leader #OWASP #WrongSecrets, dad, PSA
Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE.
Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack
Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository https://github.com/OWASP/cornucopia and give us a star ⭐
🌈 «Difference is of the essence of humanity» 🦄 – John Hume
#appsec #owasp #cornucopia #threatmodeling
20yrs Sec @CCC, @GeraffelV @cbase @loadev @AG_KRITIS @CSCBonn, #AGND #hacking #Ethik #KRITIS #Cyberresilienz, working at @HiSolutions http://Threema.id/X9H873XJ
Mastodon: @HonkHase@chaos.social
LinkedIn: www.linkedin.com/in/manuel-honkhase-atug-820b27241
IR Scholar. Universität der Bundeswehr München. Private account
IT Fetischist mit einer Affinität für Schokobons | Cyber Security|#OSINT
https://linktr.ee/Nella_allami
Joachim Telgenbüscher (Historiker, Journalist, Radfahrer, Nerd)
Focus. Result. Scaling. Ein neues digitales Produkt entwickeln, alte Systeme modernisieren, IT skalieren oder Daten für AI vorbereiten: Mit uns!
Co-founder and CEO, Freeman & Forrest.
Bestselling author of DevOps for Dummies and international keynote speaker. I’ve led Community, DevRel and Product Marketing at AWS, MSFT, and startups.
I was editingemily on Twitter.
Automated announcements of releases on media.ccc.de - For contact please use @c3voc@chaos.social or E-Mail
Relay Tracking News & Blogs about infosec, cybersec
- source removal/addition suggestions welcome !
CVE : check out @cve.skyfleet.blue
🆘 @skyfleet.blue
2nd Sight Lab. Cloud, SAAS, and App Pentesting. Security Research. AWS Security Hero . Author on Amazon. Former IANS, SANS faculty. GSE. Masters Software & Infosec.
Join the OSINT Ambition community and take your investigative skills to the next level! We share expert tips, tools, and insights on OSINT.
https://osintconference.com/
https://osintupdates.com/
https://osinttools.io/
Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her
https://shehackspurple.ca 🌻
Full Stack #CEO, #Founder @JSKongress 🦏 , @geekspace9 🤓 #scaling, 🔨🚒🐦 👉