En3pY - Sebastian Zdrojewski

12 Followers
151 Following
724 Posts
I'm trying to find a place to stick around.
Some #cybersec experience, some #watchguard knowledge, mostly into anime and comics. #DigitalArt enthusiast, I kind of enjoy talking about #ethics and #technology
Director atRights Chaint Ltd.
Linkedinhttps://www.linkedin.com/in/sebastian-zdrojewski/
Companyhttps://www.rightschain.net/it/about.php
Contactshttps://rgts.ch/c/s.zdrojewski
the reason i don't host everything with Amazon or any other single cloud provider

The U.S. Securities and Exchange Commission, a federal agency responsible for overseeing stock exchanges, recently accused #SolarWinds, a U.S. company that develops software for companies aimed at helping them manage networks, systems and IT infrastructure.

The complaint, filed on Oct. 30, 2023, alleges that the company in question misled investors by lying about its #cybersecurity #practices and related known #vulnerabilities - the indictment includes a charge for #fraud and serious internal control failures.

More specifically, the complaint refers to a kind of cyber attack that lasted almost two years and was titled "SUNBURST": the latter features the company's chief information security officer, Timothy G. Brown, as well as the company itself.

https://www.rightschain.net/en/newsroom/news/2023-10-30-sec-charges-solarwinds-and-chief-information-security-officer-with-fraud-internal-control-failures-sec.php via @RightsChain

Meta’s new “consent” wall is scam that undermines the European Court of Justice’s ruling of July.
This deceptive design pushes the user to “consent” to unrestricted use of their data. That includes intimate data that Meta obtains by tracking the user on other websites and apps.
once upon a time in the 00s

#fridayrant! Happy friday everyone, and here's this week's rant.

Speaking with a friend and colleague who sends me systematically #CVEs and fresh of the day #exploits, we had an argument (always a pleasure to have one btw) about #data #validation and other #cybersecurity issues.

My exact comment for this CVE (a #rabbitmq code injection) was: "if you don't sanitize your input and pass it to your application based on belief, you deserve the #code #injection".

Seriously, let's make a clear statement: how many #APIs do sanitize their input data? One of the very best answers I ever got was "but the data is sanitized on the client side"

Well, spoiler alert: nope. That's not gonna happen.

This problem is nothing new, truly: it's something I've been discussing since the early 2000s (actually after one the very first applications I made was so badly injected I still remember it to this day).

There is no such thing as "client side data sanitization".
You control everything coming to your application.

There is no such thing as "the #framework automagically solves this issue". You either know it or not. And if you use a framework, you probably have a legacy issue. Or will have one.

At the end of the day, #data is your main #asset and it provides value to your business and decisions.

Businesses stopped developing #software to solve problems, and often it sounds like arguing about divinities or alchemy.

It's a tool, not a magic wand.
But "any sufficiently advanced technology is indistinguishable from magic". So... are you a developer, or a believer?

Sometimes marketing has absolutely no shame. Like when they advertise an event that is all about #sustainability and #generativeai: how are those two relates? Oh right, it's in #cloud, so you don't consume any power.

The Dutch public broadcast organization NPO ( (like a BBC or PBS) is now running its own mastodon instance with handles on its main domain!

Radio 1: @nporadio1

The instance itself is at https://social.npo.nl/

Nederlandse Publieke Omroep Mastodon

Welkom op de officiële Mastodon-server van de Nederlandse Publieke Omroep.

Mastodon hosted on npo.nl

During the last 24 hours, OpenAI has been addressing what it describes as "periodic outages" linked to DDoS attacks affecting its API and ChatGPT services.

https://www.bleepingcomputer.com/news/security/openai-confirms-ddos-attacks-behind-ongoing-chatgpt-outages/

OpenAI confirms DDoS attacks behind ongoing ChatGPT outages

During the last 24 hours, OpenAI has been addressing what it describes as "periodic outages" linked to DDoS attacks affecting its API and ChatGPT services.

BleepingComputer
Come non parlare di stupro in televisione: Avanti Popolo e l’intervista di Nunzia de Girolamo
https://www.valigiablu.it/nunzia-de-girolamo-asia-avanti-popolo-stupro/
Avanti Popolo: l'intervista di Nunzia de Girolamo ad Asia

L'intervista di Nunzia de Girolamo ad Asia, la donna che ha denunciato di aver subito uno stupro di gruppo da parte di sette coetanei lo scorso luglio.

Valigia Blu
Plutopia interview with Cory Doctorow (@pluralistic), who has a problem with corporate bullies. In his latest book, THE INTERNET CON: HOW TO SEIZE THE MEANS OF COMPUTATION, Cory details how monopolies have taken control of much of the tech sector and are unlikely to give it back without a fight. "The best time to have prevented monopolies was 40 years ago but the second best time is now..." https://plutopia.io/cory-doctorow-the-internet-con/
Cory Doctorow: The Internet Con - Plutopia News Network

Cory Doctorow details how monopolies have taken control of much of the tech sector and are unlikely to give it back without a fight.

Plutopia News Network