En3pY - Sebastian Zdrojewski

12 Followers
151 Following
724 Posts
I'm trying to find a place to stick around.
Some #cybersec experience, some #watchguard knowledge, mostly into anime and comics. #DigitalArt enthusiast, I kind of enjoy talking about #ethics and #technology
Director atRights Chaint Ltd.
Linkedinhttps://www.linkedin.com/in/sebastian-zdrojewski/
Companyhttps://www.rightschain.net/it/about.php
Contactshttps://rgts.ch/c/s.zdrojewski
@thor isn't there a setting that allows you to purge data older than "x" days? It seems to be working on our instances. Although, I think it's one of the problems of the fediverse: it tends to multiply every content on all instances as your subscribers follow federated accounts (which is good but comes with a cost)
the reason i don't host everything with Amazon or any other single cloud provider

The U.S. Securities and Exchange Commission, a federal agency responsible for overseeing stock exchanges, recently accused #SolarWinds, a U.S. company that develops software for companies aimed at helping them manage networks, systems and IT infrastructure.

The complaint, filed on Oct. 30, 2023, alleges that the company in question misled investors by lying about its #cybersecurity #practices and related known #vulnerabilities - the indictment includes a charge for #fraud and serious internal control failures.

More specifically, the complaint refers to a kind of cyber attack that lasted almost two years and was titled "SUNBURST": the latter features the company's chief information security officer, Timothy G. Brown, as well as the company itself.

https://www.rightschain.net/en/newsroom/news/2023-10-30-sec-charges-solarwinds-and-chief-information-security-officer-with-fraud-internal-control-failures-sec.php via @RightsChain

Meta’s new “consent” wall is scam that undermines the European Court of Justice’s ruling of July.
This deceptive design pushes the user to “consent” to unrestricted use of their data. That includes intimate data that Meta obtains by tracking the user on other websites and apps.
once upon a time in the 00s

#fridayrant! Happy friday everyone, and here's this week's rant.

Speaking with a friend and colleague who sends me systematically #CVEs and fresh of the day #exploits, we had an argument (always a pleasure to have one btw) about #data #validation and other #cybersecurity issues.

My exact comment for this CVE (a #rabbitmq code injection) was: "if you don't sanitize your input and pass it to your application based on belief, you deserve the #code #injection".

Seriously, let's make a clear statement: how many #APIs do sanitize their input data? One of the very best answers I ever got was "but the data is sanitized on the client side"

Well, spoiler alert: nope. That's not gonna happen.

This problem is nothing new, truly: it's something I've been discussing since the early 2000s (actually after one the very first applications I made was so badly injected I still remember it to this day).

There is no such thing as "client side data sanitization".
You control everything coming to your application.

There is no such thing as "the #framework automagically solves this issue". You either know it or not. And if you use a framework, you probably have a legacy issue. Or will have one.

At the end of the day, #data is your main #asset and it provides value to your business and decisions.

Businesses stopped developing #software to solve problems, and often it sounds like arguing about divinities or alchemy.

It's a tool, not a magic wand.
But "any sufficiently advanced technology is indistinguishable from magic". So... are you a developer, or a believer?

@vertana @Edent that is a good point :D
Sometimes marketing has absolutely no shame. Like when they advertise an event that is all about #sustainability and #generativeai: how are those two relates? Oh right, it's in #cloud, so you don't consume any power.

The Dutch public broadcast organization NPO ( (like a BBC or PBS) is now running its own mastodon instance with handles on its main domain!

Radio 1: @nporadio1

The instance itself is at https://social.npo.nl/

Nederlandse Publieke Omroep Mastodon

Welkom op de officiële Mastodon-server van de Nederlandse Publieke Omroep.

Mastodon hosted on npo.nl
@vertana @Edent once you get through the thought of a paid app (that is not a bad idea), the issue arises for the use of that specific social media.