112 Followers
269 Following
63 Posts

Security Architect | DevSecOps | DevOps
Constantly learning how to be a better leader

"When you know the rules well enough to break them, that is evidence of mastery"
#infosec #devsecops #devops #leadership #cybersecurity

If you use Obsidian, and especially if you use the new Canvas feature, you should update to the latest 1.1.9 release.

Last night I reported several security and privacy issues that have now been fixed.

See https://forum.obsidian.md/t/multiple-security-privacy-issues-in-canvas-malicious-website-can-access-internal-obsidian-uri/50400 for details.

Props to the Obsidian developers for the fast turnaround.

Multiple Security/Privacy Issues in Canvas (Malicious Website can access internal Obsidian URI)

Hi, In summary: a website card that loads a malicious website into a Canvas view can corrupt arbitrary vault documents, leak some privacy information, and spawn new internal URI calls and some external processes. Details: The new canvas feature allows remote websites to trigger internal obsidian URIs like open/new/search etc. both directly and through the x-success parameter. These URIs can be triggered by the website calling a meta refresh directive i.e<meta http-equiv="refresh" content="0;UR...

Obsidian Forum
Anytime someone announces they're "giving everyone 2 minutes back" at the end of a pointless meeting, it should trigger a vote with all participants to ban them from scheduling further meetings for a month

Don't forget the "Availability" side of the CIA triad, leverage that argument to improve the lives of your engineers. Working them long hours leads to mistakes and turnover, **which is a security issue**.

Security concerns get more attention and traction as a risk than human concerns, and we can use that to help humans.

I'm featured in David Bombal's latest video. Check it out to ace your next job interview, negotiate more money, learn top tips for job success in 2023, and how to protect yourself when reporting vulnerabilities. https://youtu.be/oz7NFc-qm7E
2023 Cybersecurity job advice: Ace your job interview and earn more.

YouTube
Something about me being on a conference call triggers my dog to "reject" her breakfast
Admin Assistants and Receptionists run the company and nobody realize it, doing everything you can to make them happy is truly the key to professional success. Bring them donuts and fix their issues like they have a C in their title
Go out of your way to get recognitions and 'props' on file for your high performers; they can be used as leverage when it's time to argue for merit increases for them
Has anyone else fallen down the personal knowledge management #PKM rabbit hole and actually found the end, or does this just keep going until I have a mental breakdown
#WednesdayAddams would make a great security engineer