Toots for neilmadden@infosec.exchange account

Written by Neil Madden on 2025-02-01 at 23:48

The irony of nepo-babies like Trump and Musk worrying that some people may not be in their jobs by merit is off the scale.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-31 at 08:41

Over my 25+ years of professional software experience, one thing has remained a constant: discussions of programming languages are almost entirely driven by emotional attachment. Programmers, like all other humans, are an emotional bunch. Although we like to think we make decisions based on cold technical facts, in reality programming languages that do well are those that make their users feel good about themselves and their current level of experience.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-28 at 08:33

Attending mandatory “values and culture” training be like

https://youtu.be/W2firijxQOo?si=tBlET_YdClivgq8K

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-27 at 07:50

Downloaded a sample of “Clean Architecture” by Mad Uncle Bob, and boy is it funny!

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-24 at 20:19

Confidentiality is secrecy in a suit and tie.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-23 at 11:13

Prioritisation is for things you’re actually going to fix.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-23 at 09:22

And now @PhilippeDeRyck breaking #oauth #NDCSecurity

=> View attached media

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-23 at 08:06

Kicking off the morning session at #NDCSecurity with Scott Helme talking cryptojacking.

=> View attached media

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-22 at 18:28

Also watched a very good talk from @ladynerd at #NDCSecurity today on actually using the data in your GitHub org to find security risks. https://safestack.io looks interesting too.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-22 at 13:04

Excellent talk from Kim Wuyts at #NDCSecurity about privacy engineering.

=> View attached media

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-22 at 12:34

America is definitely starting to grate again.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-21 at 15:20

British Airways seem somehow surprised that a flight to a scandanavian country may contain a lot of people too tall fit in child-like seats. I think half of us will be standing in the isles after take off.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-21 at 13:15

On my way to #NDCSecurity Oslo. Should be fun!

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-20 at 18:27

The democratisation of democracy.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-20 at 18:26

Starting a GoFundMe to setup an actual Deep (Welfare) State.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-20 at 14:50

Thanks for everyone that replied. I’m giving Kagi a go now. So far, I’m cautiously optimistic. It’s surfacing some good pages for searches I’ve tried so far. https://infosec.exchange/@neilmadden/113855765125050760

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-19 at 15:38

I’m finding DuckDuckGo increasingly frustrating. What search engine are the cool kids using now? Or are they all drowning in SEO rubbish and sponsored results now?

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-17 at 09:43

The PCI-DSS spec requires that card numbers (PANs) are hashed with a "keyed hash" to render them unreadable and suggests HMAC, CMAC or GMAC. Putting aside issues of nonce reuse in GMAC, surely you at least want the hash to be a PRF for this usecase? GMAC seems like such a weird choice here, especially as PANs are short, so GMAC is unlikely to have much of a speed advantage.

[#]cryptography #pci

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-14 at 11:13

Introducing CVSSWSSOP: CVSS with some sense of perspective.

Essentially you just calculate CVSS as normal, then you multiply the score by the fraction of the world’s total population that might realistically be impacted by it.

=> More informations about this toot | View the thread

Written by Neil Madden on 2025-01-13 at 16:12

Ah, apparently the correct way now is to git clone directly into GOPATH. Fine, that works. Still annoying that go microservices have to be treated differently to everything else.

=> More informations about this toot | View the thread

=> This profile with reblog | Go to neilmadden@infosec.exchange account

Proxy Information
Original URL
gemini://mastogem.picasoft.net/profile/109364888964287526
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
364.480119 milliseconds
Gemini-to-HTML Time
5.413292 milliseconds

This content has been proxied by September (3851b).