Sign in

Audun Mo (he/him)

@audunmo.dev
36 followers 62 following 90 posts

I like helping people make safer software. #appsec #cloudsec

PostsRepliesMedia
Audun Mo (he/him) @audunmo.dev · 02/06/2026
Operator overloading is one of those "they were so concerned with whether or not they could, they never thought about if they should" situations
010
Audun Mo (he/him) @audunmo.dev · 05/05/2026
I learned about Docker ONBUILD the other day. You can sneak build instructions into downstream image builds. I think this is really scary, and it seems to be not very well understood I wrote about how it can be dangerous, and how to defend against those attacks www.o3c.no/knowledge/un...
o3c.no
Unmasking the Docker ONBUILD Supply Chain Attack Vector
Docker's ONBUILD directive is a feature designed to reduce boilerplate in downstream images. This article demonstrates how a compromised or malicious base image can exploit ONBUILD to intercept build-...
010
Audun Mo (he/him) @audunmo.dev · 04/04/2026
So github response to the recent TeamPCP hacks is good. I wonder if threat actors will be moving to compromise OCI images instead, as the mutability of tags in Docker presents a similar vulnerability as the mutable tags in git releases do
001
Audun Mo (he/him) @audunmo.dev · 15/03/2026
So like what are the best atproto / atmosphere apps? I'm aware of tangled, but that's about it
010
Audun Mo (he/him) @audunmo.dev · 10/03/2026
After configuring my @tangled.org knot, I've gotten kind of obsessed with the idea of self-hosting the entirety of my dev workflow. Next I'll be self-hosting a image registry I reckon, just for the hell of it. Imagine being free of the big-tech hegemonies in your hobbyprojects!
020
Audun Mo (he/him) @audunmo.dev · 08/03/2026
For open source projects, discord is great for quick chats and community building, but i don't think it's good as a hub for community info. in particular, the lack of discoverability is a problem imo. I can't stumble over a discord chat that happened last year, like i can with a gh issue
220
Audun Mo (he/him) @audunmo.dev · 08/03/2026
@tangled.org hey, the self-hosted knots section for ssh config seems to be down. I figured out my issue after a morning of trying random things. Kinda frustrating that I have to use my DID in the remote setup, as I never remember it. Can I set up an alias from audunmo.dev -> did on my knot?
100
Audun Mo (he/him) @audunmo.dev · 27/01/2026
Is Github Actions down again?
100
Audun Mo (he/him) @audunmo.dev · 05/01/2026
Mark Zuckerberg opens Emacs and writes some PHP -> the fates of Venezuela, and potentially Greenland, are uncertain. That's the butterfly effect for you
100
Audun Mo (he/him) @audunmo.dev · 15/12/2025
As much as I love the spirit and idea of DependencyTrack, I really dislike the implementation. The app is heavy on resource consumption, the API is clunky to use, and lack of token auth for automation feels ironic for a security focused project
100
Audun Mo (he/him) @audunmo.dev · 15/12/2025
I opened X to look at Elon Musk tweet. Do I hate myself? Why did I do that to myself?
000
Audun Mo (he/him) @audunmo.dev · 05/12/2025
What is h a p p e n i n g over at cloudflare. Down, again???
010
Audun Mo (he/him) @audunmo.dev · 12/11/2025
Damn, ECMAScript-like syntax and compiles to bash? Folks, I think I'm in love amber-lang.com
amber-lang.com
Amber The Programming Language
Amber The Programming Language
010
Audun Mo (he/him) @audunmo.dev · 16/10/2025
I'm thinking of forming dependency track. I think its promise could be delivered in a much simpler app. First thing is to combine the frontend and API to a single container. Second order of business would be to introduce OIDC based token auth for m2m
300
Reposted by Audun Mo (he/him)
Dr Keith Wilson 💭 @keithwilson.eu · 16/10/2025
Manifesto:
028153
Audun Mo (he/him) @audunmo.dev · 11/10/2025
Within sometime in the next five years, there will be a story of someone using an LLM like a GPS to navigate, and it will be hilarious
000
Audun Mo (he/him) @audunmo.dev · 06/10/2025
I have no earthly idea why the world landed on using SPDX over CycloneDX as its default. And I'm so sad about it
000
Audun Mo (he/him) @audunmo.dev · 02/10/2025
Today, Go's 1.25.1-bookworm image suddenly changed hash
210
Audun Mo (he/him) @audunmo.dev · 02/10/2025
The fact that tags are immutable on docker hub by default blows my mind.
000
Audun Mo (he/him) @audunmo.dev · 17/09/2025
At what point do we just classify the entirety of npm as a vulnerability, and just be done with it? Js needs a better standard library, and packages that can't randomly RCE your build pipeline if they feel like it
010
Audun Mo (he/him) @audunmo.dev · 01/07/2025
If you sell products that purport to shift left, but don't support IaC or other code-based config, the product is not doing that. UIs and click-ops invite reactive, right-end operations, and it's often a sign of other legacy thinking / approaches in your tools
000
Audun Mo (he/him) @audunmo.dev · 24/06/2025
Pushing ads on a service, then making a subscription to not have ads, is not a feature. It's not a product. And if it's the best you can think of, your company produces nothing
000
Audun Mo (he/him) @audunmo.dev · 16/06/2025
Linkedins algorithm for what to create notifications for needs to be studied. I don't think I've seen an algo less able to find relevant information
000
Audun Mo (he/him) @audunmo.dev · 12/06/2025
Bad features cause security risks, like bad road layouts lead to accidents. Case in point, github notifications. Filtering out the noise is so hard that I find drawn to separate apps to handle them. I don't because of the risk, but the avalanche ushers me in their direction
000
Audun Mo (he/him) @audunmo.dev · 12/06/2025
A long time ago, I saw a thing about programmers on dating apps who make themselves out to be much more important than they are. "Calm down, Brad. You're making computers go beep boop correctly" is still one of my favorite take down of anyone online
000
Audun Mo (he/him) @audunmo.dev · 01/05/2025
I thought to myself "the clock is just Thursday". In other words, my friend's 5 day bachelor party is going well
000
Audun Mo (he/him) @audunmo.dev · 28/04/2025
Note to anyone creating a scripting or rule or whatever language. Do not design your language so that comparison happens with =. Always assign with = and compare with ==. Otherwise all code produced in your language will be bad. And if = does both, you do not deserve good things in your life
000
Audun Mo (he/him) @audunmo.dev · 10/04/2025
It is 2025. Stop sending "hi" on slack. Just say the thing you want or need right away
100
Audun Mo (he/him) @audunmo.dev · 08/04/2025
I think "don't meet your heros" also applies to looking at your heros Twitter account
000
Audun Mo (he/him) @audunmo.dev · 08/04/2025
If it computes, someone has already installed doom on one
000
Audun Mo (he/him) @audunmo.dev · 08/04/2025
Contender for best feeling ever 🧹🧹🧹
020
Audun Mo (he/him) @audunmo.dev · 02/04/2025
Does anyone know how renovate or dependabot handles a git release tag being moved to a new commit for github actions when you've pinned your workflow to commits? Do they create new update PRs to reflect the new commit? Or do they stay on the existing pinned commit?
000
Reposted by Audun Mo (he/him)
BleepingComputer @bleepingcomputer.com · 20/03/2025
The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it, with it estimated that only 218 repositories exposed secrets due to the supply chain attack.
bleepingcomputer.com
GitHub Action supply chain attack exposed secrets in 218 repos
The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it, with it estimated that only 218 repositories exposed secrets due to the supply chain attack.
022
Audun Mo (he/him) @audunmo.dev · 20/03/2025
🧵Ref tj-actions attack. I wonder, would it be possible to retrofit a lockfile system on top of github actions?
800
Audun Mo (he/him) @audunmo.dev · 20/03/2025
Is there any way to generate an SBOM that describes github actions and their transitive dependencies? Ref tj-actions. I feel like this should be a thing
011
Audun Mo (he/him) @audunmo.dev · 20/03/2025
The cookie banners on websites should be re-implemented as native buttons in the UI of my browser, with the option of auto-rejecting all non-essential cookies forever. There shouldn't be a million different modals with different language and layout
000
Audun Mo (he/him) @audunmo.dev · 06/03/2025
I'm not in the java ecosystem. Has the {x}4j branding suffered at all? Because whenever I hear, for example neo4j, I immediately think of log4j and log4shell
000
Audun Mo (he/him) @audunmo.dev · 01/03/2025
If you're trying to pitch to devs, drop the fucking buzzwords. At the very least know what the words actually mean. I see so many people who are new to the field who slap so much bullshit lingo onto their HN/Reddit post, and it just all falls apart under a tiny bit of scrutiny. All credibility gone
000
Audun Mo (he/him) @audunmo.dev · 28/02/2025
Is it just me or does Lindsey Graham look drunk?
020
Audun Mo (he/him) @audunmo.dev · 24/02/2025
Writing a terraform provider is a purely spite-fueled exercise. You're just sitting there cursing at some half-baked API for a product your company is paying a bajillion for, stunned that they didn't ship basic IaC. In totally unrelated news, my favorite slack emoji is :no-google:
000
Audun Mo (he/him) @audunmo.dev · 24/02/2025
This plays in my head the moment I search up Bluesky on my phone youtu.be/aQUlA8Hcv4s?...
youtu.be
Electric Light Orchestra - Mr. Blue Sky (Official Video)
YouTube video by ELOVEVO
010
Audun Mo (he/him) @audunmo.dev · 18/02/2025
Also, does anyone have any experience with running ClusterFuzz? How much is the overhead to run it, and how much does the compute cost?
000
Audun Mo (he/him) @audunmo.dev · 18/02/2025
I wonder.. Could one easily take something like github.com/getkin/kin-o... and use it as a base to fuzz Go APIs with go's built-in fuzzer? 🤔
github.com
GitHub - getkin/kin-openapi: OpenAPI 3.0 (and Swagger v2) implementation for Go (parsing, converting, validation, and more)
OpenAPI 3.0 (and Swagger v2) implementation for Go (parsing, converting, validation, and more) - getkin/kin-openapi
100
Audun Mo (he/him) @audunmo.dev · 12/02/2025
I've become so annoyed at vendors for not shipping IaC that I've just begun learning to write tf providers myself. Like they almost always ship and API to manage resources, but just forget to make it useful
000
Reposted by Audun Mo (he/him)
Anthony Fu @antfu.me · 07/01/2025
Proposing an extended SemVer - 🗿 Epoch Semantic Versioning to communicate better about versions. Thinking of adopting this to all my projects, and finally eliminating my lousy habit of forever zero-major practice 😜 What do you think? 👀 antfu.me/posts/epoch-...
antfu.me
Epoch Semantic Versioning
Proposal for an extended Semantic Versioning called Epoch SemVer to provide more granular versioning information to users.
3823537
Audun Mo (he/him) @audunmo.dev · 06/02/2025
Is my system borked, or is docker hub down? Getting only 500s
322
Audun Mo (he/him) @audunmo.dev · 04/02/2025
Possibly hot take: the standard lib and tooling for Go is the reason to use it, way more so than the concurrency primitives
100
Audun Mo (he/him) @audunmo.dev · 16/01/2025
Don’t submit low effort automated bug reports for nothing and then do this
000
Audun Mo (he/him) @audunmo.dev · 01/01/2025
I'm unsure if I'm now old enough to be the target for 2000s nostalgia bait, or if the things I liked as a teen are now getting retro cool. In either case, I'm happy about the return of nu metal 🤘 open.spotify.com/track/2PcaKo...
open.spotify.com
the cost of giving up
Poppy · Negative Spaces · Song · 2024
000
Audun Mo (he/him) @audunmo.dev · 30/12/2024
Dear bug bounty hunters. I know you mean well. But please, make sure you actually demonstrate impact of a vuln. I'm so exhausted by all these emails of absolute nothing-burgers
000