Sign in

jub0bs

@jub0bs.com
2.4K followers 276 following 469 posts

infosec enthusiast • Go dev & trainer • contributor to the Go project • minimalist • chaotic good • trying to make sense of the Web • he/him Blog: jub0bs.com Free Go course: github.com/jub0bs/go-course-beginner Free 🇵🇸! Leave 🇱🇧 alone!

PostsRepliesMedia
jub0bs @jub0bs.com · 28/09/2026
Perfloop, Tomás Senart's project, identified a subtle bug (due to an oversight about preflight on my part) in the CORS library I maintain for #golang. Pretty impressive! The latest release (v1.1.3) fixes the bug in question. github.com/jub0bs/cors/... perfloop.ai
perfloop.ai
Perfloop · The Performance Machine
Perfloop learns your system from code and telemetry, hunts a wide catalog of performance patterns, and delivers a stream of proven pull requests. Software that stays fast.
000
jub0bs @jub0bs.com · 17/09/2026
Happy 40th birthday, Elliot Alderson! 🎂 #MrRobot
011
jub0bs @jub0bs.com · 10/09/2026
Well deserved. Congrats!
020
Reposted by jub0bs
Phil Eaton @eatonphil.bsky.social · 24/07/2026
I wrote an article about Go's new Green Tea garbage collector. Paywall has expired, give it a read. theconsensus.dev/p/2026/07/19...
0396
jub0bs @jub0bs.com · 30/06/2026
If "JWT" is meant to be pronounced "jot", is "JWS" meant to be pronounced "jaws"? 🦈 www.rfc-editor.org/info/rfc7519...
rfc-editor.org
RFC 7519: JSON Web Token (JWT) | RFC Editor
JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON ...
040
jub0bs @jub0bs.com · 11/06/2026
Security-related libraries (for CORS, JWTs, etc.) should be designed to be, not only easy to use, but hard to misuse: - pentesterlab.com/blog/secure-... by @snyff.pentesterlab.com - jub0bs.com/posts/2023-0...
pentesterlab.com
How to Securely Design Your JWT Library - PentesterLab's Blog
This article explores best practices for designing a secure JWT library, focusing on making secure implementations the default and minimizing potential vulnerabilities. Key strategies include disablin...
030
jub0bs @jub0bs.com · 08/06/2026
😬
010
jub0bs @jub0bs.com · 22/05/2026
Régis n'était donc pas le seul à être un con...
000
jub0bs @jub0bs.com · 14/05/2026
Pas assez cher, mon fils.
120
jub0bs @jub0bs.com · 10/05/2026
Some breadcrumbs can be found in jub0bs.com/posts/2023-0...
jub0bs.com
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation)
TL;DR ¶ In this post, I investigate why developers struggle with CORS and I derive Fearless CORS, a design philosophy for better CORS middleware libraries, which comprises the following twelve princip...
000
jub0bs @jub0bs.com · 04/05/2026
h1 triage was never perfect, but IMO it's been getting worse and worse, no doubt due to a deluge of AI-fuelled reports but also an abuse of AI tools on the triage side and an exodus of qualified triagers.
050
jub0bs @jub0bs.com · 03/05/2026
What a fall from grace for HackerOne, once my favourite bug-bounty platform. 😬 "HackerOne triage analyst incorrectly closes the report as a duplicate [...]" clickup.com/blog/april-2...
clickup.com
April 27th - What happened with our feature flag configuration | The ClickUp Blog
On April 27, 2026, a security researcher publicly disclosed that ClickUp’s client-side feature flag configuration exposed personally identifiable information. Specifically, 893 customer email addresse...
191
jub0bs @jub0bs.com · 01/05/2026
v0.13.3 through v1.0.1 of github.com/jub0bs/cors contain an embarrassing bug that affects functionality (though not security). Thanks to Herman Slatman for reporting it. 🙇 The bug is fixed in v1.0.2. Update when you can.
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
020
jub0bs @jub0bs.com · 28/04/2026
I've just filed a #golang issue aiming to explicitly exclude error messages from the Go 1 compatibility promise: github.com/golang/go/is...
github.com
x/website: explicitly exclude error messages from the Go 1 compatibility promise · Issue #78991 · golang/go
The document that specifies the Go 1 compatibility promise ("go1compat" for short) lists a number of exclusions: Security. A security issue in the specification or implementation may come to light ...
050
Reposted by jub0bs
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
jub0bs @jub0bs.com · 27/04/2026
Fun fact: GitHub (at least last time I checked) tolerates arbitrary subdomains of an OAuth app's configured redirect_uri. If you can exploit a subdomain takeover on the target, you're golden.
020
Reposted by jub0bs
Ky @ky.fyi · 24/04/2026
I wrote about why I quit my job, and how weird and tiring tech feels these days.
ky.fyi
Do I belong in tech anymore?
On quitting, the spread of AI, and the loss of an ideal.
1281791545
jub0bs @jub0bs.com · 24/04/2026
If this issue was occurring in a server written in Go, consider migrating to github.com/jub0bs/cors for CORS stuff. 😇
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
000
Reposted by jub0bs
Marcus Hutchins @malwaretech.com · 21/04/2026
Shot: "We were hit by a sophisticated AI-accelerated cyberattack"
6679
jub0bs @jub0bs.com · 11/04/2026
Issue 596 of the Golang Weekly newsletter mentions the v1 release of github.com/jub0bs/cors. Nice! #golang golangweekly.com/issues/596
golangweekly.com
Golang Weekly Issue 596: April 10, 2026
#​596 — April 10, 2026
071
jub0bs @jub0bs.com · 11/04/2026
There are no benign data races. In fact, some are lethal. ☠️ en.wikipedia.org/wiki/Therac-25
en.wikipedia.org
Therac-25 - Wikipedia
The Therac-25 was a computer-controlled radiation therapy machine produced by Atomic Energy of Canada Limited (AECL) in 1982 after the Therac-6 (neptune) and Therac-20 units (the earlier units had been produced in partnership with Compagnie générale de radiologie (CGR) of France).[1]
000
Reposted by jub0bs
Go @golang.org · 07/04/2026
🥳 Go 1.26.2 and 1.25.9 are released! 🔐 Security: Includes 10 security fixes for the standard library and the toolchain. 📢 Announcement: groups.google.com/g/golang-announce… ⬇️ Download: go.dev/dl/#go1.26.2 #golang
$ go install golang.org/dl/go1.26.2@latest
$ go1.26.2 download
Downloaded   0.0% (       0 / 63701324 bytes) ...
Downloaded  50.0% (31850662 / 63701324 bytes) ...
Downloaded 100.0% (63701324 / 63701324 bytes)
Unpacking go1.26.2.linux-arm64.tar.gz ...
Success. You may now run 'go1.26.2'
$ go1.26.2 version
go version go1.26.2 linux/arm64
25813
jub0bs @jub0bs.com · 08/04/2026
Rumour has it that it hurts all over: jub0bs.com/posts/2023-0...
jub0bs.com
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation)
TL;DR ¶ In this post, I investigate why developers struggle with CORS and I derive Fearless CORS, a design philosophy for better CORS middleware libraries, which comprises the following twelve princip...
000
jub0bs @jub0bs.com · 07/04/2026
I obviously meant 1 << 9, not 1 >> 9. 😅
120
jub0bs @jub0bs.com · 07/04/2026
🎉 After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
2205
jub0bs @jub0bs.com · 31/03/2026
💯
000
jub0bs @jub0bs.com · 31/03/2026
Is that something you're considering enforcing in gofumpt?
100
jub0bs @jub0bs.com · 29/03/2026
Yes, as far as I understand. Tip is essentially a pre-release version of go1.(n+1), where n is the most recent stable major version of Go.
000
jub0bs @jub0bs.com · 27/03/2026
I too was surprised that such a small change had so much impact on performance. And one more thing: code readability also improved (IMO). 😇
010
jub0bs @jub0bs.com · 27/03/2026
When something tantalising gets merged at tip, you can put code that relies on it in a file guarded by a //go:build go1.27 build constraint and its pre-1.27 counterpart in a file guarded by a //go:build !go1.27 build constraint. No need to update your go.mod's go directive.
150
jub0bs @jub0bs.com · 27/03/2026
I love how the conjunction of #golang's modules system and build constraints lets you have your cake and eat it too! 🍰 You can let users of your library take advantage of the bleeding edge if they so wish without cutting off one of the currently supported Go toolchains.
190
jub0bs @jub0bs.com · 26/03/2026
Even when you cannot eliminate all bounds checks within a loop, eliminating most of them may benefit performance. 😉 #golang go-review.googlesource.com/c/go/+/759100
go-review.googlesource.com
Gerrit Code Review
1110
jub0bs @jub0bs.com · 25/03/2026
Unfortunately, this proposal would require a breaking change. Therefore, I've decided to retract it.
000
jub0bs @jub0bs.com · 23/03/2026
"Marin"? 😅
000
jub0bs @jub0bs.com · 23/03/2026
My point is that, as gc becomes better at BCE, the output of go build -gcflags '-d=ssa/check_bce/debug=1' <path-to-package> contains fewer false positives for reachable panics, which eases the attacker's task of identifying true positives due to incorrect indexing. Wouldn't you agree?
130
jub0bs @jub0bs.com · 23/03/2026
Paradoxically (perhaps), as the Go compiler becomes better at eliminating bounds checks, attacker-reachable panics due to incorrect programmer assumptions about indices become easier to find. #golang
140
jub0bs @jub0bs.com · 19/03/2026
Fewer bounds checks in #golang thanks to Youlin Feng: go-review.googlesource.com/c/go/+/719881
go-review.googlesource.com
Gerrit Code Review
030
jub0bs @jub0bs.com · 12/03/2026
Generic concrete methods may well land in Go 1.27! 🤩 go-review.googlesource.com/c/go/+/746820
go-review.googlesource.com
Gerrit Code Review
010
Reposted by jub0bs
Alan Donovan @adonovan.bsky.social · 11/03/2026
Find out how the source-level inliner in Go 1.26 can help you with API migrations. go.dev/blog/inliner
go.dev
//go:fix inline and the source-level inliner - The Go Programming Language
How Go 1.26's source-level inliner works, and how it can help you with self-service API migrations.
15513
jub0bs @jub0bs.com · 10/03/2026
"Open-source but closed for contributions" is the sweet spot for me. I like @honnef.co's take on this approach: github.com/dominikh/go-...
github.com
GitHub - dominikh/go-tools: Staticcheck - The advanced Go linter
Staticcheck - The advanced Go linter. Contribute to dominikh/go-tools development by creating an account on GitHub.
050
jub0bs @jub0bs.com · 09/03/2026
I've just filed a proposal to make bool an ordered type (compatible with operators <, <=, >, and >=) in #golang: github.com/golang/go/is...
github.com
proposal: spec: make bool an ordered type · Issue #78027 · golang/go
Go Programming Experience Experienced Other Languages Experience Python, Haskell, JavaScript, C Related Idea Has this idea, or one like it, been proposed before? Does this affect error handling? Is...
190
jub0bs @jub0bs.com · 02/03/2026
Fascinating! Thanks for sharing. 🙇
100
jub0bs @jub0bs.com · 02/03/2026
#golang quiz: What happens if you try to compile and run the following program? package main import ( "fmt" "math" ) func main() { fmt.Println(int(math.NaN())) } a. It prints 0. b. It prints -1. c. It panics. d. Compilation fails. e. Something else.
100
jub0bs @jub0bs.com · 02/03/2026
Besides, I welcomed support for ranging over ints. The gain in readability over a classic three-clause loop is real, as explained in the following comment: github.com/golang/go/is...
github.com
spec: add range over int, range over func · Issue #61405 · golang/go
Following discussion on #56413, I propose to add two new types that a for-range statement can range over: integers and functions. In the spec, the table that begins the section would have a few mor...
100
jub0bs @jub0bs.com · 02/03/2026
One source of complexity surrounding iterators, IMO, is when the iterator is designed as "impure", in the sense that even if the yield function you pass it is a pure function, consuming the iterator has side effects. A subtlety that can trip even seasoned Gophers up: github.com/golang/go/is...
github.com
cmd/compile: poor escape analysis of `strings.SplitSeq` · Issue #73524 · golang/go
Go version go version go1.24.2 linux/amd64 Output of go env in your module/workspace: AR='ar' CC='gcc' CGO_CFLAGS='-O2 -g' CGO_CPPFLAGS='' CGO_CXXFLAGS='-O2 -g' CGO_ENABLED='1' CGO_FFLAGS='-O2 -g' ...
010
jub0bs @jub0bs.com · 02/03/2026
Ranging over a channel too only yields (at most) a single value.
200
jub0bs @jub0bs.com · 02/03/2026
As a consumer of iterators, you're largely isolated from the complexity they deploy under the hood, esp. if those iterators are designed as pure functions. Things are different if you have to implement iterators yourself but, again, not prohibitively so, IMO.
100
jub0bs @jub0bs.com · 01/03/2026
Thanks! Yeah, and the kind of forward compatibility that error types unlocks in comparison to error values is appreciable as well.
000
jub0bs @jub0bs.com · 01/03/2026
Well, generics certainly made the language more complex, but not prohibitively so, IMO. I think Go's agenda of simplicity is as strong as ever.
100
jub0bs @jub0bs.com · 01/03/2026
A bit of a downer, this one, lads! 😅 At some stage of this episode, Kris wishes for some (official) guidance about error handling. The following take is far from official and comprehensive, but I'd love to hear your thoughts about it: jub0bs.com/posts/2025-0...
jub0bs.com
Why concrete error types are superior to sentinel errors
TL;DR ¶ Exported concrete error types are superior to sentinel errors. They can be more performant, cannot be clobbered, and promote extensibility. Third-party function errutil.Find is a powerful alte...
110